Third-Party and Vendor Risk Management Basics

Your organisation may not control every supplier — but you are still responsible for managing...

4.9(5)
88
2-4 Hours
20
Intermediate

About This Course

Your organisation may not control every supplier — but you are still responsible for managing the risks they bring. Third-party vendors support critical business functions such as technology, cloud services, payroll, logistics, cybersecurity, and professional services. However, these relationships can introduce significant operational, cyber, privacy, compliance, and reputational risks if not properly managed.

The Third-Party and Vendor Risk Management Basics course provides practical, Australia-focused training to help organisations identify, assess, and manage third-party risks throughout the vendor lifecycle. Participants will learn how to conduct vendor due diligence, classify supplier risks, assess cybersecurity and privacy controls, strengthen contracts, monitor vendor performance, and support business continuity.

This online course explores key third-party risk management practices aligned with Australian compliance expectations, including considerations under APRA CPS 230, the Privacy Act 1988, and operational resilience requirements. Through practical examples and workplace scenarios, learners will develop the skills to improve vendor oversight, strengthen governance, and reduce supplier-related risks.

Designed for risk managers, procurement professionals, compliance teams, IT leaders, business owners, and governance professionals, this course helps organisations build stronger supplier relationships while protecting critical operations, improving resilience, and maintaining regulatory confidence.

What You'll Learn

By completing this course, you will be able to:

  • Understand third-party and vendor risk management principles.
  • Classify vendors using a risk-based approach.
  • Conduct effective supplier due diligence and risk assessments.
  • Assess cyber, privacy, operational, and compliance risks.
  • Understand APRA CPS 230 and Australian vendor governance expectations.
  • Identify fourth-party and supply chain risks.
  • Strengthen contracts, controls, and vendor assurance processes.
  • Monitor vendor performance and incident management activities.
  • Support operational resilience and business continuity planning.
  • Build an effective third-party risk management framework.

Who should Take This Course

This course is ideal for:

  • Procurement Professionals
  • Vendor Managers
  • Risk Managers
  • Compliance Officers
  • Business Owners
  • Operations Managers
  • IT Managers
  • Cybersecurity Professionals
  • Internal Auditors
  • Governance Professionals
  • Supply Chain Managers
  • Company Directors

Career opportunities

Knowledge of third-party and vendor risk management is highly valued across procurement, governance, compliance, cybersecurity, operational risk, and supply chain management. As Australian organisations strengthen outsourcing oversight and operational resilience, professionals with vendor risk expertise continue to be in high demand.

This course can support career development in roles such as:

  • Third-Party Risk Manager
  • Vendor Manager
  • Procurement Manager
  • Supply Chain Manager
  • Risk Manager
  • Compliance Officer
  • Operations Manager
  • Internal Auditor
  • IT Risk Manager
  • Cybersecurity Manager
  • Governance Professional
  • Business Continuity Manager
  • Company Director
  • Business Owner
  • Operational Risk Specialist

Requirements


There are no formal prerequisites for this course. It is suitable for procurement professionals, compliance officers, risk managers, IT teams, business owners, operations managers, governance professionals, and anyone responsible for supplier or vendor management.

Certification

Certification

Upon successful completion of the course and final assessment, learners will receive a Digital Certificate from Australian Compliance Training. This certificate demonstrates practical knowledge of third-party risk management, vendor governance, supplier due diligence, and Australian compliance obligations.

Certification

Why Choose Us

  • Gain practical, workplace-ready knowledge of third-party and vendor risk management.
  • Understand Australia's regulatory expectations for supplier governance and operational resilience.
  • Learn how to identify, assess, and manage supplier, cyber, privacy, and operational risks.
  • Develop practical skills for vendor due diligence, contract management, and ongoing monitoring.
  • Strengthen your understanding of APRA CPS 230, Privacy Act obligations, and SOCI requirements.
  • Learn through realistic Australian workplace scenarios and practical case studies.
  • Study online at your own pace with flexible, self-paced learning from any device.
  • Complete knowledge assessments to reinforce learning and improve workplace confidence.
  • Build stronger supplier governance and business resilience.
  • Receive a Digital Certificate from Australian Compliance Training upon successful completion.

Compliance and Regulatory Alignment

This course supports awareness and understanding of Australian third-party risk management and governance requirements, including:

  • APRA CPS 230 – Operational Risk Management
  • Privacy Act 1988 (Cth)
  • Australian Privacy Principles (APPs)
  • Security of Critical Infrastructure (SOCI) Act 2018
  • ISO 31000 – Risk Management Guidelines
  • ISO 27001 – Information Security Management
  • Third-Party Risk Management (TPRM) Best Practices
  • Supplier Due Diligence and Vendor Governance Principles
  • Business Continuity and Operational Resilience Frameworks
  • Corporate Governance and Internal Control Practices
  • Cybersecurity Risk Management Principles

Course Curriculum

6 sections20 lectures2-4 Hours
▶ 2.1 APRA CPS 230
▶ 2.2 Privacy Duties
▶ 2.3 SOCI Obligations
▶ 2.4 Supplier Ethics
▶ Quiz
▶ 1.1 Third-Party Risk
▶ 1.2 Vendor Categories
▶ 1.3 Risk Ownership
▶ 1.4 Vendor Inventory
▶ Quiz
▶ 3.1 Risk Tiering
▶ 3.2 Data Checks
▶ 3.3 Cyber Checks
▶ 3.4 Fourth-Party Risk
▶ Quiz
▶ 4.1 Contract Clauses
▶ 4.2 Access Controls
▶ 4.3 Vendor Evidence
▶ 4.4 Incident Escalation
▶ Quiz
▶ 5.1 Scenario Testing
▶ 5.2 Exit Planning
▶ 5.3 Board Reporting
▶ 5.4 TPRM Operating Model
▶ Quiz

Frequently Asked Questions


Third-party risk management (TPRM) is the process of identifying, assessing, monitoring, and managing risks associated with suppliers, contractors, service providers, and other external business partners.


This course is suitable for procurement professionals, vendor managers, compliance officers, risk managers, operations managers, IT professionals, cybersecurity teams, business owners, and anyone responsible for supplier oversight.


Effective vendor risk management helps organisations reduce operational, cyber, privacy, financial, and compliance risks while supporting business continuity, regulatory compliance, and stronger supplier relationships.

The course covers key Australian frameworks including APRA CPS 230, the Privacy Act 1988, the Security of Critical Infrastructure (SOCI) Act, ISO 31000 risk management principles, and recognised vendor governance best practices.


This course helps organisations strengthen supplier governance, improve due diligence, reduce third-party risks, support operational resilience, enhance compliance, and build more secure and reliable vendor relationships.