Third-Party Risk Management

We bring deep expertise in strengthening risk visibility, enhancing governance and improving resilience across complex third-party ecosystems

Who we are

We design and embed risk-based and practical Third-Party Risk Management (TPRM) frameworks that improve visibility of supplier risk and risk exposure, enforce appropriate levels
of governance and enable more effective oversight of critical service providers.

Leveraging our risk and compliance experience, we equip organisations with the appropriate tools to empower confident and compliant decision making, and strengthen overall resilience.

We also support organisations in responding to evolving regulatory expectations, including APRA CPS 230 Operational Risk Management and the Security of Critical Infrastructure Act (SOCI), strengthening oversight of material service providers that support critical operations.

Strategy, Framework & Governance

01

Identify

Classify third-parties based on risk tiers, considering service criticality, data sensitivity and regulatory obligations, and define appropriate due diligence requirements.

02

Assess

Evaluate operational and security risks, determine residual risk exposure and define remediation actions or approval conditions, supported by contingency planning.

03

Monitor

Continuously monitor third-party risk posture and performance, track issues and remediation, and trigger reassessments as required.

04

Offboard

Develop and execute structured exit strategies, including offboarding checklists and transition plans, ensuring risks related to data, access and continuity are effectively managed.

What we deliver

We deliver practical third-party risk management services that strengthen governance, improve supplier risk visibility and enhance oversight across the full lifecycle.

TPRM Governance and Framework Design

We design, uplift and embed TPRM governance frameworks, policies and operating models to support end-to-end management of third-party risk, from onboarding through to offboarding. This includes defining governance structures, roles and responsibilities, and integrating TPRM into broader risk management practices to enable consistent oversight and stronger risk-informed decision making.

Vendor Identification and Classification

We support organisations to identify and classify third-parties based on risk and criticality, using tailored frameworks aligned to business structure and regulatory expectations. This includes developing or uplifting vendor registers to ensure accurate and current information is maintained, enabling prioritised due diligence and clearer oversight of critical providers.

Vendor Risk Assessment and Due Diligence

We design and implement vendor risk assessment processes and tools to support the collection and evaluation of third-party risk information across operational and security domains. This enables organisations to better understand control environments, identify risk exposures and take timely, informed actions to address gaps or high-risk areas.

Vendor Monitoring and Reporting

We develop and implement monitoring and reporting
frameworks to provide ongoing visibility of vendor
performance and risk. This includes establishing key risk
metrics, dashboards and reporting processes to track
issues, monitor remediation and support proactive
management and reassessment of third-party risk.

These capabilities are delivered through flexible delivery models tailored to your organisation’s structure, scale and maturity.

TPRM System Implementation

We design and implement TPRM solutions within GRC systems and tooling to support centralised, end-to-end third-party risk management. This includes configuring workflows, assessment processes and reporting capabilities to improve visibility, consistency and efficiency across business units.

Managed Services

We provide flexible access to TPRM expertise through a managed service model, supporting the execution of core processes such as vendor assessments, onboarding, monitoring and reporting. This enables organisations to scale
capability, maintain consistency and strengthen oversight of third-party risk.

Our Experience

Major Medical Indemnity Insurer

Third Party Risk Management Managed Service

Amstelveen is engaged by the client to establish and deliver an ongoing Third Party Risk Management (TPRM) managed service to support compliance with CPS 234 Information Security requirements. The engagement involves designing the end-to-end third-party risk assessment framework, including the development of assessment criteria, policies, procedures, and governance processes aligned with CPS 234 and information security obligations. As part of the managed service, Amstelveen conducts risk assessments for both new and existing service providers, evaluating information security controls and identifying areas requiring remediation or enhanced oversight. Amstelveen continues to manage the third-party risk assessment lifecycle on behalf of the client, providing ongoing assurance that material service providers are assessed consistently and in alignment with regulatory expectations and information security requirements.

International Financial Services Group

CPS230 Service Provider Governance Uplift

Amstelveen resources were engaged by a global institutional bank to prepare the organisation for the implementation of CPS 230, including APRA visitation. The team members were responsible for assessing the current state of the business unit’s Service Provider Management processes, providing a roadmap to uplift this area and prepare relevant materials that enable the organisation to maintain compliance with the standard. They validated the business unit’s Material Service Provider (MSP) register, refined the Risk Management Approach and assessed contractual obligations towards the client’s MSPs. They also led the change management plan to support Relationship Managers in their revised responsibilities, including use of a new Vendor Governance system. All these activities augmented the organisation’s ability to perform Third-Party Risk Management in conformance with CPS 230, particularly the assessment and governance of MSPs.

Major Australian Airline

Security Supplier Risk Management

Amstelveen was seconded as part of a Major Australian Airline’s Cyber Security Team to uplift and maintain their Security Supplier Risk Management standards, processes and reporting. This involved developing relevant Standards, Frameworks and redesigning dashboards and metrics for consumption by Executive Management. Additionally, the existing supplier questionnaires were reviewed and uplifted, with a focus on the inclusion of attestations for vulnerability management and data encryption. The team was also responsible for directly managing and training an external managed services provider, who were responsible for liaising with third parties for the triage and completion of security questionnaires.

Australian Mutual Insurer

Third Party Cyber Risk Assessment Process

Amstelveen was engaged by an Australian Mutual Insurer to uplift a third party technology risk assessment process and associated tooling. This assessment was oriented primarily to Cyber related risks, and to Cyber related risks, and involved the review and assessment of the existing third party risk assessment model, identification of uplift activities, redrafting of the process and creation of associated tools and templates. This engagement involved significant interaction with business stakeholders and the Cyber Security, Line 2 Risk, Procurement and Legal teams. Ultimately this engagement enabled the client to implement a methodical and consistent approach to vendor assessments across its portfolio of ~100 major vendors.

Major Insurer

Procurement Spend Analysis Dashboards

Amstelveen was engaged to complete procurement spend analysis for a major medical indemnity provider to support the identification of optimisation opportunities and streamlined contract management. This involved creating a Power BI dashboard on top of supplier and contract data from their Governance, Risk & Compliance (GRC) system to conduct immediate and facilitate future analysis over cost management, spend, suppliers, and procurement performance within the organisation. The analysis and dashboards completed supported a broader supplier management analytics multi-year roadmap being undertaken by the organisation.

Ready to strengthen resilience across your supply chains?

Get in touch for any questions, or if you’d like to discuss working together