Avoid treating Third-party risk management as a one-time purchase or checklist item. Tie it to the intended outcome—evaluates and monitors supplier security obligations throughout the relationship—assign accountability, measure coverage and effectiveness, review exceptions, and update it when threats, systems or business requirements change.NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework