THIRD PARTYCURRENT
Sector desk

Financial services third-party risk

Third-party risk in financial services is shaped by operational resilience, formal lifecycle governance, concentration analysis, regulatory reporting, and evidence that can survive supervisory review.

Executive questionCan the institution explain which external services support important operations, how those dependencies are governed, and what happens when a provider or downstream service fails?

The operating context

Financial institutions do not evaluate third-party technology as an isolated procurement choice. The operating model must connect the legal entity, service, business owner, important operation, data and system access, subcontracting chain, contract, control evidence, incidents, remediation, and exit plan. That record may need to support management decisions, board reporting, regulatory requests, and the continuity response to a disruption.

The market therefore spans lifecycle platforms, integrated GRC systems, cyber-risk intelligence, assessment exchanges, managed services, procurement suites, and multi-domain intelligence. A broad platform can reduce handoffs, but breadth does not establish that critical-service mapping, concentration logic, evidence quality, or regulatory reporting will work in the institution's environment. Buyers need a representative service scenario and a defined record of decision.

Operating priorities

Map services, not only legal vendors

A single provider may support several products, contracts, regions, data flows, and important operations. The operating record should preserve those distinctions and identify the accountable internal owner for each material dependency.

Connect resilience to third-party governance

Continuity plans, tolerances, testing, incident response, substitution options, and exit planning should connect to the same relationship and service record used for diligence and ongoing oversight.

Make concentration explainable

Portfolio views should show the basis for concentration conclusions, including common providers, locations, technologies, fourth parties, and business services. A heat map without entity confidence and decision context is not enough.

Preserve supervisory evidence

The system should retain source material, reviewer judgment, exceptions, approvals, actions, and the history of material changes. Reporting should be reproducible from the operating record rather than assembled as a separate exercise.

Authorities that shape the work

The following records are primary research pathways, not a complete statement of legal applicability. Scope depends on the organization, jurisdiction, relationship, service, data, and later authority guidance.

2023 Interagency Third-Party Risk Management Guidance

It is the central cross-agency U.S. banking reference for designing and examining third-party risk programs. Product assessments should show how platforms support risk-based tiering, critical-activity oversight, lifecycle documentation, contract controls, ongoing monitoring, escalation, and termination.

Digital Operational Resilience Act (DORA)

DORA turns ICT supplier dependency into a structured, reportable resilience obligation. Buyers need complete contractual inventories, service and critical-function mappings, concentration views, subcontractor information, ongoing monitoring, tested exit strategies, and auditable evidence. The ESAs began oversight of designated critical ICT third-party providers after the first 2025 designation cycle.

EBA/GL/2019/02

It provides a detailed operating blueprint for outsourcing governance beyond purely cyber controls. Buyers need to distinguish outsourcing from other third-party arrangements, document criticality, maintain registers, preserve audit and access rights, monitor subcontracting and concentration, and maintain credible exit plans. Coverage should explicitly disclose the ongoing EBA revision rather than presenting the 2019 text as static.

APRA CPS 230

The standard connects third-party oversight to operational resilience and material-service-provider records. Programs need to identify material arrangements, preserve contractual and monitoring evidence, understand concentration and dependency, and maintain credible continuity and exit plans.

PRA SS2/21

The statement is an operating blueprint for material third-party governance. Its future version also supports expanded notification and register reporting, making data quality, relationship classification, subcontractor visibility, and retained evidence central buyer requirements.

NYDFS Cybersecurity Regulation

It creates explicit third-party cybersecurity governance and evidence expectations. The 2025 DFS guidance sharpens practical coverage across classification, due diligence, contracts, monitoring, fourth parties, geographic risk, resilience, incident coordination, access revocation, data return or destruction, and board-level oversight.

Risk domains and operating capabilities

Risk domains describe what the program is trying to govern. Capabilities describe the operating work a product may support. Buyers should keep both dimensions visible rather than treating a long feature list as proof of sector fit.

Operational resilience and service continuity

Risk that dependency on a third party could interrupt critical products, services, processes, or customer outcomes because of inadequate capacity, recovery, incident response, continuity, substitutability, or exit readiness.

Financial viability and concentration

Risk that a third party's financial deterioration, ownership change, market concentration, shared infrastructure, or limited substitutability could impair delivery or amplify loss across the organization or sector.

Cybersecurity and information security

Risk that a third party or its downstream providers cannot protect systems, software, identities, networks, or information from unauthorized access, misuse, disruption, compromise, or loss.

Fourth-party, geographic, and supply-chain dependency

Risk created by subcontractors, software and hardware components, affiliates, hosting environments, locations, countries, and shared service chains beyond the direct contractual counterparty.

Questions for a company evaluation

  • Can the product represent provider, product, service, contract, location, connection, and fourth-party dependencies separately?
  • How does a change in criticality, ownership, regulation, or service architecture reopen the appropriate review?
  • Can resilience tests, incidents, exceptions, remediation, and exit evidence remain connected to the governed service?
  • Which concentration views are based on customer records, licensed intelligence, provider attestations, or editorial inference?
  • What regulatory reports or registers are supported, and which interpretation and submission responsibilities remain with the institution?
  • What complete record can the institution export if it changes platforms or service providers?

A useful demonstration should apply these questions to one representative relationship with realistic evidence, an exception, a material change, and a decision that must be explained later. The provider should identify what is native, what depends on another product or service, what the customer must configure, and what cannot be established without implementation or independent testing.

What this desk is watching

  • Material Third-Party Reporting Implementation
  • Critical Service-Provider Registers
  • Subcontracting And Fourth-Party Dependency Visibility
  • Cloud And Technology Concentration
  • Operational-Resilience Testing And Exit Evidence

New authority guidance, incidents, product releases, transactions, research, and company documentation can change the questions without changing every prior conclusion. The publication preserves dated reporting separately from the comparative company record so readers can see what changed and what still requires proof.

Current reporting

Companies and operating models

The company set below is a research starting point drawn from provider models relevant to this desk. Appearance does not establish sector-specific deployment, product depth, customer outcomes, or a recommendation. Open each dossier for documented positioning and evidence limits.

Editorial scope: This desk synthesizes the linked primary authorities, maintained market taxonomy, company documentation, and dated reporting for buyer research. It is not legal, security, clinical, financial, or procurement advice.

Research pathway: Continue with the standards library, risk-domain library, comparison desk, and buyer guides.