August 3, 2026

Third-Party Risk Management: You Can Outsource the Task — Not the Risk

Companies rarely operate in isolation — payroll runs on one vendor's system, data sits in another provider's cloud, customer service is handled by a partner, and logistics depend, at least in part, on external carriers. Each of these relationships creates efficiency, but each can also create risk: when a third party fails, the impact falls on the company that engaged it.

That risk is no longer the exception. Episodes in which the failure of a single vendor hits multiple companies at once have become recurrent, and regulators in the United States, Europe, and Brazil have converged on the same principle: a company may outsource the execution of an activity, but never the accountability for it. As a result, Third-Party Risk Management (TPRM) has evolved from a formality at the point of contracting into a strategic capability, directly connected to cybersecurity and technological innovation (e.g., the use of Artificial Intelligence — AI — across the supply chain), business continuity, internal controls, the sustainability (ESG) agenda and, more recently, compliance topics that have returned to the spotlight (e.g., sanctions monitoring of suspicious financial operators involved in money laundering). 

The timeline below summarizes how TPRM concerns have evolved over time:

In this article, we examine why the topic has become urgent, what regulators are demanding, and how a well-structured program helps protect organizational value.

Why is Third Party Risk Management Critical Today?

TPRM is the structured process of identifying, assessing, mitigating, and monitoring the risks associated with third parties — suppliers, partners, service providers, or clients — throughout the entire relationship lifecycle.

For a long time, TPRM was treated as a formality: a questionnaire completed at the point of onboarding and then promptly filed away. That model no longer holds, and the data helps size the problem:

  • According to Verizon's 2025 Data Breach Investigations Report,1 which analyzed more than 22,000 security incidents, third-party involvement in data breaches doubled in a single year, from 15% to 30%. The associated costs are substantial: according to IBM's Cost of a Data Breach Report 2025, each data breach costs the affected organization an average of US$4.44 million.2
  • In the field of sanctions and compliance, the GSS Sanctions Survey 2025/2026 found that the quality of third-party data has overtaken the complexity of sanctions themselves as the leading compliance challenge, while 97% of surveyed executives said that collaboration and information sharing are critical to the resilience of sanctions programs.3
  • According to Everstream Analytics' 2025 annual risk report, the most significant drivers of supply chain disruption in 2025 include extreme weather events, geopolitical instability, cybercrime, shortages of critical raw materials, and repressive measures for forced labor — evidence that the traditional scope of TPRM has expanded well beyond financial and technology risks.4

The losses are not limited to the financial dimension. An incident involving a third party can halt operations, expose customer data, trigger regulatory penalties, and ( perhaps the hardest effect to reverse) erode market confidence and brand reputation.

In short: third-party risk has ceased to be an external matter and has become one of the most consequential strategic risks, with impacts that are both cross-cutting and direct on a company's results and value.

Where Do Regulators Stand? Execution Can Be Outsourced — Accountability Cannot

Recognizing the risks in third-party relationships, regulators across multiple jurisdictions have been establishing consistent standards: while execution can be outsourced, accountability cannot. Below, we explore how this approach is being implemented across major markets:

United States. In June 2023, the three main US banking authorities — the Federal Reserve, the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC) — issued joint guidance on managing risks in third-party relationships. The document consolidated previously separate guidance and made one principle explicit: conducting an activity through a third party does not diminish the institution's responsibility to operate in a safe and sound manner and in compliance with the law, to the same extent as if the activity were performed in-house.5 The guidance also organizes the topic around a lifecycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination.6

European Union. In January 2025, DORA (the Digital Operational Resilience Act) came into force, harmonizing digital operational resilience requirements for 20 different types of financial entities and Information and Communication Technology third-party service providers across Europe.7 One of its five pillars is precisely the management of technology third-party risk. DORA requires, for example, that contracts with technology providers include minimum clauses (service levels, audit rights, exit strategies, and incident notification procedures), and it created an unprecedented mechanism of direct supervision over technology providers designated as “critical.”8

