THIRD PARTYCURRENT
Capability desk

The work a third-party risk program must perform

Ten capability guides explain the operating job, the evidence it should create, common failure modes, implementation questions, and which companies document relevant positioning.

34 of 45 companies
Capability explainer

Intake And Inventory

The operating record that identifies an external relationship, the products and services involved, internal ownership, affected systems and data, criticality, and the triggers that keep the record current. The common failure is treating a legal vendor name as the complete object. One company can supply multiple products, connections, contracts, and services with different owners and risk profiles.

20 of 45 companies
Capability explainer

Inherent Risk Tiering

The method used to determine the level and type of review a relationship needs before control evidence or external findings are considered. The common failure is a generic score that hides the questions, weights, exceptions, and owner judgment behind the tier.

42 of 45 companies
Capability explainer

Due Diligence And Assessments

The collection and review of evidence used to understand whether a third party can meet the organization's control, resilience, compliance, and relationship requirements. The common failure is measuring volume and completion while unresolved evidence, compensating controls, and risk acceptance remain outside the record.

25 of 45 companies
Capability explainer

Evidence Collection

The controlled acquisition, classification, review, reuse, and retention of documents and observations supporting a third-party decision. The common failure is a document repository that knows a file exists but not which claim it supports, who reviewed it, or when it should be reconsidered.

44 of 45 companies
Capability explainer

Continuous Monitoring

The process of detecting material changes after approval and routing those changes into proportionate review and response. The common failure is alert accumulation. More signals can increase workload without improving decisions when entity matching, context, thresholds, or response ownership are weak.

37 of 45 companies
Capability explainer

Issue Remediation

The governed process for turning an identified gap into an owner, action, deadline, evidence, exception, or accepted-risk decision. The common failure is closing an issue because a response arrived rather than because an accountable reviewer confirmed the risk was resolved or accepted.

12 of 45 companies
Capability explainer

Fourth-Party Visibility

The identification and analysis of downstream providers, shared technology dependencies, and concentration beyond the direct third-party relationship. The common failure is an impressive network map with weak entity resolution, unclear relationship evidence, or no path from discovery to a material decision.

19 of 45 companies
Capability explainer

Regulatory Mapping

The connection between third-party program evidence, controls, decisions, and the obligations an organization must demonstrate. The common failure is a static crosswalk that creates apparent coverage without proving the organization's process or evidence satisfies the requirement.

45 of 45 companies
Capability explainer

Reporting

The conversion of third-party program records into information operators, executives, boards, auditors, and regulators can use for different decisions. The common failure is a polished dashboard whose metrics are not defined, reproducible, or connected to an action.

12 of 45 companies
Capability explainer

Offboarding

The controlled closure of access, data, contracts, evidence, monitoring, dependencies, and residual obligations when a third-party relationship ends. The common failure is marking a vendor inactive while tokens, accounts, data copies, subcontractors, and unresolved obligations remain.