NASBA CPE Eligible · Practitioner-Built

Risk Tide Core

A growing series of short, self-paced TPRM courses.

Earn NASBA-eligible CPE, build real third-party risk management skills, and add a practical certificate to your resume, one focused course at a time. Start with a single course or work through the whole series at your own pace.

Self-pacedNASBA CPEShareable certificatePractitioner-built
Training for your team? Get a tailored proposal →
The series

Choose your Risk Tide Core course

Self-paced online courses you can start today. More launching soon.

New Self-paced online · 1 CPE · Intermediate

Special Categories in TPRMNon-traditional third parties your program may be missing

Not every third-party relationship fits neatly into your program, and the ones that do not are where oversight quietly breaks down. Learn to find them, run them through the lifecycle, and govern the category, in about an hour. Builds on a TPRM foundation.

  • 4 modules · ~1 hour
  • On-demand access · Shareable certificate
$59One-time
Best value · Bundle

Risk Tide Core Bundle

Four Risk Tide Core courses in one path: understand third-party risk, assess the AI your vendors use, manage partnerships end to end, and audit vendor risk as a CPA. Built for risk, compliance, audit, and procurement teams, and CPAs earning CPE.

  • Why TPRM Really Matters
  • Managing Risk from AI
  • The Partnership Playbook
  • TPRM Clarity for CPAs
$179$296
Save $117 6 CPE · 4 courses Get the bundle
Coming soon

Be first to know about new courses

More self-paced TPRM courses are on the way. Follow us on LinkedIn or join The Current, our newsletter, to hear the moment they launch.

7 CPE credit hours Across all five courses

Your CPE hours, and how to report them

The five Risk Tide Core courses award 7 CPE hours in total on completion, all of it self-paced, structured self-study on third-party risk. How you report the time depends on which credential you hold.

  • CPAs. Risk Tide is a NASBA-registered CPE sponsor, so this is NASBA-eligible CPE, ready to log toward your license. This is the one we sponsor directly. Requirements vary by state: check your jurisdiction.
  • ABA professional certifications. Third-party risk sits in the exam domains for CERP and CRCM in particular. Search for Risk Tide Solutions in ABA’s Certification Manager to apply the credit. ABA uses the same 50-minute credit hour as NASBA. ABA’s CE rules.
  • ISACA certifications. ISACA’s policy recognizes structured self-study with no annual limit, provided the activity is relevant to your certification’s domains. Whether this course meets that test is your call as the certificate holder. ISACA’s CPE policy.

Whichever you report to, the paperwork is the same, and it is what all three ask you to keep: a certificate of completion showing the CPE hours earned, the course, the topic, and Risk Tide Solutions as the provider.

How you report is up to you. We award the hours and give you the documentation. Whether a course qualifies under your credential, and how you log it, is determined by you and the body that issued the credential. We do not report on your behalf.

Foundational

Inside Risk Tide Core: Why TPRM Really Matters

A self-paced online third-party risk management course that takes you through the full vendor risk lifecycle in about three hours. Across five practical modules you will learn why TPRM drives business value, how the lifecycle works from planning to termination, how governance holds up under pressure, and where the field is heading. Earn 3 CPE credits and a shareable certificate.

Self-pacedOnline
3 CPEOn completion
5 modules~3 hours
12-monthAccess

What you will cover

01

The Big Picture: Why TPRM Matters

Why third-party risk management is a business imperative, not a compliance checkbox. Define what counts as a third party, see how TPRM protects business value and creates competitive advantage, and balance competing stakeholder priorities.

02

The TPRM Lifecycle: From Need to Termination

Walk the five phases of the vendor risk lifecycle: planning and inherent risk, due diligence, contracting, ongoing monitoring, and a graceful exit. Learn the essential contract clauses and the early warning signs that matter.

03

Governance & Crisis Management: When Things Go Wrong

Apply the Three Lines Model, tell a routine finding from a formal issue, and escalate by risk tier. Build the governance and crisis response that holds up under pressure and meets regulator expectations.

04

Trends & the Future of TPRM

Where TPRM is heading: technology enablement and continuous monitoring over point-in-time reviews, assessing AI and emerging risks, and keeping pace with regulations that now have teeth.

05

Bringing It All Together: Your TPRM Playbook

Turn principles into practice. Build a true partnership between the business and TPRM, recognize the moments that matter, and apply TPRM thinking to the real vendor scenarios you will actually face.

Shareable certificate CPE on completion Practitioner-built Resume-ready
Enroll in Why TPRM Matters, $99
Take a look inside

See exactly what the course looks like

Before you enroll, take a quick walkthrough of Risk Tide Core. This is the real thing: the lesson format, how each module flows, and the kind of practical vendor scenarios you will work through. Know the look and feel before you sign up.

A walkthrough of Risk Tide Core: Why TPRM Really Matters. The full course is 5 modules, about 3 hours, 3 NASBA-eligible CPE credits.

Partnerships

Inside The Partnership Playbook

Learn to manage third-party partnerships as the strategic relationships they are. In about an hour across four modules, you will decide whether to pursue a partnership, run right-sized due diligence with the S.I.M.P.L.E. framework, put the right agreement in writing, and keep the relationship healthy through monitoring and a clean exit. Built for business, not just compliance. Earn 1 CPE credit and a certificate.

