Risk Tide Core
A growing series of short, self-paced TPRM courses.
Earn NASBA-eligible CPE, build real third-party risk management skills, and add a practical certificate to your resume, one focused course at a time. Start with a single course or work through the whole series at your own pace.
Choose your Risk Tide Core course
Self-paced online courses you can start today. More launching soon.
Why Third-Party Risk Management Really Matters
Essential TPRM concepts and the full vendor risk lifecycle in about three hours. The fastest way to earn CPE and a certificate for your resume.
- 5 modules · ~3 hours
- 12-month access · Shareable certificate
The Partnership PlaybookBuilding partnerships as third-party relationships
Navigate the full third-party partnership lifecycle, from the first decision to a clean exit, in about an hour. Built for business teams who choose and manage partners, not just compliance.
- 4 modules · ~1 hour
- Lifetime access · Shareable certificate
Managing Risk from AI Used by Third PartiesFind, assess, and monitor AI across your vendors
AI is already in your vendor ecosystem. Learn to find, assess, and monitor it through a third-party risk lens with Risk Tide’s AIMED framework, in about an hour. No data-science background needed.
- 4 modules · ~1 hour
- Lifetime access · Shareable certificate
TPRM Clarity for CPAsThird-party risk management built for CPAs and auditors
CPAs are increasingly on the front lines of third-party risk, but most TPRM training was not built for them. Learn to evaluate vendor risk programs, meet regulatory expectations, and audit a TPRM program as an independent arm, in about an hour.
- 4 modules · ~1 hour
- On-demand access · Shareable certificate
Special Categories in TPRMNon-traditional third parties your program may be missing
Not every third-party relationship fits neatly into your program, and the ones that do not are where oversight quietly breaks down. Learn to find them, run them through the lifecycle, and govern the category, in about an hour. Builds on a TPRM foundation.
- 4 modules · ~1 hour
- On-demand access · Shareable certificate
Risk Tide Core Bundle
Four Risk Tide Core courses in one path: understand third-party risk, assess the AI your vendors use, manage partnerships end to end, and audit vendor risk as a CPA. Built for risk, compliance, audit, and procurement teams, and CPAs earning CPE.
- Why TPRM Really Matters
- Managing Risk from AI
- The Partnership Playbook
- TPRM Clarity for CPAs
Be first to know about new courses
More self-paced TPRM courses are on the way. Follow us on LinkedIn or join The Current, our newsletter, to hear the moment they launch.
Your CPE hours, and how to report them
The five Risk Tide Core courses award 7 CPE hours in total on completion, all of it self-paced, structured self-study on third-party risk. How you report the time depends on which credential you hold.
- CPAs. Risk Tide is a NASBA-registered CPE sponsor, so this is NASBA-eligible CPE, ready to log toward your license. This is the one we sponsor directly. Requirements vary by state: check your jurisdiction.
- ABA professional certifications. Third-party risk sits in the exam domains for CERP and CRCM in particular. Search for Risk Tide Solutions in ABA’s Certification Manager to apply the credit. ABA uses the same 50-minute credit hour as NASBA. ABA’s CE rules.
- ISACA certifications. ISACA’s policy recognizes structured self-study with no annual limit, provided the activity is relevant to your certification’s domains. Whether this course meets that test is your call as the certificate holder. ISACA’s CPE policy.
Whichever you report to, the paperwork is the same, and it is what all three ask you to keep: a certificate of completion showing the CPE hours earned, the course, the topic, and Risk Tide Solutions as the provider.
How you report is up to you. We award the hours and give you the documentation. Whether a course qualifies under your credential, and how you log it, is determined by you and the body that issued the credential. We do not report on your behalf.
Inside Risk Tide Core: Why TPRM Really Matters
A self-paced online third-party risk management course that takes you through the full vendor risk lifecycle in about three hours. Across five practical modules you will learn why TPRM drives business value, how the lifecycle works from planning to termination, how governance holds up under pressure, and where the field is heading. Earn 3 CPE credits and a shareable certificate.
What you will cover
The Big Picture: Why TPRM Matters
Why third-party risk management is a business imperative, not a compliance checkbox. Define what counts as a third party, see how TPRM protects business value and creates competitive advantage, and balance competing stakeholder priorities.
The TPRM Lifecycle: From Need to Termination
Walk the five phases of the vendor risk lifecycle: planning and inherent risk, due diligence, contracting, ongoing monitoring, and a graceful exit. Learn the essential contract clauses and the early warning signs that matter.
Governance & Crisis Management: When Things Go Wrong
Apply the Three Lines Model, tell a routine finding from a formal issue, and escalate by risk tier. Build the governance and crisis response that holds up under pressure and meets regulator expectations.
Trends & the Future of TPRM
Where TPRM is heading: technology enablement and continuous monitoring over point-in-time reviews, assessing AI and emerging risks, and keeping pace with regulations that now have teeth.
Bringing It All Together: Your TPRM Playbook
Turn principles into practice. Build a true partnership between the business and TPRM, recognize the moments that matter, and apply TPRM thinking to the real vendor scenarios you will actually face.
