Risk-domain libraryWhat a third-party risk program is actually governing
Capabilities describe what a system does. Risk domains describe the loss, disruption, obligation, or dependency an organization is trying to govern. Serious programs need both views.
Risk domainRisk that a third party or its downstream providers cannot protect systems, software, identities, networks, or information from unauthorized access, misuse, disruption, compromise, or loss.
6 buyer questions · 6 related authorities
Risk domainRisk arising from a third party's collection, use, disclosure, localization, retention, transfer, model-training use, or destruction of personal, regulated, confidential, or otherwise sensitive data.
6 buyer questions · 4 related authorities
Risk domainRisk that dependency on a third party could interrupt critical products, services, processes, or customer outcomes because of inadequate capacity, recovery, incident response, continuity, substitutability, or exit readiness.
6 buyer questions · 5 related authorities
Risk domainRisk that a third party's financial deterioration, ownership change, market concentration, shared infrastructure, or limited substitutability could impair delivery or amplify loss across the organization or sector.
6 buyer questions · 5 related authorities
Risk domainRisk that a third party's conduct, ownership, controls, workforce, or business practices expose the buyer to legal violations, regulatory breaches, fraud, bribery, sanctions, conflicts, misconduct, or reputational harm.
6 buyer questions · 5 related authorities
Risk domainRisk created by subcontractors, software and hardware components, affiliates, hosting environments, locations, countries, and shared service chains beyond the direct contractual counterparty.
6 buyer questions · 6 related authorities
Risk domainRisk that a third party cannot meet contracted quality, timeliness, accuracy, capacity, customer-impact, control, or outcome expectations, even when no cybersecurity or compliance failure has occurred.
6 buyer questions · 4 related authorities
Taxonomy boundary
Domains overlap. A cyber incident can become a privacy, resilience, financial, legal, or concentration event. The purpose of the taxonomy is to make the required evidence and accountable functions visible without pretending every relationship needs the same review.