Third-party risk management is how an organization identifies, assesses, monitors and plans for the risks that come from the outside organizations it relies on for products and services. Vendors are one kind of those organizations.

The topic is moving up risk agendas. Risk.net's 2026 poll of operational risks in the financial industry reported that third-party and outsourcing risk climbed to third. This guide explains what third-party risk is, how the G7, NIST and the UK's National Cyber Security Centre (NCSC) describe it and how organizations manage it from first assessment to exit.

By the end, you will know:

  • what counts as a third party and how vendors fit among suppliers
  • the risks that suppliers can bring, from cyber incidents to concentration
  • the stages of managing third-party risk, from inventory to exit plans
  • how to tier suppliers by risk using the NCSC's six steps and NIST's criticality criteria

What is third-party risk management?

The practice of managing risk from the organizations you rely on for products and services

The G7's Fundamental Elements for Third Party Cyber Risk Management in the Financial Sector (October 2022) describe third-party relationships as "any business relationships or contracts between an entity and an organization to provide a product or service, regardless of the organization being an intra-group company or an external provider." The Bank of England's Prudential Regulation Authority (PRA) defines a third party in line with that wording, as "an organisation that has entered into a business relationship or contract with a firm to provide a product or service" (SS2/21, paragraph 2.2).

Both documents are written for the financial sector, but the idea is general. NIST's guidance on cyber supply chain risk management notes that all organizations rely on other organizations for critical products and services.

In plain English, third-party risk is the chance that something goes wrong at an organization you depend on and the harm lands on you. A supplier outage stops your service, a supplier breach exposes your data or a supplier fails and leaves a gap you cannot fill quickly.

Which arrangements count: outsourcing, purchases and other supplier relationships

The G7 describes outsourcing as one important type of third-party relationship, whereby "a third party provides a business function, service or process that would otherwise be provided by the entity itself." Third-party risk is wider than outsourcing.

The PRA expects firms to assess the materiality and risks of all third-party arrangements, whether or not they fall within its definition of outsourcing (SS2/21, paragraph 2.5). Its examples of arrangements that are not outsourcing "may include but are not limited to" purchases of hardware, software and other ICT products, such as data bought from data brokers, off-the-shelf machine learning models and open source software (paragraph 2.4). A purchase can therefore create a dependency in the same way a service contract does.

Vendor risk management: how vendors fit among suppliers and third parties

NIST's glossary entry for supplier describes an organization or individual that enters into an agreement with the acquirer for the supply of a product or service. In the NIST SP 800-53 Rev. 5 wording, suppliers include "vendors" and "third party partners". Under the G7 and PRA wording above, any organization that provides a product or service to you is a third party, so vendors and other suppliers fall within it.

NIST also places third-party risk management inside a wider field. It describes cyber supply chain risk management as "an overarching function that includes concepts such as third-party risk management and external dependency management" (NIST IR 8276, February 2021). That document focuses on cybersecurity risks in supply chains.

In practice the terms overlap, so this guide uses supplier, vendor and third party for the organizations you buy from. The stages and tiering steps below apply to each of them.

What does third-party risk cover?

Cyber incidents, data access, supplier failure and concentration

The G7 notes that cyber incidents resulting from third-party vulnerabilities could lead to fraud, disruption of an entity's services and inappropriate access to sensitive customer or corporate information. The risks are wider than cyber. NIST describes monitoring programs that cover security, privacy, quality, financial and geopolitical risks, and notes that severe weather and geopolitical unrest also threaten to disrupt supply chains.

Two further risks come from how many suppliers you use and how they connect:

  • Concentration. The PRA expects firms to periodically reassess and manage their overall reliance on third parties and concentration risks or vendor lock-in, including arrangements with service providers that are difficult or impossible to substitute (SS2/21, paragraph 5.24).
  • Fourth parties. The PRA gives the example of multiple otherwise unconnected service providers depending on the same sub-contractor, and NIST stresses understanding multiple layers of sub-suppliers (NIST IR 8276, section 3.4).

How is third-party risk managed?

Governance, inventory, due diligence, contracts, monitoring and exit

The G7 describes a third-party risk management life cycle. Its elements are non-binding, and it asks entities to apply them in proportion to the size, nature, scope, complexity and potential systemic significance of the relationship. Governing bodies are "ultimately responsible and accountable" for oversight, and the process runs through the stages below.

Stage What the G7 describes
Governance A documented strategy on reliance on third parties, third-party and cyber risk policies, a risk tolerance for third-party relationships and clear roles and accountabilities
Inventory and criticality A list of all third parties, the services and functions they perform, the level of access each has to systems and the type, sensitivity and location of data they hold or process
Assessment and due diligence Assessment before entering a relationship and during it, considering the criticality of the supported operations, the third party's level of access, the sensitivity of data or systems and the method of connection
Contracts Terms covering the scope of the relationship, performance standards, access, information and audit rights, reporting, data location, subcontracting and termination options
Ongoing monitoring Monitoring in proportion to the materiality of the risk, with more rigorous and frequent monitoring for critical functions
Incident response and exit Incident response plans that include critical third parties, and contingency plans and exit strategies for situations where third parties fail to meet expectations

NIST organizes similar work into eight key practices in NIST IR 8276:

  1. Integrate cyber supply chain risk management across the organization
  2. Establish a formal program
  3. Know and manage critical components and suppliers
  4. Understand the organization's supply chain
  5. Closely collaborate with key suppliers
  6. Include key suppliers in resilience and improvement activities
  7. Assess and monitor throughout the supplier relationship
  8. Plan for the full life cycle

On assessment, NIST makes one point worth remembering: a supplier assessment conducted before onboarding "is a snapshot in time", so monitoring needs to cover the whole relationship.

