ISACA Accredited·NASBA CPE Eligible·Now enrolling

Third-party risk management training and ISACA boot camps

Practical third-party risk management training and exam-ready ISACA certification boot camps, online or in-person, with skills you or your team can use the next day.

Where to start

Risk work you can act on the same afternoon

From someone’s first week in the role to the gaps in a program you have run for years.

  • Foundations, fast. The full vendor lifecycle in about three hours, for anyone who touches a vendor, not just the risk team. Why TPRM Matters
  • Specialist topics, not just the basics. AI vendors, non-traditional relationships, and audit-side scope for CPAs. Risk Tide Core
  • Depth when you own the program. In-depth and applied, or two half-days of live practice with peers. Risk Tide Deep Dive Risk Tide Labs
  • A platform or process just went live. Training built on your real screens and workflow, hosted in the LMS you already run. Post-implementation
  • Written by someone who has built these programs, not assembled from a framework.

ISACA certificationsBest for

Five credentials, from an Accredited Training Organization

AAISM, ISACA Advanced in AI Security Management AI security pros CISA, Certified Information Systems Auditor, an ISACA certification IT auditors CISM, Certified Information Security Manager, an ISACA certification Security managers CRISC, Certified in Risk and Information Systems Control, an ISACA certification IT risk pros CGEIT, Certified in the Governance of Enterprise IT, an ISACA certification Governance leaders

Every boot camp includes the exam voucher and a free retake.

Prefer to study at your own pace? Self-paced courses for all five credentials, from $1,350. See self-paced options

Accreditation is the standard. Instruction is the difference.

Boot camps are taught by a certified ISACA instructor who has run the programs these certifications describe, not just the exam.

Compare all five

Training a team, or a whole organization?

Annual TPRM programs built around your business, post-implementation training on your own screens after a platform goes live, and private ISACA cohorts on your format and schedule.

Garit Gemeinhardt, Co-Founder and Head of Learning Experiences

“Most risk training teaches you what risk is. We teach you what to do with it.”

Garit Gemeinhardt · Co-Founder & Head of Learning Experiences
A quick intro

See how we sharpen your third-party risk team

One minute on what makes Risk Tide different: practical, practitioner-built training your team can use the next day.

Practitioner-built Scenario-based Use it the next day

New from ISACA

AAISM, the first credential built for AI security management

AI landed in every security program before anyone finished writing the playbook. AAISM is ISACA’s answer, and Risk Tide is an Accredited Training Organization for it.

  • AI Governance and Program Management
  • AI Risk Management
  • AI Technologies and Controls

The boot camp works straight through ISACA’s AAISM exam content outline, with each of the three job-practice domains weighted as it is on the exam.

The platform is live. The team still is not.

Implementing a third-party risk platform does not train anyone to use it. We build the course on your real screens and your workflow, hosted in the LMS you already run.

  • Your screens, your terminology, recorded walkthroughs of the real workflow rather than a generic product tour.
  • Scenario checks from your own process, with a correct answer required to move on.
  • Assign by group and track completion in the LMS you already report from.

“Risk Tide Solutions is a leader in understanding and addressing third-party risk management.”

Robert H. · Lab Director
A course lesson titled Locating an Assigned Review, with the module list on the left and a video walkthrough of the vendor risk platform

A real lesson from a demo build, walking through the platform screen by screen. Yours is created on your own system, with your branding and your terminology.

Serious training you can actually use

Our TPRM training carries NASBA-eligible CPE, and every certificate shows the hours if you report the time to ISACA as self-study. Our ISACA certification boot camps are a separate track, delivered as an ISACA Accredited Training Organization.

ISACA Accredited Training Organization Accredited for ISACA boot camps
NASBA National Registry of CPE Sponsors Registered for CPE on TPRM training

Written by a practitioner

Every course is written by someone who has built these programs, not assembled from a framework by someone who has only read about them.

Use it the next day

Real scenarios, checklists and language you can hand to a stakeholder and apply to your program right away.

CPE that counts

NASBA-eligible CPE on every TPRM course, and the completion certificate states the hours you earned.

Mapped to how audits actually run

Current content aligned to the way audits, certifications and real third-party risk programs work in practice.

Proud to be a Vendor Member of TPRA, supporting the advancement of Third-Party Risk Management through education and training.

Visit the Third Party Risk Association
Choose your credential

Choose your ISACA certification

Five globally recognized ISACA credentials. Find the one that fits your role and goals. Risk Tide is an ISACA Accredited Training Organization (ATO).

New
AAISM, ISACA Advanced in AI Security Management

AAISM

ISACA Advanced in AI Security Management
Best for AI security pros

ISACA’s first AI-centric security management certification. Reinforce your enterprise’s security posture as AI reshapes the threat landscape.

