Pillars of Risk Management Third-Party Risk

0
0
Hire Risk Expert
You agree to our Terms and Conditions of Use, PDPA & Privacy Policy and Cookies Policy

Pillars of Risk Management Third-Party Risk

THIRD-PARTY RISK: YOUR BUSINESS MAY END AT YOUR DOOR. YOUR DEPENDENCIES DO NOT.

THIRD-PARTY RISK AS ONE OF THE PILLARS OF RISK MANAGEMENT

On the main Pillars of Risk Management page, we explained why Third-Party Risk remains alongside Technology Risk, Enterprise Risk Management, Cyber Risk, Operational Resilience, Business Continuity, Governance & Compliance, Risk Assessment and the Risk Register even as this website expands into newer areas such as A.I. & Risk, Decision Making, Human Behaviour, Future of Work, Trust, The Science of Risk, The Future Human and Signals.

Third-Party Risk belongs among these foundations because very few businesses actually do everything themselves. A small restaurant depends upon food suppliers and delivery platforms. A retailer may depend upon manufacturers, distributors, payment providers and logistics companies. A consultant may depend upon cloud storage, accounting software, videoconferencing and an A.I. assistant. A solopreneur may appear to be a business of one person, but behind that one person there may be ten or twenty external services helping the business function every day.

This creates a simple but important Risk Management question: what happens to my business when something I depend upon is controlled by somebody else?

That question has become more important because the boundaries of the modern business have changed. We outsource accounting, payroll, technology support, logistics and other specialist activities. We use cloud providers rather than maintaining our own infrastructure. We engage freelancers rather than employ everyone permanently. We rely on platforms for payments, sales and communication. Increasingly, we may also rely on A.I. companies to provide technology that performs work once done by people.

Sometimes the third party we depend upon is itself dependent upon another organisation we have never heard of. This is why Third-Party Risk is no longer simply about asking whether a supplier is reliable. Increasingly, we need to understand what the business actually depends upon, how far that dependency chain goes, and what happens if something along that chain fails.

WHAT IS THIRD-PARTY RISK?

Third-Party Risk is the risk created when an individual or business depends upon an external person, company, supplier, contractor, platform or service provider to perform something important.

The third party may be obvious. Your accountant is a third party. So is your courier, IT provider, landlord, manufacturer or cleaning contractor. But many modern third parties are less visible. Your payment platform is a third party. Your cloud-storage provider is a third party. The software holding your customer records may be provided by a third party. The A.I. assistant your employees use is almost certainly a third party.

The dependency can also extend beyond the organisation with which you have a direct contract. A software provider may rely upon a cloud provider. An A.I. application may rely upon somebody else's foundation model. A supplier may rely upon a manufacturer in another country, which in turn depends upon raw materials arriving through a particular shipping route.

Your direct supplier is your third party. The organisations on which that supplier depends are sometimes described as fourth parties, and the chain can continue beyond them. For a small business, mapping every organisation in that chain would be unnecessary and unrealistic. The more useful question is whether a dependency several steps away could still materially affect the business.

HOW DID THIRD-PARTY RISK COME ABOUT?

Third-Party Risk may sound like a modern Risk Management discipline, but the underlying problem is as old as trade itself.

A merchant depended upon somebody to supply goods. A farmer depended upon someone to transport produce. A shopkeeper depended upon wholesalers. A manufacturer depended upon raw materials arriving on time. The basic questions were familiar: will my supplier deliver, is the quality acceptable, can I trust this person, what happens if the goods arrive late, and should I have another supplier?

Long before anybody used terms such as third-party due diligenceconcentration risk or vendor risk management, people were already managing these exposures. They checked reputations, inspected goods, negotiated contracts, maintained additional stock and kept relationships with more than one supplier.

The professional terminology came later. The dependency came first.

HOW DID SMALL BUSINESSES TRADITIONALLY MANAGE THIRD-PARTY RISK?

One of the oldest Third-Party Risk tools is also one of the simplest: have another supplier.

If a restaurant depends entirely upon one supplier for an important ingredient, identifying an alternative reduces the consequences if the original supplier cannot deliver. Another traditional tool is the contract. What exactly has the supplier agreed to provide, at what price, within what time, and what happens when something goes wrong?

