This message was posted by a user wishing to remain anonymous
We determine third-party risk reviews based on the classification we have given to specific third-party. We have High, Medium and Low risk classifications. A classification is given based on the risk of losing them, their importance to the business, the availability of an alternative solution, etc. At a minimum:
- High Risk - reassessed annually, at a minimum
- Medium Risk - reassessed every 2 years, at a minimum
- Low Risk - may or may not be reassessed
Risk assessments are also done on contract/agreement renewal.
I hope this helps.