Third-party risk management (TPRM) is the discipline to identify, assess, and monitor the operational, regulatory, reputational, and data-related risk a vendor or outsourcing partner introduces to your institution.
Regulators now expect this to be documented, which puts real weight on what's written into vendor and outsourcing agreements.
Contract review is where TPRM enforcement happens in practice. A playbook can flag a missing vendor risk assessment clause, an inadequate data security provision, or a liability cap that doesn't match your institution's risk constraints, before the agreement gets signed.
LegalOn's review flags these deviations against your own standards (after you build custom playbooks) rather than providing generic red flags that don't reflect your institution's TPRM program.