Businesses also used due diligence before entering important relationships. Is the supplier established? Does it have a good reputation? Can it actually deliver what it promises? Over time, more formal tools developed around the same problems: supplier questionnaires, references, financial checks, insurance requirements, contractual clauses, performance monitoring, service-level agreements and periodic reviews.

For a small business, however, these tools should remain proportionate. If you are buying stationery, a 200-question supplier questionnaire would make little sense. If you are giving a company access to all your customers' confidential information, asking no questions at all would be equally inappropriate.

That leads to one of the most useful principles in modern Third-Party Risk: the amount of due diligence should reflect how much you depend upon the third party and what could happen if it fails.

NOT EVERY THIRD PARTY IS EQUALLY IMPORTANT

A business may have dozens or even hundreds of suppliers, but they do not all deserve the same level of attention. The company supplying office plants does not require the same assessment as the company storing all your customer information or processing your payments.

This is where third-party risk tiering or criticality assessment becomes useful. Instead of asking every supplier the same questions, the business first considers how important the relationship is.

Does the third party handle confidential or personal information? Does it support an important activity? Would customers be affected if it failed? Could the service be replaced easily? Would failure create a significant financial loss? Does the provider have access to internal systems? Is the business heavily dependent upon it?

These questions allow a small company to separate ordinary suppliers from critical or material third parties. The tool itself is not especially new. What is changing is the type of third party that may now turn out to be critical.

FROM THE LOCAL SUPPLIER TO THE DIGITAL SUPPLY CHAIN

Once, Third-Party Risk was easier to see. You ordered something from a supplier, and the supplier either delivered it or did not.

Today, much of the supply chain is invisible. A small business may use a software application without knowing where the application is hosted. The software provider may rely on another company's cloud infrastructure. That cloud provider may operate data centres across several countries, while other components depend upon still more technology providers.

The same pattern is emerging with A.I. A business may subscribe to an A.I. product from Company A, but Company A may not have developed the underlying foundation model. It may depend upon Company B's model and Company C's cloud infrastructure.

This means that having several suppliers does not always mean that the business is genuinely diversified. Three different A.I. vendors may ultimately rely upon the same model or infrastructure provider. Five apparently separate technology services may share the same cloud dependency.

This is concentration risk, and it is becoming one of the more important extensions of traditional Third-Party Risk. Having several suppliers does not necessarily mean having several independent sources of resilience. Sometimes many suppliers lead back to one hidden dependency.

YOU CAN OUTSOURCE THE WORK, BUT YOU CANNOT ASSUME THE CONSEQUENCES HAVE DISAPPEARED

This is perhaps the most important principle on this page.

Businesses outsource because outsourcing can make enormous sense. A specialist may perform an activity better or more cheaply. Technology providers can give a small company capabilities it could never afford to build itself. Freelancers provide flexibility, while cloud services allow very small businesses to use sophisticated infrastructure without maintaining it themselves.

Outsourcing is therefore not inherently a problem. The issue is what happens when the business assumes that outsourcing the activity also outsources all of the consequences.

Imagine that a small business outsources payroll. If the payroll provider fails to pay employees correctly, the provider may have caused the problem, but employees will still turn to their employer. If customer data is stored with an external provider and that provider suffers a serious breach, contractual responsibility may sit partly with the provider, but customers may still associate the incident with the business they trusted with their information.

The same applies to A.I. If a business uses an external A.I. service to generate advice or make recommendations, saying that “the vendor did it” may not remove the business consequences if the outcome is poor.

For this reason, a more accurate principle is that the activity can be outsourced, but accountability for understanding and managing the resulting dependency cannot simply be outsourced with it.

There is an important nuance. Some financial consequences can be transferred through insurance, and responsibilities can be allocated through contracts. But risk transfer does not necessarily remove the underlying exposure. Insurance may reimburse part of a financial loss after an incident, but it does not automatically restore customer trust, recover lost data, reopen a disrupted shipping route or keep the business operating while the problem is being resolved.

