Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Third-Party Risk

TPRM Dashboard KRIs: What to Show Management vs. the Board

Your TPRM program has two audiences with completely different information needs. Here's how to separate operational vendor risk metrics from board-level indicators — with sample KRIs, escalation thresholds, and a structure that survives examiner scrutiny.

By Rebecca Leung · May 29, 2026 ·
Table of Contents

TL;DR

  • The 2023 interagency third-party risk guidance separates board oversight from management implementation — your dashboard design should reflect that distinction
  • Board-level TPRM KRIs should cover concentration risk, critical vendor performance, program health, and escalated exceptions — not operational completion rates
  • Management-level KRIs track the operational detail: overdue reviews, unresolved findings, SLA exception trends, and fourth-party exposure signals
  • If your board and your TPRM team see the same dashboard, neither audience is getting what they need

Your TPRM dashboard has 47 metrics. It updates weekly. Your board sees it once a quarter, attached as an appendix to a 60-page risk report. By slide 38, three committee members are looking at their phones.

This is the wrong problem. The question isn’t how to get board members to read more slides. The question is whether your TPRM dashboard was ever designed for a board in the first place — or whether you’ve been presenting a management operations report to an oversight body and wondering why it doesn’t land.

The June 2023 Interagency Guidance on Third-Party Relationships: Risk Management is explicit about the separation. The board is responsible for oversight of third-party risk management programs. Management is responsible for implementation. Those aren’t cosmetic distinctions — they prescribe different information needs, different reporting frequencies, and different levels of aggregation. Your dashboard design should start there.

Why One Dashboard Doesn’t Work for Two Audiences

Most TPRM dashboards were built bottom-up. A vendor management team started tracking what they needed to manage their workflow — assessment completion rates, contract review queues, open questionnaire items — and that same view got promoted to the board report because there wasn’t a better one.

The result is a board that receives operational data it can’t act on and a management team that never built the tools to separate leading risk indicators from program activity metrics.

The distinction matters for three reasons:

Regulatory expectation. The interagency guidance specifically calls out that boards should receive information about concentration risk and critical third-party performance at an appropriate level of aggregation. “Appropriate level” is doing real work there — it means aggregated, not granular.

Decision relevance. A board’s function is oversight: setting risk appetite, approving exceptions to that appetite, holding management accountable for program health. Forty-seven operational metrics don’t serve that function. Four to six meaningful KRIs do.

Examiner defensibility. When an examiner asks to see your board-level TPRM reporting, they’re assessing whether your board actually performs its oversight function. A board summary that looks like a transposed management report signals that the board is receiving information, not performing oversight.

The Board-Level TPRM KRI Set

Board-level KRIs should answer one question: Is our third-party risk program operating within our risk appetite, and are there emerging concentrations or exceptions that require board attention?

That question maps to four KRI categories.

1. Concentration Risk

Concentration is the vendor risk the board understands best because it maps directly to strategic and liquidity risk concepts they already manage. A single critical vendor going down during their peak period, or a cloud provider outage, lands at the board — so the board should be monitoring the conditions that make that scenario more or less likely.

KRIWhat It MeasuresBoard-Level Threshold Guidance
Critical function single-vendor dependency% of a critical business function reliant on one third partyAmber: >50% reliance; Red: >70%
Cloud provider concentration% of critical workloads on one hyperscaler (AWS/Azure/GCP)Amber: >40%; Red: >60%
Top 3 vendor revenue/spend concentration% of TPRM budget or vendor spend in top 3 relationshipsTrack trend quarterly; flag if top 3 > 60%
Critical vendor exit dependency# of critical vendors without a viable exit planAmber: >2 without exit plans; Red: >4

2. Critical Vendor Performance

The board doesn’t need to know that Vendor X missed an SLA in week 14. The board needs to know whether the pattern of critical vendor performance is trending toward risk appetite breach.

