Feature Third-Party Risk
TPRM Dashboard KRIs: What to Show Management vs. the Board
Your TPRM program has two audiences with completely different information needs. Here's how to separate operational vendor risk metrics from board-level indicators — with sample KRIs, escalation thresholds, and a structure that survives examiner scrutiny.
Table of Contents
TL;DR
- The 2023 interagency third-party risk guidance separates board oversight from management implementation — your dashboard design should reflect that distinction
- Board-level TPRM KRIs should cover concentration risk, critical vendor performance, program health, and escalated exceptions — not operational completion rates
- Management-level KRIs track the operational detail: overdue reviews, unresolved findings, SLA exception trends, and fourth-party exposure signals
- If your board and your TPRM team see the same dashboard, neither audience is getting what they need
Your TPRM dashboard has 47 metrics. It updates weekly. Your board sees it once a quarter, attached as an appendix to a 60-page risk report. By slide 38, three committee members are looking at their phones.
This is the wrong problem. The question isn’t how to get board members to read more slides. The question is whether your TPRM dashboard was ever designed for a board in the first place — or whether you’ve been presenting a management operations report to an oversight body and wondering why it doesn’t land.
The June 2023 Interagency Guidance on Third-Party Relationships: Risk Management is explicit about the separation. The board is responsible for oversight of third-party risk management programs. Management is responsible for implementation. Those aren’t cosmetic distinctions — they prescribe different information needs, different reporting frequencies, and different levels of aggregation. Your dashboard design should start there.
Why One Dashboard Doesn’t Work for Two Audiences
Most TPRM dashboards were built bottom-up. A vendor management team started tracking what they needed to manage their workflow — assessment completion rates, contract review queues, open questionnaire items — and that same view got promoted to the board report because there wasn’t a better one.
The result is a board that receives operational data it can’t act on and a management team that never built the tools to separate leading risk indicators from program activity metrics.
The distinction matters for three reasons:
Regulatory expectation. The interagency guidance specifically calls out that boards should receive information about concentration risk and critical third-party performance at an appropriate level of aggregation. “Appropriate level” is doing real work there — it means aggregated, not granular.
Decision relevance. A board’s function is oversight: setting risk appetite, approving exceptions to that appetite, holding management accountable for program health. Forty-seven operational metrics don’t serve that function. Four to six meaningful KRIs do.
Examiner defensibility. When an examiner asks to see your board-level TPRM reporting, they’re assessing whether your board actually performs its oversight function. A board summary that looks like a transposed management report signals that the board is receiving information, not performing oversight.
The Board-Level TPRM KRI Set
Board-level KRIs should answer one question: Is our third-party risk program operating within our risk appetite, and are there emerging concentrations or exceptions that require board attention?
That question maps to four KRI categories.
1. Concentration Risk
Concentration is the vendor risk the board understands best because it maps directly to strategic and liquidity risk concepts they already manage. A single critical vendor going down during their peak period, or a cloud provider outage, lands at the board — so the board should be monitoring the conditions that make that scenario more or less likely.
| KRI | What It Measures | Board-Level Threshold Guidance |
|---|---|---|
| Critical function single-vendor dependency | % of a critical business function reliant on one third party | Amber: >50% reliance; Red: >70% |
| Cloud provider concentration | % of critical workloads on one hyperscaler (AWS/Azure/GCP) | Amber: >40%; Red: >60% |
| Top 3 vendor revenue/spend concentration | % of TPRM budget or vendor spend in top 3 relationships | Track trend quarterly; flag if top 3 > 60% |
| Critical vendor exit dependency | # of critical vendors without a viable exit plan | Amber: >2 without exit plans; Red: >4 |
2. Critical Vendor Performance
The board doesn’t need to know that Vendor X missed an SLA in week 14. The board needs to know whether the pattern of critical vendor performance is trending toward risk appetite breach.
| KRI | What It Measures | Board-Level Threshold Guidance |
|---|---|---|
| Critical vendor SLA breach rate (rolling 12 months) | % of critical vendor SLAs missed | Green: <5%; Amber: 5–10%; Red: >10% |
| Critical vendor open incidents (unresolved >30 days) | Count of unresolved vendor incidents above severity threshold | Amber: 2 or more; Red: 4 or more |
| Vendor regulatory action flag | Critical vendors subject to enforcement or supervisory concern | Any active flag: escalate immediately |
The vendor regulatory action indicator should function as an out-of-cycle trigger. If a critical vendor receives an OCC consent order, a CFPB action, or a material safety-and-soundness concern, that’s board information — not waiting for the next quarterly report.
3. Program Health Against Risk Appetite
The board approved the risk appetite statement and the TPRM program structure. They need enough visibility to know whether management is actually operating within that framework.
| KRI | What It Measures | Board-Level Threshold Guidance |
|---|---|---|
| Critical vendor assessment completion rate | % of critical/high-tier vendors with current (not overdue) assessments | Green: >95%; Amber: 85–95%; Red: <85% |
| High-risk exception volume (board-approved) | Count of board-level risk exceptions approved for critical vendors | Any exception: report in narrative; Red if >2 open |
| Annual TPRM program review status | Whether program review has been completed within the last 12 months | Red if overdue |
4. Escalated Issues
Any issue that has been escalated above the TPRM team — because it breached a threshold, triggered an operational resilience concern, or required management escalation — belongs in the board summary. The board needs to know it was escalated, the current status, and whether management’s response is on track.
This is typically a narrative section, not a metric. But it’s the section boards read most carefully, and the section that most TPRM teams underinvest in.
