• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » Third-Party Risk Management

Third-Party Risk Management

Definition

Third-Party Risk Management

Third-party risk management is the continuing programme by which an organisation identifies, assesses and oversees risk across its whole supplier portfolio. It covers the portfolio — a single supplier evaluation is one input into it, not the programme itself.

The scope is a lifecycle rather than a checkpoint — planning, due diligence, contracting, ongoing monitoring and termination each carry their own risk activities and their own owners.

Criticality tiering is what makes it affordable. A programme applying equal effort to 400 suppliers collapses; one applying graded effort to a tiered population survives.

The discipline came from financial regulation and spread outward. Supervisory expectations for banks now shape how most large organisations structure supplier oversight.

Key takeaways

  • The programme covers all suppliers across the whole relationship lifecycle.
  • Criticality tiering directs effort where failure would actually hurt.
  • Monitoring after contracting is where most programmes are weakest.
  • Ownership must sit with a named function, not be shared across procurement and risk.

How it works

The programme defines tiers, sets the required activity at each stage for each tier, assigns owners, and reports exposure upward. Without tiering and named ownership it becomes an inventory rather than a control.

Regulators set the structure explicitly. Interagency guidance “outlines the third-party risk management life cycle and identifies risk management principles applicable to each stage” of that cycle.

StageCore activityFrequent gap
PlanningDecide whether to outsource at allDecision taken before risk is consulted
Due diligenceAssess the candidate supplierQuestionnaires accepted unverified
ContractingEmbed audit, exit and continuity rightsStandard terms used for critical suppliers
MonitoringTrack performance and changesReviewed at renewal only
TerminationExecute exit and recover dataNo exit plan ever written

The monitoring row is where programmes fail — diligence is done thoroughly once and then nothing happens for three years, by which time the supplier is a different business.

The guidance is deliberately broad in reach. It applies “to all banks with third-party relationships” and replaced each agency’s separate general guidance on the subject.

UK supervision takes the same path. The regulator’s supervisory statement expands on expectations in chapters covering data security and “business continuity and exit plans”, which are the two most neglected areas.

Tiering has to be reviewed. A supplier that was peripheral at onboarding can become critical within a year, and nothing in the original classification will catch that on its own.

Reporting closes the loop. A programme that never presents portfolio exposure to a board produces diligence files rather than decisions, and the suppliers carrying the most risk stay funded and unexamined.

Examples

Programmes look similar on paper and differ enormously in execution. The four cases below show what separates a working programme from a register of suppliers.

A bank tiers 600 suppliers into three bands and reserves deep diligence for 40. The vendor management team reviews the critical band quarterly.

A retailer runs excellent onboarding diligence and no monitoring at all. A critical supplier is acquired, restructures its delivery and nobody notices for 14 months.

A healthcare group maps supplier dependencies against its own critical processes. Two apparently minor suppliers turn out to sit inside a regulated pathway.

A multi-vendor buyer discovers four of its providers rely on the same underlying platform. The concentration was invisible until the programme looked one level deeper.

Related terms

Supplier oversight spans assessment, management and regulation, and the labels overlap heavily. The entries below separate the programme from its inputs and its supervisory sources.

FAQ

How does this differ from a vendor risk assessment?

An assessment evaluates one supplier at a point in time. The programme covers every supplier continuously, across planning, diligence, contracting, monitoring and exit.

How should suppliers be tiered?

By the impact of their failure on critical processes and by the sensitivity of the data they handle. Spend is a poor proxy for either.

Who should own the programme?

A single named function, usually risk or procurement, with security, legal and the business as contributors. Shared ownership reliably means nobody owns it.

What is the weakest stage in most programmes?

Monitoring. Diligence is performed thoroughly at onboarding and then rarely repeated, so the picture ages while the supplier changes.

Does it apply outside financial services?

Yes. The lifecycle model originated in banking supervision but is now standard practice across healthcare, retail, technology and the public sector.

How deep into the supply chain should it go?

At least one level beyond your direct suppliers for critical services, because concentration and dependency usually become visible only there.

Build your supplier portfolio from verified partners in the Outsource Accelerator directory.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image