The process companies use to manage the risks posed by their providers.
Third Party Risk Management describes how a company handles the risks arising from suppliers, service providers and other third parties. This includes information security, data protection, financial stability and resilience. TPRM isn't a one-off check but an ongoing cycle of selection, assessment, monitoring and reassessment. In regulated industries it's mandatory and closely tied to rules such as DORA.
For providers, TPRM means the review doesn't stop after the contract. Existing customers regularly send new questionnaires, request updated certificates or an annual assessment. That ties up time without a new deal in sight, and often lands on the same one or two people who know where the answers are. Whoever handles these recurring requests efficiently keeps customers happy without it grinding the team to a halt.
With Tendry you answer recurring TPRM requests from your existing customers out of an always up-to-date knowledge base too. So ongoing review stays a click instead of a project.