Every third party should enter the inventory and receive an initial risk classification. The depth and frequency of assessment should then be proportionate to the relationship's access, criticality, data exposure and regulatory impact.
FAQ
Third-Party Risk Management