KRIWhat It MeasuresBoard-Level Threshold Guidance
Critical vendor SLA breach rate (rolling 12 months)% of critical vendor SLAs missedGreen: <5%; Amber: 5–10%; Red: >10%
Critical vendor open incidents (unresolved >30 days)Count of unresolved vendor incidents above severity thresholdAmber: 2 or more; Red: 4 or more
Vendor regulatory action flagCritical vendors subject to enforcement or supervisory concernAny active flag: escalate immediately

The vendor regulatory action indicator should function as an out-of-cycle trigger. If a critical vendor receives an OCC consent order, a CFPB action, or a material safety-and-soundness concern, that’s board information — not waiting for the next quarterly report.

3. Program Health Against Risk Appetite

The board approved the risk appetite statement and the TPRM program structure. They need enough visibility to know whether management is actually operating within that framework.

KRIWhat It MeasuresBoard-Level Threshold Guidance
Critical vendor assessment completion rate% of critical/high-tier vendors with current (not overdue) assessmentsGreen: >95%; Amber: 85–95%; Red: <85%
High-risk exception volume (board-approved)Count of board-level risk exceptions approved for critical vendorsAny exception: report in narrative; Red if >2 open
Annual TPRM program review statusWhether program review has been completed within the last 12 monthsRed if overdue

4. Escalated Issues

Any issue that has been escalated above the TPRM team — because it breached a threshold, triggered an operational resilience concern, or required management escalation — belongs in the board summary. The board needs to know it was escalated, the current status, and whether management’s response is on track.

This is typically a narrative section, not a metric. But it’s the section boards read most carefully, and the section that most TPRM teams underinvest in.

The Management-Level TPRM KRI Set

Management KRIs track the operational detail that the board summary intentionally omits. These are the metrics your TPRM team needs to catch problems before they escalate — the leading indicators of the board-level KRIs above.

This is where critical vendor KRIs covering SLA breaches, incidents, and control failures belong. And where fourth-party exposure signals live.

Assessment and Review Operations

  • Overdue periodic assessments by tier: Count and % of tier-1, tier-2, and tier-3 vendors past their assessment due date. Board sees the completion rate; management sees the aging and the specific vendors at risk.
  • Questionnaire response aging: Days since questionnaire sent to vendors with no response. Amber at 20 business days; Red at 30.
  • Evidence receipt rate: % of vendors who returned required documentation (SOC 2, pen test, BCP) within required window.

Finding and Remediation Tracking

Vendor due diligence KRIs around missing evidence and overdue reviews track the operational inputs that determine program quality. At the management level, you’re tracking:

  • Open remediation items by vendor and severity: Count of open findings, broken out by severity, with aging. Red if any Critical or High finding is >90 days without a closure plan.
  • Reopened findings rate: % of “closed” vendor findings that were reopened because evidence failed validation or the issue recurred. Amber if >5% of closed findings reopen within 60 days.
  • Exception volume by approval tier: Count of exceptions approved at management level vs. escalated to board. Track quarter-over-quarter trend.

Fourth-Party and Subcontractor Signals

This is the area most TPRM programs underinvest in. Fourth-party risk — the risk from your vendor’s vendors — doesn’t show up in your assessment cycle unless you’re actively monitoring for it.

Management-level fourth-party KRIs include:

  • Critical subcontractor change notifications received: How many of your critical vendors notified you of a material change to their own vendor dependencies? If the answer is “we’ve never received one,” the KRI itself is the finding.
  • Fourth-party cloud concentration by critical vendor: Do multiple critical vendors depend on the same cloud provider? If AWS goes down, how many of your tier-1 vendors go with it?
  • Subcontractor SOC report carve-out volume: How many of your vendors’ SOC 2 reports contain carve-outs that shift subcontractor risk to you?

The Dashboard Architecture

The clearest structure separates the board and management views explicitly:

Board TPRM Summary (quarterly, 1-2 pages):

  • 5-6 headline KRIs with RAG (Red/Amber/Green) status
  • Concentration risk summary
  • Critical vendor performance trend (period-over-period)
  • Escalated issues narrative
  • Program health status against approved risk appetite

Management TPRM Dashboard (monthly):

  • Assessment completion and aging
  • Open findings by vendor, tier, and severity
  • Remediation tracking and exception volume
  • Fourth-party and subcontractor signals
  • Upcoming assessment calendar

TPRM Operations View (weekly/as-needed):

  • Individual vendor queue: outstanding questionnaires, pending evidence, open communications
  • Remediation task assignments and due dates
  • Escalation tracking for any Amber/Red items

KRI governance — who owns the metric, threshold, escalation, and remediation — applies here just as it does in operational risk. Every TPRM KRI should have a named data source, a named owner, a defined threshold, and a defined escalation path before it goes on any dashboard.

