Hi, thanks for the question. To help you get started, I wanted to provide an example of policy language for Contracting as well as Performance Monitoring, both key aspects to TPRM. Beyond policy, this task can be done via simple internal questionnaires, but should allow for your business to escalate if there are trends or even a single occurrence of missed service level agreements or any contractual obligation.
Contracting:
Contracts for critical or high-risk products and services must sufficiently address the following:
- Performance standards
- Reporting
- Audit Rights
- Confidentiality and security
- Business resumption and contingency plans
- Default and termination
Performance Monitoring:
Our monitoring efforts objectively verify vendors are consistent with the written agreement terms and may include:
- Reviewing reports relating to the third party's performance in contractual requirements and performance standards, including both service level agreements and quality standards, with appropriate follow-up as needed.
- Monitoring for compliance with applicable laws, rules, and regulations.
- Meeting with third-party representatives to discuss performance and operational issues.
I hope this helps. Does anyone else have input to share?