Skip to main content
Category: Third-Party Risk

Third-Party Risk

Also known as: Vendor Risk, Supply Chain Risk, Third-Party Vendor Risk
Simply put

Third-party risk is the potential for adverse outcomes that an organization may face because it relies on external parties such as vendors, suppliers, partners, or intermediaries. When an organization outsources functions or works with others in its ecosystem or supply chain, the actions, failures, or exposures of those outside parties can create risk for the organization itself. Managing this risk is commonly addressed through a practice known as third-party risk management (TPRM).

Formal definition

Third-party risk denotes the category of risk introduced to an organization through its dependence on external parties, including vendors, suppliers, service providers, partners, and intermediaries within its ecosystem or supply chain. It commonly arises when business functions are outsourced, and encompasses the potential adverse outcomes attributable to the performance, conduct, or exposures of those external parties. This term is distinct from the discipline of third-party risk management (TPRM), which refers to the practice of identifying, assessing, monitoring, and reducing such risks; third-party risk is the underlying exposure, while TPRM is the process applied to treat it. The specific risk domains implicated (for example, operational, information security, financial, or compliance-related) vary by the nature of the relationship and are not enumerated in the evidence provided here.

Why it matters

Organizations increasingly depend on external vendors, suppliers, partners, and intermediaries to deliver core functions, and each of these relationships extends the organization's risk surface beyond its own boundaries. When a business outsources a function or relies on others within its ecosystem or supply chain, the performance, conduct, or exposures of those outside parties can translate directly into adverse outcomes for the organization itself. This is significant because the organization typically remains accountable for outcomes even when the underlying activity is performed by someone else, so the failures of a third party can become the organization's problem to explain and remediate.

The concern has grown in prominence as organizational ecosystems have become more interconnected and reliant on external providers. Industry commentary, such as Deloitte's discussion of why third-party risk is on the rise, points to this increasing dependence as a driver of heightened attention to the topic. Because the specific risk domains implicated vary by the nature of each relationship, the potential adverse outcomes can span multiple areas rather than being confined to a single category, which makes third-party risk a cross-cutting concern rather than an isolated one.

Recognizing third-party risk as a distinct exposure allows organizations to apply structured attention to relationships that might otherwise be assumed to be low-risk simply because they sit outside the organization. Left unmanaged, dependence on external parties can create blind spots, since the organization may have limited direct visibility into how those parties operate.

Who it's relevant to

Risk Managers
Risk managers are responsible for identifying and assessing the exposure that external relationships introduce to the organization, and for ensuring that dependence on vendors, suppliers, and partners is treated as part of the broader risk picture rather than left unexamined.
Compliance Officers
Where reliance on third parties touches obligations the organization must meet, compliance officers have an interest in how those relationships are managed, since the organization commonly remains accountable for outcomes even when activities are performed by external parties. The specific obligations involved depend on jurisdiction, sector, and the nature of the relationship.
Procurement and Vendor Management Teams
Those who select and manage external providers are positioned at the point where third-party relationships are established and maintained, making them central to how the associated risks are surfaced and monitored over the life of the relationship.
Internal Auditors
As an independent assurance function, internal auditors may evaluate whether the organization's approach to managing third-party risk is designed and operating as intended, remaining distinct from the management activities that own and treat the risk directly.
Governance Professionals and Boards
Because dependence on external parties can create outcomes the organization is answerable for, those responsible for oversight have an interest in understanding how significant third-party exposures are governed and whether accountability for them is clearly assigned.

Inside Third-Party Risk

Third-Party Relationship Scope
The range of external parties that can introduce risk, commonly including suppliers, vendors, service providers, contractors, agents, distributors, and other business partners. The specific parties in scope typically depend on the organization's operating model, industry, and jurisdiction.
Risk Domains
The categories of exposure a third party may create, which commonly span operational, financial, reputational, compliance and regulatory, information security and data privacy, and concentration or geographic risk. The relevant domains vary by the nature of the relationship and the services provided.
Due Diligence
The pre-contract and ongoing assessment activities used to evaluate a third party's capabilities, controls, financial stability, and compliance posture. Depth of due diligence is typically calibrated to the criticality and inherent risk of the relationship.
Contractual and Onboarding Controls
The terms, rights, and obligations established through agreements, such as service levels, audit and information rights, security and privacy requirements, and remediation expectations. These represent management controls that shape how risk is allocated and treated.
Ongoing Monitoring
The continuous or periodic oversight of third-party performance and risk over the life of the relationship, which may include performance reviews, control attestations, and reassessment triggered by changes in the relationship or environment.
Fourth-Party and Subcontractor Exposure
Risk arising from a third party's own dependencies on other providers. Such downstream relationships can extend an organization's exposure beyond its direct counterparties and may be harder to observe or control.
Lifecycle Management
The end-to-end handling of a relationship from planning and selection through onboarding, ongoing management, and termination or offboarding, including secure return or destruction of data and orderly transition of services.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Risk.

