ProcessRisk & Resilience
The third-party risk management process, from tiering to tested exit
A third-party risk management process works as a loop of six stages: inventory and tiering, proportionate due diligence, contracting, continuous monitoring, issue management and exit. Effort should follow inherent risk, so a critical cloud or AI provider gets deep scrutiny while a low-risk stationery supplier gets almost none. This page sets out each stage, what it must produce, and which EU and US rules expect it.
On this page
- Six stages of the third-party lifecycle, run as a loop
- Why questionnaire-driven vendor programs stall
- Inherent-risk tiering factors and what each tier triggers
- What each lifecycle stage must leave behind
- Which rules expect which lifecycle stages
- Fourth parties, concentration and AI model providers
- A hypothetical insurer re-tiers its supplier base
- Questions and answers
- Sources
Six stages of the third-party lifecycle, run as a loop
- Inventory and tiering
Every third party recorded, with the service it supports and an inherent-risk tier.
- Due diligence
Depth scaled to tier: security, financial health, resilience, compliance and ESG.
- Contracting
Audit rights, incident notification, sub-outsourcing limits, exit and data return.
- Continuous monitoring
Trigger events and periodic reviews that can change the tier.
- Issue management
Findings with owners, deadlines, escalation and acceptance decisions.
- Exit and offboarding
Planned, tested transition, data return and access removal, feeding the inventory.
Why questionnaire-driven vendor programs stall
Many programs begin as a long security questionnaire sent to every supplier once a year. The result is predictable: suppliers copy answers from their last response, risk teams drown in documents nobody reads, and the relationships that matter most get the same treatment as those that barely matter.
Two principles fix this. Proportionality means effort follows inherent risk, which is also what supervisors ask for: US banking agencies expect practices commensurate with the bank's risk profile and with the criticality of the activity supported1. Continuous assurance means the picture is updated when something changes, such as a breach at the supplier, a change of ownership or a new subcontractor, rather than waiting for the next annual cycle.
Inherent-risk tiering factors and what each tier triggers
Score each factor before any diligence. The highest-scoring factor usually sets the tier, not the average.
| Factor | Low tier | Elevated tier | Critical tier |
|---|---|---|---|
| Function supported | Non-core, easily paused | Important to a business line | Supports a critical service or regulated function |
| Data access | None or public data | Internal or limited personal data | Sensitive, regulated or bulk personal data |
| Network and system access | No connection | Restricted, monitored access | Privileged or persistent integration |
| Substitutability | Many alternatives, quick switch | Alternatives exist with effort | Hard to replace within months |
| Concentration | Unique to one minor process | Shared by several processes | Shared across many services or with peers |
What each lifecycle stage must leave behind
Inventory and tier
Build one register of third parties linked to the services and data they touch. Procurement, accounts payable and IT asset records each reveal suppliers the others miss.
Run proportionate due diligence
Low tiers get a light check; critical tiers get security evidence, financial review, resilience testing results, compliance and ESG checks, and an interview with the supplier's control owners.
Contract for the risk you found
Translate diligence findings into terms: audit and access rights, incident notification windows, approval of material subcontractors, security obligations, termination rights, exit assistance and data return.
Monitor on triggers and on schedule
Define trigger events that reopen the assessment, such as a breach, ownership change, adverse news or a missed service level, and set review frequency by tier.
Manage issues to closure
Log each finding with an owner and deadline, escalate overdue items, and record formal risk acceptance by someone with the authority to accept it.
Plan and rehearse exit
For critical tiers, write an exit plan covering an alternative provider or in-house option, data return format, transition support and timeline, then walk through it before it is needed.
Which rules expect which lifecycle stages
Names and scope are summarized; read the official texts for your entity type.
Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA)
EU financial entitiesApplies whenA financial entity in scope uses ICT services from third-party providers; the Regulation applies from 17 January 20252.
NIS2 Directive, Directive (EU) 2022/2555
EU essential and important entitiesApplies whenAn entity falls within the Directive's sectors and size thresholds as transposed into national law3.
EBA Guidelines on outsourcing arrangements and the guidelines on third-party risk for non-ICT services
EU banks, investment firms, payment and e-money institutionsApplies whenAn institution outsources functions, especially critical or important ones; the newer non-ICT guidelines will repeal the outsourcing guidelines once applicable4.
Interagency Guidance on Third-Party Relationships: Risk Management
US banking organizations supervised by the Federal Reserve, FDIC and OCCApplies whenA banking organization enters or maintains any business arrangement with a third party1.
Fourth parties, concentration and AI model providers
Your supplier's suppliers can stop your service as surely as the supplier can. Ask critical third parties to disclose material subcontractors, require notice before changes, and map where several of your suppliers depend on the same cloud region, payment processor or software component. That map often reveals a single point of failure that no individual assessment would show.
AI providers deserve explicit treatment. A product built on a third-party model inherits that provider's outages, model version changes, data handling terms and acceptable use policies. Tier them like any other critical dependency, ask how model changes are announced and tested, and plan a fallback, whether an alternative model or a manual process, before the first production release. Continuous signals about supplier health are where AI supplier risk monitoring fits into stage four.
A hypothetical insurer re-tiers its supplier base
Questions and answers
How large should a third-party risk team be for a mid-market firm?
Size follows the number of critical and elevated relationships, not the total supplier count. A mid-market firm with a short list of critical providers can often run the program with a small central function that sets the method and handles critical tiers, while relationship owners in the business carry day-to-day monitoring. Regulated financial entities usually need more dedicated capacity because of register, reporting and supervisory review obligations.
Do we need dedicated TPRM software?
Not at first. A well-structured register, a tiering method, standard diligence templates and an issue log can run in tools you already have. Dedicated platforms become worthwhile when volumes grow, when you need workflow across procurement, legal and risk, or when a regulator expects a structured register such as DORA's register of information. Buy after the method is stable, so the tool supports your process rather than defining it.
How often should third parties be reassessed?
Set a periodic cycle by tier, with critical providers reviewed most often and low-tier suppliers rarely or only at renewal. More important than the calendar are trigger events: a security incident at the supplier, a change of control, adverse financial news, a new material subcontractor or a significant change in the service. Any trigger should reopen the assessment regardless of the next scheduled date.
Should cloud and AI model providers be treated as outsourcing?
Treat them as third parties in the same lifecycle and tier them on the same factors. Whether a particular arrangement counts as outsourcing, or as an ICT service supporting a critical or important function, depends on the rules that apply to you and needs a legal view. In practice their concentration and change risks usually put them in the highest tier.
Sources
- Third-Party Relationships: Interagency Guidance on Risk Management (OCC Bulletin 2023-17) — Office of the Comptroller of the Currency · checked 10 October 2026
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — EUR-Lex · checked 10 October 2026
- Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
- Guidelines on the sound management of third-party risk related to non-ICT services — European Banking Authority · checked 10 October 2026