ProcessRisk & Resilience

The third-party risk management process, from tiering to tested exit

A third-party risk management process works as a loop of six stages: inventory and tiering, proportionate due diligence, contracting, continuous monitoring, issue management and exit. Effort should follow inherent risk, so a critical cloud or AI provider gets deep scrutiny while a low-risk stationery supplier gets almost none. This page sets out each stage, what it must produce, and which EU and US rules expect it.

Reviewed 7 min read

On this page
  1. Six stages of the third-party lifecycle, run as a loop
  2. Why questionnaire-driven vendor programs stall
  3. Inherent-risk tiering factors and what each tier triggers
  4. What each lifecycle stage must leave behind
  5. Which rules expect which lifecycle stages
  6. Fourth parties, concentration and AI model providers
  7. A hypothetical insurer re-tiers its supplier base
  8. Questions and answers
  9. Sources

Six stages of the third-party lifecycle, run as a loop

01Inventory andtiering02Due diligence03Contracting04Continuousmonitoring05Issue management06Exit and offboarding
  1. Inventory and tiering

    Every third party recorded, with the service it supports and an inherent-risk tier.

  2. Due diligence

    Depth scaled to tier: security, financial health, resilience, compliance and ESG.

  3. Contracting

    Audit rights, incident notification, sub-outsourcing limits, exit and data return.

  4. Continuous monitoring

    Trigger events and periodic reviews that can change the tier.

  5. Issue management

    Findings with owners, deadlines, escalation and acceptance decisions.

  6. Exit and offboarding

    Planned, tested transition, data return and access removal, feeding the inventory.

Conceptual lifecycle of a third-party relationship. Monitoring and issue management repeat for as long as the relationship lasts; it is not a timeline.

Why questionnaire-driven vendor programs stall

Many programs begin as a long security questionnaire sent to every supplier once a year. The result is predictable: suppliers copy answers from their last response, risk teams drown in documents nobody reads, and the relationships that matter most get the same treatment as those that barely matter.

Two principles fix this. Proportionality means effort follows inherent risk, which is also what supervisors ask for: US banking agencies expect practices commensurate with the bank's risk profile and with the criticality of the activity supported1. Continuous assurance means the picture is updated when something changes, such as a breach at the supplier, a change of ownership or a new subcontractor, rather than waiting for the next annual cycle.

Inherent-risk tiering factors and what each tier triggers

Score each factor before any diligence. The highest-scoring factor usually sets the tier, not the average.

FactorLow tierElevated tierCritical tier
Function supportedNon-core, easily pausedImportant to a business lineSupports a critical service or regulated function
Data accessNone or public dataInternal or limited personal dataSensitive, regulated or bulk personal data
Network and system accessNo connectionRestricted, monitored accessPrivileged or persistent integration
SubstitutabilityMany alternatives, quick switchAlternatives exist with effortHard to replace within months
ConcentrationUnique to one minor processShared by several processesShared across many services or with peers

What each lifecycle stage must leave behind

  1. Inventory and tier

    Build one register of third parties linked to the services and data they touch. Procurement, accounts payable and IT asset records each reveal suppliers the others miss.

    Output
    Tiered third-party register
    Owner
    Third-party risk lead
  2. Run proportionate due diligence

    Low tiers get a light check; critical tiers get security evidence, financial review, resilience testing results, compliance and ESG checks, and an interview with the supplier's control owners.

    Output
    Due diligence file and risk rating
    Owner
    Risk and procurement
  3. Contract for the risk you found

    Translate diligence findings into terms: audit and access rights, incident notification windows, approval of material subcontractors, security obligations, termination rights, exit assistance and data return.

    Output
    Executed contract with risk schedule
    Owner
    Legal
  4. Monitor on triggers and on schedule

    Define trigger events that reopen the assessment, such as a breach, ownership change, adverse news or a missed service level, and set review frequency by tier.

    Output
    Monitoring plan and alert routing
    Owner
    Relationship owner
  5. Manage issues to closure

    Log each finding with an owner and deadline, escalate overdue items, and record formal risk acceptance by someone with the authority to accept it.

    Output
    Issue log and acceptance records
    Owner
    Relationship owner and risk
  6. Plan and rehearse exit

    For critical tiers, write an exit plan covering an alternative provider or in-house option, data return format, transition support and timeline, then walk through it before it is needed.

