What Is a Third-party Risk Management Program? 

Third-party risk management (TPRM) is the practice of assessing and monitoring the risks associated with outsourcing business functions to service providers. An effective TPRM program helps organizations identify risks before they create disruptions. This proactive assessment can allow companies to better develop policies for hiring and continuing business with vendors while reducing exposure.

Why Is Managing Third-party Risks Important? 

Monitoring third-party risk is critical for organizations to effectively manage business threats. Vendors often have access to confidential information, such as personally identifiable information (PII), and support essential operations. As a result, weaknesses in a third party’s security or performance can expose organizations to data breaches, regulatory scrutiny and operational disruption. For vendors that support customer-facing services, these weaknesses can directly undermine an organization’s commitments to its customers.

The challenge is that effective TPRM requires coordination of executive leadership, legal, compliance and risk management teams across the organization. Teams often find themselves allocating time and effort to certain aspects of TPRM, potentially overlooking more impactful strategies for managing vendor risks.

Shared challenges organizations face when it comes to managing third-party risk include:

  • Immature Vendor Acceptance and Risk Management Strategies
  • Incomplete Vendor Inventories
  • Inadequate Understanding of Data Sharing and Cybersecurity Responsibilities on the Part of the Company and the Vendor
  • Lack of Technical Skills To Provide a Clear View of Potential Vendor Risk
  • Lack of Risk-based Vendor Classification/Stratification
  • Volume of Vendors To Be Onboarded and/or Assessed Exceeds the Capabilities of the Team
  • Existing Vendors That Don’t Match Established Risk Tolerances, Creating Risk Gaps
  • Inability of the TPRM Program To Scale With the Business

Today’s organizations increasingly rely on third parties, such as IT and cloud service providers, payment processors, and logistics and transportation providers, to assist business operations. These relationships introduce varying degrees of risk, ranging from data breaches and security vulnerabilities to regulatory non-compliance, reputational damage and risks related to vendor financial stability.

When a third party experiences a security incident, outage or operational failure, the impact can extend to the organizations that rely on that vendor. These scenarios, often referred to as supply chain attacks or disruptions, occur when weaknesses at one organization cascade across interconnected business relationships, amplifying risk and business impact.

In July 2024, a faulty configuration update from CrowdStrike caused a widespread outage affecting Microsoft Windows systems globally. According to CNN Business, the disruption resulted in more than $5 billion in direct losses for Fortune 500 companies alone and led to cancelled flights, hospital disruptions and significant operational downtime worldwide. This incident, which some have called the largest IT outage in history, highlights how failures at a single third party can quickly cascade into material business impact across industries.

As the U.S. Securities and Exchange Commission (SEC) has made known through its new cybersecurity disclosure rule, organizations using third parties are responsible for the material impacts of a security breach for those third parties. This underscores the potential risks and legal implications of inadequate TPRM oversight, making it a crucial component for any business, especially those that serve public companies.

By “right-sizing” resources and focusing on meaningful strategies, organizations can proactively identify vendor security and operational weaknesses, strengthen their third-party risk management practices and reduce the likelihood of material business impact.

Third-party Vendor Risk Best Practices

While creating and executing a third-party risk management program can be challenging, there are multiple strategies companies can leverage to help overcome common pitfalls.

Utilize Data-driven Due Diligence When Selecting Vendors  

Before engaging with any third-party vendor, contractor, business partner or supplier, it is essential to conduct thorough due diligence. This often includes background checks and research into a third party’s financial stability, reputation and security controls, as well as (typically lengthy) due diligence questionnaires to create a comprehensive risk profile.

And yet, an overwhelming majority of third-party risks are identified after the due diligence process. According to Gartner, 73% of risk identification efforts are allocated to due diligence and recertification, while only 27% of effort is allocated to ongoing monitoring.

Focus on Continuously Identifying, Monitoring and Managing Vendor Risk 

Once a third-party vendor is engaged, the vendor should be part of the company's third-party vendor ecosystem and subject to ongoing review and monitoring. The depth and extent of the ongoing review and monitoring are dependent on the extent, depth and nature of how the company integrates the vendor into its business processes.

At a minimum, all companies should have a TPRM program as defined by policies, procedures and standards. Having a formal, documented program helps organizations consistently assess third-party risks across the organization.

TPRM programs are never “one-size fits all” because every organization has different risk impacts and tolerances. TPRM programs require effective alignment of risk, technology, process and the people executing the program. The TPRM “living” program must be implemented properly, constantly maintained and refined on a regular basis. Review and update frequency should depend on the organization’s risk appetite and the risk level associated with each vendor.

Key questions that this program should address:

  • How are we providing guidance and support on managing vendor risk during the vendor onboarding process?
  • How does our program monitor vendor risk?
  • How does our program measure vendor risk?
  • How does our program respond to vendor risk?
  • How and who do we report vendor risk to within the organization?

Remember that Vendor Segmentation and Stratification Is Key to TPRM Success

According to a survey by the CyberRisk Alliance, the average organization engages with 88 third-party organizations. It also found that the number of engaged third parties increases as the size of the organization does. When working with many third parties, it can be hard to keep track of each one of them, especially if the organization does not have a dedicated third-party risk management office.

To help keep track of their third-party relationships, organizations should segment these providers into a hierarchy. This means categorizing third parties based on their risk profiles, such as their potential impact on the organization's operations, their level of access to sensitive data, and their compliance with relevant regulations.

