Skip to main content
← All controls
ID.SC-4 / A.15.1.3 NIST Cybersecurity Framework v1.1

Do you have defined KPIs for TPRM (cycle time, exception rate, reassessment compliance, finding remediation)?

Demonstrate that the organization has documented, actively tracked, and reported measurable KPIs for TPRM program efficiency and effectiveness, including cycle time, exception rates, reassessment compliance, and remediation velocity.

Description

What this control does

This control requires organizations to establish and monitor quantitative Key Performance Indicators (KPIs) for their Third-Party Risk Management (TPRM) program, specifically tracking cycle time (duration from initiation to completion of assessments), exception rate (frequency of approved deviations from standard requirements), reassessment compliance (adherence to scheduled periodic reviews), and finding remediation (time to close identified vulnerabilities or gaps). These metrics enable management to identify process bottlenecks, resource constraints, and systemic compliance weaknesses in the vendor risk lifecycle. Without defined KPIs, TPRM programs operate reactively, lack accountability, and cannot demonstrate continuous improvement or board-level oversight effectiveness.

Control objective

What auditing this proves

Demonstrate that the organization has documented, actively tracked, and reported measurable KPIs for TPRM program efficiency and effectiveness, including cycle time, exception rates, reassessment compliance, and remediation velocity.

Associated risks

Risks this control addresses

  • Undetected degradation of TPRM program performance allows high-risk vendors to operate without timely assessment or oversight
  • Excessive exception approvals without tracking enable systematic bypassing of security standards across the vendor portfolio
  • Failure to monitor reassessment compliance results in outdated risk profiles and expired security validations for critical third parties
  • Prolonged remediation cycles for vendor findings leave exploitable vulnerabilities in supply chain components
  • Inability to demonstrate TPRM effectiveness to regulators during examinations results in enforcement actions or consent orders
  • Resource allocation decisions made without empirical data lead to chronic understaffing and perpetual backlogs in vendor reviews
  • Executive leadership lacks visibility into TPRM health metrics, preventing strategic risk-based decisions about third-party relationships

Testing procedure

How an auditor verifies this control

  1. Request the current TPRM KPI framework documentation, including definitions, calculation methodologies, target thresholds, and reporting frequency for each metric
  2. Obtain the most recent 12 months of TPRM KPI reports or dashboards showing actual measurements for cycle time, exception rate, reassessment compliance, and finding remediation
  3. Select a sample of 10-15 third-party assessments completed within the review period and independently calculate cycle time by comparing initiation and completion timestamps against reported metrics
  4. Review the exception management log or system to verify that exception rates are accurately calculated and categorized by risk level, business unit, or vendor type
  5. Cross-reference the vendor inventory against the reassessment schedule to validate compliance percentage calculation, identifying any vendors overdue for periodic review
  6. Examine finding remediation tracking records for a sample of 8-10 vendor-related findings, verifying time-to-closure matches reported remediation KPIs and validating closure evidence
  7. Interview TPRM program leadership to confirm KPIs are reviewed in governance meetings, trigger escalation workflows when thresholds are breached, and inform process improvement initiatives
  8. Verify that KPI data is communicated to executive leadership or board-level committees through regular reporting mechanisms such as quarterly risk dashboards or annual program assessments
Evidence required Auditors collect TPRM KPI definition documents, 12 months of KPI tracking reports or dashboard exports showing trend data, vendor assessment records with timestamps for cycle time validation, exception approval logs with categorization and volume data, reassessment compliance schedules cross-referenced against vendor inventory, finding remediation tickets or workflow records with closure dates, and governance meeting minutes or executive reports demonstrating KPI review and action. Screenshots of automated dashboards, data extracts from GRC platforms showing metric calculations, and email trails documenting threshold breaches or corrective actions provide additional corroboration.
Pass criteria The control passes if documented KPIs for TPRM cycle time, exception rate, reassessment compliance, and finding remediation are defined with clear calculation methodologies, actively tracked with at least quarterly reporting over the past 12 months, independently validated calculations match reported metrics within 10% variance, and evidence confirms KPIs are reviewed by management with documented actions taken in response to performance gaps.