Third-Party Risk Management Program Maturity Model and Assessment

If a regulator asked you tomorrow to prove your TPRM program is working, could you? Find out where you stand. Then close the gaps. 

Start assessment

5 Dimensions of Maturity

A Comprehensive View of Your Maturity

Vendor Inventory & Onboarding

How third parties are identified, onboarded, and tracked across the organization.

Connected Compliance Data

How TPRM connects to COI, gifts and entertainment, incident management, and broader risk systems.

Analytics & Insights

How data identifies risk patterns, informs decisions, and measures program effectiveness.

Screening & Monitoring

How sanctions, adverse media, ESG, and ownership risks are detected and acted on at onboarding and continuously.

Supply Chain Visibility

How far third-party oversight extends into sub-tier and indirect supplier relationships.

Take the Assessment

Get your TPRM maturity score in minutes

  • 10 questions
  • Covers all 5 dimensions of TPRM maturity
  • Personalized results and recommendations

If the embedded assessment does not load in your browser, open it in a new tab.

THE GAN INTEGRITY TPRM MATURITY MODEL

Five phases. A clear path forward

1

Informal

Vendor data in spreadsheets with no consistent due diligence or oversight.

2

Reactive

Assessments happen at onboarding, but monitoring is minimal and data is siloed.

3

Structured

Standardized workflows and centralized data, but disconnected from the broader compliance program.

4

Proactive

Continuous monitoring, connected risk signals, and AI-assisted screening across the full vendor portfolio.

5

Optimized

Predictive intelligence embedded in enterprise risk strategy, with board-level visibility and supply chain depth.

PROVEN RESULTS

What moving up the curve delivers

 

86%

reduced risk exposure vs. 50% for competitors

73%

increased employee satisfaction vs. 40% for competitors

55%

observed increase in ethical behavior vs. 39% for competitors

Resource

Get the full TPRM maturity guide

Detailed phase breakdowns, a side-by-side maturity comparison matrix, and real customer outcomes. 

tprm cover_gan

Customer Results

Real organizations, measurable progress

70% faster onboarding

Managing thousands of third parties, Clarios built a centralized TPRM program with GAN Integrity that cut onboarding time by 70%, reduced rework by 20%, and streamlined questionnaires by 37%, while earning recognition as one of the world's most ethical companies.

97% faster review time

Following its IPO, medmix needed to move fast. By replacing inherited systems with the GAN Integrity platform, medmix cut third-party review cycle times by 97%.

Consolidated oversight

Fragmented tools and growing complexity were pulling compliance teams away from high-priority work. One of the world's largest mining companies consolidated over 14 risk domains into a single third-party management platform.

Frequently Asked Questions

What is TPRM program maturity?

TPRM maturity describes how systematically an organization identifies, assesses, monitors and responds to risk across its third-party population. A mature program does not just screen vendors at onboarding. It monitors continuously, connects third-party risk signals to the broader compliance program, and produces evidence that the program is working. Most organizations sit at phase two or three of five: assessments happen but monitoring is minimal and risk data stays siloed from the rest of compliance.

How do I know what maturity level my TPRM program is at?

The fastest way is a structured assessment across the five core dimensions: vendor inventory and onboarding, screening and monitoring, connected compliance data, analytics and insights, and supply chain visibility. Each dimension has clear markers for each phase. Organizations at phase one rely on spreadsheets and handle risk reactively. Organizations at phase four have continuous monitoring, connected risk signals and AI-assisted screening. Most programs land at phase two or three: assessments at onboarding, limited ongoing monitoring, and data disconnected from COI and incident management.

What does the DOJ look for when evaluating a TPRM program?

The DOJ's Evaluation of Corporate Compliance Programs asks three core questions: Is the compliance program well-designed? Is it being implemented effectively? Does it work in practice? For third-party risk specifically, prosecutors look for risk-based due diligence proportionate to the level of risk, ongoing monitoring rather than point-in-time screening, documentation showing decisions were made and why, and evidence the program catches problems before they become violations. A spreadsheet-based program with no ongoing monitoring will not satisfy these criteria regardless of how thorough the initial screening was.

What is the difference between reactive and proactive TPRM?