SOLPRENEURS AND NANOPRENEURS MAY MAKE THIRD-PARTY RISK MORE IMPORTANT, NOT LESS

The emergence of solopreneurs and very small businesses creates an interesting contradiction. The business itself may be getting smaller while its dependency network becomes larger.

One person can now create a business using cloud accounting, online payments, outsourced fulfilment, digital marketing platforms, freelance designers, virtual assistants, online marketplaces, cloud storage, videoconferencing and A.I. Twenty years ago, some of these activities might have required employees or internal infrastructure. Today, one entrepreneur can assemble them from external services.

This means we should not assume that small business equals small Third-Party Risk. In some cases, the opposite may be true.

A solopreneur may have extraordinarily high third-party dependency because there is very little internal capability available when an external service disappears. If the booking platform fails, there may be no IT department. If the A.I. tool stops working, there may be no alternative analyst. If the payment platform suspends the account, there may be no treasury function. If cloud storage is inaccessible, there may be no internal server holding another copy.

The modern small business may therefore resemble a network of external capabilities coordinated by one entrepreneur. The more useful question is not how many employees the company has, but how many external dependencies sit behind the activities it needs to perform every day.

THE FUTURE OF WORK IS CHANGING WHO COUNTS AS A THIRD PARTY

Changing work patterns add another dimension. Businesses increasingly rely on freelancers, contractors, consultants, virtual assistants, gig workers and specialist external providers. Remote work also means that people contributing to the same business may be spread across different locations and may never meet physically.

This connects Third-Party Risk directly with Future of Work. An external freelancer may have access to customer information. A contractor may administer an important system. A virtual assistant may handle business correspondence. A consultant may possess knowledge that nobody inside the business has.

These arrangements create questions that sit between Third-Party Risk, Human Behaviour, Cyber Risk and Governance. What access should the contractor have? What happens when the engagement ends? Who owns the work that was created? Where is company information stored? What happens if the freelancer suddenly disappears? Does anyone inside the business know how the work was performed?

As workforce boundaries become less distinct, third-party dependency and workforce dependency increasingly overlap.

COVID-19 CHANGED THE WAY WE THINK ABOUT SUPPLIERS

COVID-19 exposed how easily businesses could misunderstand their supply-chain dependencies. A supplier could be financially healthy and operationally competent yet still be unable to deliver because factories closed, workers became unavailable, transport capacity disappeared or borders became harder to cross.

It also showed how several suppliers could fail at the same time because they depended upon the same location or upstream source. This challenged the traditional assumption that supplier management was mainly about assessing the individual supplier's financial health and performance.

Sometimes the supplier itself is not the problem. The environment surrounding the supplier is the problem.

That lesson remains relevant beyond the pandemic.

TRADE WARS, PHYSICAL WARS AND THE RETURN OF GEOGRAPHY

Third-Party Risk increasingly needs to consider where important dependencies are located and how goods or services actually reach the business.

A company may have an excellent supplier with strong finances, good controls and a long history of reliable delivery. But what happens if the route between the supplier and the business becomes disrupted? What if trade restrictions, sanctions, conflict or shipping congestion affect the flow of goods? What if the alternative supplier uses the same route?

This shifts Third-Party Risk from asking only whether the supplier is reliable towards asking whether the supply chain surrounding the supplier is resilient.

This is where Third-Party Risk connects naturally with Signals → Geopolitical Risk, Climate Risk and Emerging Risk. A trade dispute can affect tariffs and availability. A conflict can threaten transport routes. Extreme weather can affect ports and logistics infrastructure. Drought can reduce the capacity of important waterways. Political developments can alter where companies are able or willing to do business.

A small-business owner does not need to become a geopolitical strategist. But where an important supplier depends heavily on one country, one port, one route or one upstream source, some awareness of that concentration can become very valuable.

THIS IS WHERE SIGNALS BECOMES USEFUL

Traditional supplier management can be backward-looking. Did the supplier meet its service level last month? Were deliveries on time? Did it pass the annual review?

These are useful questions, but a supplier can have an excellent historical record while the environment around it deteriorates. Political tension may be increasing where it operates. Shipping delays may be becoming more frequent. New tariffs may be proposed. An upstream supplier may be struggling. Extreme weather may be affecting a transport corridor.

