Country Risk Briefings are live — 10+ markets, refreshed continuously.Explore
All news
Insight

Third-party risk assessment: building a programme that actually runs

RisQo Research Team
Illustration of supplier nodes connected to a central company shield

Third-party risk assessment (TPRA) is the discipline of understanding what your suppliers, vendors, distributors and outsourcing providers can do to you — financially, operationally, legally and reputationally — and keeping that understanding current for as long as the relationship lasts. Most programmes fail not because the questionnaire is wrong but because every third party is treated identically, so the critical ones receive the same attention as the stationery supplier.

Tier before you assess

Classify third parties by what would happen if they stopped, failed or breached: business criticality, data access, regulatory exposure, spend and substitutability. Tiering is what makes the rest proportionate — deep due diligence and contractual controls for the few that matter, lightweight verification for the many that do not.

Verify the entity, then the capability

Start with KYB fundamentals: legal existence, status, ownership and control, sanctions and adverse media. Then assess capability — financial resilience, security and continuity arrangements, sub-contracting, and concentration of your own volume in their business. A supplier that depends on you for most of its revenue is a risk in both directions.

Put the controls in the contract

Audit and information rights, security and continuity obligations, sub-contracting consent, incident notification deadlines, exit assistance and termination triggers belong in the agreement, not in the assessment file. Regulated firms in the EU face explicit contractual requirements for ICT third parties under DORA, but the same clauses are good practice for any critical supplier.

Maintain a register, including the fourth parties

Keep a single inventory of third parties, the services they provide, their tier, their assessment date and their material sub-contractors. Concentration risk usually hides one level down, where several of your critical suppliers all depend on the same platform or provider.

Monitor between assessments

An annual questionnaire tells you what a supplier believed twelve months ago. Continuous monitoring of financial deterioration, ownership change, insolvency events, sanctions and adverse media tells you what is true this week — and gives you time to qualify an alternative before a critical supplier fails.

Plan the exit at the start

For every critical third party, know how you would leave: where the data is, how it comes back, who else could do the work, and how long a transition takes. An exit plan written under pressure is a negotiation position you have already lost.

RisQo Research Team, Infocredit Group

More on credit risk

Read the full guide, the glossary of terms, and case studies of publicly documented credit failures.