Is third-party risk the same as vendor or supplier risk?
Not exactly. Vendor or supplier risk is commonly treated as a subset of third-party risk. Third-party risk is broader, extending to any external party an organization relies on or is exposed to through a relationship, which may include service providers, agents, distributors, joint venture partners, outsourced function providers, and other counterparties. Using the terms interchangeably can cause an organization to scope its program too narrowly and overlook relationships that do not fit a traditional procurement or purchasing model.
Does transferring an activity to a third party also transfer the associated risk and accountability?
Generally, no. Outsourcing or contracting an activity to a third party may shift certain operational tasks, but in many frameworks and under many regulatory regimes the accountability for managing the associated risk typically remains with the organization that owns the relationship and the underlying objective. A contract may allocate certain responsibilities and liabilities between parties, but this is distinct from the organization's own governance and oversight obligations, which commonly persist regardless of the arrangement.
How can an organization identify which third parties warrant the most oversight?
A common approach is to segment or tier third parties based on factors such as the criticality of the service or function they support, the sensitivity of data or systems they access, their role in delivering regulated activities, and the potential impact of their failure on the organization's objectives. Higher-tier relationships typically receive more extensive due diligence, contractual controls, and ongoing monitoring. The specific criteria and thresholds vary by organization, sector, and jurisdiction, and are usually documented in the organization's own methodology rather than prescribed uniformly.
What activities are commonly performed across the lifecycle of a third-party relationship?
Third-party risk management is often described as a lifecycle spanning planning and risk assessment before engagement, due diligence and selection, contracting and control specification, ongoing monitoring during the relationship, and structured termination or exit. The intensity of activity at each stage commonly reflects the tier or criticality assigned to the relationship. Specific practices, documentation, and tooling vary by organization and are outside the scope of this general description.
How do the lines of the three lines model typically relate to third-party risk?
In organizations that apply the three lines model of the IIA, the relationship or business owner in the first line commonly owns and manages the third-party risk day to day, second line functions such as risk and compliance may set policy, provide oversight, and challenge, and the third line internal audit may provide independent assurance over the design and operation of the program. This is a division of responsibility, not a transfer of accountability; the assurance activities of the third line should remain distinct from the management activities they evaluate.
How does third-party risk connect to fourth-party or subcontractor exposure?
Third parties frequently rely on their own subcontractors, sometimes referred to as fourth parties, which can extend an organization's exposure beyond its direct relationships. Programs commonly address this through contractual provisions, disclosure requirements, and consideration of concentration and chain dependencies during due diligence and monitoring. The depth of visibility achievable into these downstream parties varies, and expectations may differ across jurisdictions and sectors, particularly where regulatory guidance addresses supply chain or subcontracting arrangements.

Common misconceptions

Third-party risk management is primarily a procurement or purchasing function.
Third-party risk commonly spans governance, risk management, and compliance. While procurement often participates in sourcing and contracting, oversight typically involves risk, compliance, information security, legal, and business owners, with responsibilities frequently distributed across lines of defense.
Outsourcing an activity to a third party transfers the underlying risk and accountability away from the organization.
Delegating an activity does not typically transfer accountability for the associated risk or for regulatory obligations. In many jurisdictions and sectors, the organization remains responsible for outcomes and compliance regardless of who performs the work.
A due diligence assessment completed at onboarding is sufficient to manage the risk.
Point-in-time due diligence captures a single moment; third-party risk profiles can change over time. Ongoing monitoring and periodic reassessment are commonly needed to keep the risk view current.

Best practices

Maintain an inventory of third-party relationships and tier or classify them by criticality and inherent risk so that oversight effort can be calibrated proportionately.
Calibrate the depth of due diligence to the risk tier, applying more rigorous assessment to relationships involving critical services, sensitive data, or significant regulatory exposure.
Establish contractual provisions that address security, privacy, audit or information rights, service levels, and remediation, aligned to the applicable jurisdictional and sectoral requirements.
Implement ongoing monitoring with defined reassessment triggers, such as material changes in the relationship, the third party's control environment, or the external environment.
Seek visibility into material fourth-party and subcontractor dependencies to understand concentration and downstream exposure that may not be apparent from the direct relationship.
Define clear roles and accountability across business owners, risk, compliance, and assurance functions, keeping independent assurance activities distinct from the management of the relationships themselves.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.