A proportionate third-party risk system: decide how much diligence a supplier warrants before you run any, then run the right depth for that tier.
Most third-party risk programmes fail the same way – they apply deep diligence to everything, exhaust the team, and quietly stop. The tiering model solves that by scoring suppliers on data access, operational criticality, regulatory exposure and substitutability, and assigning a proportionate assessment path.
WHAT IS INCLUDED
• TPRM Tiering Model (Excel) – scored tiering with an assessment path per tier.
• Supplier Security Questionnaire (Excel) – scaled by tier, not one questionnaire for everyone.
• DPA Requirements Checklist (Word) – what a data processing agreement has to contain.
• MSA Clause Checklist (Word) – the commercial read of a master agreement, before legal review.
• Contract Stack Map (PowerPoint) – order of precedence, explained so a stakeholder understands why the SOW does not override the MSA.
• Exit and Transition Clause Set (Word) – negotiable at signature, unobtainable afterwards.
• SLA and Service Credit Designer (Excel) – service levels with a measurement method, not just a target.
IMPORTANT
This is educational and commercial material, not legal advice. It exists so you can identify what matters commercially and ask better questions of your own legal adviser. Contract law and data protection obligations vary by jurisdiction.
WHAT YOU RECEIVE
The primary document is a 10-slide guide covering the material above, in the same consulting layout used throughout this series: a headline that states the point, a body that evidences it, and a closing line that tells you what to do with it. It is designed to be read on its own or presented internally.
The accompanying archive contains 7 working files – Excel models with live formulas, Word templates and, where relevant, PowerPoint canvases. Nothing is password-protected or locked. A locked template a professional cannot adapt is worth nothing.
HOW THE SPREADSHEETS ARE BUILT
Every workbook uses the standard financial-modelling colour convention, applied consistently: blue text on a pale yellow fill is an input you type over, black text is a formula you should not overwrite, and green text is a reference to another sheet that must be changed at source. Each model carries one worked example row, shaded and italicised, which you delete once your own data is in, and an assumptions block at the top that should be read before any output below it is trusted. Print areas and page setup are configured on every sheet.
WHAT THIS IS NOT
This is educational and commercial material, not legal, tax or financial advice. Contractual content exists so that you can identify what matters commercially and ask better questions of whoever does advise you; contract law and regulatory obligations vary by jurisdiction. All case material is composite – figures are drawn from real engagements, but no case describes a single identifiable organisation and every company name is invented.
A licence page inside each file sets out the terms of use: unrestricted use for your own work and inside your own organisation, no resale or redistribution outside it.
Got a question about the product? Email us at support@flevy.com or ask the author directly by using the "Ask the Author a Question" form. If you cannot view the preview above this document description, go here to view the large preview instead.
Source: Best Practices in Vendor Management PowerPoint Slides: Third-Party Risk Management and Contracting Toolkit PowerPoint (PPTX) Presentation Slide Deck, Davide Sferrazza
|
Receive our FREE presentation on Operational Excellence
This 50-slide presentation provides a high-level introduction to the 4 Building Blocks of Operational Excellence. Achieving OpEx requires the implementation of a Business Execution System that integrates these 4 building blocks. |