Back to Glossary

Entry · Business

Third-Party Risk Management

Third-party risk management is the process of identifying, assessing, controlling and monitoring risks created when a business relies on outside providers. It covers selection, contracts, performance, incidents and exit. The depth of review should reflect what the provider does and the harm if it fails, not just the size of the invoice.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A company outsources payroll to a vendor with access to employee records and bank instructions, which presents different risks from a supplier of office stationery. Third-party risk management asks what the dependency is, what could go wrong and who will follow it after signature.

Keep an inventory of material providers, recording services, data access, critical systems, business owner, contract and sub-providers where relevant, because an unknown vendor cannot be assessed or contacted quickly during an incident. Classify criticality before designing the questionnaire, since a critical cloud host may need security, continuity and exit checks while a low-impact purchase may need basic identity and payment controls but not a fifty-page cyber survey.

The US banking agencies interagency guidance describes a lifecycle and says risk practices should be proportionate to the bank profile and the activity criticality, though it applies to banks, not as a universal legal checklist for other businesses. Perform due diligence before commitment by verifying legal identity, relevant capability, financial resilience, references, security or privacy controls and regulatory status where needed, evaluating evidence rather than simply collecting yes-or-no answers.

The NIST 2026 supply-chain due-diligence guide discusses researching supplier and product information for informed decisions, with a focus on ICT suppliers, and its topics include ownership, provenance, resilience and cyber practices, while other vendor categories need different questions. Define risk ownership internally, since procurement may coordinate the process but operations, finance, security and legal may own different aspects, and a vendor score without someone accountable for action is a coloured spreadsheet.

Put material controls into the contract, including service levels, incident notice, audit or assurance rights, sub-contractor limits, data handling, termination and transition support, matched to risk and the provider's ability to perform them. Monitor after onboarding by reviewing performance, unresolved disputes, financial signals, breaches and material changes, because a strong pre-contract review can become stale after a merger, new sub-processor or product change.

Track dependencies beyond the direct contract, since a provider may rely on one data centre or specialist subcontractor, so ask about those dependencies for critical services and document uncertainty if visibility is limited. Plan for interruption, because backup processes, alternative vendors, data exports and internal skills can reduce reliance on one supplier, and a contract right to exit is not useful if the business cannot actually transition the service.

Identify concentration risk, since several apparently independent vendors may share the same cloud platform or shipping hub, so assess correlated failure when continuity matters rather than assuming diversity from separate logos. Use risk acceptance deliberately, because some exposure cannot be removed economically but leadership should know and record the decision, and an overdue assessment should not silently become approval.

An illustrative current-review rate is critical providers with an in-date documented review divided by critical providers identified, so if 36 of 40 qualify it is 90%, and the four exceptions should be investigated, particularly whether they hold sensitive data. Protect provider information, since security reports, financial statements and incident histories may be confidential, so control access while giving decision makers a concise summary of unresolved issues.

Trigger reassessment on contract renewal, scope changes or a serious incident, because an annual review alone may miss a vendor receiving a new data feed next week, and at exit revoke access, return or destroy data under applicable terms, recover assets and settle outstanding obligations, verifying completion rather than assuming termination of the invoice ended the risk. For owners, third-party risk management is not about eliminating every vendor but about knowing what a partner can affect, making a proportionate choice, and keeping that choice sound as the relationship changes.

In practice

Real-world examples.

1

Example

A payroll vendor receives a deeper data and payment-control review than a stationery vendor.

2

Example

A new sub-processor triggers reassessment under the existing contract.

3

Example

A critical provider exit plan includes data export and access revocation.

Formula

Calculation

Illustrative current-review coverage = critical providers with current documented reviews / critical providers inventoried x 100. Worked example. A company inventories 40 critical providers, and 36 have a documented review completed within the period its policy requires. Coverage = 36 / 40 x 100 = 90%. The four exceptions are ranked by data sensitivity and impact, so a payroll provider holding employee bank details is reviewed before a low-risk logistics vendor. After the four reviews are completed, coverage = 40 / 40 x 100 = 100%, though a complete review rate does not prove the providers are safe.

Case study

Seen in the real world.

This entirely fictional example follows Stonebridge Retail, an invented chain. A payment-services vendor changed a subcontractor without the operations team noticing. The business updated its vendor inventory and change-notice review. It then tested an alternative checkout route. The case does not imply every subcontractor change requires the same response.

Watch out

Common mistakes.

  • Sending the same lengthy questionnaire to every vendor regardless of risk.
  • Assuming a signed contract is enough without monitoring material changes.
  • Ending a contract without verifying data return and access removal.

Questions

People also ask.

What is third-party risk management?

Managing risks from outside providers throughout selection, operation and exit.

Is it only about cybersecurity?

No. It includes financial, operational, legal, privacy and concentration risks.

How much review is enough?

Scale diligence and monitoring to the activity and possible harm.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.