Third-Party Risk
What is Third-Party Risk?
The potential threat to an organisation's data security and privacy posed by the actions or security posture of its vendors, partners, and service providers. Managing third-party risk is essential for GDPR compliance, particularly regarding data processors.
Terms that appear alongside third-party risk
Each of these is named in at least one of the same controls as third-party risk. The number is how many controls name both.
- due diligence 13 shared controls
- cybersecurity 12 shared controls
- audit 10 shared controls
- concentration risk 9 shared controls
- compliance 8 shared controls
- governance 7 shared controls
- resilience 6 shared controls
- breach notification 5 shared controls
Frameworks that govern third-party risk
What the standards actually require on third-party risk
Requirements naming third-party risk across 6 standards, quoted from the control text.
Third party service providers are subject to due diligence, contractual security requirements, and ongoing monitoring.
IS-IX.A.1 · Third Party Risk Management →Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangeme...
DORA-Art.28 · ICT third-party risk: general principles →Operate third-party risk + supply chain + resilience + metrics + continuous improvement per NRF framework. Third-party risk must (a) maintain vendor inventory categorised by data access + critical service + payment processing + e-commerce platform + cloud serv...
NRFCS-8 · Third-Party Risk, Supply Chain, Vendor Management, Resilience, Peak-Season Readiness, Metrics, Continuous Improvement →Third party risk assessments. The company should assess cyber risks introduced by third parties (vendors, ports, agents) and reflect them in the risk assessment and contracts.
BIMCO-6.3 · Third party risk assessments →THIRD-PARTIES domain. Identify and manage cybersecurity risks arising from third parties and external dependencies (suppliers, service providers, vendors).
THIRD-1 · Identify and Manage Third-Party Risk →Operate third-party risk within Heightened Standards + integrate with broader bank regulation. Third-party risk per Heightened Standards must (a) integrate with OCC Bulletin 2013-29 Third-Party Risk Management + Interagency Guidance on Third-Party Relationship...
OCCHS-8 · Third-Party Risk Within Heightened Standards and Integration with Broader Regulation →Questions people ask about third-party risk
What is Third-Party Risk?
Why is Third-Party Risk important for compliance?
Which compliance frameworks address Third-Party Risk?
Where can I learn more about Third-Party Risk?
See how Third-Party Risk applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.