Skip to content

Third-Party Risk

What is Third-Party Risk?

The potential threat to an organisation's data security and privacy posed by the actions or security posture of its vendors, partners, and service providers. Managing third-party risk is essential for GDPR compliance, particularly regarding data processors.

Privacy

Each of these is named in at least one of the same controls as third-party risk. The number is how many controls name both.

What the standards actually require on third-party risk

Requirements naming third-party risk across 6 standards, quoted from the control text.

Third party service providers are subject to due diligence, contractual security requirements, and ongoing monitoring.

IS-IX.A.1 · Third Party Risk Management
DORA2 controls

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangeme...

DORA-Art.28 · ICT third-party risk: general principles

Operate third-party risk + supply chain + resilience + metrics + continuous improvement per NRF framework. Third-party risk must (a) maintain vendor inventory categorised by data access + critical service + payment processing + e-commerce platform + cloud serv...

NRFCS-8 · Third-Party Risk, Supply Chain, Vendor Management, Resilience, Peak-Season Readiness, Metrics, Continuous Improvement

Third party risk assessments. The company should assess cyber risks introduced by third parties (vendors, ports, agents) and reflect them in the risk assessment and contracts.

BIMCO-6.3 · Third party risk assessments
C2M21 control

THIRD-PARTIES domain. Identify and manage cybersecurity risks arising from third parties and external dependencies (suppliers, service providers, vendors).

THIRD-1 · Identify and Manage Third-Party Risk

Operate third-party risk within Heightened Standards + integrate with broader bank regulation. Third-party risk per Heightened Standards must (a) integrate with OCC Bulletin 2013-29 Third-Party Risk Management + Interagency Guidance on Third-Party Relationship...

OCCHS-8 · Third-Party Risk Within Heightened Standards and Integration with Broader Regulation

Questions people ask about third-party risk

What is Third-Party Risk?
The potential threat to an organisation's data security and privacy posed by the actions or security posture of its vendors, partners, and service providers. Managing third-party risk is essential for GDPR compliance, particularly regarding data processors.
Why is Third-Party Risk important for compliance?
Third-Party Risk is a key concept in Privacy. Understanding third-party risk helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Third-Party Risk?
Third-Party Risk appears in the requirement text of FFIEC IT Examination Handbook, DORA, NRF Cybersecurity and Data Privacy Framework (National Retail Federation), BIMCO Cyber Security, C2M2. Across these standards we have identified 13 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Third-Party Risk?
Explore our compliance framework pages to see how third-party risk applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Third-Party Risk applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.