Third-Party Risk: Managing Risk You Don’t Directly Control
You can’t directly control a third party’s security practices. Third-party risk management is the discipline of managing that risk anyway — through visibility, tiering, and ongoing attention.
The business problem
Third-party risk is unlike most other security risk in one important way: you don’t control the systems or practices involved. A company can have excellent internal controls and still take on significant risk the moment it grants a vendor access to sensitive data or critical systems — and many companies manage that risk, if at all, only once, at the moment of signing a contract.
What third-party risk management actually involves
A real program has a defined lifecycle: intake (what does this vendor need access to, and how sensitive or critical is it), risk-based tiering (not every vendor deserves the same level of scrutiny), assessment (a proportionate review — from a light questionnaire to a deep evidence review, depending on tier), formal approval before the relationship goes live, and ongoing monitoring and periodic reassessment for as long as the relationship continues.
Why ongoing monitoring matters most
A vendor’s risk posture at the moment you signed the contract is not a permanent fact — they can lose key security staff, get acquired, change their own subcontractors, or simply let controls decay over time. A program that only ever assesses at onboarding has no way to detect any of that, which is exactly why renewal and periodic reassessment triggers matter as much as the initial review.
“A vendor you approved eighteen months ago isn’t the same vendor today. Third-party risk that stops at onboarding is measuring a moment that’s already passed.”
Signs third-party risk management is stuck at onboarding
- Vendors are reviewed once, at signup, with no plan to ever revisit the assessment
- Every vendor gets the same level of scrutiny regardless of what data or systems they can access
- There’s no formal approval gate — a completed questionnaire is treated as sufficient on its own
- Risk acceptances for known gaps aren’t documented with a reason, an approver, or an expiration
- Vendor status changes (termination, offboarding) aren’t tracked or verified to have actually happened
Practical guidance
Tier vendors by the sensitivity of what they can access — not every vendor needs the same depth of review — and build reassessment triggers into the lifecycle: renewal dates, periodic review windows, and material changes (a breach disclosure, an acquisition) that should prompt an out-of-cycle look. Keep a clear, auditable record of every approval, risk acceptance, and termination, since "we assessed them once" is not the same as an ongoing, managed relationship.
See how vendor lifecycle management — intake through termination — is handled at a program level.
Explore Supply Chain Risk ManagementQuestions, answered directly.
The terms are largely used interchangeably in practice — "third-party risk" is the broader industry term for the discipline, while "vendor" refers to the specific relationships being managed within it.
No — proportionate review based on what data or systems the vendor can access (a tiering approach) is more efficient and effective than applying the same deep review to a low-risk scheduling tool and a payroll processor alike.
Common triggers include contract renewal, a defined periodic review window (commonly annual for higher-risk vendors), and material events like a disclosed breach, an acquisition, or a significant change in what access the vendor has.
A formal risk acceptance is documented — a specific risk, a named approver, a reason, and often an expiration date; an undocumented gap that nobody formally decided to accept is much harder to distinguish from an oversight later, especially during an audit or after an incident.
Want a structured way to manage risk across your full third-party population?
30 minutes. No obligation. No sales pitch.