Third-Party-Risk-Management (TPRM) covers the identification, assessment, and ongoing management of risks arising from relationships with suppliers and service providers. This includes an inventory of all third parties, their classification by criticality, the assessment of their security practices, and contractual and organizational controls across the entire lifecycle – from procurement to exit. The goal is transparency about which providers support critical functions and how robust their security posture actually is.
Security of the digital Supply Chain
How to systematically assess and manage the security of your IT, cloud, and AI supply chain – from supplier selection through to continuous monitoring.
197control objectives in the CCM across 17 domains
261yes/no questions in CAIQ v4.0
247control objectives in AICM v1.1 across 18 security domains
320questions in the accompanying AI-CAIQ v1.1
Today, most security-relevant risks no longer arise solely within your own network but through third parties: cloud services, software suppliers, managed service providers, and increasingly AI services. With NIS2 and DORA, assessing direct suppliers has shifted from a recommendation to a regulatory obligation. Cloud and AI providers are special cases here: they process sensitive data outside your own control and require standardized, verifiable assessment procedures. For precisely these cases, industry bodies such as the Cloud Security Alliance have created established frameworks – the CAIQ for cloud providers and the AI Controls Matrix for AI services. Third-Party-Risk-Management (TPRM) combines these building blocks into an end-to-end process from selection through to ongoing monitoring.
The Essentials at a Glance
Six topic blocks — tap to expand.
The regulatory framework
Four sets of rules reach into the supply chain — tap a tab for the core obligations.
- Art. 21(2)(d) requires supply chain security measures for relationships with direct suppliers and service providers.
- Art. 21(3) requires taking into account the vulnerabilities of each direct supplier and the quality of its cybersecurity practices — including the coordinated risk assessments under Art. 22.
Art. 21(2)(d)Art. 21(3)Art. 22direct suppliers
- Governs ICT third-party risk for the financial sector in Chapter V.
- Core elements include strategy and register of information (Art. 28), concentration risk (Art. 29), and minimum contractual provisions (Art. 30).
Chapter VArt. 28Art. 29Art. 30register of informationconcentration risk
- Extends these obligations to products with digital elements and their components.
digital elementscomponents
- The ISO/IEC 27001 controls A.5.19–A.5.23 operationalize these requirements for supplier relationships and cloud use.
supplier relationshipscloud use
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Consensus Assessment Initiative Questionnaire (CAIQ) & Cloud Controls Matrix (CCM)
CAIQ as a yes/no questionnaire for the CCM; CCM with 197 control objectives across 17 domains; CAIQ v4.0 with 261 questions; CCM and CAIQ merged from v4.1 onward.
STAR Registry (Security, Trust, Assurance and Risk)
Public registry; Level 1 free self-assessment (updated annually), Level 2 paid third-party audit (STAR Attestation/SOC 2, STAR Certification/ISO 27001).
AI Controls Matrix (AICM) v1.1
247 control objectives across 18 domains, Model Security domain with 13 AI-specific controls, accompanying AI-CAIQ with 320 questions; released June 2026, synchronized with CCM v4.1.
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2)(d) supply chain security for direct suppliers, Art. 21(3) assessment of suppliers, Art. 22 EU-coordinated risk assessments of critical supply chains.
Verordnung (EU) 2022/2554 (DORA)
Chapter V, Art. 28–31 on ICT third-party risk (strategy, register of information, due diligence, concentration risk, exit strategies); applicable since January 17, 2025.
Related Services
Supplier and provider risks under control?
We assess your critical cloud and AI service providers against CAIQ and AICM and build a robust Third-Party-Risk-Management with you. Talk to us.