Signals and horizon scanning therefore add an earlier layer to Third-Party Risk by asking: what is changing around the third party that could change our dependency on it?

This is not about predicting every war, tariff or supply-chain interruption. It is about noticing when yesterday's assumptions about a supplier may no longer be safe assumptions for tomorrow.

HOW THIRD-PARTY RISK CONNECTS WITH TECHNOLOGY RISK

Technology Risk and Third-Party Risk increasingly overlap because much of the technology used by small businesses is no longer owned by the business.

A cloud application may be reliable, secure and well designed, but the company using it still depends upon someone else to operate it. Technology Risk asks whether the technology itself is reliable, recoverable and appropriately managed. Third-Party Risk asks what happens because part of that technology is controlled outside the business.

This distinction becomes especially important with cloud computing, SaaS platforms and A.I., where the business may have very little direct control over the underlying infrastructure. The same service can therefore be both a Technology Risk and a Third-Party Risk without the two concepts becoming duplicates.

We are simply looking at the same dependency from different angles.

HOW THIRD-PARTY RISK CONNECTS WITH CYBER RISK

Cyber Risk follows the third party too.

A business can have strong internal cyber controls and still be exposed through an external provider that has access to its systems or information. This is why modern cyber due diligence may consider what data the third party receives, what system access it has, how accounts are protected, whether incidents must be reported and what happens to information when the relationship ends.

The dependency can also extend further. A cyberattack against a supplier's supplier can still interrupt your business. This is why fourth-party cyber risk and technology concentration are becoming increasingly important.

The organisation experiencing the cyberattack may be several steps removed, but the operational consequence can still reach your business.

HOW THIRD-PARTY RISK CONNECTS WITH OPERATIONAL RESILIENCE AND BUSINESS CONTINUITY

The Operational Resilience and Business Continuity pages ask what happens when something important disappears. Third-Party Risk helps identify how often that “something” belongs to somebody else.

Operational Resilience asks whether an important service can continue when the third party fails. Business Continuity asks what the business will actually do during that disruption.

Perhaps there is another supplier. Perhaps the work can be performed manually. Perhaps additional inventory is held. Perhaps data can be exported to another platform. Perhaps an activity can temporarily be brought back in-house.

This is why a good Third-Party Risk assessment should not end with the conclusion that “the vendor passed.” A more useful question is: if this vendor disappears tomorrow, what would we actually do?

That question connects due diligence directly with resilience.

HOW THIRD-PARTY RISK CONNECTS WITH GOVERNANCE & COMPLIANCE

The Governance & Compliance page asks who owns a decision, what obligations apply and who remains accountable. Third-Party Risk provides one of the clearest examples of why those questions matter.

A company can delegate an activity without necessarily delegating all accountability for the outcome. Governance therefore needs to establish who owns the third-party relationship, who approves important vendors, who monitors performance and who decides when the relationship is no longer acceptable.

Compliance may also follow the activity outside the company. Depending on the circumstances, legal, regulatory, privacy, confidentiality or contractual obligations may still matter when an external provider performs the work.

The contract is therefore an important Third-Party Risk tool, but the contract is not magic. A well-drafted contractual right to recover damages does not necessarily keep your business operating while the dispute is being resolved. Contracts and insurance need to sit alongside continuity and contingency planning rather than replace them.

HOW THIRD-PARTY RISK BECOMES ENTERPRISE RISK

A third party becomes an Enterprise Risk when the dependency is important enough to affect the wider objectives or survival of the business.

Imagine a small online retailer that receives 80% of its sales through one marketplace. The marketplace is technically a third party, but losing access to it could threaten the entire business model. At that point, this is no longer simply a vendor-management problem. It is also Enterprise Risk.

The same can happen when one supplier provides a critical product, one payment provider processes almost all revenue or one A.I. platform becomes embedded throughout the company's work.

Third-Party Risk identifies and examines the dependency. Enterprise Risk asks what that dependency means for the business as a whole.