Self-pacedOnline
1 CPEOn completion
4 modules~1 hour
LifetimeAccess

What you will cover

01

The Decision

Approach a new partnership deliberately. Tell a partnership mindset from a checkbox mentality, and assign ownership before you commit.

02

Due Diligence

Use the S.I.M.P.L.E. framework for focused, risk-based vetting that surfaces real control gaps, not paperwork.

03

The Agreement

Turn risk findings into clear, enforceable terms covering deliverables, data handling, and accountability for any arrangement.

04

Relationship Health

Design tiered oversight, spot early warning signs, and plan a clean exit before you need one.

Shareable certificate CPE on completion Practitioner-built Resume-ready
AI risk

Inside Managing Risk from AI Used by Third Parties

AI is already in your vendor ecosystem, and most third-party risk programs were not built to catch it. The risk does not begin when a vendor sets out to build a model. It begins when AI quietly shows up inside tools you already use. This practical, foundational course gives you the frameworks to find, assess, and monitor AI across your vendors through a third-party risk lens. It is built around AIMED, Risk Tide’s framework for evaluating AI vendor risk, and you do not need a data-science background to use it. Earn 1 CPE credit and a certificate.

Self-pacedOnline
1 CPEOn completion
4 modules~1 hour
LifetimeAccess

What you will cover

01

AI 101Foundations

See what makes AI-related third-party risk different from traditional vendor risk, the common categories and model types of AI in vendor relationships, and why existing vendor inventories often fail to capture them.

02

AI Governance FrameworkGovernance

Define the core components of an AI governance framework, how policy, process, and procedures work together, and what sets AI governance apart from existing third-party frameworks.

03

AI Assessment in ActionAssessment

Identify where AI exerts influence along the TPRM lifecycle, and see how each component of AIMED maps to the appropriate stage of that lifecycle.

04

Monitor, Report, RepeatMonitoring

Recognize why continuous, event-driven monitoring is required for AI vendors, identify the signals for reassessment, and let your governance framework dictate what to monitor and report.

Shareable certificate 1 CPE on completion AIMED framework Lifetime access Resume-ready
Audit and assurance

Inside TPRM Clarity for CPAs

Third-party risk now lands on the CPA’s desk, and the question that follows is how to audit the program that manages it. In about an hour across four modules, you will map the third-party risk lifecycle to the documentation an auditor actually needs at each stage, place it against current regulatory expectations, and take the assessor’s view of whether a program is doing what it claims to. Earn 1 CPE credit and a certificate.

Self-pacedOnline
1 CPEOn completion
4 modules~1 hour
$59One-time

What you will cover

01

Why TPRM Is Now a CPA Issue

Why third-party risk has become a core CPA responsibility, and how the auditor’s role is evolving with it.

02

The TPRM Lifecycle: A CPA’s Map

Every stage of the lifecycle and what audit-ready documentation looks like at each phase.

03

The Lens Today: Where TPRM Meets Regulatory Reality

The regulatory requirements relevant to third-party oversight, and where scrutiny is growing.

04

How Do I Audit a TPRM Program?

The auditor’s mindset: assess whether a program is doing what it is intended to do.

Shareable certificate CPE on completion Practitioner-built No audit background assumed
Enroll for CPAs, $59
Intermediate

Inside Special Categories in TPRM

The third parties your program misses are rarely the ones on the vendor list. In about an hour across four modules, you will learn to spot the relationships that carry real risk without fitting your vendor process, apply the lifecycle you already run to them without rebuilding it, govern them at the category level rather than as one-off exceptions, and report that oversight to leadership. Builds on TPRM fundamentals. Earn 1 CPE credit and a certificate.

Self-pacedOnline
1 CPEOn completion
4 modules~1 hour
$59One-time

What you will cover

01

Understanding Non-Traditional Third Parties

What makes a third party “special,” and why the label matters less than the risk it carries.

02

Same Lifecycle, Different Uses

Apply the lifecycle you already run to relationships it was not designed for, without rebuilding it from scratch.

03

Govern the Category, Not Just the Relationship

Structure and documentation that hold up at the category level, not one-off exceptions.

04

Monitor, Document, Report. Then Do It Again.

What good governance looks like in practice, and how to show leadership it is actually happening.

Shareable certificate CPE on completion Intermediate level Category-level governance
Enroll in Special Categories, $59
Built for you

Who is this for?

Risk Tide Core is built for anyone who chooses, manages, or oversees third-party relationships, whatever your title.

Common roles in our courses include:

Business stakeholders Partnership managers Risk & compliance teams Sourcing & supplier teams CPAs Anyone managing third-party relationships
Garit Gemeinhardt, Co-Founder and Head of Learning Experiences at Risk Tide
Meet your course creator

Garit Gemeinhardt

Co-Founder & Head of Learning Experiences

Garit brings more than 15 years of industry experience into every training. He combines real-world insight with practical application to create engaging sessions that challenge perspectives and prepare professionals to lead with confidence.

“Most risk training teaches you what risk is. We teach you what to do with it.”

More about the Risk Tide team
For teams & organizations

Training your stakeholders or TPRM team?

Many organizations want their stakeholders and third-party risk teams trained together, on their own program and vendors. We build private, tailored sessions around your business and deliver them online or on-site, with volume pricing for groups.

Tailored to your program Your vendors & scenarios Online or on-site Volume pricing

Team Training? We've Got You Covered.