Due Diligence Is Not a Document. It’s a Practice.
Many organizations address vendor security by forwarding a questionnaire they received from their own enterprise client and filing whatever comes back. No assessment. No analysis. No follow-up. No program.
That approach does not satisfy the intent of a Third-Party Risk Management (TPRM) obligation — regulatory, insurance, or contractual. It produces paperwork, not due diligence. And it will not hold up under scrutiny.
Data Security Partners builds a real vendor risk management program — documented, standards-based, actively managed, and built to produce a defensible record of due diligence across every qualifying vendor relationship.

THE GOVERNING FRAMEWORK
At the heart of every engagement is the TPRM Document — the governing framework that defines how your organization conducts vendor risk management. Produced during the foundation phase and maintained as a living document throughout the program, it is what separates a defensible program from an ad hoc exercise.
The TPRM Document Establishes:
• Your definition of sensitive data in the organization’s
specific context
• What constitutes an in-scope vendor relationship (data
flow criteria)
• Security expectations placed on in-scope vendors
• Reporting requirements and cadence
• Verification and monitoring approach
• Consequences of vendor non-compliance
• The questionnaire framework and evaluation metrics
• Decision-making process for vendor risk acceptance
• Applicable standards and best practices
The TPRM Document mirrors the Cybersecurity Governance Program as a governing counterpart — where the Governance Program governs your internal security, the TPRM Document governs your external vendor perimeter. Both follow the same governance architecture; both point to the same underlying standards.
Standards Alignment
Both the TPRM Document and the vendor questionnaire framework are built on recognized industry standards. This helps ensure the program withstands regulatory, insurance, and contractual scrutiny — and that vendors take the questionnaire process seriously.
Legal Component
If desired by the client, each in-scope vendor signs an attestation document acknowledging receipt of your relevant policies, their duty to comply, and their obligation to submit truthful information. This creates a legal record of vendor obligations and awareness.
ENGAGEMENT MODES
Standalone. Concurrent. Or as a Continuation.
The TPRM Program can be engaged in three modes — depending on where you are with your internal governance program and when your TPRM obligation becomes pressing.
Standalone
For clients whose TPRM obligation is immediate and whose own internal governance program is either in place or being addressed separately.
Concurrent
TPRM runs alongside the 3-Year Cybersecurity Governance Program. Both governing documents are developed in alignment from the outset — eliminating duplication in discovery, obligation mapping, and document production. $5,000 package discount applies.
Continuation
TPRM follows completion of the 3-Year Governance Program. Your internal security posture is established; attention turns to the vendor perimeter.
PACKAGE DISCOUNT – CONCURRENT ENGAGEMENT
$5,000 off the TPRM foundation phase when programs run concurrently
This is not a promotional bundling incentive — it reflects real, tangible economies in discovery, obligation mapping, sensitive data definition, and document production when both programs are developed in alignment rather than duplicated separately.
HOW WE START
Every Engagement Begins With a Foundation.
The first 90 days are entirely client-facing. No vendor contact occurs during this phase. The work is internal — understanding your obligations, mapping your sensitive data perimeter, and building the governing framework that every subsequent vendor interaction depends on.
Month I
Discovery
Review of your cybersecurity policies and procedures; duty-to-protect obligation mapping; sensitive data definition; sensitive data flow mapping. Preliminary vendor inventory developed with placeholder fields for information to be gathered in the ongoing program.
Month 2
TPRM Document Development
The governing framework defining how your organization conducts vendor risk management, built on recognized standards and best practices. Evaluation criteria developed and tailored to your obligations and vendor access profiles. Vendor questionnaire framework developed (prioritized, structured for progressive deployment across the 3-year engagement).
Month 3
Scoping Study
Definitive vendor count established, block assignment confirmed, program roadmap developed for the following 33 months. Vendor attestation document prepared for legal review.
At the end of 90-days you will have:
✓ Complete TPRM Document (governing framework)
✓ Vendor Inventory (with sensitive data mapping and placeholder fields)
✓ Evaluation Criteria (tailored to your obligations and vendor profiles)
✓ Vendor Questionnaire Framework (optimized for 3-year deployment)
✓ Definitive vendor count and block assignment
✓ First Quarterly Business Review
These deliverables are yours to keep — regardless of what comes next. A partially completed vendor inventory with documented gaps is more valuable than no inventory.
90-DAY DECISION POINT
We’re Confident in What We Deliver. You Should be too – Before You Commit.
At the end of your Foundation Phase — Day 90 — we sit down for your first Quarterly Business Review. We walk you through the TPRM Document, the vendor inventory, and exactly what the next 33 months look like. At that point — you decide to continue, or not. No penalty. No pressure. You keep everything we built.