This practice offers organizations the opportunity to prioritize their risk management efforts, allocating time and resources where they are needed most — with the highest-risk segmented third parties. Lower-risk segments may only require periodic checks, especially if triggers and internal controls are in place. This process helps the organization to maximize the value generated from suppliers, optimize resources, leverage innovation and prioritize critical third parties to provide an enhanced service model to their customers.

Implement a Process To Assess and Respond to Vendor Risk

Clear expectations around security, data protection, incident response and compliance help guide how vendor risks are assessed and managed over time. An ongoing continuous monitoring program should be implemented that includes a variety of techniques, such as the completion of vendor risk assessments (VRAs), audits, and special information requests, with the goal that the third party is meeting the company’s security and compliance standards.

VRAs should evaluate multiple categories of risk, including:

  • Cybersecurity Risk
  • Privacy and Data Protection Risk
  • Compliance and Regulatory Risk
  • Operational and Replacement Risk

Keep in mind that the vendor segmentation/stratification process should drive the extent and scope of the individual vendor risk assessment process. Vendors may not require the completion of a VRA, whereas some vendors may require a thorough VRA. Some vendors may require a site audit to be performed above and beyond a third-party risk assessment.

By spending more time monitoring the third-party relationship through VRA and audits, organizations can better identify and address emerging risks before they become major issues. An effective VRA process creates a wealth of data that can be utilized on an ongoing basis and identifies new and emerging risks in its vendor portfolio by providing period-to-period comparative data.

Existing data can be used to determine the critical due diligence questions that need to be asked based on relevant laws and regulations, as well as identify which questions have been the most effective in indicating potential risk. In addition, by utilizing existing technology to analyze third-party risk, organizations can make informed decisions and enhance their risk management strategies by identifying and evaluating potential risks associated with a vendor's operations and their potential impact on the organization.

Without using intelligence, VRAs often become a “one size fits all,” potentially missing critical risks important for the organization to understand before engaging with the third party. This may result in oversight of financial, reputational and cyber risks that are critical for the organization.

Create Internal Triggers and Controls To Monitor Vendor Risk

It may seem impossible to continuously monitor third-party relationships, especially if a team is managing multiple third-party vendors. However, teams can more easily and effectively monitor their third-party network through triggers to signal for any potential changes or threats to the relationship and by setting up appropriate access controls.

Building Triggers

Using business intelligence reporting, organizations can build automated trigger reports to identify emerging risks based on metrics that were established through the due diligence process. These triggers can be set to monitor various aspects of the third-party relationship, such as financial stability, security controls and compliance with contractual obligations. When metrics are not being met or have the potential to not be met, a report can be triggered for legal and compliance to review, mitigating the risk in real time.

Deploy Access Controls

When engaging a third party, organizations will most likely have access to sensitive information and/or data. Unfortunately, most data breaches occur because a third party was granted too much access, access that was granted to appropriate personnel was misused, or the third party was unknowingly accessing sensitive data. It is important to implement access controls to manage third parties and improve the organization’s ongoing monitoring practices. With internal controls in place, an organization can control what the third party can access, when and to what extent.

In a Zero Trust security model, every user and device, whether inside or outside the organization's network, is treated as a potential threat. Identity and Access Management (IAM) is a key component of this model, used to control access to sensitive data and to enforce security protocols. IAM can also monitor activity and detect emerging risks that could indicate a security threat. By implementing a Zero Trust security model and using IAM, organizations can verify the identity of users and devices before granting them access to certain data, applications and systems, thereby enhancing their third-party risk management practices.

Leverage Automation To Avoid Cross-functional Miscommunication

Several organizations still rely on manually intensive processes and overworked staff to manage third-party risk. Using automation can help save time and free up resource capacity by automating processes such as data collection, risk assessments, performance and compliance monitoring/triggers, contract management, and vendor onboarding.

While legal and compliance teams are typically the owners of third-party risk management, there are several others within the organization who have a stake in improving risk management and associated business outcomes. By utilizing automation, risk management functions across departments can be better unified, reducing miscommunication, manual data entry and errors and overall, creating a more strategic third-party risk management plan.

Collaborate With an External Auditor

Managing the success of vendor relationships can be a daunting task, especially for organizations that are not internally set up to employ access controls or leverage automation tools. In such cases, the support and expertise of an external auditor can be invaluable in building an effective third-party risk management program, providing a sense of reassurance and support.  

How Cherry Bekaert Can Help 

Third-party risk management is a critical component of any cyber and risk management program. Cherry Bekaert’s Information Assurance & Cybersecurity and Risk Advisory practices can guide organizations through comprehensive TPRM programs, risk assessments, internal controls evaluations, cyber, and incident response plans to enhance their third-party management program and mitigate risks sustainably and effectively.

Connect With Us

Related Insights

Kurt Manske headshot

Kurt Manske

Cybersecurity Leader

Partner, Cherry Bekaert Advisory LLC

Nina McAvoy

Cybersecurity

Sr. Manager, Cherry Bekaert Advisory LLC

Contributors

Connect With Us

Kurt Manske headshot

Kurt Manske

Cybersecurity Leader

Partner, Cherry Bekaert Advisory LLC

Nina McAvoy

Cybersecurity

Sr. Manager, Cherry Bekaert Advisory LLC

Recommended Insights