Back to Glossary

Entry · Business

Third-Party Risk

Third-party risk is the chance that an outside organisation a business relies on causes loss, disruption or harm. Suppliers, contractors, agents and technology providers can create operational, financial, security and legal exposure. Managing the risk means knowing the dependencies and checking them over time.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A distributor uses one warehouse company for all orders, so if that facility closes unexpectedly the distributor may miss customer deliveries even though the failure happened outside its own offices. This is an operational third-party risk.

Other exposures differ: a payroll provider may hold sensitive data, an agent may act improperly, and a manufacturer may deliver unsafe parts, so the third party's role and the harm of failure determine the right checks. Start with a list of material relationships, including services purchased outside central procurement, subcontractors when relevant and businesses with access to data or systems, because a contract register without owners or current service descriptions is hard to use.

Assess criticality before collecting a stack of questionnaires by asking what happens if the service stops, whether customers are affected and how long replacement takes, since a vendor with little spend can still be critical if it runs a core system. Due diligence checks claims before a relationship starts or expands, and NIST describes researching pertinent supplier and product information to support informed choices in cybersecurity supply chains, with the depth tailored to the type and scale of risk.

Evidence may include financial information, business continuity plans, references, certifications, security reviews and site visits, but a clean questionnaire is a lead, not proof that controls work, so verify important claims where practical. Contracts should define deliverables, service expectations, data handling, incident notice and termination rights as needed, because they cannot eliminate every failure but can make responsibilities and access to information clearer.

Legal review may be warranted for high-impact arrangements. Concentration matters, since two suppliers with different names can depend on the same cloud platform, factory or logistics route, and mapping only direct contracts may leave a common point of failure unnoticed.

A backup should be usable, because a name on a contingency list does not mean spare capacity, compatible systems or permission to move data, so test switching steps for the most critical services. Monitor after onboarding by reviewing performance, incidents, financial warning signs and changes in ownership or subcontracting, with the amount of review reflecting how rapidly the risk can change.

An OCC interagency guide for banks describes a third-party risk lifecycle and notes that relationships differ in criticality, and its banking rules are not a universal legal requirement for other businesses, though the general idea of proportionate oversight is still useful. Assign a relationship owner who can act on warnings, since procurement may keep the contract, IT may assess security and operations may see delivery problems first, and their signals should be brought together for material vendors.

Risk scores need context, because a 'medium' score across many areas may conceal one severe dependency, so record the scenario, likely impact, controls and remaining exposure rather than relying only on a heat-map colour. One illustrative metric is critical-party spend divided by total third-party spend, so $4 million of $10 million is 40%, but this does not measure actual risk because a low-cost sole-source provider may be the most dangerous dependency.

Consider exit before there is a crisis by asking whether the business can retrieve its data, replace the service and preserve customer commitments, since contractual transition support and a tested export process can be more useful than a vague right to terminate, and when an incident occurs, coordinate response with the provider and define contact routes and information needs beforehand. Small firms need not copy bank-size programmes and can list their ten most consequential partners, check key claims and plan for failure, but they should not assume outsourcing transfers all responsibility, since a contract can allocate duties between parties without making harmed customers whole automatically or settling regulatory obligations, so for owners the task is to know who matters most, verify important promises and have a credible response if one partner fails.

In practice

Real-world examples.

1

Example

A sole logistics provider closes a warehouse and delays customer orders.

2

Example

A sales agent committing improper acts triggers a compliance investigation.

3

Example

A payroll vendor reports a breach involving employee data.

Formula

Calculation

Illustrative critical-party spend share = spend with designated critical third parties / total third-party spend x 100. Worked example. A company spends $10 million a year with third parties, of which $4 million goes to providers designated critical. Share = $4,000,000 / $10,000,000 x 100 = 40%. This is not a risk score: a $50,000 sole-source software provider that runs the order system is only 0.5% of spend ($50,000 / $10,000,000 x 100) but may be the most dangerous dependency.

Case study

Seen in the real world.

This entirely fictional example follows Summit Pharma, an invented distributor that depended on one warehouse operator. After a service outage, it documented the dependency and assessed an alternative facility. It tested whether stock and order data could be transferred before treating the alternative as a backup. The scenario does not claim the added site removed all risk.

Watch out

Common mistakes.

  • Using supplier spend alone to decide what is critical.
  • Keeping a backup supplier name without testing capacity or transition.
  • Assessing a provider once and ignoring changes or incidents.

Questions

People also ask.

What is third-party risk?

Potential harm arising from dependence on an outside organisation.

What are examples?

Supplier failure, agent misconduct, service outages and data breaches.

How is it managed?

Map dependencies, assess criticality, verify claims, monitor changes and plan an exit.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.