Third-Party Risk
Definition
The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud providers, and contractors. Third-party risk is not limited to data breaches; it includes service disruption, compliance exposure, and reputational harm arising from the vendor's conduct.
- Scope
- Vendors, suppliers, cloud providers, contractors
- Risk types
- Security, operational, legal, reputational
- Beyond breaches
- Service disruption, compliance exposure
- Management tool
- Vendor risk assessments
Common questions
How is third-party risk different from a direct security breach?+
The organisation is exposed through another party's failure, such as a vendor's data breach or a supplier's service outage, rather than a compromise of its own systems, yet the consequences often land on it anyway.
Why does reputational harm count as third-party risk?+
Customers and regulators frequently hold an organisation accountable for the conduct of its partners and vendors, so a vendor's misconduct can damage the contracting organisation's standing without any direct technical failure of its own.
Related terms
- Due Diligence Questionnaire (DDQ)
- A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor...
- Offboarding Controls
- The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and...
- Right-to-Audit Clause
- A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a...
- Subprocessor
- A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR...
- Vendor Tiering
- The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such...