Information Security Group
|
Services > Third Party Risk

Third Party Risk Management

As Tech Mahindra engages with suppliers providing IT services and products, it is necessary that the risks involved in such relationships are identified and mitigated, as necessary. Third-Party Risk Management (TPRM) is the process of analyzing and minimizing risks associated with suppliers providing IT services and products to TechM and their access to information, IT assets, IT infrastructure and facilities of TechM and/ or its Client information.

Important Note: Some clients prohibit further subcontracting of their work while some allow it based on prior approval. From a compliance perspective it is therefore necessary that the Project Manager should check if such clauses exist in the client agreement and proceed accordingly.

TPRM Lifecycle Process flow: Phase Details PM Actions
Security assessment for new supplier
  • Supplier assessment Checklist
  • Security Certification
  • Web risk assessment
Supplier onboarding and contracting
  • Valid Contract/MSA
  • Organisational level NDA
  • Privacy impact assessment
Supplier compliance and Monitoring
  • Compliance regularly reviewed by ISG
  • Security Audit
  • Supplier annual Risk assessment
Supplier Termination
  • Return of Assets
  • Revocation of logical and physical assess
  • Data archival/deletion asper agreement sign

For any queries write to : ISGTPSRM ISGTPSRM@TechMahindra.com


Copyright © Tech Mahindra Limited. All Rights Reserved