So What? The Exam Question You Need to Answer

When an examiner pulls your TPRM board reporting, they’re asking two questions: Does the board have appropriate visibility into third-party risk? And does management receive the operational detail needed to run the program?

The answers are not the same artifact. A board report that answers the second question is a management report — and it signals the board isn’t performing its oversight function. A management report that tries to answer the first question is too thin for effective TPRM operations.

Build the two-page board summary. Build the monthly management dashboard separately. Make sure the board summary has a clear escalation trigger for out-of-cycle reporting. And make sure every KRI on both reports has an owner who’s accountable for the data quality behind the number.

If you’re building or rebuilding your TPRM KRI program and need a starting point, the Third-Party Risk Management (TPRM) Kit includes pre-built vendor risk KRI templates, tiering frameworks, and quarterly reporting formats mapped to the interagency guidance. Access it here.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is a TPRM KRI dashboard?
A TPRM KRI dashboard is a reporting artifact that tracks leading indicators of third-party risk — metrics that signal developing problems before they become incidents. It is distinct from a vendor management operational report (which tracks SLA completion, assessment status, and open items) and from a board summary (which aggregates exposure concentration, program health, and escalated risk at a strategic level). Most programs need all three, layered to fit their audience.
What does the 2023 interagency third-party risk guidance say about board reporting?
The June 2023 Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17, Federal Reserve SR 23-04, FDIC FIL-29-2023) is explicit: the board is responsible for oversight of third-party risk management programs and should receive information at an appropriate level of aggregation to perform that oversight. Management is responsible for implementation and operational execution. The guidance specifically calls out concentration risk and critical third-party performance as areas requiring board-level visibility.
How many KRIs should go into a board-level TPRM report?
For most community banks and mid-size fintechs, four to six board-level KRIs is the right range. The board needs to understand concentration exposure, critical vendor performance, program health against risk appetite, and unresolved high-risk exceptions. More than six metrics tends to bury signal in operational noise. If you find yourself reporting fifteen vendor risk indicators to the board, you've given them a management report, not a board report.
What's the difference between a TPRM KRI and a TPRM KPI?
A KPI (Key Performance Indicator) measures how well your TPRM program is operating: assessment completion rates, contracts reviewed, onboarding cycle times. A KRI (Key Risk Indicator) measures whether vendor risk is trending toward a tolerance breach: a rising concentration ratio, a surge in unresolved SOC exceptions, a vendor declining security rating trend. KPIs tell you about your process; KRIs tell you about your risk exposure. Your board needs KRIs. Your TPRM team needs both.
What vendor risk KRIs should escalate automatically to the board?
Three categories warrant immediate board escalation regardless of reporting cycle: (1) any critical vendor incident that triggers your operational resilience impact tolerance, (2) a single-vendor or cloud concentration breach above your board-approved limit (typically 30-40% of a critical process), and (3) a regulatory action or safety-and-soundness concern against a critical third party. These should be in your escalation protocol as out-of-cycle reporting triggers, not waiting for the next quarterly committee.
Can I use the same dashboard for the board and for management?
Not effectively. Board-level TPRM KRIs should aggregate to exposure and risk appetite. Management-level TPRM KRIs should surface operational details — specific vendor exceptions, overdue reviews, open remediation items. A combined dashboard tends to serve neither audience well: too granular for the board to draw conclusions, too aggregated for the TPRM team to act on. The better design is a management dashboard that rolls up into a two-page board summary with five to six headline metrics and a narrative.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Third-Party Risk Management (TPRM) Kit

Complete vendor risk management lifecycle from initial due diligence to ongoing oversight.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.