Shared Assessments, Tools and Products

Coming Soon: Product Release 2027

SIG EV is here. And there’s more ahead. For more than 20 years, the SIG has served as the industry’s trusted playbook for supplier assessments–bringing organizations and their suppliers together around one shared, widely-adopted framework for risk assessment. This release...

Read More
Best Practices, Framework, Industry Guidance, and Regulations

Audit Readiness is an Operational Discipline

If your third-party risk management program has existed for more than a couple of years, you know that audits and examinations no longer qualify as occasional interruptions. External auditors, internal auditors, regulatory examiners, and other external specialists are asking more...

Read More
Best Practices, Cybersecurity, Framework, Industry Guidance, and Regulations

Evaluating Third-Party AI Use: How to Address Three Real-World Scenarios

Third parties are rapidly integrating artificial intelligence (AI) into products, services, and business processes. Whether a legal team buys an AI-powered research tool, a software vendor uses generative AI to write code, or a critical supplier quietly adds AI capabilities...

Read More
Best Practices, Framework, Industry Guidance, and Regulations

Third-Party Risk Board Reporting: Making Every Metric Count

Boards are demanding clearer, decision-focused insight into third-party risk driven in part by regulations such as DORA and NIS 2 which explicitly elevate board accountability for Information and Communication Technology (ICT) resilience. Directors are now expected to actively oversee risk...

Read More
Emerging Technologies

Quantum Computing & Third-Party Risk: Why TPRM Leaders Need to Prepare Now

Quantum computing promises enormous opportunity, but it also accelerates the urgency of rethinking cryptography across your company and its third parties. By beginning the transition now — through inventories, vendor engagement, and roadmap development — TPRM leaders can establish resilience...

Read More
Best Practices, Risk Landscape

Types of Vendor Risk and How to Mitigate Them

Types of Vendor Risk and How to Mitigate Them Vendor partnerships enable organizations to innovate, scale operations, and improve service delivery. Yet these same relationships introduce exposures that can impact operational stability and compliance integrity. When third-party relationships are not...

Read More
Shared Assessments, Tools and Products

SIG EV: The Cloud-Based Evolution of the SIG for Modern TPRM Teams

Introducing the Next Evolution of the SIG SIG EV: A Cloud-Based Platform for Modern TPRM Teams For nearly two decades, the Standardized Information Gathering (SIG) Questionnaire has set the benchmark for third-party risk assessments. Trusted by organizations across every industry,...

Read More
Framework, Industry Guidance, and Regulations

NIST vs. ISO: What’s the Difference?

NIST vs. ISO: Key Differences and Choosing the Right Framework Cybersecurity frameworks are the foundation of effective risk management. They help organizations protect sensitive data, maintain compliance, and build trust with stakeholders. Two of the most widely recognized are NIST...

Read More
Best Practices

Essential Guide to Effective Third-Party Due Diligence Practices

Essential Guide to Third-Party Due Diligence Modern organizations operate through a complex web of vendors, suppliers, contractors, and service providers. These partnerships enable innovation, efficiency, and growth, but they also expose companies to new layers of risk that can affect...

Read More
Best Practices

Five Takeaways From EY’s New TPRM Research

On June 25th, Shared Assessments hosted another in a series of “All Committee” meetings designed to bring together members from a diverse set of TPRM interest groups to engage on a single topic. The June meeting’s focus was “From Insight...

Read More
Tools and Products

Coming Soon: 2026 SIG Workbook: Key Updates and Enhancements

The Shared Assessments Standardized Information Gathering (SIG) Questionnaire has long been the industry’s most trusted third-party risk assessment tool—used by thousands of organizations globally to assess vendor controls efficiently and consistently. With the upcoming September 19, 2025 release, the SIG...

Read More
Shared Assessments

Building Strategic Alliances: Advocating for Your TPRM Program through Executive Sponsorship

For companies that are building a TPRM (third-party risk management) program from scratch—as well as any hoping to improve the programs they already have—there are a lot of important puzzle pieces to put into place. Our first Foundations Committee meeting...

Read More
1 2 3