
Most third-party risk reporting fails a simple test: could a director make a decision with it? A slide that says "142 assessments completed this quarter" answers a question nobody on the board asked. Activity counts describe effort. Boards allocate capital and accept risk, and they need metrics that describe exposure and trajectory.
This article gives you four TPRM metrics that survive contact with a board meeting, the formula behind each, and a one-page template that fits them together. None of them require expensive tooling to start. All of them require honest data.
Why activity metrics fail in the boardroom
Assessments sent, questionnaires returned, vendors onboarded: these are throughput numbers. They rise when your team works harder and fall when it drowns, but they say nothing about whether the organization is more or less exposed than last quarter. Worse, they invite the wrong conversation. A director who sees "142 assessments" asks why not 180, and now you are defending headcount instead of discussing risk.
The metrics that work share three properties. They are ratios, not raw counts, so they stay comparable as the vendor list grows. They are tied to consequence, usually through your vendor tiering model, so a change in the number maps to a change in real exposure. And each one has a target and a trend, because a board reads direction before it reads magnitude.
The four metrics, with formulas
1. Coverage: are the vendors that can hurt us actually assessed?
Coverage is the percentage of vendors with a current, completed assessment, weighted by tier. Report it per tier, never as a blended average, because a blended average lets 400 assessed low-tier vendors hide 6 unassessed critical ones.
Formula: for each tier, Coverage = (vendors with an assessment completed inside the tier's reassessment window) / (total vendors in tier).
A "current" assessment is one completed within the cadence your tiering policy defines, for example every 12 months for critical vendors and every 24 to 36 months for low tiers. An assessment from three years ago is not coverage. It is archaeology.
Target: 100 percent for the top tier, and be suspicious of any program reporting exactly that. A healthy top-tier number in a growing program often sits at 90 to 95 percent with a named list of the exceptions and a date for each.
2. Time in remediation: how long do known problems stay open?
Every assessment produces findings. The metric that matters is not how many findings exist but how long severe ones stay open. Report the median age of open findings by severity, plus the count aging past your SLA.
Formula: Time in remediation = median(today minus finding opened date) for open findings, computed separately for critical and high severity. Pair it with SLA breach count = findings open longer than the committed clock.
Median beats mean here because one abandoned two-year-old finding should not distort the picture, and it beats "percent closed" because closure rates are easy to game by closing the trivial items first. If your remediation numbers look good but deals with vendors keep stalling, read why most vendor remediation efforts fail before you present them.
3. Divergence rate: how often does reported posture disagree with observed reality?
This is the newest of the four and the one boards find most interesting once they understand it. A vendor's questionnaire answers are a claim. External signals, breach disclosures, expired certificates, leaked credentials, degraded security ratings, are observations. Divergence rate measures how often the claim and the observation disagree.
Formula: Divergence rate = (vendors where an external signal materially contradicts an attested answer in the last 12 months) / (vendors with both an assessment and monitoring in place).
"Materially contradicts" needs a written definition or the metric becomes an argument. A workable starting rule: the external signal, if known at assessment time, would have changed the finding severity or the approval decision. Platforms that keep assessment answers and monitoring signals on one vendor record can compute this automatically; ThirdSentry, for example, flags the disagreement on the vendor record itself so the rate falls out of the data rather than a quarterly manual review. Even computed by hand across your top tier only, this number changes board conversations, because it answers the question directors quietly hold: can we trust what vendors tell us?
4. Concentration: how much of our operation runs through how few parties?
Boards understand concentration instinctively from credit and market risk. Apply the same lens to vendors: what share of critical business processes depends on your top three providers, and how many critical vendors share a single cloud, region, or identity provider underneath?
Formula (simple version): Concentration = (critical processes dependent on the single most-depended-on provider) / (total critical processes). Report the top three providers by this measure, plus a count of critical vendors sharing a common fourth-party dependency.
Concentration is the metric that connects vendor risk to enterprise resilience, and it is the one most likely to trigger a real board directive, because the mitigations (dual sourcing, exit plans, contractual recovery commitments) cost money that only the board can approve. The real cost of a vendor breach multiplies when the affected vendor is also a concentration point.
The one-page template
Resist the dashboard instinct. One page, four rows, read top to bottom in under three minutes. Each row carries the current value, the trend arrow against last quarter, the target, and one sentence of narrative. The sentence is not optional. It is where you convert a number into a decision request.
| Metric | Current | Trend | Target | Narrative (one sentence) |
|---|---|---|---|---|
| Coverage, Tier 1 | 93% | Up | 100% | Two acquired-entity vendors outstanding, assessments due Oct 15, 2026. |
| Median time in remediation, critical findings | 34 days | Flat | Under 30 | One vendor accounts for the overage; escalated to contract owner Aug 4, 2026. |
| Divergence rate, Tier 1 | 8% | New | Baseline year | Three vendors flagged; one reassessment moved up as a result. |
| Concentration, top provider | 41% of critical processes | Up | Board risk appetite TBD | Requesting the board set an appetite threshold this cycle. |
The numbers above are illustrative, not benchmarks. Your first quarter's job is to establish honest baselines, and an ugly honest baseline builds more board trust than a clean number nobody believes.
Three rules for presenting these numbers
- Never present a metric without its denominator. "12 SLA breaches" means nothing. "12 of 240 open findings past SLA, all in one vendor relationship" is a story with an ending.
- Attach one decision request per quarter. A metrics page with no ask trains the board to skim it. Rotate the ask: risk appetite for concentration this quarter, remediation escalation authority next.
- Show the same four metrics every quarter. The value compounds through comparability. Adding a fifth metric costs less than swapping one, so choose carefully and then hold the line.
Getting the data without a quarter of manual work
Coverage and time in remediation fall out of any structured vendor register with assessment dates and finding records. Divergence rate needs assessment answers and external monitoring signals joined on the same vendor, which is painful across two disconnected tools and trivial when both live on one data model. Concentration needs fourth-party dependency data, which most programs collect during onboarding and then never structure.
ThirdSentry runs assessments, continuous external monitoring, and findings on a single vendor record, so all four metrics are computed from live data rather than assembled by hand each quarter, and the divergence flag is raised the moment a vendor's reported posture stops matching observed reality. If your board deck currently takes a week to build, that is the part worth automating first.