Germany. In January 2023, the German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz — LkSG) came into force — one of the first pieces of legislation to turn third-party risk management into a comprehensive legal obligation. It requires companies to conduct periodic risk analyses across their supply chain, adopt preventive and corrective measures to address human rights violations and certain environmental risks, and establish grievance mechanisms and continuous monitoring. The LkSG has inspired similar legislation in France, the Netherlands, and Austria and its scope is not limited to direct suppliers: under certain circumstances, companies must also investigate risks identified at indirect suppliers.9

Brazil. The movement has reached Brazil as well. CMN Resolution No. 4,893/2021 establishes governance and management requirements for financial institutions contracting material data processing, data storage, and cloud computing services.10 More recently, Joint Resolution No. 16/2025, which regulated the Banking as a Service model, reinforced the same principle seen in the United States: outsourcing transfers the execution of activities, but neither regulatory accountability nor the duty of diligence owed to clients and to the supervisor.11

The common thread across all four jurisdictions is the same: regulators will not accept that a supplier's failure exempts the contracting company. Accountability remains with the party that outsourced.

What is the Market Doing to Manage AI Risk Related to TPRM?

The market itself has begun to move ahead — even on topics where regulators have not yet spoken, such as the contracting of artificial intelligence providers. In some instances, industry organizations have started to develop frameworks for managing risk in areas where there is no clear regulatory guidance to date. ‘

Recently, the Brazilian Association of Technology and Financial Services Companies (Zetta) announced its Guia de Avaliação de IA Generativa — Generative AI Evaluation Guide (GAIAG), a practical framework for the responsible contracting of AI providers in the financial sector.12 The product of roughly a year of collaborative work among specialists in regulation, risk, technology, and data protection, the guide establishes clear evaluation criteria, requires verifiable evidence from vendors, and adopts a logic of proportionality to risk. Initiatives like this show that the most mature companies do not wait for the regulator: together, they build standards that reduce their exposure to third-party risk.

How Does TPRM Connect with Other Risk Disciplines?

A common mistake is to treat third-party risk as a standalone topic. In practice, it is a cross-cutting issue — one that influences, and is influenced by, several other disciplines within the organization. Understanding these connections is what separates a merely bureaucratic or theoretical program from one that genuinely protects value.

Cybersecurity and technology. This is the most obvious connection. A considerable share of today's cyber incidents originates from a vendor: a misconfigured access, a compromised credential, an outdated system. In addition, technological innovation — including the use of AI — brings opportunities and new supply chain risks in equal measure. Assessing third parties' security maturity is, in practice, equivalent to defending the organization's own perimeter.

Business continuity and resilience. The disruption of a critical supplier's operations can paralyze the company itself. Mature programs therefore stop treating major suppliers merely as contracts and start treating them as resilience partners — with recovery plans, joint testing, and maximum recovery times agreed by contract.

Compliance and internal controls. Third-party relationships must be covered by policies, monitoring, auditable evidence, and clear lines of accountability. This is where TPRM meets integrity programs: anti-money laundering, anti-corruption, and counter-terrorism financing (areas where misconduct by a supplier, anywhere in the supply chain, can reverberate onto the contracting company). Increasingly, the expectation is that a company's internal controls also extend across its supplier base. Against this backdrop, practices such as Know Your Supplier (KYS) and Know Your Client (KYC), grounded in in-depth due diligence processes, have become more relevant than ever.

Sustainability (ESG). This is the most recent — and still frequently overlooked — connection. IFRS S1 and S2, issued by the International Sustainability Standards Board (ISSB) in 2023, require companies to disclose sustainability-related risks and opportunities not only in their own operations, but across their entire value chain.13

In Brazil, the securities regulator (Comissão de Valores Mobiliários — CVM) incorporated these standards through CVM Resolution No. 193 of 2023.14 In May 2026, CVM Resolution No. 244 replaced that mandate with a “comply-or-explain” model: disclosure is no longer compulsory, but companies that choose not to disclose must justify that decision to the market.15 Mandatory or not, the message to companies remains the same: understanding what happens across the supply chain is no longer just a detail. It has become part of how the market assesses risks and opportunities.