    Output
    Tested exit plan
    Owner
    Business service owner

Which rules expect which lifecycle stages

Names and scope are summarized; read the official texts for your entity type.

Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA)

EU financial entities

Applies whenA financial entity in scope uses ICT services from third-party providers; the Regulation applies from 17 January 20252.

  • Maintain a register of information on all contractual arrangements for ICT services from third-party providers2.
  • Assess concentration risk and include specified key provisions in ICT contracts2.
  • Have exit strategies for ICT services supporting critical or important functions2.

NIS2 Directive, Directive (EU) 2022/2555

EU essential and important entities

Applies whenAn entity falls within the Directive's sectors and size thresholds as transposed into national law3.

  • Article 21(2)(d) requires supply chain security, including the security aspects of relationships with direct suppliers and service providers3.
  • Measures must take account of each direct supplier's vulnerabilities and the quality of its products and cybersecurity practices3.

EBA Guidelines on outsourcing arrangements and the guidelines on third-party risk for non-ICT services

EU banks, investment firms, payment and e-money institutions

Applies whenAn institution outsources functions, especially critical or important ones; the newer non-ICT guidelines will repeal the outsourcing guidelines once applicable4.

  • Assess arrangements supporting critical or important functions with particular care4.
  • Check the application date of the newer guidelines before redesigning policies around them4.

Interagency Guidance on Third-Party Relationships: Risk Management

US banking organizations supervised by the Federal Reserve, FDIC and OCC

Applies whenA banking organization enters or maintains any business arrangement with a third party1.

  • Manage risk across the relationship life cycle, from planning and due diligence to ongoing monitoring and termination1.
  • Scale practices to the risk and criticality of each relationship1.

Fourth parties, concentration and AI model providers

Your supplier's suppliers can stop your service as surely as the supplier can. Ask critical third parties to disclose material subcontractors, require notice before changes, and map where several of your suppliers depend on the same cloud region, payment processor or software component. That map often reveals a single point of failure that no individual assessment would show.

AI providers deserve explicit treatment. A product built on a third-party model inherits that provider's outages, model version changes, data handling terms and acceptable use policies. Tier them like any other critical dependency, ask how model changes are announced and tested, and plan a fallback, whether an alternative model or a manual process, before the first production release. Continuous signals about supplier health are where AI supplier risk monitoring fits into stage four.

A hypothetical insurer re-tiers its supplier base

Questions and answers

How large should a third-party risk team be for a mid-market firm?

Size follows the number of critical and elevated relationships, not the total supplier count. A mid-market firm with a short list of critical providers can often run the program with a small central function that sets the method and handles critical tiers, while relationship owners in the business carry day-to-day monitoring. Regulated financial entities usually need more dedicated capacity because of register, reporting and supervisory review obligations.

Do we need dedicated TPRM software?

Not at first. A well-structured register, a tiering method, standard diligence templates and an issue log can run in tools you already have. Dedicated platforms become worthwhile when volumes grow, when you need workflow across procurement, legal and risk, or when a regulator expects a structured register such as DORA's register of information. Buy after the method is stable, so the tool supports your process rather than defining it.

How often should third parties be reassessed?

Set a periodic cycle by tier, with critical providers reviewed most often and low-tier suppliers rarely or only at renewal. More important than the calendar are trigger events: a security incident at the supplier, a change of control, adverse financial news, a new material subcontractor or a significant change in the service. Any trigger should reopen the assessment regardless of the next scheduled date.

Should cloud and AI model providers be treated as outsourcing?

Treat them as third parties in the same lifecycle and tier them on the same factors. Whether a particular arrangement counts as outsourcing, or as an ICT service supporting a critical or important function, depends on the rules that apply to you and needs a legal view. In practice their concentration and change risks usually put them in the highest tier.

Sources

  1. Third-Party Relationships: Interagency Guidance on Risk Management (OCC Bulletin 2023-17) — Office of the Comptroller of the Currency · checked 10 October 2026
  2. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) — EUR-Lex · checked 10 October 2026
  3. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
  4. Guidelines on the sound management of third-party risk related to non-ICT services — European Banking Authority · checked 10 October 2026

More in Risk & Resilience

Back to Risk & Resilience

Next step

Get your supplier tiering reviewed

Share your supplier register, or an export from procurement, and the services you consider critical. We will suggest a tiering method, show where diligence effort is misallocated and outline what a rehearsed exit would need for your top providers.

Review my TPRM program