THIRD PARTYCURRENT
Third-party risk domain

Privacy and data governance

Risk arising from a third party's collection, use, disclosure, localization, retention, transfer, model-training use, or destruction of personal, regulated, confidential, or otherwise sensitive data.

How the risk enters through third parties

Risk arising from a third party's collection, use, disclosure, localization, retention, transfer, model-training use, or destruction of personal, regulated, confidential, or otherwise sensitive data. The exposure becomes operational when the organization depends on an external company, product, service, location, component, identity, or downstream provider and cannot see or govern the conditions that would change the relationship decision.

The useful unit of analysis is not always the legal vendor. Teams may need to distinguish contracts, products, integrations, facilities, data flows, business services, and fourth parties so a finding reaches the right owner and response.

Signals and evidence to examine

Evidence should be proportionate to the relationship and sufficiently current for the decision. Operators should preserve source, date, reviewer, affected object, uncertainty, exception, and disposition rather than reducing the domain to an unexplained status.

  • Relationship purpose, owner, systems, data, services, locations, contracts, and criticality.
  • Source documents, observed signals, assurance reports, test results, incidents, and unresolved findings.
  • Downstream dependencies, concentration, substitutability, and conditions that trigger reassessment.
  • Actions, deadlines, approvals, accepted risk, compensating measures, and closure evidence.

Capabilities used to govern this domain

Intake And Inventory

establishing an accountable record of relationships, products, owners, and critical services. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Inherent Risk Tiering

using relationship context to determine proportional diligence and review. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Due Diligence And Assessments

collecting and reviewing evidence before and during a relationship. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Evidence Collection

preserving source material, responses, and reviewer context. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Continuous Monitoring

bringing material external and internal change into an owned response workflow. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Issue Remediation

assigning findings, deadlines, exceptions, and closure evidence. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Fourth-Party Visibility

identifying and explaining important downstream dependencies. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Regulatory Mapping

connecting program records to obligations and examination needs. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Reporting

turning program activity into operator, executive, and board-ready information. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Offboarding

closing access, data, evidence, and residual obligations when a relationship ends. The implementation should preserve the domain-specific evidence and decision context rather than treating the capability label as proof.

Relevant authorities and standards

HIPAA Security Rule and business-associate requirements

Healthcare buyers must know which vendors create, receive, maintain, or transmit ePHI; document business-associate agreements; obtain safeguards and incident commitments; manage subcontractor flow-down; and retain evidence. The rule creates durable requirements for inventory, data-access scoping, contract controls, risk analysis, incident response, and offboarding.

NYDFS Cybersecurity Regulation

It creates explicit third-party cybersecurity governance and evidence expectations. The 2025 DFS guidance sharpens practical coverage across classification, due diligence, contracts, monitoring, fourth parties, geographic risk, resilience, incident coordination, access revocation, data return or destruction, and board-level oversight.

Digital Operational Resilience Act (DORA)

DORA turns ICT supplier dependency into a structured, reportable resilience obligation. Buyers need complete contractual inventories, service and critical-function mappings, concentration views, subcontractor information, ongoing monitoring, tested exit strategies, and auditable evidence. The ESAs began oversight of designated critical ICT third-party providers after the first 2025 designation cycle.

PCI DSS v4.0.1

Outsourcing payment functions does not eliminate the customer's oversight responsibility. Buyers need an accurate service-provider inventory, documented responsibility matrices, evidence of due diligence, contract terms, scoped control ownership, and recurring compliance-status monitoring.

Current market changes

UpGuard adds fourth-party API access and questionnaire-remediation changes

Downstream relationship data is moving from static visualization toward integration with governed response workflows.

ISO/IEC 27036-1 enters systematic review

Programs and vendors need version-aware standards records that distinguish a review milestone from a changed requirement.

NIST finalizes its C-SCRM Due Diligence Assessment Quick-Start Guide

The guide gives buyers a neutral baseline for testing whether intake, evidence, review, escalation, and decision records support a defensible supplier-diligence process.

UpGuard publishes a higher-education vendor breach study

Relationship-scale datasets can reveal concentration and downstream exposure, while also increasing the importance of transparent methods and population boundaries.

Research boundary

The domain model is editorial taxonomy. Company inclusion below reflects provider operating models and documented capability intersections, not proof that a company comprehensively manages this risk or satisfies a regulation.

Companies to investigate

Full directory