Risk
Vendor Management & Third-Party Risk Fundamentals
This course gives operations, compliance, procurement, and management professionals a practical foundation in managing vendors and third-party risk across the full relationship lifecycle. You will learn to govern that lifecycle, tier vendors by inherent and residual risk, define decision rights, and build a reliable vendor inventory. From there the course covers risk-based due diligence, cybersecurity and privacy reviews, and the contract controls, SLAs, and right-to-audit clauses that make expectations enforceable. Final lessons address ongoing monitoring, issue remediation and risk acceptance, renewals and concentration risk, and secure offboarding with audit-ready evidence. Practical templates, checklists, and workplace scenarios help you apply each step to your own vendor portfolio.
One-time purchase — own the course forever, certificate included.
Course outline
Module 1
Vendor Risk Foundations and Lifecycle Governance
- • Third-Party Risk and the Vendor Lifecycle · 15 min
- • Inherent Risk, Residual Risk, and Tiering · 15 min
- • Governance Roles, Policies, and Decision Rights · 15 min
- • Building a Vendor Inventory · 15 min
Module 2
Due Diligence, Contracts, and Control Evaluation
- • Risk-Based Due Diligence · 15 min
- • Cybersecurity and Privacy Reviews · 15 min
- • Contract Controls, SLAs, and Right-to-Audit · 15 min
- • Financial, Operational, and Compliance Risk · 15 min
Module 3
Ongoing Monitoring, Issue Remediation, and Offboarding
- • Ongoing Monitoring and Performance Reviews · 15 min
- • Issue Remediation and Risk Acceptance · 15 min
- • Renewals, Change Management, and Concentration Risk · 15 min
- • Secure Offboarding and Audit Readiness · 15 min
Ready to start? $39 one-time · 3 CEU hours · 12 lessons
Get started