With this third-party risk framework, responsibility of vendor management rests with a single group, such as the compliance office or the third-party risk management team. It’s the recommended approach to third-party risk in organizations – in larger ones, a hybrid model may be better with the centralized group setting the standard but operating day-to-day through business relationship managers as the first line of defense.