Skip to content
Resilience agents
Risk, Trust & ResilienceResilienceThird-Party Intake, Criticality & Due Diligence

Third-Party Intake Router

Turns a proposed vendor relationship into a complete, risk-based diligence plan.

Captures the service, business owner, customer impact, data, access, jurisdictions, subcontracting and substitutability once, then routes only the diligence needed for the relationship's real risk. It detects renewals and scope changes, refuses ownerless submissions and cannot mark its own intake approved.

Authority

Prepare

Team role

Routes work to specialists

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Third-Party Intake, Criticality & Due Diligence

Desk workflow

Relationship intake, then service and data mapping, then independent criticality, then risk-domain diligence, then evidence verification, then accountable approval.

Collaboration

Works within a defined desk workflow

Decision boundary

Assembles the work product; approval remains elsewhere.

Systems and capabilities involved

  • Procurement intake

  • Business service catalog

  • Policy and obligation library

  • Diligence-agent directory

Handoffs

What this role gives and receives

Capabilities offered

Route a third-party intake

Produce a complete relationship record and proportionate diligence plan.

Receives:
Vendor proposal, service, owner, data, access, locations and subcontracting
Returns:
TPRM case with missing facts, routed reviews, owners and due dates

Delegates

Third-Party Criticality Judge

Independently determine relationship and service criticality. Trigger: Minimum service, impact and substitutability facts are complete Returns: Criticality tier, impact drivers and mandatory diligence.

Delegates

Vendor Due-Diligence Specialist

Investigate the risk domains selected by the tier decision. Trigger: Criticality and diligence scope are approved Returns: Domain findings, residual risk and evidence gaps.

Delegates

Vendor Evidence Verification Agent

Verify provenance and freshness of material vendor assertions. Trigger: Vendor evidence is received Returns: Verified, contradicted or unverified claims with source lineage.

External handoff

Business owner

External handoff

Procurement

Context

What the role needs to do the work

Current work
Relationship proposal, missing facts, candidate criticality and active diligence plan.
Prior interactions
Prior relationships, abandoned procurements, renewals and scope changes.
Policies and reference
TPRM taxonomy, business-service map, data classes and jurisdictional requirements.
Working method
Intake completeness and risk-domain routing rules.

Illustrative workflow

How the work moves

Starting point

Treasury proposes a cloud service that will originate payment files.

  1. 01

    Capture service impact, transaction authority, data, locations, subcontractors and fallback.

  2. 02

    Match the vendor and service against existing relationships and important business services.

  3. 03

    Commission independent criticality, full diligence and evidence verification.

Result

A high-criticality TPRM case with named reviews, evidence requests and accountable owners.

Checks and boundaries

What must be tested or reviewed

  1. 01Routes a low-spend provider that supports a critical payment service as high criticality.
  2. 02Recognizes a renewal that adds customer data and opens incremental privacy and security reviews.
  3. 03Returns an intake with no accountable business owner instead of assigning procurement by default.

Human authority

  • Business owner attests service facts
  • TPRM officer accepts diligence scope

Keep exploring