A.I. IS CREATING A NEW FORM OF THIRD-PARTY DEPENDENCY

A.I. may become one of the most important new extensions of Third-Party Risk because most businesses using A.I. do not develop the underlying technology themselves. They purchase access to it.

This means that many A.I. risks arrive through third parties. A business may need to ask whether confidential information can be entered into the A.I. system, what happens to the data afterwards, where it is processed, what happens if the provider changes the model, whether the service can be substituted and whether several A.I. applications ultimately depend upon the same foundation model.

These sound like new A.I. questions, and they are. But many are also evolved Third-Party Risk questions.

The established toolkit still helps: due diligence, criticality assessment, contractual protection, data assessment, concentration analysis, performance monitoring, contingency planning and exit planning. The questions simply need to be adapted to a new type of provider.

This creates a natural bridge from Third-Party Risk → A.I. & Risk → A.I. Governance → Operational Resilience.

WHAT IF MY A.I. VENDOR HAS AN A.I. VENDOR?

This may become one of the defining Third-Party Risk questions of the A.I. era.

A business purchases an A.I. application from Vendor A. Vendor A uses a foundation model supplied by Vendor B. Vendor B depends upon cloud infrastructure from Vendor C. Other components may rely upon still more providers.

The business may have a contract with Vendor A, but its operational dependency extends far beyond Vendor A.

Traditional vendor management concentrated heavily on the direct contractual counterparty. Modern Third-Party Risk increasingly needs to ask what sits underneath the service being purchased.

Not every fourth party needs to be assessed individually. A more practical approach is to identify material subcontractors, concentration points and dependencies whose failure could materially affect the service.

This is where third-party mapping begins to look less like a supplier list and more like a dependency map.

HOW IS THE THIRD-PARTY RISK TOOLKIT CHANGING?

The traditional toolkit remains valuable: supplier due diligence, questionnaires, references, contracts, service-level agreements, financial checks, insurance requirements, risk assessments, performance reviews and alternative suppliers.

But the toolkit is expanding because the nature of dependency is changing.

Criticality assessments help determine which third parties deserve deeper attention. Dependency mapping helps identify what important services rely upon. Concentration analysis asks whether apparently different providers share the same underlying dependency. Fourth-party analysis looks beyond the direct vendor where important subcontractors matter. Exit planning asks how the business would leave an important provider and whether its information, processes or services are actually portable.

Scenario testing asks what happens if an important provider suddenly becomes unavailable, while geographic and geopolitical analysis can help identify concentrations in particular countries, routes or regions. Continuous monitoring can supplement annual due diligence by identifying changes in financial health, cyber events, operational incidents or external conditions.

Increasingly, A.I. supply-chain assessment may also need to identify underlying models, cloud dependencies and other material providers supporting an A.I. service.

The old supplier questionnaire has not disappeared. It simply cannot answer every question we now need to ask.

WHAT ARE RISK PRACTITIONERS BEGINNING TO ADAPT NOW?

One important change is the movement from vendor management towards dependency management.

A vendor list tells us who we pay. A dependency map tells us what we cannot operate without. Those are not always the same thing.

Risk practitioners are therefore paying more attention to critical third parties, concentration, fourth parties, substitutability, exit capability and end-to-end dependency mapping.

Scenario analysis is also becoming more useful. Instead of asking only whether a supplier has a Business Continuity Plan, practitioners can ask what happens if that supplier is unavailable for a week, whether the alternative supplier is genuinely independent, what happens if a shipping route becomes unavailable, or whether several business applications rely on the same A.I. model provider.

These questions connect traditional Third-Party Risk tools to a much more interconnected world.

HOW WILL INSURANCE COPE AS THIRD-PARTY RISK SPREADS MORE WIDELY?

Insurance remains one way of transferring some of the financial consequences of Third-Party Risk, but increasingly interconnected dependencies create difficulties for insurers too.

A single event can affect many insured businesses simultaneously. A major cloud outage can affect thousands of companies. A cyber event can spread through a widely used provider. A shipping chokepoint can affect large numbers of supply chains. A major concentration around A.I. infrastructure could eventually create similar accumulation risks.

This means insurers increasingly need to understand not only the direct insured business but also common dependencies across many insureds.

