THIRD PARTYCURRENT
Risk-domain library

What a third-party risk program is actually governing

Capabilities describe what a system does. Risk domains describe the loss, disruption, obligation, or dependency an organization is trying to govern. Serious programs need both views.

Risk domain

Cybersecurity and information security

Risk that a third party or its downstream providers cannot protect systems, software, identities, networks, or information from unauthorized access, misuse, disruption, compromise, or loss.

6 buyer questions · 6 related authorities

Risk domain

Privacy and data governance

Risk arising from a third party's collection, use, disclosure, localization, retention, transfer, model-training use, or destruction of personal, regulated, confidential, or otherwise sensitive data.

6 buyer questions · 4 related authorities

Risk domain

Operational resilience and service continuity

Risk that dependency on a third party could interrupt critical products, services, processes, or customer outcomes because of inadequate capacity, recovery, incident response, continuity, substitutability, or exit readiness.

6 buyer questions · 5 related authorities

Risk domain

Financial viability and concentration

Risk that a third party's financial deterioration, ownership change, market concentration, shared infrastructure, or limited substitutability could impair delivery or amplify loss across the organization or sector.

6 buyer questions · 5 related authorities

Risk domain

Legal, regulatory, and business integrity

Risk that a third party's conduct, ownership, controls, workforce, or business practices expose the buyer to legal violations, regulatory breaches, fraud, bribery, sanctions, conflicts, misconduct, or reputational harm.

6 buyer questions · 5 related authorities

Risk domain

Fourth-party, geographic, and supply-chain dependency

Risk created by subcontractors, software and hardware components, affiliates, hosting environments, locations, countries, and shared service chains beyond the direct contractual counterparty.

6 buyer questions · 6 related authorities

Risk domain

Performance, quality, and service delivery

Risk that a third party cannot meet contracted quality, timeliness, accuracy, capacity, customer-impact, control, or outcome expectations, even when no cybersecurity or compliance failure has occurred.

6 buyer questions · 4 related authorities

Taxonomy boundary

Domains overlap. A cyber incident can become a privacy, resilience, financial, legal, or concentration event. The purpose of the taxonomy is to make the required evidence and accountable functions visible without pretending every relationship needs the same review.