Third-Party Risk
Pronunciation: THURD PAHR-tee RISK
Definition
Third-party risk is exposure created by external organizations, services, people, systems, or subcontractors that support an organization’s activities. Decision-makers use Third-Party Risk to compare exposure with appetite and limits, select treatment, assign actions, monitor indicators, and accept documented residual risk when justified. A score for Third-Party Risk is not the risk itself; results depend on model assumptions, data quality, scenario boundaries, control effectiveness, and changing operating conditions.
Overview
Third-party risk includes security, privacy, operational, financial, legal, compliance, concentration, reputation, and continuity exposure. Providers may process data, hold assets, operate infrastructure, make decisions, or connect directly to customers and critical systems.
Contracts and certifications do not eliminate risk, particularly when assurance scope is narrow or lower-tier subcontractors remain unknown. Multiple vendors can also depend on the same cloud, software, bank, custodian, or geographic region.
Organizations should classify critical parties, assess before engagement, define requirements, limit access, monitor changes and incidents, and maintain exit plans. Due diligence should follow real data and service flows, while testing confirms that continuity, replacement, data return, and revocation procedures work.
Third-party risk is exposure created by external organizations, services, people, systems, or subcontractors that support an organization’s activities. Third-party risk remains the organization’s exposure, requiring lifecycle oversight, dependency visibility, controlled access, evidence, continuity, and tested exit.
For Third-Party Risk, the assessment should evaluate exposure created by external organizations, services, people, systems, or subcontractors that support an organization’s activities. The assessment record should separate observed evidence supporting exposure created by external organizations, services, people, systems, or subcontractors that support an organization’s activities from assumptions, state the time horizon and existing controls, and identify who owns any remaining exposure. Monitoring should test whether the conditions described in exposure created by external organizations, services, people, systems, or subcontractors that support an organization’s activities have changed enough to require a new rating, treatment, or approval.
Decision-makers should use findings about exposure created by external organizations, services, people, systems, or subcontractors that support an organization’s activities to select treatment, assign remediation, set review thresholds, and document why any residual exposure is accepted.
Key Takeaway
Third-party risk remains the organization’s exposure, requiring lifecycle oversight, dependency visibility, controlled access, evidence, continuity, and tested exit.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)