Third-Party Risk Management
Definition
Third-Party Risk Management
Third-party risk management is the continuing programme by which an organisation identifies, assesses and oversees risk across its whole supplier portfolio. It covers the portfolio — a single supplier evaluation is one input into it, not the programme itself.
The scope is a lifecycle rather than a checkpoint — planning, due diligence, contracting, ongoing monitoring and termination each carry their own risk activities and their own owners.
Criticality tiering is what makes it affordable. A programme applying equal effort to 400 suppliers collapses; one applying graded effort to a tiered population survives.
The discipline came from financial regulation and spread outward. Supervisory expectations for banks now shape how most large organisations structure supplier oversight.
Key takeaways
- The programme covers all suppliers across the whole relationship lifecycle.
- Criticality tiering directs effort where failure would actually hurt.
- Monitoring after contracting is where most programmes are weakest.
- Ownership must sit with a named function, not be shared across procurement and risk.
How it works
The programme defines tiers, sets the required activity at each stage for each tier, assigns owners, and reports exposure upward. Without tiering and named ownership it becomes an inventory rather than a control.
Regulators set the structure explicitly. Interagency guidance “outlines the third-party risk management life cycle and identifies risk management principles applicable to each stage” of that cycle.
| Stage | Core activity | Frequent gap |
|---|---|---|
| Planning | Decide whether to outsource at all | Decision taken before risk is consulted |
| Due diligence | Assess the candidate supplier | Questionnaires accepted unverified |
| Contracting | Embed audit, exit and continuity rights | Standard terms used for critical suppliers |
| Monitoring | Track performance and changes | Reviewed at renewal only |
| Termination | Execute exit and recover data | No exit plan ever written |
The monitoring row is where programmes fail — diligence is done thoroughly once and then nothing happens for three years, by which time the supplier is a different business.
The guidance is deliberately broad in reach. It applies “to all banks with third-party relationships” and replaced each agency’s separate general guidance on the subject.
UK supervision takes the same path. The regulator’s supervisory statement expands on expectations in chapters covering data security and “business continuity and exit plans”, which are the two most neglected areas.
Tiering has to be reviewed. A supplier that was peripheral at onboarding can become critical within a year, and nothing in the original classification will catch that on its own.
Reporting closes the loop. A programme that never presents portfolio exposure to a board produces diligence files rather than decisions, and the suppliers carrying the most risk stay funded and unexamined.
Examples
Programmes look similar on paper and differ enormously in execution. The four cases below show what separates a working programme from a register of suppliers.
A bank tiers 600 suppliers into three bands and reserves deep diligence for 40. The vendor management team reviews the critical band quarterly.
A retailer runs excellent onboarding diligence and no monitoring at all. A critical supplier is acquired, restructures its delivery and nobody notices for 14 months.
A healthcare group maps supplier dependencies against its own critical processes. Two apparently minor suppliers turn out to sit inside a regulated pathway.
A multi-vendor buyer discovers four of its providers rely on the same underlying platform. The concentration was invisible until the programme looked one level deeper.
Related terms
Supplier oversight spans assessment, management and regulation, and the labels overlap heavily. The entries below separate the programme from its inputs and its supervisory sources.
- OCC third-party guidance: the supervisory statement that defines the lifecycle model most programmes follow.
- Risk outsourcing: the allocation question of which party should carry which exposure.
- Business risk: the organisational exposure the programme exists to contain.
- Business continuity clause: one of the contractual outputs the programme is meant to produce.
- NIST AI Risk Management Framework: a parallel structure for suppliers deploying automated systems.
FAQ
How does this differ from a vendor risk assessment?
An assessment evaluates one supplier at a point in time. The programme covers every supplier continuously, across planning, diligence, contracting, monitoring and exit.
How should suppliers be tiered?
By the impact of their failure on critical processes and by the sensitivity of the data they handle. Spend is a poor proxy for either.
Who should own the programme?
A single named function, usually risk or procurement, with security, legal and the business as contributors. Shared ownership reliably means nobody owns it.
What is the weakest stage in most programmes?
Monitoring. Diligence is performed thoroughly at onboarding and then rarely repeated, so the picture ages while the supplier changes.
Does it apply outside financial services?
Yes. The lifecycle model originated in banking supervision but is now standard practice across healthcare, retail, technology and the public sector.
How deep into the supply chain should it go?
At least one level beyond your direct suppliers for critical services, because concentration and dependency usually become visible only there.
Build your supplier portfolio from verified partners in the Outsource Accelerator directory.







Independent