The key takeaway is that these disciplines do not compete with one another. By knowing its third parties well, a company simultaneously strengthens cybersecurity, continuity, compliance, and sustainability reporting. The effort is shared and the benefits multiply across all fronts.

How Does a Good TPRM Program Protect Value?

It is worth translating these principles into concrete terms. A well-structured TPRM program is built around the organization's specific characteristics and is typically organized along the lifecycle of the third-party relationship. Each stage delivers a specific layer of protection:

  • Understanding the environment and setting methodological premises. The starting point is to gain clarity about the organization's strategic drivers, how those drivers may affect operations and the future supply chain, and the current behavior of that chain — including which supply categories are critical to the business. Without understanding what is and is not critical to the organization, no program will be sufficient to adequately mitigate its third-party risks. This requires integration with related disciplines including enterprise risk management, internal controls, compliance, health and safety, environment, finance, information security, among others. It is at this stage that the TPRM program is made to interact with the entire organization in a standardized, effective, and cross-functional way.
  • Planning. Before contracting, the organization should determine the degree of criticality (risk level) of the activity to be outsourced. Not every activity carries the same level of risk. Treating all engagements uniformly, or planning based solely on the supplier as a legal entity rather than on the activity being outsourced, wastes resources and, therefore, results in ineffective risk management.
  • Due diligence and selection. Organizations should assess the supplier before the contract is signed, considering the activity to be performed by the vendor, and their financial health, security posture, track record, compliance, their own dependencies, and the risks specific to the nature of the engagement.

Illustrative example: an infrastructure company is engaging the same engineering firm for two different scopes. The first is a consultative technical opinion, with no field workforce mobilized and no specific regulatory requirements; the second is the execution of a construction project requiring the mobilization of roughly one thousand professionals on site, performing activities such as work at height and in confined spaces, among others. For this organization, the risk level of the first scope is considerably lower than that of the second. The same supplier will therefore go through two due diligence processes, one for each supply scope — each with a level of rigor consistent with what was defined in the first stage.

  • Contract. Organizations should translate expectations into objective clauses: service levels, audit rights, incident notification, exit strategies.
  • Ongoing monitoring. Organizations should track the third party throughout the relationship — not only at onboarding. The risk profile may change over time, and monitoring must keep pace with that evolution, incorporating any new engagements, assessments by contract managers, and other inputs.
  • Termination. Organizations should plan the exit in advance, ensuring the return of data and an orderly transition, to avoid disruptions and crises.

When these stages operate in an integrated way, the gains go beyond simply preventing problems. The company reduces both the likelihood and the impact of incidents, responds faster when a failure does occur, meets regulatory requirements with evidence readily at hand and — perhaps most importantly — begins to make contracting decisions based on risk, not just price. That is the essence of value protection: fewer losses, greater resilience, and more trust.

What Lies Ahead?

Two movements will likely shape the topic in the coming years. The first is artificial intelligence. This will impact organizations on two fronts: as a new source of risk to be assessed in the suppliers that use it and, simultaneously, as a tool to scale third-party assessments themselves (within the TPRM program). The second is the intensification of regulatory pressure, with increasingly detailed rules and supervisors paying progressively closer attention to the supply chain as a whole.

The direction is clear: third-party risk management has moved from a one-off contracting task to a continuous, strategic capability.

From Theory to Practice

While regulators worldwide now mandate TPRM and hold institutions accountable for third-party failures, building an effective program requires going beyond checklists. Effective programs require sector and technical expertise, combined with an in-depth study of the organization's specific environment. To build resilience where it matters, organizations should design and implement TPRM frameworks built on five core attributes:

  1. Adaptability to different types of risk;
  2. Integration with the other risk management functions, especially enterprise risk management (ERM);
  3. Transparency across the entire chain;
  4. Scalability as the business grows; and
  5. Orientation by real data on the supply chain.

