Corrective action: fixing the cause rather than the symptom
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
Third party risk management is mostly bookkeeping: a list of who you rely on, what each one holds, and what happens if they stop. The paperwork only matters because it forces those three answers.
Third party risk management is the practice of knowing which outside organisations your business depends on, what each of them can do to you if something goes wrong, and what you have agreed with them about it. It gets treated as a compliance exercise because that is usually when it starts — a customer sends a questionnaire, or an auditor asks for a supplier list — but the underlying question is operational and would be worth answering even if nobody ever asked.
The question is this: if any one of your suppliers disappeared tomorrow, or leaked your data, or raised their price by half, would you know within a day, and would you know what to do? For most small companies the honest answer is no, because nobody has ever written the list down.
Third party risk management fails most often at the first step, because people go looking for a methodology before they have an inventory. The inventory is the hard part and the useful part. Every organisation you pay, that holds your data, or that sits inside something you sell, goes on one list.
Most companies find between two and five times more third parties than they expected, and the surprises are rarely the big contracts. They are the small monthly subscriptions somebody expensed, which quietly hold customer data and were never reviewed by anyone.
Once the list exists, sort it. Not by spend — by consequence. A NOK 200-a-month tool that holds your entire customer list is a bigger risk than a NOK 50,000 supplier you could replace in a week. Three tiers is enough for most companies.
Supplier risk management questionnaires vary enormously, but the substance behind them is narrow. Does the supplier know where your data is. Do they have someone accountable for security. Do they tell you when something goes wrong, and how fast. Can you get your data out. Who do they in turn depend on — because their suppliers become yours whether you agreed to that or not.
That last point is where most of the unpleasant surprises live. A supplier who is entirely reliable can still take you down because the platform they run on failed. Ask critical suppliers who their critical suppliers are, and you often find three of yours concentrate on one provider.
Diversification sounds like advice for investors, but it is the single most practical output of third party risk management. When you have the list, group it by underlying provider rather than by vendor name. If your email, your file storage, your backups and your authentication all sit with one company, you do not have four suppliers. You have one, with four invoices.
That may still be the right choice — running everything in one place is cheaper and simpler, and simplicity has real value. The point is to make it a decision rather than an accident, and to know what the fallback is if that decision goes wrong.
A register reviewed once and forgotten is worse than none, because it creates confidence that is out of date. The maintenance is small if it is attached to something that already happens: a new supplier gets added when the first invoice is approved, and a departing one gets removed when access is revoked. Both of those are events somebody already handles.
Ettex Records is built for exactly this shape of thing — a structured list where each row is a supplier, with fields for tier, owner, data held, review date and links to the contract, so the register is one table rather than a spreadsheet somebody keeps a private copy of. Reviews and evidence live against the record instead of in an inbox.
What it does not do is assess anybody for you. There is no supplier scoring service behind it, no automatic feed of breach notifications, no questionnaire library that fills itself in. It holds the register and the review schedule; the judgement about whether a supplier is acceptable stays with you, and where a regulator or a customer contract sets specific requirements, those requirements govern rather than any template.
The practice of identifying the outside organisations your business depends on, assessing what each could do to you if it failed or was breached, and managing that exposure through contracts, monitoring and alternatives.
With an inventory. List every organisation you pay, that holds your data, or that sits inside something you deliver. Most companies find far more than they expected.
By consequence of failure rather than spend. What they hold, what breaks the day they stop, and how long a replacement would take.
The suppliers your suppliers depend on. They affect you whether or not you have a relationship with them, and they are the usual source of hidden concentration.
Annually for critical suppliers, less often for the rest — but the practical trick is attaching additions and removals to events that already happen, like invoice approval and access revocation.
Regulation makes it mandatory in some sectors, but the operational value — knowing your dependencies and your fallbacks — applies to any business. Where rules do apply, follow them rather than a generic template.
Third party risk management is not a framework problem. Write the list, sort it by what failure would cost, name an owner for the ones that matter, and check where they all quietly overlap.
A corrective action stops a problem recurring. Most of what gets recorded as one is a repair — the thing you do to the affected item, which changes nothing about the next occurrence.
A conflict of interest policy is mostly a register and a habit. The point is not to forbid overlapping interests but to have them written down before anyone has reason to ask.
A record of processing activities lists what personal data you hold, why, where it goes and how long you keep it. It is dull to build and it answers half the questions anyone will ever ask you.