Third-party risk is operational risk with an external dependency attached. Outsourcing can improve scale, speed and specialist capability, but it also creates concentration risk, dependency risk, visibility gaps and incident-reporting complexity. For financial firms, that means third-party oversight has to be treated as a full lifecycle discipline rather than a procurement checkpoint.
This framing matters because the way most firms structure their third-party risk activity does not reflect it. Due diligence at onboarding is frequently rigorous, well-documented and genuinely thorough. What happens after the contract is signed is, in many organisations, considerably weaker. That asymmetry is a real vulnerability, because the risk a third party poses to a firm rarely stays static once a relationship begins. A supplier that was financially stable, well-controlled and low-risk at onboarding can deteriorate significantly over a multi-year contract term, and a firm that only assessed risk once, at the start, has no mechanism to notice.
Start with governance, policy and the register
A practical programme begins with a board-approved policy, clear materiality criteria and an up-to-date register of outsourcing and material third-party relationships. Without those foundations, firms struggle to prioritise attention and to explain why some providers receive deeper oversight than others.
The register is more foundational than it might initially appear. Many firms, when asked directly, struggle to produce a complete and current list of every material third party they depend on, particularly once subsidiary relationships and sub-outsourcing arrangements are taken into account. Building and maintaining this register, with clear materiality criteria that determine which relationships warrant intensive oversight and which can be managed more lightly, is the prerequisite for everything else in the programme. Materiality criteria typically consider factors such as the criticality of the service to important business functions, the volume and sensitivity of data the provider can access, the cost or difficulty of replacing the provider if the relationship ended, and any regulatory or reputational exposure the relationship creates. A board-approved policy then sets the overarching expectations for how the firm manages these relationships across their full lifecycle, giving the whole programme formal status rather than leaving it to informal procurement practice.
Due diligence should be risk-based, not box-based
Understand the supplier before signing
Due diligence should assess financial stability, operational resilience, control maturity, regulatory alignment, information security and service dependency. The depth of review should reflect the criticality of the arrangement rather than applying one flat questionnaire to every vendor.
A standard due diligence questionnaire applied uniformly to every supplier, regardless of how critical the relationship is, tends to produce two unhelpful outcomes simultaneously: it asks low-risk suppliers for more information than is genuinely proportionate, creating friction and delay for relationships that pose minimal risk, while often failing to dig deeply enough into the firm's most critical dependencies, where a more thorough, tailored assessment is genuinely warranted. A risk-based approach scales the depth of review to the materiality of the relationship: for the firm's most critical suppliers, this might include detailed financial analysis, independent security assessments or certifications, site visits or audits, and explicit assessment of the supplier's own sub-outsourcing arrangements, while lower-risk relationships can be managed with a lighter, proportionate process.
Write contracts that support resilience
Material outsourcing agreements must cover key items such as defined service levels, access and audit rights, data security, exit strategies, business continuity, and, for critical functions, resolution clauses.
The operational value of these clauses only becomes obvious when something fails, which is precisely why they need careful attention at the negotiation stage rather than being treated as standard legal boilerplate. Audit rights that exist on paper but were never genuinely negotiated to be practically exercisable are not much use when the firm actually needs to investigate a supplier's control environment following an incident. Exit provisions that were never seriously thought through become a genuine operational crisis if the relationship needs to end quickly, whether due to supplier failure, a serious control breakdown, or a strategic decision to bring the service back in-house. Business continuity obligations on the supplier, including their own tested recovery capabilities, deserve the same scrutiny the firm would apply to its own internal resilience planning, because from a customer's perspective, a third-party failure and an internal failure produce the same outcome.
Ongoing monitoring is where many programmes weaken
Once onboarding is complete, firms often underestimate the importance of live monitoring. KPI and KRI tracking, periodic reviews, issue escalation, control assessments and refresh due diligence are what turn a third-party framework into continuous oversight. A vendor that was low risk at onboarding may not stay that way.
Building genuine ongoing monitoring requires deliberate design, because it does not happen by default once the contract is signed and operational handover is complete. Collecting KPIs from service providers and tracking them against agreed thresholds is not only good practice; in many jurisdictions it is becoming an explicit regulatory expectation. This might include service level performance, incident frequency and resolution times, and any control or compliance attestations the supplier is contractually obliged to provide. For the firm's most material vendors, where service disruption would have a genuinely significant impact, periodic audits or independent control assessments add a level of assurance that performance metrics alone cannot provide.
Refresh due diligence, conducted periodically across the life of the relationship rather than only at the point of renewal, is what catches the kind of deterioration described above: a supplier whose financial position has weakened, whose security posture has changed following an acquisition or restructuring, or whose own sub-outsourcing arrangements have shifted in ways the firm was never informed of. The frequency and depth of refresh due diligence should, like initial onboarding, scale with the materiality of the relationship.
Incident response and exit planning must be real
Third parties need to be embedded into incident response plans, not referenced abstractly. Where ICT providers or critical suppliers fail, firms may still carry the reporting burden themselves. Exit planning matters for the same reason: if a service becomes unacceptable, the firm needs a realistic route to transition or substitute it without introducing intolerable additional risk.
This point deserves particular emphasis because it is frequently misunderstood. Outsourcing a function does not outsource the regulatory and customer-facing responsibility for that function. If a critical cloud provider experiences a major outage, the firm's own customers experience the consequences, and the firm's own regulator expects the firm to respond appropriately, including, where thresholds are met, formal incident notification. Major ICT incidents at vendors, such as significant cloud outages, can trigger the same reporting obligations under DORA as an internal incident would. Contracts and processes should therefore require vendors to report incidents promptly and with enough detail for the firm to assess its own reporting obligations, and the firm's own incident response plan must explicitly incorporate scenarios where the failure originates with a third party rather than internally.
Exit planning is the discipline most often left until it is genuinely needed, which is precisely the wrong time to develop it. A realistic exit plan, considered seriously at the point of contracting rather than only when a relationship turns sour, addresses practical questions that are far harder to answer under pressure: how quickly could the service genuinely be transitioned to an alternative provider or brought in-house, what data and knowledge transfer would be required, and what interim arrangements would need to be in place during any transition period. Firms that have never seriously worked through these questions for their most critical suppliers often discover, at exactly the wrong moment, that they are more dependent on a single provider than their risk assessments had assumed.
Regulatory alignment
While the effective management of third parties is good for business, it is also a regulatory requirement in pretty much all relevant jurisdictions. Adhering to frameworks such as DORA, the EBA Guidelines on the Sound Management of Third-Party Risk, and FCA and PRA requirements should all be taken into consideration when designing and implementing your third-party risk management programme.
These frameworks have moved in a consistent direction over recent years: greater specificity about what good third-party governance looks like, more explicit expectations around concentration risk and critical service dependencies, and clearer rules around incident reporting that extend to third-party failures. Firms that build their third-party risk programme around the lifecycle described above, rather than treating regulatory compliance as a separate documentation exercise layered on top of existing practice, generally find that meeting these regulatory expectations becomes a natural by-product of good practice rather than an additional burden.
Conclusion
Strong third-party risk management does not mean distrusting suppliers. It means understanding dependency, documenting expectations, monitoring performance and planning for disruption before it arrives. In current regulatory conditions, that is not just prudent. It is expected.
Building a third-party risk programme with genuine strength across the full lifecycle, from due diligence through to exit planning, rather than one that is strong only at onboarding, is covered in detail in our full whitepaper. Download the complete Operational Risk whitepaper for the full approach to outsourcing and third-party oversight, and how it connects to the rest of your operational risk framework.