Where 12 authorities intersect with 7 third-party risk domains
The sources differ in legal force, jurisdiction, audience, and scope, but they repeatedly return to inventory, due diligence, monitoring, accountability, resilience, evidence, and controlled exit.
No single authority defines a universal TPRM operating model
NIST publications, banking guidance, DORA, EBA outsourcing guidance, HIPAA, NYDFS, and PCI DSS address different populations and obligations. Read together, they reveal recurring operating questions without becoming interchangeable legal requirements.
Key findings
Intake And Inventory is mapped to 12 of the 12 maintained authority records, the highest count in the crosswalk. Offboarding is mapped to 10. A lower count does not make a capability unimportant; it can reflect the specific audience and subject of the selected authorities.
The strongest common pattern is lifecycle evidence. Authorities repeatedly require or imply that organizations know which relationships matter, perform risk-proportionate diligence, assign accountable owners, monitor material change, manage issues and disruptions, preserve records, and plan termination or transition. The terms vary, and legal applicability must be determined separately.
The authority records
NIST SP 800-161 Rev. 1 Update 1
United States; broadly adopted as voluntary guidance outside federal use · Guidance unless made mandatory by law, regulation, contract, acquisition terms, or organizational policy. Foundational NIST guidance for integrating cybersecurity supply-chain risk management into enterprise risk management. It covers strategy, policy, risk assessment, acquisition, supplier oversight, controls, and risk response across organizational levels and the system life cycle. For third-party risk operators, It gives buyers a defensible operating model for identifying, assessing, and mitigating risk in products, services, suppliers, and downstream supply chains. It is a strong reference point for program design, assessment criteria, evidence requirements, supplier monitoring, and fourth-party visibility.
NIST SP 1326
United States; usable as voluntary guidance by public- and private-sector acquirers · Guidance unless incorporated into a requirement, contract, acquisition process, or organizational policy. An implementation-oriented guide for conducting due-diligence research on ICT suppliers and products before acquisition or during an existing relationship. Its assessment components are foreign ownership, control, or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers. For third-party risk operators, It converts a broad C-SCRM obligation into a repeatable minimum-research model for supplier due diligence. The five assessment components can become explicit evidence fields, analyst questions, and scoring dimensions in provider profiles and buyer tools.
2023 Interagency Third-Party Risk Management Guidance
United States banking organizations supervised by the issuing agencies · Supervisory guidance that states it does not impose new requirements; it explains the agencies' views on sound third-party risk-management principles and applicable obligations. Joint supervisory guidance covering the full third-party relationship life cycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. It emphasizes proportionality, governance, inventory, critical-activity identification, documentation, independent review, and oversight of subcontractors where appropriate. For third-party risk operators, It is the central cross-agency U.S. banking reference for designing and examining third-party risk programs. Product assessments should show how platforms support risk-based tiering, critical-activity oversight, lifecycle documentation, contract controls, ongoing monitoring, escalation, and termination.
Digital Operational Resilience Act (DORA)
European Union financial sector and in-scope ICT third-party arrangements · Directly applicable EU regulation for entities within scope. A harmonized digital-operational-resilience regime for EU financial entities. Chapter V requires ICT third-party risk to be managed within the ICT risk framework and includes strategy, contractual, concentration, register-of-information, criticality, exit, and oversight provisions. For third-party risk operators, DORA turns ICT supplier dependency into a structured, reportable resilience obligation. Buyers need complete contractual inventories, service and critical-function mappings, concentration views, subcontractor information, ongoing monitoring, tested exit strategies, and auditable evidence. The ESAs began oversight of designated critical ICT third-party providers after the first 2025 designation cycle.
EBA/GL/2019/02
EU credit institutions, investment firms, payment institutions, and electronic-money institutions within the stated scope · Supervisory guidelines addressed to competent authorities and financial institutions under the EBA framework. Applicable EBA guidance defining outsourcing, identifying critical or important functions, and setting expectations for governance, records, pre-outsourcing analysis, due diligence, contracting, access and audit rights, security, subcontracting, monitoring, concentration, exit strategies, and supervisory cooperation. The EBA has been updating the framework to align non-ICT third-party risk with DORA. For third-party risk operators, It provides a detailed operating blueprint for outsourcing governance beyond purely cyber controls. Buyers need to distinguish outsourcing from other third-party arrangements, document criticality, maintain registers, preserve audit and access rights, monitor subcontracting and concentration, and maintain credible exit plans. Coverage should explicitly disclose the ongoing EBA revision rather than presenting the 2019 text as static.
HIPAA Security Rule and business-associate requirements
United States covered entities and business associates subject to HIPAA · Binding federal regulation for covered entities and business associates within scope. The Security Rule requires covered entities and business associates to protect electronic protected health information with administrative, physical, and technical safeguards. Organizational requirements include written business-associate arrangements, satisfactory assurances, flow-down obligations to subcontractors, incident reporting, and required documentation. For third-party risk operators, Healthcare buyers must know which vendors create, receive, maintain, or transmit ePHI; document business-associate agreements; obtain safeguards and incident commitments; manage subcontractor flow-down; and retain evidence. The rule creates durable requirements for inventory, data-access scoping, contract controls, risk analysis, incident response, and offboarding.
NYDFS Cybersecurity Regulation
New York DFS-regulated covered entities · Binding regulation for covered entities; the 2025 industry letter clarifies requirements and recommends practices without imposing new obligations. Part 500 requires a risk-based cybersecurity program for covered entities. Section 500.11 requires written policies and procedures for third-party service providers with access to information systems or nonpublic information, including identification, risk assessment, minimum practices, due diligence, periodic assessment, and relevant contractual protections. For third-party risk operators, It creates explicit third-party cybersecurity governance and evidence expectations. The 2025 DFS guidance sharpens practical coverage across classification, due diligence, contracts, monitoring, fourth parties, geographic risk, resilience, incident coordination, access revocation, data return or destruction, and board-level oversight.
