You're now visiting the official Saudi
website of GLOMACS International

Third-Party Risk Management (TPRM)

An Interactive 5-Day Training Course

Third-Party Risk Management (TPRM)

Governing Third-Party Risk, Supplier Resilience & Extended Enterprise Exposure

NASBA
Scheduled Dates
Date Venue Fees
26 - 30 Oct 2026 London $ 7,500
19 - 23 Apr 2027 London $ 7,500
25 - 29 Oct 2027 London $ 7,500

Course Summary

The Third-Party Risk Management (TPRM) training course equips professionals with a comprehensive framework for identifying, evaluating, governing and overseeing risks associated with suppliers, vendors, service providers, technology partners and other third-party relationships. As organisations increasingly rely on outsourcing arrangements, cloud platforms, SaaS solutions and interconnected supply chains, disruptions involving third parties can lead to significant operational, financial, cyber, regulatory and reputational consequences. Effective third-party risk management therefore requires a coordinated governance approach that spans due diligence, contracting, monitoring, assurance and exit activities.

This training course explores the full third-party risk lifecycle from a practical and risk-based perspective. Participants will examine governance structures, accountability frameworks, supplier segmentation, due diligence processes, contractual safeguards, cyber and technology risks, fourth-party dependencies, supply chain resilience, ESG considerations and geopolitical exposures. The training course also reviews emerging areas of concern, including AI providers, digital concentration risk and evolving regulatory requirements. By the end of the learning experience, participants will be able to apply proportionate controls, enhance supplier resilience and support the advancement of a mature TPRM framework.

This Third-Party Risk Management (TPRM) training course will highlight:

  • Establishing governance structures and accountability for third-party risk management
  • Applying risk-based supplier classification, due diligence and onboarding practices
  • Managing cyber, cloud, SaaS, AI and fourth-party risk exposures
  • Improving supply chain resilience against operational and geopolitical challenges
  • Integrating ESG and responsible sourcing considerations into third-party oversight
  • Enhancing monitoring, assurance and executive reporting practices

Skills & Competencies

From this Third-Party Risk Management (TPRM) training course, participants will develop the following key skills and competencies:

  • Third-party governance and oversight
  • Supplier due diligence assessment
  • Risk-based vendor classification
  • Cyber and technology risk evaluation
  • Third-party monitoring and assurance
  • Executive risk reporting capabilities

Key Learning Outcomes

At the end of Third-Party Risk Management (TPRM) training course, you will learn to:

  • Establish a risk-based TPRM governance framework aligned with enterprise risk management
  • Apply supplier onboarding, due diligence and risk-tiering approaches
  • Assess cyber, cloud, AI, technology and fourth-party risks
  • Evaluate supply chain, ESG, geopolitical and concentration exposures
  • Implement monitoring, assurance and supplier performance oversight activities
  • Develop executive reporting processes and TPRM improvement roadmaps

How You Will Learn

This training course uses a blend of expert-led presentations, facilitated discussions, third-party risk scenarios, due diligence exercises, supplier assessment reviews and practical case studies. Participants will examine vendor classification techniques, risk assessment practices, cyber risk considerations, supply chain interdependencies, contractual safeguards, monitoring metrics and assurance methods. Particular emphasis is placed on applying controls that are proportionate to the risk profile and importance of individual third-party relationships.

Who should Attend?

This Third-Party Risk Management (TPRM) training course is designed for professionals involved in managing, evaluating or overseeing risks arising from suppliers, vendors and external business relationships, including:

  • Third-Party Risk Managers
  • Enterprise Risk Managers
  • Vendor and Supplier Risk Professionals
  • Procurement and Supply Chain Managers
  • Operational Risk Professionals
  • Compliance Professionals
  • Information Security and Cyber Risk Professionals
  • Technology Risk Managers
  • Business Continuity and Resilience Professionals
  • Internal Auditors
  • Contract and Commercial Managers
  • Governance and Assurance Professionals
Course Outline
Day 1

Building the Foundations of Third-Party Governance

This day explores the role of outsourcing, cloud services and SaaS environments in shaping third-party risk, together with governance frameworks, accountability structures, risk appetite considerations, board oversight responsibilities and relevant regulatory expectations. The topics covered will include:

  • Outsourcing, cloud and SaaS are reshaping third-party risk
  • Embedding TPRM into ERM and the Three Lines Model
  • Governance structures with clear accountability and ownership
  • Setting risk appetite for supplier relationships
  • Board oversight of the extended enterprise
  • Navigating DORA and sector-specific regulations
Day 2

Due Diligence, Onboarding and Governing the Supplier Base

This day explores the processes involved in supplier onboarding, risk-based due diligence, vendor segmentation, lifecycle risk management, supplier viability assessment and the incorporation of risk requirements within contractual arrangements. The topics covered will include:

  • Screening and onboarding vendors before contract award
  • Risk-proportionate due diligence frameworks
  • Tiering suppliers by risk exposure
  • Operational risk across the vendor lifecycle
  • Evaluating supplier financial health and viability
  • Embedding risk clauses into contracts and SLAs
Day 3

Managing Cyber, Technology and Digital Supply Chain Risk

This day explores approaches to managing cyber and technology-related risks, including cybersecurity assessments, cloud and SaaS risk models, concentration concerns, fourth-party dependencies, AI vendor exposures and resilience preparedness. The topics covered will include:

  • Cyber risk frameworks — ISO/IEC 27036, NIST SP 800-161
  • Cybersecurity due diligence questionnaires
  • Cloud and SaaS shared-responsibility risk models
  • ICT concentration and fourth-party exposure
  • AI vendor risk — data governance and model assurance
  • Coordinated incident response and resilience testing
Day 4