-

These results illustrate the scale of the opportunity. When organizations implement a comprehensive TPRM program, with centralized governance, risk-based qualification processes, real-time tracking indicators, and dedicated team training, they gain significantly more than compliance. They unlock the capacity to scale third-party relationships faster, with greater visibility and control. Most importantly, they transform TPRM from a box-ticking exercise into a strategic capability: the ability to see and respond to risk before it becomes a crisis.

The views and opinions expressed in this article are those of the authors.

Read Past Raising The Bar Issues


References

  1. Verizon, “2025 Data Breach Investigations Report (DBIR).” https://www.verizon.com/about/news/2025-data-breach-investigations-reporthttps://www.verizon.com/business/resources/T16f/reports/2025-dbir-data-breach-investigations-report.pdf
  2. IBM, “Cost of a Data Breach Report 2025.” https://www.ibm.com/reports/data-breach
  3. Global Screening Services, “GSS Sanctions Survey 2025.” https://www.gss-rose.com/gss-sanctions-survey-2025-26/
  4. Everstream Analytics, “2025 Annual Risk Report.” https://www.everstream.ai/media/everstream-analytics-unveils-2025-annual-risk-report/
  5. Board of Governors of the Federal Reserve System, FDIC, and OCC, “Interagency Guidance on Third-Party Relationships: Risk Management,” 2023. https://www.federalreserve.gov/frrs/guidance/interagency-guidance-on-third-party-relationships.htm
  6. OCC, “Agencies Issue Final Guidance on Third-Party Risk Management,” Bulletin 2023-17. https://www.occ.treas.gov/news-issuances/news-releases/2023/nr-ia-2023-53.html
  7. European Insurance and Occupational Pensions Authority (EIOPA), “Digital Operational Resilience Act (DORA).” https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en
  8. European Supervisory Authorities (EBA, EIOPA, ESMA), “European Supervisory Authorities Designate Critical ICT Third-Party Providers Under DORA.” https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital
  9. German Federal Government, “Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz),” 2023. https://www.gesetze-im-internet.de/lksg/
  10. Conselho Monetário Nacional, “Resolução CMN nº 4.893, de 26 de fevereiro de 2021.” https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20CMN&numero=4893
  11. Banco Central do Brasil and Conselho Monetário Nacional, “Resolução Conjunta nº 16, de 28 de novembro de 2025.” https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20Conjunta&numero=16
  12. Zetta, “GAIAG — Guia de Avaliação de IA Generativa (Generative AI Evaluation Guide).” https://gaiag.somoszetta.org.br/
  13. IFRS Foundation, “IFRS S1 General Requirements for Disclosure of Sustainability-related Financial Information” and “IFRS S2 Climate-related Disclosures,” June 2023. https://www.ifrs.org/issued-standards/ifrs-sustainability-standards-navigator/ifrs-s1-general-requirements/
  14. Comissão de Valores Mobiliários, “Resolução CVM nº 193, de 20 de outubro de 2023.” https://conteudo.cvm.gov.br/legislacao/resolucoes/resol193.html
  15. Comissão de Valores Mobiliários, “CVM amends Resolution 193 to revoke the mandatory disclosure of sustainability-related financial information” (Resolução CVM nº 244, de 29 de maio de 2026, which replaced the mandate with the comply-or-explain model). https://www.gov.br/cvm/pt-br/assuntos/noticias/2026/cvm-altera-resolucao-193-para-revogar-obrigatoriedade-da-divulgacao-de-informacoes-financeiras-relacionadas-a-sustentabilidade
Authors

Isabela Daguer

Director

Clara Jordão

Manager
FOLLOW & CONNECT WITH A&M