ITPRM Institute for Third Party Risk Management
About

A member-governed institute

ITPRM is a non-profit association founded in 2026 by practitioners in contract management and third party risk. It exists because the discipline is practised in every large organisation and defined consistently in almost none of them.

The institute does not sell software, audits or consulting. It publishes method, maintains shared toolkits, and convenes the people who run these programmes across Europe.

2026
Founded
Non-profit
Association, no share capital
Europe
DORA, NIS2, ISO 37301
Open
Method published, not licensed away

Principles

01

Definitions before dashboards

A measure means nothing until two organisations compute it the same way. Definitions are versioned and dated.

02

Vendor neutral

Service providers are welcome as members and are bound by a code of conduct that forbids selling to the membership through the institute.

03

Published reasoning

Every model states its assumptions and the objections raised in review, so a member can defend an adaptation.

04

One member, one vote

A corporate member holds ten seats and a single vote. Size buys participation, not influence.

Governance

The general assembly of members elects a board of five for two-year terms. The board appoints the secretariat and approves the annual accounts, which are published to members.

Working groups are chaired by an elected member and produce the toolkits. A publication is issued only after review by two members outside the group.

Statutes, the code of conduct and the conflict of interest policy will be published in full before the institute opens for membership.

Working groups

GroupStatus
KPI frameworkActive
Assessment modelActive
Contract governanceDrafting
Regulatory mappingForming
Academic liaisonForming
Volunteer for a group