Course overview
Organizations now depend on a web of suppliers for cloud services, software, logistics, and specialized work, and each of those relationships imports risk. A vendor's data breach becomes your breach, a supplier's failure becomes your outage, and a partner's misconduct becomes your reputational and regulatory problem. Third-party risk management is the discipline of seeing and controlling risk that sits outside your own walls but lands squarely on you.
This course, held at EuroQuest International Training, builds that discipline across the vendor life cycle: selecting and vetting suppliers, writing risk into contracts, monitoring them over time, and governing the whole portfolio. Named standards and controls are treated as educational subject matter; the course builds practical judgment and is not legal advice, and specific contract terms should go to qualified counsel.
Why the risk does not stop at your suppliers
The problem rarely ends with the vendor you signed. That vendor relies on its own suppliers, and their weaknesses become yours through a chain you may not even see, known as fourth-party risk. When many critical services depend on the same underlying provider, a single failure can cascade widely. Managing this well overlaps closely with the security dimension covered in Supply Chain Cybersecurity and Third-Party Risk.
Course objectives
By the end of the course, participants will be able to:
- Discover which subcontractors stand behind a hired vendor.
- Vet a supplier through due diligence ahead of any commitment.
- Verify certificate scope against the service actually purchased.
- Contract data-protection duties before a service goes live.
- Demand the audit access a contract already grants.
- Reassess a supplier when ownership or key staff shift.
- Inherit the disclosure duty for an incident at a supplier.
- Replace a provider whose failure would stop several services.
- Exit a vendor with data returned and access closed.
Course outline
Unit 1: Introduction to third-party and vendor risk management
- Third-party risk in data handling, access, and uptime.
- Exposure that remains after the vendor keeps every promise.
- The point in a vendor relationship where leverage runs out.
- Fourth-party and concentration risk.
Unit 2: Due diligence and vendor selection
- Finding which vendors cannot be replaced within a quarter.
- Assessment questionnaires and evidence review.
- Checking that a SOC 2 or ISO 27001 scope names the service.
- Chasing proof behind an answer that could not be checked.
Unit 3: Contracting and compliance controls
- Service levels, security, and data-protection clauses.
- Audit rights written into a contract and never exercised.
- Exit clauses that hold when the relationship ends badly.
- Holding regulatory duties that no contract can transfer.
Unit 4: Ongoing vendor monitoring and risk mitigation
- Vendor ownership moving to a competitor without notice.
- Reassessing risk as circumstances change.
- Managing incidents involving a vendor.
- Escalation to whoever at a vendor can authorize the fix.
Unit 5: Building resilient vendor governance programs
- Contracts whose internal owner has since left the business.
- Portfolio views that expose the same supplier repeatedly.
- Three services, one provider, and no visible alternative.
- Offboarding and secure exit.
How the course is delivered
The course is delivered through facilitated discussion, worked examples, and documented case studies of vendor failures and breaches, with structured analysis of assessment and contracting decisions. It builds practical judgment and is educational; it is not legal advice, and contract terms should be reviewed by qualified counsel.
Who should attend
The course suits risk, procurement, security, and compliance professionals, vendor and contract managers, and anyone responsible for supplier relationships and their risk. Those wanting the broader risk framework will find Business Risk Assessment and Management Frameworks a useful companion.
About EuroQuest International Training
EuroQuest International Training, founded in 2015 and headquartered in Bratislava, delivers professional courses to more than 15,000 participants across over 1,000 titles, in cities including Dubai, London, Barcelona, Istanbul, Vienna, Paris, and Geneva, led by experienced practitioners.
Frequently asked questions
Is this course about cybersecurity or procurement?
Both, and the space between them. Third-party risk spans security, operations, finance, and compliance, so the course suits procurement, risk, and security staff who need a shared approach.
Does the course give legal advice on contracts?
No. It covers the risk and compliance clauses that belong in a vendor contract as educational subject matter. It is not legal advice, and specific terms should be reviewed by qualified counsel.
Will we work through real vendor scenarios?
Yes. The course uses documented cases of vendor failures and breaches and structured analysis, so you practice assessing and controlling supplier risk rather than only reading about it.
Related courses
- Compliance and Regulatory Risk Management
- Business Risk Assessment and Management Frameworks
- Procurement and Vendor Management in Projects
- ISO 27001: Information Security Risk Management
Register for this course
To reserve a place or ask about dates and in-house delivery, contact EuroQuest International Training and our team will help you arrange the details.
All Course Dates & Locations
26 dates · 14 cities · Oct 2026 – Jul 2027