How to tier suppliers by risk: the NCSC's six steps and NIST's criticality criteria

NIST defines critical suppliers as "those suppliers which, if disrupted, would create a negative business impact on the organization." It lists several criteria for judging criticality: revenue contribution, whether a supplier processes critical data such as regulated data or intellectual property, the volume of data it can access, whether it has access to systems and network infrastructure and whether it could become an attack vector if compromised.

The NCSC's guidance on assessing supply chain cyber security, published in October 2022, turns tiering into a repeatable method. It is aimed at medium to large organizations in commercial and public sectors and at procurement specialists, risk managers and cyber security professionals. It supplements the NCSC's 12 supply chain security principles, which run across four stages: understand the risks, establish control, check your arrangements and continuous improvement. Its approach has six steps:

  1. Create a set of security profiles. The NCSC recommends 3 to 5 tiered profiles, and its example uses 3 tiers based on the impact on reputation, business operations and processes and financial or legal consequences.
  2. Determine the security profile for each supplier, using a series of questions to triage them.
  3. Define the minimum cyber security requirements for each profile, with more stringent requirements as the risk level rises.
  4. Decide how to assess suppliers. The NCSC lists question-based surveys, interviews, site visits, independent assessment or certification and automated assessment, and advises that most organizations will need a combination.
  5. Plan for non-compliance. Where a supplier falls short but you still want to work with it, create a security management plan that sets out the controls needed and a schedule.
  6. Create contractual clauses. Common clauses cover subcontractors, incident notification timeframes, audit rights and a break clause if the supplier's security does not meet expected standards.

The NCSC adds that "evidence-based assurance should be maintained throughout the contract duration and not just at onboarding stage." Its guidance covers cyber security, so financial failure or poor service quality would need criteria of their own alongside it.

How a mid-sized company assesses a cloud payroll provider: a fictional walk-through

This scenario is illustrative. It applies the NCSC and G7 material above and does not describe a real company.

A mid-sized company is choosing a cloud payroll provider. The provider would process employee personal data. In the NCSC's example tiers, third-party processing of personally identifiable data is listed under the high impact profile, so the company places the provider in the highest tier.

The company then asks for evidence of the provider's controls instead of relying on a questionnaire alone, drawing on the independent assessment options the NCSC lists, such as Cyber Essentials Plus, SOC 2 reports and ISO 27001. It writes incident notification timeframes, audit rights and a break clause into the contract. It also records how payroll would move to another provider or back in-house if the relationship ended suddenly, which are the options the G7 gives for exit strategies, and tests that plan as far as is feasible.

A supplier of office stationery with no connection to the company's network and no access to its data matches the NCSC's low impact profile and needs far lighter checks.

How common is supplier risk review? What UK survey data shows

The UK government's Cyber Security Breaches Survey 2025/26 is a survey about cyber security. It found that 15% of businesses reviewed the risks posed by their immediate suppliers and 6% looked at their wider supply chain. Among medium businesses 30%, and among large businesses 48%, reviewed the cyber security risks posed by their immediate suppliers.

The survey covers UK businesses across all sectors and counts only what organizations identified and were willing to report, so it shows a pattern in practice and not a measure of every supplier failure.

Frequently asked questions about third-party risk management

How is third-party risk different from outsourcing risk?

Outsourcing is one type of third-party relationship, where a third party provides a function that the organization would otherwise provide itself. Third-party risk also covers purchases and other supplier relationships, such as bought data and software (G7 Fundamental Elements; PRA SS2/21, paragraphs 2.4 and 2.5).

Does an organization stay responsible for work it hands to suppliers?

The G7 states that "entities remain responsible for ensuring the safe and sound operation of services provided to them by third parties." For firms regulated by the PRA, SS2/21 paragraph 4.3 says boards and senior management "cannot outsource their responsibilities" and that firms "remain fully accountable for complying with all their regulatory obligations." Organizations in other sectors should check the rules of their own regulators.

What is a critical supplier?

NIST describes critical suppliers as those which, if disrupted, would create a negative business impact on the organization, including suppliers that provide components supporting its critical business missions. Identifying them starts with identifying critical missions, assets, systems, processes and data.

What is an exit plan?

An exit plan sets out how an organization would stop using a supplier and carry on delivering its service. The G7 says contingency plans and exit strategies should assure an entity's ability to deliver critical functions, and that options may include transferring the service back to the entity or to another third party. The PRA expects firms to take reasonable steps to test exit plans, in particular those relating to stressed exits (SS2/21, paragraph 10.24).

From supplier to exit plan: how third-party risk management connects to risk appetite and key risk indicators

Risk appetite and risk indicators sit inside the third-party risk life cycle. The G7 lists "setting a risk tolerance for third-party relationships" as part of governance and says exit strategies address third parties that "pose cyber risks outside the entity's risk appetite." It also says an entity "may collect and analyse cyber risk metrics and risk indicators to support monitoring." For PRA-regulated firms, SS2/21 paragraph 4.4 says boards set the appetite and tolerance levels for outsourcing and third-party risk management.

Ideagen Risk Management connects risks, controls and objectives in one system for financial, operational and strategic risk.

Explore risk management solutions

Roll up your risk into one system for full visibility, maximum control coverage and joined-up reporting.