CertClue
Courses · Compliance
Third-Party Risk Analyst

Third-Party (Vendor) Risk Analyst

Manage a payment firm's technology suppliers under DORA for a week: fix the gaps in the register of ICT arrangements, decide which services support critical functions, assess a new provider, check its contract against what the rules require, and report concentration risk to the board.
1.5 hrs taught · 4.5 to 8 hrs applied 7 modules 20 lessons 4 portfolio artifacts Completion certificate Updated September 2026
Created by the CertClue team
What you'll build

Real portfolio pieces built during the course, not a certificate for its own sake. Each one is work you can show.

  • Register remediation planThe gaps in the register of ICT arrangements, counted properly, put in order of risk, with how each will be filled, by whom and by when.
  • Criticality assessmentWhich ICT services support the firm's critical or important functions and which do not, with the reason for each, including a service that inherits criticality from what runs on it.
  • Contract gap analysisA provider's draft contract checked against the firm's checklist for critical-function ICT services, the gaps explained in plain words, and what happens to go-live.
  • Board third-party risk updateThe update for the board risk committee: how complete the register is, the new provider's status, and concentration on one cloud provider stated plainly with what is being done.

What you'll learn

Third-party risk, kept short
The job, decoded
A day in the seat
The rhythm of the job
Into the simulation: Linnhale's third-party risk desk
Building the portfolio
What comes next

Course content · 7 modules, 20 lessons

Sign up to unlock every lesson - the titles below show exactly what is inside.

What the job is, DORA in plain words, and the life of a supplier from choosing it to leaving it.

What a third-party risk analyst does
DORA in plain words
The supplier lifecycle

Requirements

  • Comfortable with the fundamentals this course's own Module 1 covers, or equivalent experience.
  • No prior experience in this field is required to start.
  • A computer with a reliable internet connection.
  • Comfortable using a web browser - no software to install.

Description

Every CertClue course follows the same seven-part shape: fundamentals, the role translated out of job-posting language, a real working day, the job's recurring rhythms, a multi-day simulation, the portfolio you build along the way, and a handoff into your next move. Here is what that looks like for third-party risk analyst.

Who this course is for

Anyone aiming to become a third-party risk analyst, including career changers with no background in it yet. This is the entry rung of a realistic ladder:

entry
Third-Party Risk Analyst

Keeps the record of which technology suppliers the firm relies on, assesses them, and checks their contracts.

Registers of ICT arrangementsCriticality assessmentDue diligenceContract review against DORA
mid
Third-Party Risk Manager

Owns the supplier risk framework and decides with the business which risks are acceptable.

Risk appetite for suppliersExit planningConcentration riskWorking with regulators
senior
Head of Operational Resilience

Answers to the board for how the firm keeps its important services running, whoever supplies them.

Resilience strategyBoard reportingTesting programmesRegulatory relationships
Reviews

No reviews yet. Reviews come from learners who have taken the course, so this stays empty until someone leaves one.

Sign in to leave a review.

Students also explore