The classic five steps of risk management are identify, assess, evaluate or prioritize, treat or mitigate, and monitor. In a third party context that means finding your vendors, assessing their controls, ranking them by risk, applying safeguards or remediation, and watching them over time. Treating it as a continuous loop rather than a one-off keeps the program effective.