AI security · New credential · Boot camp
CISA, Certified Information Systems Auditor, an ISACA certification

CISA

Certified Information Systems Auditor
Best for IT auditors

The global standard for IS audit, control, and assurance. Prove you can assess risk, report on compliance, and implement controls.

Audit & assurance · Boot camp · CPE eligible
CISM, Certified Information Security Manager, an ISACA certification

CISM

Certified Information Security Manager
Best for security managers

Bridge security and business. Build and govern an enterprise security program ready for breaches, ransomware, and constant change.

Security management · Boot camp · CPE eligible
CRISC, Certified in Risk and Information Systems Control, an ISACA certification

CRISC

Certified in Risk and Information Systems Control
Best for IT risk pros

The leading IT risk credential. Identify and assess enterprise IT risk, then design controls that align with business objectives.

IT risk & controls · Boot camp · CPE eligible
CGEIT, Certified in the Governance of Enterprise IT, an ISACA certification

CGEIT

Certified in the Governance of Enterprise IT
Best for governance leaders

Prove your expertise governing enterprise IT, optimizing resources, benefits, and risk at the strategic, board-facing level.

IT governance · Boot camp · CPE eligible

Risk management news and regulatory trends, translated into Monday-morning action.

An email newsletter from Risk Tide, published every other week.

  • Regulatory change, translated. What moved, and what it means for a third-party program.
  • Practical, from real programs. What we see in assessments, not framework theory.
  • Every other week. Free to join, and no filler.

Double opt-in, so watch for the confirmation email. Past issues live on Risk Tide Current.

Risk Tide Current
Start today

Find the training that fits you

Practical third-party risk skills, exam-ready ISACA boot camps, NASBA-eligible CPE, and a certificate for your resume. Pick your path and start in minutes.

FAQ

Questions, answered

What is third-party risk management (TPRM)?

TPRM stands for third-party risk management: how you understand and manage the risk that comes with the outside organizations you rely on. It reaches further than the vendors on your payment list: any entity, individual, or organization in a business arrangement with your organization counts, with or without a contract or a payment. Done well, it protects your organization, your customers, and your reputation. Start with Why Third-Party Risk Management Really Matters.

What does Risk Tide offer?

Two things. Practical third-party risk management (TPRM) training, self-paced or live, and exam-ready ISACA certification boot camps for CISA, CISM, CRISC, CGEIT, and AAISM. Both are available to individuals and to teams.

Are you ISACA accredited?

Yes. Risk Tide is an ISACA Accredited Training Organization (ATO), so our boot camps are official ISACA training. Every ISACA boot camp includes an exam voucher and a free retake if you do not pass the first time.

Do I earn CPE credits?

Yes. Risk Tide is a NASBA CPE sponsor, and our TPRM courses award NASBA-eligible CPE you can log toward your CPA or other certifications. ISACA boot camp hours also count toward the CPE requirements of credentials you already hold.

Self-paced or live?

Both. TPRM courses like Risk Tide Core and Deep Dive are self-paced and start anytime. ISACA boot camps run as live virtual cohorts, and most also have a self-paced option. Prefer in-person? Register interest for Risk Tide Labs.

Do I get a certificate?

Every Risk Tide course finishes with a shareable certificate you can add to LinkedIn and your resume. ISACA certifications themselves are earned by passing ISACA’s exam. Our boot camps prepare you to do exactly that.

What are the stages of the third-party risk lifecycle?

Risk Tide teaches it as five stages, from need to termination: planning, due diligence, contracting, ongoing monitoring for both risk and performance, and a graceful exit. Risk Tide Deep Dive walks all five, and Risk Tide Labs runs a live scenario through the whole thing.

What makes a third party critical?

Criticality comes from how exposed you are across the risk domains, most often information security, privacy, compliance and resiliency, with reputational risk added depending on your industry and risk appetite. There is no universal list: your organization defines its own taxonomy, and a risk appetite statement or a risk tolerance metric is the place to start. Calling a third party critical has consequences, because critical means more effort, more oversight and board involvement. If they go down, you go down. Special Categories covers the relationships most programs never tier at all.

Is Risk Tide TPRM training a certification?

No, and we are deliberate about the difference. Our TPRM courses award a shareable certificate of completion plus NASBA-eligible CPE hours, which is what most people need to evidence training. A certification is a separate thing: an exam awarded by a certifying body. The certifications we prepare you for are ISACA’s, earned by passing ISACA’s exam, and we deliver that training as an Accredited Training Organization.

Can you train my whole team?

Yes. We offer corporate and team training tailored to your program, for both TPRM and ISACA certifications. Book a time with our team to scope it, or explore corporate TPRM training.