<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What are the 5 stages of third party management?"
title: "What Are the 5 Stages of Third Party Management"
seoTitle: "The 5 Stages of Third-Party Risk Management"
summary: "The five stages of third-party management are planning and sourcing, due diligence and selection, contracting, ongoing monitoring, and termination or offboarding. The same lifecycle is often called the five pillars of vendor management. Most programs are strong at due diligence, weak at ongoing monitoring, and absent at offboarding, which is where access from departed vendors survives."
publishedAt: "2026-08-18"
keywords:
  - "5 stages of third party management"
  - "vendor management lifecycle"
  - "third party risk management"
  - "TPRM stages"
  - "5 pillars of vendor management"
  - "four third party risk types"
pillar: "Beyond SOC 2"
faqs:
  - question: "What are the five stages of third-party risk management?"
    answer: "Planning and sourcing, due diligence and selection, contracting, ongoing monitoring, and termination or offboarding. Some frameworks split contracting from onboarding, giving six, but the lifecycle is the same."
  - question: "What types of third-party risk are there?"
    answer: "Commonly cybersecurity, compliance and regulatory, operational, financial, and reputational. A single vendor usually presents several at once, which is why tiering by data access and business criticality works better than by category."
  - question: "Which stage do most programs get wrong?"
    answer: "Offboarding. Due diligence gets attention because it happens before money is spent. Offboarding happens after the relationship is over, nobody owns it, and the result is retained access, unreturned data, and vendors still listed in a register years later."
---

## What are the 5 stages of third party management?

The five stages are **planning and sourcing, due diligence and selection, contracting, ongoing monitoring, and termination or offboarding**. Together they describe a vendor relationship from before it exists to after it ends. The same lifecycle is often published as the five pillars of vendor management, and some frameworks split contracting from onboarding to make six, but the sequence does not change.

### The five stages

| Stage | What happens | Evidence it produces |
|---|---|---|
| **Planning and sourcing** | Define the need, identify candidates, set risk criteria | Requirements, approved vendor criteria |
| **Due diligence** | Assess security, compliance, and financial standing | Completed questionnaires, SOC 2 or ISO reports, review records |
| **Contracting** | Negotiate terms including security obligations | Signed contract, DPA, BAA where PHI is involved |
| **Ongoing monitoring** | Reassess on a cadence set by risk tier | Periodic review records, refreshed attestation reports |
| **Termination** | Revoke access, retrieve or delete data, close the record | Offboarding checklist, access revocation evidence |

## The two stages that fail

**Ongoing monitoring** fails because it has no natural trigger. Due diligence happens when someone wants to buy something, so it gets done. A reassessment twelve months later has nobody waiting on it. The usual result is a register full of vendors last reviewed on the day they were onboarded.

**Termination** fails worse, because it happens after anyone cares. Access is not revoked, data is not retrieved, and the vendor remains in the register indefinitely. This is where auditors find the most durable findings, since a departed vendor with live API credentials is a concrete exposure rather than a paperwork gap.

## Risk tiering is what makes the lifecycle affordable

Reviewing every vendor at the same depth is not achievable, and programs that try either stall or become theatre. Tiering by **data access and business criticality** is what makes it work:

- **Critical:** processes production data or customer PII, or an outage stops the business. Annual review, SOC 2 or ISO report required.
- **Moderate:** internal data, replaceable. Lighter review, longer cadence.
- **Low:** no sensitive data access. Record the vendor, review at renewal.

The four common risk categories a review considers are cybersecurity, compliance and regulatory, operational, and financial, with reputational often added as a fifth. Most real vendors present several at once, which is why tiering by access beats tiering by category.

## What SOC 2 and ISO 27001 test

- **SOC 2** CC9.2 covers vendor and business partner risk management. The auditor asks for the vendor inventory, the criteria used to assess them, and evidence that reviews happened on the stated cadence.
- **ISO 27001** Annex A 5.19 through 5.22 cover supplier relationships, agreements, ICT supply chain, and monitoring of supplier services.

Both test the cadence more than the depth. A program that reviews critical vendors annually and can show the records will do better than one with elaborate questionnaires that were only ever completed once.

The hard part is keeping the register current once the vendor count passes about thirty. See [vendor management](/product/vendors) for how vendors get discovered from your codebase and infrastructure config, risk-tiered, and put on a review cadence automatically.
