Supply Chain & Third-Party Risk Management (TPRM)
We look through your vendors to their vendors — surfacing concentration risk, contractual gaps and the exit routes you have never tested.
Your resilience is capped by your weakest critical supplier. We build a tiered third-party register mapped to your important business services, audit the vendors that matter, quantify concentration exposure across cloud and logistics, and develop exit and substitution strategies that can actually be executed under duress.
Vendor auditing, concentration tracking and cloud exit strategy
From onboarding due diligence through to stressed exit: we test whether a critical provider can be replaced, in what timeframe, at what cost, and whether your contracts give you the rights to do it.
- Critical and important third-party identification tiered against your IBS
- Vendor resilience audits, site visits and control attestation review
- Concentration risk tracking across cloud, connectivity, logistics and payments
- Fourth-party and sub-outsourcing visibility down the chain
- Cloud and critical-service exit strategy design plus stressed-exit testing
- Contractual resilience clauses, SLAs and regulatory register maintenance
Tiered third-party and fourth-party register
Vendor resilience audit reports and remediation plans
Concentration risk dashboard
Cloud and critical-service exit playbooks
Contract clause library and negotiation support