Third-Party Intake Router
Turns a proposed vendor relationship into a complete, risk-based diligence plan.
Captures the service, business owner, customer impact, data, access, jurisdictions, subcontracting and substitutability once, then routes only the diligence needed for the relationship's real risk. It detects renewals and scope changes, refuses ownerless submissions and cannot mark its own intake approved.
Authority
Prepare
Team role
Routes work to specialists
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Third-Party Intake, Criticality & Due Diligence
Desk workflow
Relationship intake, then service and data mapping, then independent criticality, then risk-domain diligence, then evidence verification, then accountable approval.
Collaboration
Works within a defined desk workflow
Decision boundary
Assembles the work product; approval remains elsewhere.
Systems and capabilities involved
Procurement intake
Business service catalog
Policy and obligation library
Diligence-agent directory
Handoffs
What this role gives and receives
Capabilities offered
Route a third-party intake
Produce a complete relationship record and proportionate diligence plan.
- Receives:
- Vendor proposal, service, owner, data, access, locations and subcontracting
- Returns:
- TPRM case with missing facts, routed reviews, owners and due dates
Delegates
Independently determine relationship and service criticality. Trigger: Minimum service, impact and substitutability facts are complete Returns: Criticality tier, impact drivers and mandatory diligence.
Delegates
Investigate the risk domains selected by the tier decision. Trigger: Criticality and diligence scope are approved Returns: Domain findings, residual risk and evidence gaps.
Delegates
Verify provenance and freshness of material vendor assertions. Trigger: Vendor evidence is received Returns: Verified, contradicted or unverified claims with source lineage.
Handoff to
Receives from
Receives from
External handoff
Business owner
External handoff
Procurement
Context
What the role needs to do the work
- Current work
- Relationship proposal, missing facts, candidate criticality and active diligence plan.
- Prior interactions
- Prior relationships, abandoned procurements, renewals and scope changes.
- Policies and reference
- TPRM taxonomy, business-service map, data classes and jurisdictional requirements.
- Working method
- Intake completeness and risk-domain routing rules.
Illustrative workflow
How the work moves
Starting point
Treasury proposes a cloud service that will originate payment files.
- 01
Capture service impact, transaction authority, data, locations, subcontractors and fallback.
- 02
Match the vendor and service against existing relationships and important business services.
- 03
Commission independent criticality, full diligence and evidence verification.
Result
A high-criticality TPRM case with named reviews, evidence requests and accountable owners.
Checks and boundaries
What must be tested or reviewed
- 01Routes a low-spend provider that supports a critical payment service as high criticality.
- 02Recognizes a renewal that adds customer data and opens incremental privacy and security reviews.
- 03Returns an intake with no accountable business owner instead of assigning procurement by default.
Human authority
- Business owner attests service facts
- TPRM officer accepts diligence scope
Keep exploring