See exactly what the course looks like
Before you enroll, take a quick walkthrough of Risk Tide Core. This is the real thing: the lesson format, how each module flows, and the kind of practical vendor scenarios you will work through. Know the look and feel before you sign up.
A walkthrough of Risk Tide Core: Why TPRM Really Matters. The full course is 5 modules, about 3 hours, 3 NASBA-eligible CPE credits.
Inside The Partnership Playbook
Learn to manage third-party partnerships as the strategic relationships they are. In about an hour across four modules, you will decide whether to pursue a partnership, run right-sized due diligence with the S.I.M.P.L.E. framework, put the right agreement in writing, and keep the relationship healthy through monitoring and a clean exit. Built for business, not just compliance. Earn 1 CPE credit and a certificate.
What you will cover
The Decision
Approach a new partnership deliberately. Tell a partnership mindset from a checkbox mentality, and assign ownership before you commit.
Due Diligence
Use the S.I.M.P.L.E. framework for focused, risk-based vetting that surfaces real control gaps, not paperwork.
The Agreement
Turn risk findings into clear, enforceable terms covering deliverables, data handling, and accountability for any arrangement.
Relationship Health
Design tiered oversight, spot early warning signs, and plan a clean exit before you need one.
Inside Managing Risk from AI Used by Third Parties
AI is already in your vendor ecosystem, and most third-party risk programs were not built to catch it. The risk does not begin when a vendor sets out to build a model. It begins when AI quietly shows up inside tools you already use. This practical, foundational course gives you the frameworks to find, assess, and monitor AI across your vendors through a third-party risk lens. It is built around AIMED, Risk Tide’s framework for evaluating AI vendor risk, and you do not need a data-science background to use it. Earn 1 CPE credit and a certificate.
What you will cover
AI 101Foundations
See what makes AI-related third-party risk different from traditional vendor risk, the common categories and model types of AI in vendor relationships, and why existing vendor inventories often fail to capture them.
AI Governance FrameworkGovernance
Define the core components of an AI governance framework, how policy, process, and procedures work together, and what sets AI governance apart from existing third-party frameworks.
AI Assessment in ActionAssessment
Identify where AI exerts influence along the TPRM lifecycle, and see how each component of AIMED maps to the appropriate stage of that lifecycle.
Monitor, Report, RepeatMonitoring
Recognize why continuous, event-driven monitoring is required for AI vendors, identify the signals for reassessment, and let your governance framework dictate what to monitor and report.
Inside TPRM Clarity for CPAs
Third-party risk now lands on the CPA’s desk, and the question that follows is how to audit the program that manages it. In about an hour across four modules, you will map the third-party risk lifecycle to the documentation an auditor actually needs at each stage, place it against current regulatory expectations, and take the assessor’s view of whether a program is doing what it claims to. Earn 1 CPE credit and a certificate.
What you will cover
Why TPRM Is Now a CPA Issue
Why third-party risk has become a core CPA responsibility, and how the auditor’s role is evolving with it.
The TPRM Lifecycle: A CPA’s Map
Every stage of the lifecycle and what audit-ready documentation looks like at each phase.
The Lens Today: Where TPRM Meets Regulatory Reality
The regulatory requirements relevant to third-party oversight, and where scrutiny is growing.
How Do I Audit a TPRM Program?
The auditor’s mindset: assess whether a program is doing what it is intended to do.
Inside Special Categories in TPRM
The third parties your program misses are rarely the ones on the vendor list. In about an hour across four modules, you will learn to spot the relationships that carry real risk without fitting your vendor process, apply the lifecycle you already run to them without rebuilding it, govern them at the category level rather than as one-off exceptions, and report that oversight to leadership. Builds on TPRM fundamentals. Earn 1 CPE credit and a certificate.
What you will cover
Understanding Non-Traditional Third Parties
What makes a third party “special,” and why the label matters less than the risk it carries.
Same Lifecycle, Different Uses
Apply the lifecycle you already run to relationships it was not designed for, without rebuilding it from scratch.
Govern the Category, Not Just the Relationship
Structure and documentation that hold up at the category level, not one-off exceptions.
Monitor, Document, Report. Then Do It Again.
What good governance looks like in practice, and how to show leadership it is actually happening.
Who is this for?
Risk Tide Core is built for anyone who chooses, manages, or oversees third-party relationships, whatever your title.






Common roles in our courses include:
Garit Gemeinhardt
Co-Founder & Head of Learning Experiences
Garit brings more than 15 years of industry experience into every training. He combines real-world insight with practical application to create engaging sessions that challenge perspectives and prepare professionals to lead with confidence.
More about the Risk Tide team →“Most risk training teaches you what risk is. We teach you what to do with it.”
Training your stakeholders or TPRM team?
Many organizations want their stakeholders and third-party risk teams trained together, on their own program and vendors. We build private, tailored sessions around your business and deliver them online or on-site, with volume pricing for groups.
Team Training? We've Got You Covered.
ISACA Accredited Training Organization
NASBA National Registry of CPE Sponsors
TPRM TRAINING
