TPR-240Third-Party & Supply Chain Risk

Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification

What you leave with

A monitoring standard: what triggers a reassessment, expiry ladders for SOC reports and DPAs, and an offboarding checklist.

Same obligation, two realities

Early-stage and SMEalerts to one inbox, act on the critical ones.
Enterpriseescalation chain, KRIs and risk register integration.

How the course runs

  • The obligation: where the responsibility comes from, cited by section.
  • Two realities: how it is met in a small organisation and in an enterprise.
  • The method: step-by-step practice with templates and edge cases.
  • Paired labs: complete the one matching your work, read the other.
  • Artefact and assessment: submit the artefact; a rubric and a short scenario quiz decide the certificate.