01
Check a third party you already have
A fast read on one relationship: who owns it, what is known, and where the gaps are.
The Lab Vault
Start with the free eight questions check, which runs in your browser and keeps what you type on your device. Then find the course module or template for the job in front of you. Editable Word and Excel templates open soon, bought and downloaded through Third Party Labs Academy.
Free tool · runs in your browser
From Module 03, Part A, of the Academy. Pick one third party you know. Ask each question of the person who should know the answer, then record what you heard. Print the result or save it as a PDF.
01 · Third-Party Governance
Who is the named owner of this relationship in our organisation, and when was the last governance meeting with the third party?
Listen for: A name and a date. A role title is acceptable if the person in the role is aware of the responsibility.
02 · Subcontracting and Fourth-Party Risk
Which subcontractors does this third party use to deliver the parts of the service we depend on?
Listen for: Named companies and a location in the contract or the register.
03 · Operational and Resilience Risk
What is the longest this service could be unavailable before our customers or the regulator notice, and has the third party ever recovered inside that time in a test?
Listen for: A number in hours and a test date. A recovery target that has never been tested is a target, not a capability.
04 · Information and Cyber Risk
Exactly which categories of our data does this third party hold, in which country, and who at the third party can access it?
Listen for: Data categories, a country, a role list, and the last time it was reviewed.
05 · Compliance and Regulatory Risk
Have we engaged any third party located in a country on a sanctions list?
Listen for: A date when all active third parties were last reviewed for location, and a process that prevents onboarding a third party from a sanctioned country.
06 · Financial Risk
Is this third party owned, funded, or controlled by anyone we would not have chosen to deal with directly, and how would we know if that changed?
Listen for: Ownership known and a change-of-control clause in the contract.
07 · Emerging Technology Risk
Where in this product does an AI model make or shape a decision that affects our customers, and what does it decide?
Listen for: A specific function and a decision. "Our product uses AI" without a location is not an answer.
08 · Social and Environmental Risk
What evidence has this third party given us of labour conditions in its supply chain?
Listen for: Evidence supplied, not a policy statement. Evidence we had to chase is weaker than evidence offered.
A conversation starter, not an assessment. It does not replace your organisation's own due diligence, and it is not an audit or advice. Nothing you enter is sent to Third Party Labs.
Find what you need by task
Free on this site Course in the course e-book Vault editable template (coming soon) Service done with you
01
A fast read on one relationship: who owns it, what is known, and where the gaps are.
02
Decide how deep to go before the contract, based on how the third party is classified.
03
Tell the responsible party and your legal team what the assessment found and what needs protecting.
Third Party Labs is a risk practice, not a law firm. Use our content to brief your legal team, not to replace them.
04
Agree what gets checked, how often, and what evidence proves it, by classification.
05
Rules in the policy, names in the register. Start from a structure that has been used before.
06
Make sure the activities that set a relationship up well are done, and someone owns each one.
07
One jurisdiction at a time: the regulator, the framework, and what they have in common.
08
Your policy, in your words, as an assessed course with completion reporting.
09
What changed, which regulator and jurisdiction, and what to do about it this month.
How it works
Choose a template or a bundleEach template is sold on its own, or with a core course in a bundle.
Pay once in the AcademyCard payment in Australian dollars. No GST is charged. Sign in with Google, LinkedIn or email.
Download straight awayYour files sit in your Academy account. Each template is the version current on the day you buy it.
Templates
Join the waitlist for any template and we will email you once when it is available to buy.
One general APAC template for a Group-wide third-party risk policy, in editable Word. For risk and compliance teams writing a policy for the first time or refreshing one.
A working monitoring framework in Excel for the team that runs ongoing oversight of third parties.
For procurement to summarise what the risk assessment found before contracting, and present it to the responsible party and legal.
Third Party Labs is a risk practice, not a law firm. Use our content to brief your legal team, not to replace them.
Sets how deep due diligence goes for each third party, based on how it is classified.
Bundles
Bundles are bought in one checkout in the Academy and cost less than buying each item separately.
Coming to the Vault
A self-assessment your team runs on its own third-party risk program. You follow the method and make your own calls. It is a tool, not an audit, assurance or advice, and Third Party Labs does not issue an opinion on the result.
One email when it opens. See our Privacy Policy.
Need the policy tailored to your organisation rather than a template?
That is a fixed-price service, quoted after a scoping call. See Services.
Templates are general information for your organisation to adapt. They are not legal or regulatory advice. Licence terms, prices and refunds are set out in our Terms of Use.