Brooklyn solutions logo
  • Products
    • Contract Lifecycle Management
    • Customer-Supplier Relationship Management
    • Third Party Risk Management
    • DORA Regulations
    • Governance, Risk & Compliance (GRC)
    • Brooklyn ESGa+
    • Digital Assessment Frameworks
    • Integrations
  • Use Cases
    • Onboarding & Segmentation
    • Policy, Governance & Workload Orchestration
    • Performance, Scorecards & Reporting
    • SLA & KPI Processing
    • Contract & Obligation Management
    • Innovation, Issues, Change & Dispute Management
    • Structured Reviews & Action Tracking
    • Operational Risk Capture, Mitigation & Controls
    • Third Party Risk Management
    • Meeting Regulatory Compliance
    • Environmental, Social and Governance
    • Contract Assessments
  • Services
    • Services for Success
    • Professional Services
    • Rapid Start Programme
  • Resources
    • News & Insights
    • Resource Library
    • Upcoming Events
  • Company
    • About us
    • Partners
    • Meet The Team
    • Careers
Rapid Start Programme Get Started
Brooklyn solutions logo
Rapid Start Programme Get Started
  • Products
    • Contract Lifecycle Management
    • Customer-Supplier Relationship Management
    • Third Party Risk Management
    • DORA Regulations
    • Governance, Risk & Compliance (GRC)
    • Brooklyn ESGa+
    • Digital Assessment Frameworks
    • Integrations
  • Use Cases
    • Onboarding & Segmentation
    • Policy, Governance & Workload Orchestration
    • Performance, Scorecards & Reporting
    • SLA & KPI Processing
    • Contract & Obligation Management
    • Innovation, Issues, Change & Dispute Management
    • Structured Reviews & Action Tracking
    • Operational Risk Capture, Mitigation & Controls
    • Third Party Risk Management
    • Meeting Regulatory Compliance
    • Environmental, Social and Governance
    • Contract Assessments
  • Services
    • Services for Success
    • Professional Services
    • Rapid Start Programme
  • Resources
    • News & Insights
    • Resource Library
    • Upcoming Events
  • Company
    • About us
    • Partners
    • Meet The Team
    • Careers
Solutions

Building a Target Operating Model for Third-Party Risk Management (TPRM)

June 13, 2024 Strategy TPRM Emily Devereux

Building a Target Operating Model for Third-Party Risk Management (TPRM)

Share this article:
Building a Target Operating Model for Third-Party Risk Management (TPRM) thumbnail

Target Operating Models (TOM) are a tool to support new organisational functions to meet the specific needs of a function, whilst aligning to wider corporate objectives.

At the heart of all well-designed functions, is a shared vision and strategy that aligns with a company’s culture, behaviour and strategic goals. For a risk management function, this vision should be rooted in the businesses’ overarching objectives and underpin its approach to managing third-party risks effectively.

But how do you create and implement a Target Operating Model for a TPRM function? In this blog, we dive into the essential steps to develop a comprehensive TOM for a Third-Party Risk Management (TPRM) function.

 

Target operating model

What elements do you need for a TPRM Target Operating Model?

  1. Start by creating the required structure and capability needed to support the TPRM function – What roles and necessary skills/expertise do you need for the optimum department?  Use this to calculate the number of roles, and skilled individuals required to fulfil and effectively run the function.
  2. Establish effective decision-making bodies and clear terms of reference for governance committees overseeing the TPRM function. Ensure alignment with other departments such as finance, HR, and legal, and implement clear policies and procedures for performance management. This will likely exist for other departments so it is a case of altering it to suit a TPRM perspective.
  3. Identify and assess the risks inherent in the TPRM function and implement appropriate controls to mitigate these risks effectively. This includes ensuring robust processes and controls are in place to manage and monitor third-party risks.
  4. Develop a framework for evaluating the performance of third-party vendors and suppliers. Define key metrics and indicators to measure performance and identify areas for improvement or risk mitigation.
  5. Establish processes for gathering and leveraging relevant information from third parties to support TPRM activities. Ensure that the necessary information is obtained to assess and manage third-party risks effectively.Determine your technology landscape, and identify IT applications and infrastructure needed to facilitate risk assessment, monitoring, and reporting within the TPRM function.
  6. Assess the financial resources required to establish and maintain the TPRM function. You’ll need to consider both initial capital outlay and ongoing operational costs to ensure adequate funding for TPRM activities.
  7. Create the processes and workflows for the delivery of TPRM services. Establish clear procedures for risk assessment, vendor due diligence, contract management, and ongoing monitoring of third-party relationships.

Conclusion

Following the above steps, you can develop a robust Target Operating Model (TOM) for your TPRM function. A well-designed TOM ensures alignment with corporate objectives, effective governance and oversight, and the ability to mitigate third-party risks proactively. With a comprehensive TOM in place, businesses strengthen their resilience, protect their interests, and foster trust with stakeholders in an increasingly complex business landscape.

Share this article:
Related Articles
The Great U.S Tariff Shock: Navigating the New Trade Landscape
April 22, 2025
Compliance Strategy TPRM
Why a Digital Platform Beats Spreadsheets for DORA Compliance
January 21, 2025
Compliance TPRM

Deal Signed. Time to Deliver.

Book a demo today
Get Started Contact Sales
Get the latest from Brooklyn Solutions in your inbox
A monthly digest of the latest news and insights from Brooklyn Solutions
Brooklyn Solutions logo
Solutions
Customer-Supplier Relationship Management Contract Lifecycle Management Third Party Risk Management Governance, Risk & Compliance (GRC)
Services
Professional Services Services for Success Rapid Start Programme Integrations
Company
About Us Partners Team ESG Rating
© Brooklyn Solutions Privacy Policy
Designed & Built by Creo