Traditional products may cover parts of the exposure depending on their terms, including cyber insurance, cargo and marine insurance, business-interruption cover and contingent-business-interruption cover. But insurance cannot make the operational dependency disappear.

As Third-Party Risk becomes more interconnected, concentration analysis, accumulation modelling, scenario analysis, exclusions, sublimits and a deeper understanding of supply-chain dependencies are likely to become increasingly important.

For a small-business owner, however, the practical message is simpler: insurance can be part of the Third-Party Risk toolkit, but it should not be the entire toolkit.

THE QUESTIONS PEOPLE ASK TODAY SOUND VERY DIFFERENT

Few solopreneurs are likely to ask an A.I. assistant to construct a formal Third-Party Risk Management framework. They are more likely to ask what happens if Shopify, Stripe, Microsoft, Google or another important platform goes down; whether it is safe to give an A.I. tool customer information; whether they remain responsible when an outsourced bookkeeper makes a mistake; or whether having two suppliers really provides protection when both depend upon the same shipping route.

These are modern questions, but they are still Third-Party Risk questions.

A one-person business may ask why it needs to think about vendor risk at all. In reality, that may be exactly the business that should. The smaller the internal team, the more capability may sit outside the organisation.

The language changes. The dependency remains.

WHICH NEWER RISKS MAKE THE EVOLUTION OF THIRD-PARTY RISK USEFUL?

The evolution of Third-Party Risk connects particularly strongly with A.I. & Risk, Future of Work and Signals, while continuing to connect with the established Pillars of Technology Risk, Cyber Risk, Enterprise Risk, Operational Resilience, Business Continuity and Governance & Compliance.

A.I. introduces new external technology providers, foundation-model dependencies, data questions and concentration risks. Future of Work changes the boundary between employees and external workers as businesses use more freelancers, contractors and specialist service providers. Signals becomes increasingly useful because Geopolitical Risk, Climate Risk, Regulatory Change, Technology Trends and Emerging Risk can all alter the reliability of an external dependency before the supplier itself appears to be in trouble.

This is why the traditional Third-Party Risk toolkit is evolving from checking the vendor towards understanding the dependency.

Due diligence remains useful. Contracts remain useful. Insurance remains useful. Alternative suppliers remain useful. But increasingly these sit alongside criticality assessments, concentration analysis, fourth-party mapping, exit planning, substitutability analysis, geopolitical and geographic exposure mapping, continuous monitoring, scenario testing and A.I. supply-chain analysis.

The tools have evolved because the third party has evolved.

YOU MAY BE A BUSINESS OF ONE. YOU ARE PROBABLY NOT AN ECOSYSTEM OF ONE.

Perhaps this is the biggest change in Third-Party Risk.

Technology has made it possible for businesses to become extraordinarily small while simultaneously giving them access to extraordinary capability. A solopreneur can use software developed on another continent, infrastructure operated by one of the world's largest cloud providers, payments processed by another company, products manufactured elsewhere, marketing performed by freelancers and A.I. supplied through several layers of technology providers.

The organisation has become smaller, but the ecosystem around it has become larger.

That makes Third-Party Risk more relevant, not less.

It also takes us back to the philosophy of the Pillars of Risk Management. The newer risks do not necessarily replace the established disciplines. Often, they reveal why those disciplines still matter.

A geopolitical conflict may look like a new Signals problem until it closes the route used by your supplier. An A.I. system may look like an A.I. Risk problem until you discover that your business depends entirely upon an external model provider. A freelancer may look like a Future of Work story until that person leaves with knowledge nobody else possesses. A cloud outage may look like Technology Risk until you discover that several apparently different suppliers all depend upon the same infrastructure.

The modern Third-Party Risk question is therefore no longer simply whether you trust your supplier. It is whether you understand what you depend upon that third party to do, what they depend upon in turn, how badly their failure could affect you and what you could do if they were suddenly no longer available.

You can outsource the work. You can allocate responsibilities through contracts. You can transfer some financial consequences through insurance. But outsourcing the activity does not mean the consequences automatically become somebody else's problem.

That is why Third-Party Risk remains one of the Pillars of Risk Management.