PCI DSS v4.0.1
Organizations whose payment-card obligations require PCI DSS compliance and their relevant third-party service providers · Industry standard generally enforced through payment-card ecosystem contracts and program rules rather than as a statute. The current PCI DSS baseline for protecting account data. Requirement 12.8 addresses management of third-party service-provider relationships, including due diligence, agreements, clear responsibility allocation, a maintained provider list, and at least annual monitoring of provider compliance status. For third-party risk operators, Outsourcing payment functions does not eliminate the customer's oversight responsibility. Buyers need an accurate service-provider inventory, documented responsibility matrices, evidence of due diligence, contract terms, scoped control ownership, and recurring compliance-status monitoring.
APRA CPS 230
APRA-regulated banks, insurers, private health insurers, and registrable superannuation entity licensees · Binding prudential standard for APRA-regulated entities within scope. CPS 230 requires APRA-regulated entities to manage operational risk, maintain critical operations through disruption, and manage risks arising from service providers through policy, formal agreements, monitoring, and accountable governance. For third-party risk operators, The standard connects third-party oversight to operational resilience and material-service-provider records. Programs need to identify material arrangements, preserve contractual and monitoring evidence, understand concentration and dependency, and maintain credible continuity and exit plans.
PRA SS2/21
PRA-regulated firms in the United Kingdom · Supervisory expectations for PRA-regulated firms, read with applicable PRA rules. SS2/21 sets expectations for governance, materiality, pre-contract assessment, due diligence, contracts, data security, access and audit rights, subcontracting, monitoring, business continuity, concentration, and exit across outsourcing and third-party arrangements. For third-party risk operators, The statement is an operating blueprint for material third-party governance. Its future version also supports expanded notification and register reporting, making data quality, relationship classification, subcontractor visibility, and retained evidence central buyer requirements.
NIS2 Directive
EU Member States and essential or important entities within the directive's scope as implemented in national law · EU directive requiring national transposition; obligations apply through Member State law. NIS2 establishes cybersecurity risk-management and incident-reporting obligations for covered entities. Article 21 expressly includes supply-chain security and security-related aspects of relationships with direct suppliers and service providers. For third-party risk operators, Covered organizations must treat supplier and service-provider relationships as part of cybersecurity risk management. The directive supports disciplined supplier scoping, security criteria, evidence, incident coordination, vulnerability handling, and monitoring while leaving implementation detail to national law and organizational risk decisions.
ISO/IEC 27036-1:2021
Voluntary international standard unless adopted through contract, policy, certification scope, or regulatory expectation · Voluntary standard unless made mandatory by contract, policy, or another authority. Part 1 establishes the concepts and framing for information and communication technology supplier relationships, including risks that arise when organizations acquire products and services or participate in supply chains. For third-party risk operators, The standard provides durable language for separating customer and supplier responsibilities, understanding relationship context, and structuring information-security expectations across the supplier lifecycle. Its 2026 systematic review makes version tracking relevant without implying the current edition has already changed.
The risk-domain lens
A control or workflow can support several risk domains, but the evidence and decision differ. Cybersecurity asks about systems, identities, vulnerabilities, and control effectiveness. Privacy asks what data is collected, used, transferred, retained, and disclosed. Resilience asks whether a critical service can continue or be replaced. Financial and concentration risk asks how failure or common dependency amplifies loss. Legal and integrity risk asks whether conduct, ownership, sanctions, licensing, or contractual exposure changes the relationship.
Fourth-party and geographic dependency requires relationship mapping beyond the direct contract. Performance and service-delivery risk requires operating measures, quality, issue ownership, and escalation. These domains should share relationship identity and governance where practical, but they should not be collapsed into one synthetic score that conceals different evidence, confidence, and consequences.
How to use the crosswalk
- Determine which authorities actually apply with qualified legal, regulatory, compliance, and business owners.
- Identify the relationships, services, data, systems, locations, and downstream dependencies inside scope.
- Map each applicable expectation to an accountable decision, required evidence, review cadence, exception path, and retained record.
- Use capability and provider pages to identify products worth investigating, not to substitute software language for program design.
- Test the workflow with representative relationships, including a difficult case and a material change.
Methodology
The Research Desk selected current primary sources that materially shape third-party risk work across cyber supply chain, U.S. banking, European digital resilience and outsourcing, U.S. health information, New York financial services, and payment-card security. Each record preserves the issuing authority, jurisdiction, status, legal-force description, publication or application dates, official source, audience, lifecycle stages, capability mappings, and an interpretation boundary.
Limitations
- The library is intentionally selective and is not a complete inventory of global laws, regulations, contracts, standards, or sector guidance.
- Mappings are editorial interpretations designed for research navigation; they are not legal advice.
- A capability mapping does not establish that a product satisfies an authority.
- Authorities can overlap, conflict, or apply differently by entity, service, geography, and contract.
- Dates and status require continued monitoring of the official source.
Reproducibility and updates
Every entry links to an official source and a dedicated standards record. A mapping change requires a documented reason and source review. Superseded versions remain part of the historical record rather than disappearing when a new edition or deadline arrives.
Crosswalk record
Authorities: 12. Risk domains: 7. Normalized capabilities: 10. Jurisdictions represented: 12. Verification date: July 19, 2026.