Discover and onboard third parties
Turn vendor names already present in Asset Management into governed TPRM records, or create and import relationships directly.
1. Discover candidates from Assets
Use Discover from Assets to scan existing Asset vendor references and surface names that may represent unmanaged third-party relationships. Candidate cards show the suggested name, the number of related Assets and a confidence indicator where available.
2. Accept or dismiss each candidate
Review each suggestion before turning it into a managed third party.
- Accept when the candidate represents a real relationship that should enter TPRM.
- Dismiss when the name is internal, duplicate, irrelevant or should not become a managed relationship.
- Use the Asset count and source context to resolve ambiguous names.
3. Complete the third-party record
Confirm the legal or trading name, relationship status, countries, owners, dates and next-review information. Use ownership fields to separate relationship, business and procurement responsibilities where your operating model requires them.
4. Add services and Asset dependencies
Record the specific services the third party provides. A service can carry its own criticality, data-processing, access, recovery and review information, and can be linked to the Assets it supports.
- Use direct third-party-to-Asset links for the overall vendor relationship.
- Use service-to-Asset links where the dependency belongs to a specific service.
- Mark the appropriate Asset as the risk-subject Asset when that relationship is used in a Risk workflow.
5. Use bulk import when appropriate
For larger onboarding exercises, use the current third-party import template and validate a small sample first. Preserve required headers and use stable identifiers to reduce duplicate records.
Verify onboarding
- The candidate decision is recorded.
- The third party has the correct relationship status and accountable owners.
- Relevant services are captured separately.
- Asset and service dependencies point to the intended records.
- Next due-diligence and review dates are populated when known.
- The relationship is ready for tiering.
Common problems
The same company appears more than once
Review aliases, legal/trading names and the source Asset references before accepting another candidate. Prefer one managed third party with aliases and multiple services.
An Asset vendor should not be a TPRM relationship
Dismiss the candidate. Discovery is intentionally a suggestion workflow, not an automatic conversion.
A vendor supports several services
Create separate service records so criticality, data exposure, recovery requirements and reviews can differ by service.