Supply Chain Resilience, ESG and Geopolitical Exposure

This day explores methods for strengthening supply chain resilience through dependency analysis, sourcing strategies, ESG oversight, responsible sourcing due diligence and the assessment of geopolitical and country-specific risks. The topics covered will include:

  • Mapping single points of failure and dependencies
  • Diversified sourcing and contingency planning
  • ESG risk frameworks across the supplier base
  • Modern slavery and responsible-sourcing due diligence
  • Geopolitical, sanctions and country-risk evaluation
  • Scenario planning for supply chain disruption
Day 5

Monitoring, Assurance, Reporting and Long-Term Maturity

This day explores the mechanisms required to sustain effective third-party oversight through monitoring, performance management, assurance activities, executive reporting, vendor exit planning and long-term maturity development. The topics covered will include:

  • Continuous monitoring built on Key Risk Indicators
  • Tracking vendor performance and SLA compliance
  • Third-party audits and independent assurance
  • Executive and board risk dashboards
  • Managing vendor offboarding and exit planning
  • Roadmap for continuous TPRM maturity
Certificates
  • Upon successful completion of this training course, GLOMACS Certificate will be awarded to the delegates. Continuing Professional Education credits (CPE): In accordance with the standards of the National Registry of CPE Sponsors, one CPE credit is granted per 50 minutes of attendance
Providers

Endorsed Education Provider

NASBA
Options & Brochure
Related Certificates
NASBA

Customisation & In-House Delivery

Delivering this training course in-house enables organisations to tailor third-party risk management practices to their specific operational environment, supplier ecosystem and risk priorities. Customisation supports the alignment of governance, due diligence, monitoring and resilience activities with organisational objectives, regulatory obligations and third-party risk challenges.

Why Choose Saudi GLOMACS?

Saudi GLOMACS is the official Saudi Arabian division of GLOMACS International (glomacs.com), delivering internationally recognised training courses both within Saudi Arabia and across international locations. Our training courses are aligned with the highest professional and institutional standards, supported by a strong understanding of the professional landscape in Saudi Arabia and access to global expertise.

Saudi GLOMACS enables professionals and organisations to strengthen leadership, capability, and long-term excellence through consistently high-quality learning experiences.

Official Saudi Presence

Official Saudi Arabian division of GLOMACS with established global credibility.

International Benchmarks

Internationally benchmarked training courses aligned with professional best practices.

Trusted Across Sectors

Trusted by professionals and institutions across public and private sectors.

Flexible Delivery

Training courses delivered within Saudi Arabia and across international locations.

Additional Benefits of this course for Organisations and Professionals in Saudi Arabia

Organisations & Professionals in KSA will have the following additional benefits from this Third-Party Risk Management (TPRM) training course:

  • Stronger oversight of third-party and supplier risks
  • Improved supplier due diligence consistency
  • Enhanced visibility of critical dependencies
  • Greater resilience against operational disruption
  • More effective monitoring and assurance practices
  • Better executive awareness of material exposures
Related Courses
Frequently Asked Question

Saudi GLOMACS combines three decades of global training experience with a clear focus on Saudi market relevance. This allows it to deliver training that is both internationally credible and locally applicable, across a broader range of disciplines than niche or single-focus providers.

Participants include professionals from public sector, semi-government, and private sector organisations, across a wide range of roles and industries. Attendees range from administrative and operational professionals to technical specialists, managers, and senior decision-makers.

Yes. Saudi GLOMACS designs and delivers bespoke in-house training tailored to organisational objectives, sector requirements, and workforce needs. Training can be delivered in Saudi Arabia or internationally, depending on requirements.

Courses delivered in Saudi Arabia are adapted to reflect local regulatory frameworks, organisational structures, sector conditions, and professional expectations. This ensures training is relevant, practical, and aligned with Saudi workplace realities.

No. Saudi GLOMACS delivers courses in Saudi Arabia and internationally, including delivery across Europe and Asia. This allows organisations and professionals to access training both locally and abroad.

No. While governance and leadership are part of the portfolio, Saudi GLOMACS delivers training across the entire business and professional lifecycle, including administrative, technical, legal, regulatory, and sector-specific training.

Saudi GLOMACS offers professional training across a wide range of disciplines, including administration, leadership and management, governance and regulation, law, oil and gas, energy, engineering, finance, digital technologies, and sector-specific specialisations.

Training supports professionals across all career stages, from operational roles to specialist and senior responsibilities.

GLOMACS has been delivering professional training for over thirty years, with courses delivered across Europe, the Middle East, Asia, and other international markets.

Saudi GLOMACS is a Saudi-based professional training provider delivering courses tailored to the Saudi market and applicable internationally. It operates within the global GLOMACS framework and draws on more than three decades of international training experience.

No. Our training courses are delivered globally through international locations and online platforms, enabling participants from Saudi Arabia and around the world to learn together. This global delivery approach ensures exposure to diverse perspectives, international best practices, and cross-cultural insights while maintaining strong relevance to regional and organisational needs.

View All Training Locations

Yes, in-house and customised strategy training courses are available to support organisations seeking tailored strategic capability development. These courses can be aligned with your industry context, organisational challenges, and long-term strategic objectives.

For further details or to discuss customisation requirements, you may call or WhatsApp +966 (54) 286 8546 or email [email protected] . You can also submit a detailed enquiry through our in-house training page at: https://sa.glomacs.com/in-house-seminars

If you would like further information about these training courses, our team is available to provide professional guidance and support. We are pleased to assist with course selection, the registration process, and any other related enquiries.

For personalised assistance or detailed enquiries, please contact our team on +966 (54) 286 8546 or email us at [email protected]

Related Categories & Certificates