Note: If you completed a TPRM Scoping Study prior to engaging the program, your $7,500 scoping study fee is credited toward the foundation phase — reducing your investment at the 90-day decision point accordingly.
ONGOING PROGRAM
Active Management. Documented Evidence. Every Vendor, Every Year.
The following phases are executed for each qualifying vendor. The cycle repeats annually with increasing questionnaire depth across three years. Quarterly virtual touchpoints maintain active oversight between annual reviews.
All meetings include pre- and post-meeting preparation. Written reports are maintained in the client file as documented evidence of due diligence.

Questionnaire depth progresses across three years, with increasing depth each year. This mirrors the real-world experience of clients who receive progressively deeper questionnaires from their own enterprise clients each year. The annual cadence distributes vendor workload, allows relationships to mature alongside question depth, and is more defensible than a one-time snapshot.
PRICING
Priced by Vendor Block. No Per-Vendor Billing.
Vendor count is established during the TPRM Scoping Study or at the end of the foundation phase. “Qualifying” vendors are those with access to your sensitive data. Pricing is structured in blocks rather than per-vendor to eliminate administrative friction — and to ensure clients are never incentivized to minimize their reported vendor population.
The block price covers the full program — documentation, client QBRs, vendor-facing work, and ongoing management — for organizations with up to the block ceiling in qualifying vendors.

Block Management Notes
• Block assignment is reviewed at the annual vendor review cycle and adjusted up or down based on definitive vendor count.
• Mid-year upward adjustment: if 3 or more vendors are added beyond your current block ceiling, a mid-year block adjustment
conversation is triggered. Fewer than 3 over the ceiling is absorbed until the annual review.
• Downward movement is handled at the annual review only.
• Vendor offboarding is a documented TPRM activity — it does not reduce scope mid-year. Offboarding requires active management:
data disposition, access revocation, contractual wind-down, and residual risk monitoring. The end of a vendor relationship may
temporarily increase risk rather than reduce it.
INVESTMENT
Full Transparency. No Surprises.

Figures assume $15,000 foundation fee + monthly block fee × 36 months. Monthly fees begin Month 1 and run concurrently with the foundation phase. If a TPRM Scoping Study was completed prior to engagement, the $7,500 scoping study fee is credited toward the foundation phase.
WHAT TO EXPECT
Consistent Engagement. Documented Evidence. Always Know Where You Stand.
You Always Have a Plan
Every quarter begins with a clear agenda — which vendors are being reviewed, what’s being assessed, and what’s being delivered. No guesswork.
You Always See the Results
Every QBR includes a written report — vendor review progress, assessment findings, action items, and priorities for the coming quarter. Your program is documented and measurable.
Your File Is Always Current
Questionnaire responses, assessment notes, meeting records, and attestation documents are maintained in your client file throughout the program. When a regulator, insurer, or enterprise client asks for proof of vendor due diligence, the answer is already documented and readily available.
Your Program Grows With You
Block assignment is reviewed annually. Questionnaire depth progresses across three years. As your vendor relationships and business obligations evolve, your program adapts.
Ready to build a defensible vendor risk management program?
The next step is a 30-minute conversation — about your business, your vendors, your obligations, and what a program would look like for you.
Not sure yet what a TPRM program would involve for your business?
Our TPRM Scoping Study is a 30-day, $7,500 engagement that maps your sensitive data, identifies your in-scope vendors, and establishes your compliance obligations — before you commit to a full program. The full fee is credited toward your foundation phase if you engage within 90 days
Need to manage your internal security program?
The 3-Year Cybersecurity Governance Program addresses your internal security posture. Running both programs concurrently qualifies for a $5,000 package discount on the TPRM foundation phase — and produces governing documents built in alignment from the outset.

