What is a TPM statement? 

TPM Statement

A Third-Party Management (TPM) statement is a formal document prepared by an independent audit party. This statement provides insights into the control of security and privacy risks at vendors and service providers. The purpose of the statement is to give customers, auditors, and regulators an objective and qualitative judgment on the management of these risks. 

This statement usually includes a comprehensive description of the environment, context, and service in scope of the statement, control objectives, and measures taken to achieve those objectives. 

Need help with Third Party Management?

Our consultants are happy to help you.

Contact us

 

Why is a TPM statement important? 

A TPM statement is important in sectors where information security and privacy play a major role. With this statement, your organization objectively demonstrates that it complies with standards and regulations such as ISO 27001, NIST and AVG/GDPR.  

Furthermore, possessing a TPM statement can help strengthen your organization's reputation. It demonstrates that you are aware of digital risks and are actively working to manage them. 

What does a TPM statement look like? 

A qualitative TPM statement follows a clear and standardized structure. The document begins with a header stating who prepared it, which version it is, and how long the statement is valid. 

The introduction clarifies the purpose and specifies for whom the statement is intended, such as auditors, management and external regulators. The main sections typically include: 

  • Supplier OverviewNames, roles, and the importance of suppliers. 
  • Assessment method: Risk assessment such as risk matrices and due diligence processes. 
  • Results and conclusions: The effectiveness of measures against control objectives and any areas for improvement. 

In addition, organizations often receive additional recommendations to further improve their own risk management, although this is usually not shared externally. 

What are the benefits of a TPM statement? 

A TPM statement offers several key benefits for organizations: 

Saving on audit costs: Organizations do not have to have the same audits performed over and over again for different clients. This saves time and money. 

Clear communication With a TPM statement, you transparently demonstrate how effective your control measures are, which helps customers with faster assessment and onboarding. 

Commercial benefits: You can use the statement externally to attract potential customers and demonstrate your compliance with specific (legal) requirements. 

Strengthening market position By demonstrably managing your digital risks, you are stronger in negotiations and enhance your organization's reputation. 

Comply with regulations For certain sectors, such as specific parts of government and public institutions, it is mandatory to have a TPM statement for specific IT services. 

Who prepares the TPM statement? 

Drafting a TPM statement requires specific expertise and collaboration from different departments within your organization and external specialists such as IT auditors. Key stakeholders include: 

  • CISO of Information Security Team: Ultimately responsible for risk management. 
  • Compliance Officer of Legal Department: Monitors compliance with laws and guidelines. 
  • Procurement and Vendor Management: Provides essential information about vendors. 
  • Internal Audit and external IT auditors: Independently validate the statement. 

Our experienced IT auditors have extensive expertise in preparing TPM statements according to recognized standards such as SOC 2, ISAE 3402, NEN 7510, DigiD, ISO 27001 and other relevant frameworks. 

A well-drafted TPM statement provides your organization with the tools to effectively manage risks and communicate transparently. It not only increases confidence but also contributes to operational efficiency and compliance. Contact us for advice and discover how we can support your organization. 

    Want to learn more about a TPM statement? Follow us on social media.