Third-Party Risk Lifecycle
- Onboarding, due diligence and continuous monitoring
- Inherent risk assessment and tiering
- Residual risk scoring and third-party exit
- Risk exception tracking, approvals and escalation
Rohan Kalyan · TPRM Portfolio Lead, Deloitte USI
From assessment execution to risk-led portfolio ownership.
Owning the end-to-end TPRM lifecycle — onboarding, due diligence, continuous monitoring, exception tracking and third-party exit — across global technology, software and BFSI supplier portfolios, and validating GenAI-generated risk assessments as the domain subject-matter expert.
Assessor → QA → Team lead → Independent lead → Portfolio lead
Career totals across the Deloitte USI tenure. Per-engagement figures — including 5,500+ assessments on a single program and a 57% turnaround reduction — are stated inside the case studies below, each scoped to its own engagement.
01 — Expertise
Each capability below is drawn from work actually performed on client engagements, not from framework familiarity.
02 — Career progression
Responsibility moved from executing assessments, to assuring their quality, to leading teams, to owning a supplier portfolio answerable directly to the client.
Executed reputational and contractual compliance assessments of business partners as third parties entered the client's ecosystem week over week.
Automated weekly intake and redesigned the assessment workflow, more than halving turnaround on that program. In parallel, mapped the privacy regulatory baseline into an assessable requirement framework with direct client stakeholders.
Ran privacy and cybersecurity walkthroughs for third-party developers, then moved into QA review and PMO coordination — accountable for the quality of other people's assessments as well as my own.
Led deep-dive control assessments of ads measurement partners at roughly sixteen hours per third party, directing a three-person assessment team from evidence validation through severity reporting, remediation and SLA monitoring.
Progressed inside the enterprise TPRM program from assessor to QA to lead for three client-facing workstreams, and took portfolio-level ownership of the end-to-end lifecycle — inherent risk through due diligence, continuous monitoring, exception tracking and third-party exit. Advises Chief Control Office, Compliance, Legal and Risk stakeholders, and concurrently led a separate client's assessments independently.
Acting as TPRM subject-matter expert on an internal GenAI assessment accelerator: validating AI-generated assessment responses against source evidence, identifying the failure modes that undermine them, and feeding QA refinements back into the tool. AI-driven automation raised vendor onboarding efficiency by a quarter.
Also supported cost, revenue and recovery data analysis for a separate client in 2022 — high-volume dataset work, listed here as supporting experience rather than a flagship engagement.
03 — Selected work
Client identities are anonymised. Every figure is scoped to the engagement it belongs to. Where a detail was not documented it has been left out rather than estimated.
Ownership of the end-to-end third-party risk lifecycle across a global portfolio of technology, software and network suppliers for Fortune 500 and BFSI clients — onboarding through due diligence, continuous monitoring, exception tracking and third-party exit, with the risk and control framework governance that holds it together.
Governance boundary. Risk profiles were maintained, findings evidenced, exceptions tracked and escalations raised. Final risk acceptance remained with the client.
Progressed from assessor to QA to lead of three client-facing workstreams inside the client's enterprise TPRM program, owning risk from inherent rating through residual score and remediation.
Governance boundary. Findings and severity ratings were assessed, evidenced and reported. The decision to accept, mitigate or exit each risk remained with the client.
Sixteen-hour technical control assessments of measurement partners, leading a three-person team from evidence validation through remediation closure and SLA monitoring.
Privacy and cybersecurity walkthroughs of third-party developers, moving from assessor into QA review and PMO coordination.
High-volume reputational and contractual compliance assessment of business partners, rebuilt into a faster, automated intake process.
Translated privacy regulation into an assessable requirement framework, built with client stakeholders to survive future regulatory change.
Led third-party assessments for a separate client without senior oversight, and designed the pointed assessment framework used to run them.
Included as evidence of independent ownership and framework design. The engagement was deliberately small and is not presented as a volume achievement.
04 — Method
Two sequences run at once. The lifecycle governs the relationship from onboarding to exit; the assessment sequence governs what happens inside any single risk review.
The relationship — third-party lifecycle
The review — inside a single assessment
What the third party does, what data and systems it touches, and how the business depends on it.
Exposure before any control is credited — data sensitivity, criticality, access and regulatory reach.
The controls actually claimed, assessed against ISO 27001, NIST, GDPR and PCI-DSS expectations.
Whether the artefacts support the claim. A policy is not a control; a control without evidence is not assurance.
What exposure remains once validated controls are applied to the inherent rating.
Severity rated, owners agreed, progress monitored against SLA, and what stays open escalated.
05 — GenAI & TPRM
Deloitte internal · GenAI TPRM Accelerator · 2025 – Present
My role TPRM subject-matter expert, evidence validation and output QA. Not model engineering — the contribution is the domain judgment that tells you when an AI-generated risk assessment is wrong.
Third-party evidence and documentation
GenAI analysis of the submitted evidence
AI-generated TPRM assessment response
Every response tested back against the source evidence
Failure modes identified and fed back
Refinements returned to the tool and re-tested
Assessment output that is evidence-backed and defensible
The value is not that a model can draft a risk assessment. It is that someone who has run several thousand of them can tell when the draft is wrong, name why, and make the next one defensible.
06 — About
I am a Senior Consultant and TPRM Portfolio Lead at Deloitte USI, working across third-party risk, cybersecurity and technology risk. Based in Gurgaon, India.
My work started in high-volume assessment delivery — several thousand third-party assessments and the process redesign that made them faster — then moved into quality assurance and PMO responsibility, then into deep-dive control assessments leading a three-person team through remediation. I now own the end-to-end TPRM lifecycle across a global portfolio of technology, software and network suppliers for Fortune 500 and BFSI clients: onboarding, due diligence, continuous monitoring, exception tracking and third-party exit.
That means maintaining complete risk profiles rather than issuing point-in-time reports, and working directly with Chief Control Office, Compliance, Legal, Risk and Control Assurance stakeholders — including support for global regulatory requests and examinations.
Alongside that I am the TPRM subject-matter expert on an internal GenAI assessment accelerator, validating AI-generated assessment output against source evidence and identifying the failure modes that make it unreliable.
Download résuméCertifications held
In progress
Frameworks & standards
Platforms
Recognition
Education
Languages
07 — Contact
Third-party and vendor risk, technology risk, cybersecurity GRC, financial-services risk and AI-enabled risk programs.