Why TPRM is now a board-level obligation
Optus, Medibank, HWL Ebsworth, Latitude and MediSecure all exposed weaknesses in supplier or partner controls, not just internal controls. APRA CPS 230 (effective 1 July 2025) now requires regulated entities to manage material service providers as a board responsibility. The SOCI Act adds responsibility for material service providers supporting critical infrastructure. The Privacy Act reform raises the cost of any breach traceable to a third party.
The TPRM lifecycle
Five lifecycle stages
- Identify. Maintain a single vendor register, including fourth parties for Tier 1 providers.
- Tier. Classify by data sensitivity, system criticality and concentration risk — not by spend.
- Assess. Due diligence proportional to tier: SIG/CAIQ for Tier 1, condensed for Tier 2.
- Monitor. Continuous attack-surface, certification expiry and incident-feed monitoring for Tier 1.
- Offboard. Evidence data return/destruction, access revocation and contractual closure.
Mapping TPRM to Australian frameworks
- APRA CPS 230 / CPS 234 — material service-provider register, board accountability, incident reporting flow.
- SOCI Act + CIRMP — material supplier identification for critical infrastructure entities.
- ISO 27001:2022 A.5.19–A.5.23 — supplier relationships, contractual security, cloud services.
- ACSC Essential Eight — vendors with privileged access included in your maturity scoring.
- OAIC NDB scheme — third-party breaches involving personal information still trigger your notification clock.
Tiering vendors that actually scales
Tier on data sensitivity, system criticality and concentration risk — not on contract value. Tier 1 vendors (touching critical operations, sensitive personal data, or high concentration) get full due diligence and continuous monitoring. Tier 2 get a condensed assessment and annual attestation. Tier 3 get a self-attestation. Document the rule, not the verdict — auditors challenge inconsistent tiering far more often than they challenge any single rating.
FOR VENDOR RISK OWNERS
Run vendor decisions through framework-anchored options.
FORTE/CYBERx generates three ranked strategic options and a tactical plan for vendor consolidation, supply-chain risk and concentration trade-offs — defensible to your board, your CRO and your APRA assessor.
Start a free missionDue-diligence question set
- Where is data stored, processed and backed up — and under whose sovereignty?
- What independent assurance exists (ISO 27001, IRAP, SOC 2 Type II) and when does it expire?
- What is the incident notification SLA back to us — and has it been rehearsed?
- Who are the sub-processors / fourth parties, and how are they assured?
- What is the exit and data-destruction commitment, and is it contractually enforceable?
Continuous monitoring and concentration risk
Point-in-time assessments age fast. Tier 1 vendors warrant attack-surface monitoring, certification-expiry alerts and threat-intelligence feeds. Track concentration risk explicitly: more than one critical operation depending on a single cloud, payments processor or managed service is a board-reportable exposure under CPS 230.
How AI decision support accelerates vendor risk decisions
The hard part of TPRM is not collecting evidence — it is making defensible trade-offs (consolidate vs diversify, in-source vs outsource, terminate vs remediate). FORTE/CYBERx structures each decision into three ranked options with confidence ratings and a tactical plan mapped to CPS 230, CPS 234, SOCI and ISO 27001 — and keeps a defensible decision record.
FAQ
What is third-party risk management (TPRM)?
TPRM is the discipline of identifying, assessing, monitoring and offboarding the risks introduced by vendors, suppliers, contractors and service providers that handle your data, systems or critical operations. In Australia it intersects with APRA CPS 230, CPS 234, the SOCI Act, ISO 27001:2022 (controls A.5.19–A.5.23) and the Privacy Act.
Why is TPRM important in Australia right now?
Several of the most material Australian incidents — Optus, Medibank, HWL Ebsworth, Latitude and MediSecure — exposed weaknesses in supply-chain assurance, not just internal controls. APRA, OAIC, ASIC and the Cyber and Infrastructure Security Centre have all sharpened expectations on third-party risk evidencing.
How does TPRM relate to APRA CPS 230?
CPS 230 (effective 1 July 2025) requires APRA-regulated entities to identify their critical operations, manage material service providers and maintain a register. CPS 234 already required information security obligations to flow through to providers. Together they make supply-chain assurance a board-level obligation, not a procurement task.
How do you tier vendors?
Most Australian programs use three tiers based on data sensitivity, system criticality and concentration risk. Tier 1 vendors (those touching critical operations or sensitive personal data) get full due diligence, contractual security schedules and continuous monitoring. Tier 2 get periodic assurance. Tier 3 get a lightweight self-attestation.