Third-Party Risk
Third-party risk is the potential for adverse outcomes that an organization may face because it relies on external parties such as vendors, suppliers, partners, or intermediaries. When an organization outsources functions or works with others in its ecosystem or supply chain, the actions, failures, or exposures of those outside parties can create risk for the organization itself. Managing this risk is commonly addressed through a practice known as third-party risk management (TPRM).
Third-party risk denotes the category of risk introduced to an organization through its dependence on external parties, including vendors, suppliers, service providers, partners, and intermediaries within its ecosystem or supply chain. It commonly arises when business functions are outsourced, and encompasses the potential adverse outcomes attributable to the performance, conduct, or exposures of those external parties. This term is distinct from the discipline of third-party risk management (TPRM), which refers to the practice of identifying, assessing, monitoring, and reducing such risks; third-party risk is the underlying exposure, while TPRM is the process applied to treat it. The specific risk domains implicated (for example, operational, information security, financial, or compliance-related) vary by the nature of the relationship and are not enumerated in the evidence provided here.
Why it matters
Organizations increasingly depend on external vendors, suppliers, partners, and intermediaries to deliver core functions, and each of these relationships extends the organization's risk surface beyond its own boundaries. When a business outsources a function or relies on others within its ecosystem or supply chain, the performance, conduct, or exposures of those outside parties can translate directly into adverse outcomes for the organization itself. This is significant because the organization typically remains accountable for outcomes even when the underlying activity is performed by someone else, so the failures of a third party can become the organization's problem to explain and remediate.
The concern has grown in prominence as organizational ecosystems have become more interconnected and reliant on external providers. Industry commentary, such as Deloitte's discussion of why third-party risk is on the rise, points to this increasing dependence as a driver of heightened attention to the topic. Because the specific risk domains implicated vary by the nature of each relationship, the potential adverse outcomes can span multiple areas rather than being confined to a single category, which makes third-party risk a cross-cutting concern rather than an isolated one.
Recognizing third-party risk as a distinct exposure allows organizations to apply structured attention to relationships that might otherwise be assumed to be low-risk simply because they sit outside the organization. Left unmanaged, dependence on external parties can create blind spots, since the organization may have limited direct visibility into how those parties operate.
Who it's relevant to
Inside Third-Party Risk
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Risk.
