Skip to content

GroundWorks · Supplier & Third-Party Risk Management (TPRM)

Every risk decision has an owner, a case file and a proportionate response.

Coordinate onboarding, evidence collection, risk review, remediation and periodic reassessment around one supplier record.

The Workblock

Supplier & Third-Party Risk Management (TPRM) · GroundWorks Sentinel

The buyer question
Can we take the manual case-building out of supplier decisions without weakening risk ownership or replacing the systems we trust?
System of work
Supplier lifecycle and third-party risk system of work
Maturity
2 reference / 0 defined / 3 roadmap

Modules

  • Supplier onboarding: Coordinate data, documents, checks and approvals around one supplier onboarding record.
  • Supplier master data and qualification: Resolve supplier identity, govern low-risk master attributes and maintain qualification and segment evidence.
  • Third-party risk review: Assemble the case, draft the assessment and route consequential risk decisions to accountable humans.
  • Third-party risk signal tracking: Track approved evidence sources, suppress duplicates, test materiality and open evidence-complete supplier risk cases.
  • Supplier remediation and exit coordination: Coordinate mitigation, certificate renewal, offboarding, transition and closure while preserving decision authority.

The question, answered

The decision and the action live in different systems. A named person accepts the risk, but the supplier is created in the ERP, access is granted elsewhere and mitigations are tracked in a third place. A master write can fail after approval and leave a case that looks active. A certification expires or an alert names a supplier, and nobody can say which engagement it touches or which prior decision it reopens.

The burden lands twice. Suppliers repeat information they have already provided, and reviewers rebuild the context by hand for every case. A questionnaire can be complete and still answer no question, because completeness is not a decision. The missing piece is not more risk data. It is the work between a signal and a proportionate decision with a named owner.

  • Can we take the manual case-building out of supplier decisions without weakening risk ownership or replacing the systems we trust?

    Today a supplier starts as a name in a request. Someone searches the master for the party, the requester or the supplier keys in profile, tax and bank data, and each risk function issues its questionnaire from its own tool. Reviewers read responses, certificates and external signals, then carry findings through email, meetings and workflow tasks.

What changes

The case opens with what the organisation already holds, the supplier is asked only for what the decision still needs, and only material exceptions reach a named owner.

A signal is matched to the party and engagement, tested for materiality, and arrives as a case carrying the supporting evidence, the prior decision it affects and a named decision owner.

  • From forms and chasing to an assembled case

    Every supplier receives the full questionnaire pack, teams chase documents by email, and reviewers work through the same approval steps regardless of risk.

  • From risk alerts to managed exceptions

    Monitoring produces scores, news alerts and colour ratings, and someone must work out whether each event is real, material and theirs to act on.

The principles it holds to

  • One party, many relationships

    A supplier record is not a risk decision. The same party can serve two engagements with different data, access and criticality, so every decision names the engagement it covers and the evidence behind it.

  • Assessment is a proposal

    Workblocks assemble the case, draft findings and show where evidence conflicts. Residual risk is accepted only by the named owner within a delegated threshold, with conditions and expiry on the record.

  • Review sized to the relationship

    Policy sets the evidence plan from the engagement's purpose, data, access and criticality. Low-risk suppliers take the short route, and the rule behind every extra requirement stays visible.

The records it authors

Supplier master change. A controlled proposal linked to its supporting records to change supplier identity, address, tax, payment or banking attributes.

Supplier offboarding case. A controlled transition that removes procurement eligibility and access while resolving commitments, data, assets, continuity and evidence obligations.

Supplier onboarding case. A governed case that collects, verifies and resolves the evidence required to create or activate a supplier relationship.

Supplier risk case. A governed exception case created when correlated evidence may require restriction, reassessment, remediation, suspension or exit.

Supplier qualification. An effective-dated eligibility or certification decision for a supplier within a category, geography, legal entity or business purpose.

Supplier risk assessment. A versioned, scoped evaluation of supplier inherent risk, controls, evidence, residual risk and an authority-bound disposition.

Supplier remediation action. A measurable corrective action with owner, evidence, due state and verification criteria arising from supplier risk or performance evidence.

Supplier risk signal. A deduplicated, time-bounded observation that may change supplier risk, eligibility or required action but is not itself a risk decision.

Supplier tier link. An effective-dated, evidence-scored dependency from one supplier or site to an upstream supplier, facility or critical resource.

Supplier profile. The effective-dated procurement lifecycle, verification and eligibility projection for a supplier, linked to the canonical shared party identity.

  • Case records

    Durable, owned units of work. Each one holds the condition that opened it, the evidence gathered against it, the proposed action and the committed disposition, and it stays open until the condition is answered.

  • Decision records

    Determinations and the proposals that precede them, each pinned to the exact policy, rule and evidence versions it was made against, and each kept structurally distinct from the action it authorises.

  • Control records

    The governed rules, grants and pre-commitment assessments that bound what may be committed, on which records and by whom.

  • Event records

    Immutable observations that something happened, time-bounded and linked to their source, and never a decision in themselves.

  • Reference records

    Shared descriptors the whole estate reads. One canonical service owns each of them, and policy filters what any Workblock is shown.

  • Party records

    The people and organisations that participate. Verified external identifiers are held as namespaced attributes, never as the canonical key.

The roles it serves

Execution flow and task definitions are not published. The dossiers name what each Workblock owns and how much of it there is; the definitions themselves travel with a delivery.

Workblocks can be versioned and changed independently, enabling continuous client tailoring.

  • Onboarding coordinator

    Move each supplier case from proposal to a confirmed readiness state, coordinating evidence and handoffs across procurement, risk, finance and the ERP. Which cases are stuck, what does each one wait on, and who owns the next decision?

  • Supplier-master steward

    Protect supplier identity, sites, tax and bank data so that every transaction lands on the right record. Is this party already in the master, and which record is the true one?

  • Accountable risk owner

    Decide whether the risk that remains after controls is accepted, mitigated, transferred or declined. What exactly am I accepting, on what evidence, and until when?

  • TPRM programme owner

    Own the review method: tiering, evidence rules, decision rights and review cadence across the third-party population. Is the review proportionate to the actual relationship, and does the method still fit the rules we are held to?

  • Supplier contact

    Answer for the supplier: provide the information, documents and corrections the relationship depends on. What do you still need from us, why do you need it, and when can we start?

  • Module maturity

    2 reference / 0 defined / 3 roadmap, of this Workblock's five business modules.

The rest of the register

  • Previous

    Contract Lifecycle Management (CLM)

    Every clause, control and obligation stays attached to its contract, with a named owner for each one.

    Open the Workblock
  • The map

    The GroundWorks map

    Five stages and nine domain Workblocks, summarised once, each linked to the register page that holds it.

    Back to the map
  • Next

    Purchasing & Ordering

    The compliant route is the easiest one, and every exception reaches a named owner.

    Open the Workblock

Let's talk

Once you start, you're ahead.

In the enterprise, real execution matters. That's where we lead.