The Lab Vault

Tools and templates for third-party risk.

Start with the free eight questions check, which runs in your browser and keeps what you type on your device. Then find the course module or template for the job in front of you. Editable Word and Excel templates open soon, bought and downloaded through Third Party Labs Academy.

Free tool · runs in your browser

The eight questions. One per risk domain.

From Module 03, Part A, of the Academy. Pick one third party you know. Ask each question of the person who should know the answer, then record what you heard. Print the result or save it as a PDF.

01 · Third-Party Governance

Who is the named owner of this relationship in our organisation, and when was the last governance meeting with the third party?

Listen for: A name and a date. A role title is acceptable if the person in the role is aware of the responsibility.

What did you hear?

02 · Subcontracting and Fourth-Party Risk

Which subcontractors does this third party use to deliver the parts of the service we depend on?

Listen for: Named companies and a location in the contract or the register.

What did you hear?

03 · Operational and Resilience Risk

What is the longest this service could be unavailable before our customers or the regulator notice, and has the third party ever recovered inside that time in a test?

Listen for: A number in hours and a test date. A recovery target that has never been tested is a target, not a capability.

What did you hear?

04 · Information and Cyber Risk

Exactly which categories of our data does this third party hold, in which country, and who at the third party can access it?

Listen for: Data categories, a country, a role list, and the last time it was reviewed.

What did you hear?

05 · Compliance and Regulatory Risk

Have we engaged any third party located in a country on a sanctions list?

Listen for: A date when all active third parties were last reviewed for location, and a process that prevents onboarding a third party from a sanctioned country.

What did you hear?

06 · Financial Risk

Is this third party owned, funded, or controlled by anyone we would not have chosen to deal with directly, and how would we know if that changed?

Listen for: Ownership known and a change-of-control clause in the contract.

What did you hear?

07 · Emerging Technology Risk

Where in this product does an AI model make or shape a decision that affects our customers, and what does it decide?

Listen for: A specific function and a decision. "Our product uses AI" without a location is not an answer.

What did you hear?

08 · Social and Environmental Risk

What evidence has this third party given us of labour conditions in its supply chain?

Listen for: Evidence supplied, not a policy statement. Evidence we had to chase is weaker than evidence offered.

What did you hear?

0 of 8 domains checked

0Clear answer
0Claim, no evidence
0Gap found
  • Clear answer, with evidenceThe domain is covered for this third party. Note who gave the answer; that is the owner. Domains: None yet.
  • An answer, but no evidenceTreat it as a claim until it is shown. Ask what would demonstrate it, and when you can see it. Domains: None yet.
  • No answer, or nobody knowsYou have found a gap. Raise it with the relationship owner, or with your risk team if there is no owner. Domains: None yet.

A conversation starter, not an assessment. It does not replace your organisation's own due diligence, and it is not an audit or advice. Nothing you enter is sent to Third Party Labs.

Find what you need by task

Nine jobs. Where to start on each.

Free on this site   Course in the course e-book   Vault editable template (coming soon)   Service done with you

09

Keep up with regulatory change

What changed, which regulator and jurisdiction, and what to do about it this month.

How it works

Choose a template or a bundleEach template is sold on its own, or with a core course in a bundle.

Pay once in the AcademyCard payment in Australian dollars. No GST is charged. Sign in with Google, LinkedIn or email.

Download straight awayYour files sit in your Academy account. Each template is the version current on the day you buy it.

Templates

Four templates, opening with the Academy.

Join the waitlist for any template and we will email you once when it is available to buy.

Risk and ComplianceIn production

Third-Party Risk Policy Template

One general APAC template for a Group-wide third-party risk policy, in editable Word. For risk and compliance teams writing a policy for the first time or refreshing one.

  • 20 sections and four schedules
  • Rules in the policy, names in the register
  • Goes further than the policy skeleton in TPRM Foundations

Word · price at release

Risk and Compliance · Responsible PartyIn production

Monitoring Framework Template

A working monitoring framework in Excel for the team that runs ongoing oversight of third parties.

  • Key risk indicators (KRIs) for each of the eight risk domains
  • Thresholds by classification
  • Reporting lines and a working register

Excel · price at release

Procurement and Supply ChainIn production

Contract Summary Template

For procurement to summarise what the risk assessment found before contracting, and present it to the responsible party and legal.

  • What the risk assessment found
  • Which of the six contract provisions each finding affects
  • What the organisation needs protected, and questions for legal
  • No clause wording

Third Party Labs is a risk practice, not a law firm. Use our content to brief your legal team, not to replace them.

Editable template · price at release

Procurement and Supply Chain · Risk and ComplianceIn production

Due Diligence Scope Guide

Sets how deep due diligence goes for each third party, based on how it is classified.

  • What evidence to ask for at each classification level
  • How often to refresh it
  • Organised by the eight risk domains

Editable template · price at release

Bundles

A core course and the templates that go with it.

Bundles are bought in one checkout in the Academy and cost less than buying each item separately.

Risk and ComplianceIn production

TPRM Practitioner Bundle

  • TPRM Foundations: APAC Financial Services (course)
  • Third-Party Risk Policy Template
  • Monitoring Framework Template
Procurement and Supply ChainIn production

Procurement Risk Bundle

  • Third-Party Risk in Financial Services Procurement (course)
  • Contract Summary Template
  • Due Diligence Scope Guide

Coming to the Vault

The Lab Check.

A self-assessment your team runs on its own third-party risk program. You follow the method and make your own calls. It is a tool, not an audit, assurance or advice, and Third Party Labs does not issue an opinion on the result.

One email when it opens. See our Privacy Policy.

Need the policy tailored to your organisation rather than a template?

That is a fixed-price service, quoted after a scoping call. See Services.

Templates are general information for your organisation to adapt. They are not legal or regulatory advice. Licence terms, prices and refunds are set out in our Terms of Use.