Reactive TPRM treats third-party risk as a checklist at onboarding. Vendors are screened once, questionnaires are sent, and the file is closed. Risk changes. Ownership structures shift, individuals are added to watchlists, new adverse media emerges. But the program does not see it until the annual review. Proactive TPRM monitors the third-party population continuously, surfaces alerts when something changes, and connects screening results to COI disclosures, gifts records and hotline cases from the same entity. The difference is not effort. It is architecture.

How long does it take to move from one TPRM maturity phase to the next?

It depends on where you are starting and what is blocking you. Moving from Informal to Reactive, meaning getting vendor data centralized and assessment workflows in place, typically takes three to six months with the right platform. Moving from Reactive to Structured requires standardizing workflows and connecting data sources, which takes six to twelve months. The bigger moves require both technology and process change. The organizations that move fastest are usually those replacing a patchwork of point solutions with a single connected platform rather than trying to bolt integrations together.

What is sub-tier or supply chain visibility in TPRM?

Sub-tier visibility means understanding not just who your direct suppliers are but who supplies them. A manufacturer may screen its tier-one suppliers rigorously but have no visibility into the subcontractors those suppliers use in high-risk jurisdictions. UFLPA and CSDDD enforcement has made sub-tier visibility a regulatory requirement in some sectors, not just a best practice. Phase five TPRM programs map risk beyond the first tier and have mechanisms for identifying when sub-tier relationships create exposure.

What is the difference between TPRM and vendor management?

Vendor management focuses on commercial performance: delivery, service levels, contract compliance. TPRM focuses on risk: corruption, sanctions, modern slavery, data security, financial stability and reputational exposure. The two overlap but serve different purposes. The mistake most organizations make is treating TPRM as a procurement function. It is a compliance function. The evidence standard is different, the regulatory context is different, and the consequences of getting it wrong are different.

How does connected compliance data improve TPRM?

When TPRM runs in isolation from the rest of your compliance program, you can miss patterns that are only visible across programs. A third party that appears clean in screening may have employees who have filed COI disclosures involving that entity, or who have submitted gifts disclosures from the same vendor. A hotline case may name a supplier your TPRM team cleared six months ago. Connected compliance data surfaces these patterns automatically. Disconnected tools cannot. The information exists but no one sees it in the same place at the same time.

What metrics should a mature TPRM program track?

At minimum: coverage rate, meaning what percentage of third parties have been assessed and when; time-to-complete, meaning how long onboarding and reassessment takes; escalation rate, meaning what percentage of assessments flag issues requiring action; remediation close rate, meaning of the issues flagged how many were resolved and how quickly; and monitoring alert volume and resolution time. Board-level reporting should show risk distribution across the portfolio, trend lines, and evidence that the program identifies and responds to risk rather than just processing paperwork.

How often should third-party risk assessments be repeated?

Risk-based frequency is the right answer, not a fixed annual cycle. High-risk third parties in sensitive markets should be reassessed more frequently than low-risk domestic suppliers. Continuous monitoring fills the gaps between formal assessments for any tier. The DOJ ECCP is explicit that point-in-time screening is insufficient. Effective programs monitor continuously and reassess when material changes occur in the third party's profile. Many organizations still run annual cycles for all vendors regardless of risk level, which is a phase two behavior.

What is the ROI of a mature TPRM program?

The direct ROI case is enforcement avoidance. FCPA settlements average over $100 million, and the DOJ gives explicit credit for effective compliance programs in charging decisions. The indirect case is operational: mature programs reduce the time compliance teams spend on manual review, improve vendor onboarding speed, and reduce the rework that comes from incomplete or inconsistent screening. GAN Integrity customers have reduced review cycle times by 97% and onboarding time by 70%. The comparison point is not the cost of the platform. It is the cost of a breach, an enforcement action, or a reputational event traced to a third party your program should have flagged.

Can a small compliance team run a mature TPRM program?

Yes, with the right platform. Most phase one and two programs are not limited by team size. They are limited by tool architecture. A two-person compliance team using a connected platform with automated screening, risk scoring and continuous monitoring can run a more mature program than a ten-person team managing spreadsheets and manual questionnaire reviews. The platform does the work that scale requires. The team focuses on decisions and escalations, not data management.

 
 

Let's Get Started

Ready to assess your program?

Take the assessment to see where you stand — or talk to our team about building a more mature TPRM program with GAN Integrity.

Explore TPRM software