ITPRM Institute for Third Party Risk Management
Toolkits

Instruments, not templates to admire.

Each toolkit is versioned, documented and revised by a working group. Members may adapt them internally; the reasoning behind every choice is written down so an adaptation can be defended to an auditor or a regulator.

Toolkit 01 · v0.9

KPI framework

KeySupportingPrescriptiveDetective

Twenty-seven contract management and third party risk indicators, each with a definition, a formula, a data source, an owner and a tolerance band. The four classifications separate what the board reads from what explains it, and what prevents a failure from what detects one.

Toolkit 02 · v1.0

Third party risk assessment tool

BrowserExcel

Criticality tiering, an inherent risk score across eight domains, control evidence, and a residual rating that sets the depth of due diligence. Deliberately simple: one screen, no login, nothing to install. The spreadsheet edition holds the same model for portfolio use.

Toolkit 03 · In draft

Contract governance pack

Working group open

Clause checklists, exit and step-in planning, obligation registers and a review calendar, mapped to the register fields the assessment tool expects. Written to be adapted, not adopted whole.

Notify me on release
Toolkit 04 · Planned 2027

Regulatory mapping

DORANIS2ISO 37301

One matrix from register field and KPI to the obligation it evidences, so a European programme can show coverage without maintaining three parallel control sets.

Follow the working group