The Management-Level TPRM KRI Set
Management KRIs track the operational detail that the board summary intentionally omits. These are the metrics your TPRM team needs to catch problems before they escalate — the leading indicators of the board-level KRIs above.
This is where critical vendor KRIs covering SLA breaches, incidents, and control failures belong. And where fourth-party exposure signals live.
Assessment and Review Operations
- Overdue periodic assessments by tier: Count and % of tier-1, tier-2, and tier-3 vendors past their assessment due date. Board sees the completion rate; management sees the aging and the specific vendors at risk.
- Questionnaire response aging: Days since questionnaire sent to vendors with no response. Amber at 20 business days; Red at 30.
- Evidence receipt rate: % of vendors who returned required documentation (SOC 2, pen test, BCP) within required window.
Finding and Remediation Tracking
Vendor due diligence KRIs around missing evidence and overdue reviews track the operational inputs that determine program quality. At the management level, you’re tracking:
- Open remediation items by vendor and severity: Count of open findings, broken out by severity, with aging. Red if any Critical or High finding is >90 days without a closure plan.
- Reopened findings rate: % of “closed” vendor findings that were reopened because evidence failed validation or the issue recurred. Amber if >5% of closed findings reopen within 60 days.
- Exception volume by approval tier: Count of exceptions approved at management level vs. escalated to board. Track quarter-over-quarter trend.
Fourth-Party and Subcontractor Signals
This is the area most TPRM programs underinvest in. Fourth-party risk — the risk from your vendor’s vendors — doesn’t show up in your assessment cycle unless you’re actively monitoring for it.
Management-level fourth-party KRIs include:
- Critical subcontractor change notifications received: How many of your critical vendors notified you of a material change to their own vendor dependencies? If the answer is “we’ve never received one,” the KRI itself is the finding.
- Fourth-party cloud concentration by critical vendor: Do multiple critical vendors depend on the same cloud provider? If AWS goes down, how many of your tier-1 vendors go with it?
- Subcontractor SOC report carve-out volume: How many of your vendors’ SOC 2 reports contain carve-outs that shift subcontractor risk to you?
The Dashboard Architecture
The clearest structure separates the board and management views explicitly:
Board TPRM Summary (quarterly, 1-2 pages):
- 5-6 headline KRIs with RAG (Red/Amber/Green) status
- Concentration risk summary
- Critical vendor performance trend (period-over-period)
- Escalated issues narrative
- Program health status against approved risk appetite
Management TPRM Dashboard (monthly):
- Assessment completion and aging
- Open findings by vendor, tier, and severity
- Remediation tracking and exception volume
- Fourth-party and subcontractor signals
- Upcoming assessment calendar
TPRM Operations View (weekly/as-needed):
- Individual vendor queue: outstanding questionnaires, pending evidence, open communications
- Remediation task assignments and due dates
- Escalation tracking for any Amber/Red items
KRI governance — who owns the metric, threshold, escalation, and remediation — applies here just as it does in operational risk. Every TPRM KRI should have a named data source, a named owner, a defined threshold, and a defined escalation path before it goes on any dashboard.
So What? The Exam Question You Need to Answer
When an examiner pulls your TPRM board reporting, they’re asking two questions: Does the board have appropriate visibility into third-party risk? And does management receive the operational detail needed to run the program?
The answers are not the same artifact. A board report that answers the second question is a management report — and it signals the board isn’t performing its oversight function. A management report that tries to answer the first question is too thin for effective TPRM operations.
Build the two-page board summary. Build the monthly management dashboard separately. Make sure the board summary has a clear escalation trigger for out-of-cycle reporting. And make sure every KRI on both reports has an owner who’s accountable for the data quality behind the number.
If you’re building or rebuilding your TPRM KRI program and need a starting point, the Third-Party Risk Management (TPRM) Kit includes pre-built vendor risk KRI templates, tiering frameworks, and quarterly reporting formats mapped to the interagency guidance. Access it here.
Sources:
- OCC Bulletin 2023-17: Third-Party Relationships: Interagency Guidance on Risk Management
- Federal Register — Interagency Guidance on Third-Party Relationships: Risk Management
- FDIC FIL-29-2023: Interagency Guidance on Third-Party Relationships
- VendorCentric: Incorporating KRIs into Your Third-Party Risk Management Reporting
- Mitratech: 25 Most Important KPIs and KRIs for TPRM
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a TPRM KRI dashboard?
What does the 2023 interagency third-party risk guidance say about board reporting?
How many KRIs should go into a board-level TPRM report?
What's the difference between a TPRM KRI and a TPRM KPI?
What vendor risk KRIs should escalate automatically to the board?
Can I use the same dashboard for the board and for management?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Third-Party Risk Management (TPRM) Kit
Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.
◆ Keep reading
Related posts.
Third-Party Risk
Third-Party Risk Management Lifecycle RACI: Fix the Handoffs Between Procurement, Security, Legal, Business Owners, and Risk
A TPRM lifecycle RACI that assigns clear ownership at each stage — planning, due diligence, contracting, onboarding, monitoring, and offboarding — so findings don't fall between functions.
Jul 24, 2026
Third-Party Risk
Vendor Due Diligence Without a SOC 2: What Evidence Can Actually Substitute
A vendor due diligence checklist for evaluating security evidence when a vendor has no SOC 2 report, with a risk-based substitution matrix.
Jul 23, 2026
Third-Party Risk
Three Vendors, One Existential Risk: What the OCC's Community Bank Core Provider RFI Actually Asked
The OCC published Bulletin 2025-39 asking community banks hard questions about their relationships with Fiserv, FIS, and Jack Henry. The questions reveal exactly what examiners are now checking — and what most TPRM programs haven't addressed.
Jul 23, 2026