Skip to content

Third-Party Risk

Definition

The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud providers, and contractors. Third-party risk is not limited to data breaches; it includes service disruption, compliance exposure, and reputational harm arising from the vendor's conduct.

Scope
Vendors, suppliers, cloud providers, contractors
Risk types
Security, operational, legal, reputational
Beyond breaches
Service disruption, compliance exposure
Management tool
Vendor risk assessments

Common questions

How is third-party risk different from a direct security breach?+

The organisation is exposed through another party's failure, such as a vendor's data breach or a supplier's service outage, rather than a compromise of its own systems, yet the consequences often land on it anyway.

Why does reputational harm count as third-party risk?+

Customers and regulators frequently hold an organisation accountable for the conduct of its partners and vendors, so a vendor's misconduct can damage the contracting organisation's standing without any direct technical failure of its own.

Related terms

Due Diligence Questionnaire (DDQ)
A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor...
Offboarding Controls
The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and...
Right-to-Audit Clause
A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a...
Subprocessor
A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR...
Vendor Tiering
The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.