Special Categories in TPRM: A Guide to Non-Traditional Relationships
The third parties your program misses are rarely the ones on the vendor list.
Non-traditional third-party relationships are among the most overlooked risk categories in third-party risk management. Most programs were not built with them in mind. This course builds on the TPRM foundation you already have and gives you a practical approach to identifying, assessing, and governing the relationships your program may be missing.
Everything you need to bring overlooked relationships into your program
From naming what makes a third party “special” to monitoring, documenting, and reporting the category over time.
Identify and document non-traditional relationships across your vendor ecosystem, including the ones nobody labels that way.
What to ask when your standard questionnaire does not apply, and how to tailor monitoring without rebuilding the program.
Define the governance structure, decide what gets documented at the category level, and demonstrate active oversight.
NASBA-eligible CPE that also counts toward ISACA CPE for credentials you already hold.
Earn a certificate of completion you can post on LinkedIn and add to your resume. It states the CPE hours you earned.
See exactly what the course looks like
Before you enroll, take a quick tour of the course. This is the real thing: the lesson format, how the four modules flow, and the kind of non-traditional third-party relationships you will work through. Know the look and feel before you sign up.
A demo of Special Categories in TPRM. The full course is 4 modules, about 1 hour, 1 NASBA-eligible CPE credit.
Four modules, from spotting the gap to proving oversight
Every module and what you will be able to do when you finish it.
Understanding Non-Traditional Third Parties
FoundationsWhat makes a third party “special,” and why the label matters less than the risk.
- 01Identify the types of relationships that qualify as special categories, including those your organization may not currently label that way.
- 02Recognize why special category third parties need consistent TPRM oversight as part of their lifecycle, regardless of how they are named or classified.
Same Lifecycle, Different Uses
LifecycleApply the lifecycle you already run to relationships it was not designed for, without rebuilding it from scratch.
- 01Distinguish between the lifecycle needs of special categories and those of traditional third-party relationships.
- 02Evaluate each lifecycle stage, as applied to a special category relationship, and determine who owns the process.
Govern the Category, Not Just the Relationship
GovernanceStructure and documentation that hold up at the category level, not one-off exceptions.
- 01Define the governance structure needed to manage special categories consistently.
- 02Identify what needs to be documented at the category level.
Monitor, Document, Report. Then Do It Again.
OversightWhat good governance looks like in practice, and how to show leadership it is actually happening.
- 01Recognize what good governance looks like for a special category, and who it gets communicated to.
- 02Evaluate a reporting approach that communicates oversight clearly across both leadership and other stakeholders.
Your CPE hours, and how to report them
This course awards 1 CPE hour on completion, all of it self-paced, structured self-study on third-party risk. How you report the time depends on which credential you hold.
- CPAs. Risk Tide is a NASBA-registered CPE sponsor, so this is NASBA-eligible CPE, ready to log toward your license. This is the one we sponsor directly. Requirements vary by state: check your jurisdiction.
- ABA professional certifications. Third-party risk sits in the exam domains for CERP and CRCM in particular. Search for Risk Tide Solutions in ABA’s Certification Manager to apply the credit. ABA uses the same 50-minute credit hour as NASBA. ABA’s CE rules.
- ISACA certifications. ISACA’s policy recognizes structured self-study with no annual limit, provided the activity is relevant to your certification’s domains. Whether this course meets that test is your call as the certificate holder. ISACA’s CPE policy.
Whichever you report to, the paperwork is the same, and it is what all three ask you to keep: a certificate of completion showing the CPE hours earned, the course, the topic, and Risk Tide Solutions as the provider.
How you report is up to you. We award the hours and give you the documentation. Whether a course qualifies under your credential, and how you log it, is determined by you and the body that issued the credential. We do not report on your behalf.
Questions, answered
What is a “special category” third party?
It is any relationship that carries third-party risk but does not fit neatly into the vendor process your program was built around. That includes relationships your organization may not currently label as third parties at all. The course starts by helping you name them, because the label matters less than the risk.
Do I need prior TPRM experience?
Some. This is an intermediate course that builds on a foundation, so you should have basic familiarity with foundational TPRM concepts and the vendor risk lifecycle. If you are starting from zero, take Why Third-Party Risk Management Really Matters first.
How long is the course, and what is the format?
About one hour across four self-paced online modules, delivered as video and instructional content on the Risk Tide site in any web browser. On-demand: start anytime and finish on your schedule.
Do I earn CPE credit?
Yes. The course awards 1 NASBA-eligible CPE credit. If you hold CISA, CRISC, CISM, or CGEIT, the same hour counts toward ISACA CPE: ISACA accepts structured self-study with no annual limit, you self-report the hour, and your certificate states the CPE hours you earned.
Who is this course for?
TPRM professionals, risk and compliance professionals, internal auditors, enterprise risk managers, procurement and vendor managers, and CPAs. Anyone accountable for showing that oversight covers the whole third-party population, not just the easy part of it.
Do I get a certificate?
Yes. You earn a shareable certificate of completion you can post on LinkedIn and add to your resume.
Can we roll this out to a team?
Yes. The course works for an individual or an enterprise-wide rollout. Ask about volume pricing and enterprise access options: book a time with our team.
Garit Gemeinhardt
Co-Founder & Head of Learning Experiences
Garit brings more than 15 years of industry experience into every training. He combines real-world insight with practical application to create engaging sessions that challenge perspectives and prepare professionals to lead with confidence.
More about the Risk Tide team →“Most risk training teaches you what risk is. We teach you what to do with it.”
Ready to cover the relationships your program is missing?
Bring non-traditional third parties into the same lifecycle, governance, and reporting as everything else. One hour, 1 NASBA-eligible CPE credit that also counts toward ISACA CPE, and a certificate for your resume, for $59.
Enroll now, $59 →Rolling this out to a team or firm? Ask about volume pricing and enterprise access. Book a time with our team →
Team Training? We've Got You Covered.
Popular courses
Pages
