64 professional files (6 PDFs + 58 Excel workbooks) | 349+ spreadsheet tabs | 2,730+ rows of structured content | 11 organised folders
Third-party risk management has moved from an annual questionnaire exercise to a continuous operational discipline. Regulators, customers, and incident data all push in the same direction: know your critical vendors, monitor them properly, and act when their risk changes. A structured programme turns third-party risk from an audit finding into a source of resilience.
WHAT YOU GET: A THREE-PHASE JOURNEY
Phase 1: Diagnose. Seven domain assessments (30 questions each, 210 total) score your maturity across Process Strategy, Risk Classification, Due Diligence Procedures, and related areas. You can complete the Quick Scan diagnostic in under an hour and know exactly where the biggest gaps and opportunities sit.
Phase 2: Set Goals. Five PM template workbooks with roadmaps, RACI matrices, milestone trackers, risk registers, and stakeholder communication plans. These lock in scope, timeline, and accountability before a single line of implementation work starts, which is consistently where programmes succeed or stall.
Phase 3: Implement. Nine operational runbooks and checklists covering deployment, incident response, vendor and third-party handling, and day-to-day operations. Every runbook is built to be followed by a working team, not read and filed. Pro tips, example rows, and common-mistake callouts give you the benefit of hard-won practitioner experience from the first day.
7 DOMAIN ASSESSMENTS (210 QUESTIONS)
• Process Strategy
• Risk Classification
• Due Diligence Procedures
• Contractual Governance
• Continuous Monitoring
• Incident Response Coordination
• Compliance Framework Alignment
9 OPERATIONAL RUNBOOKS
• Continuous Monitoring Operations Checklist
• Contractual Obligations Tracking Register
• CrossDomain Integration Checklist
• Security Control Validation Checklist
• ThirdParty DueDiligence Runbook
• ThirdParty Incident Response Playbook
• ThirdParty Security Awareness Task Guide
• Vendor Handoff Protocol Template
• Vendor Onboarding Checklist
The full kit also includes a practitioner-grade library of PM forms spanning all five PMBOK process groups, KPI dashboards, risk and compliance registers, and reference cards. Every template comes pre-populated with domain-specific example data so your team can start editing, not staring at blank rows. You get a consistent operating system across diagnostic, planning, delivery, and sustainment, which is how mature programmes compound improvement year over year.
WHO THIS IS FOR: Programme leaders, practice heads, senior consultants, and delivery teams accountable for outcomes in this discipline.
Aligned with leading industry standards and PMBOK project management practice.
Instant download. Start your first assessment within the hour.
Got a question about the product? Email us at support@flevy.com or ask the author directly by using the "Ask the Author a Question" form. If you cannot view the preview above this document description, go here to view the large preview instead.
Source: Best Practices in Vendor Management Excel: TPSGOS Aligned Third-Party Security Governance Playbook Excel (XLSX) Spreadsheet, Gerard Blokdijk
|
Receive our FREE presentation on Operational Excellence
This 50-slide presentation provides a high-level introduction to the 4 Building Blocks of Operational Excellence. Achieving OpEx requires the implementation of a Business Execution System that integrates these 4 building blocks. |