THIRD PARTYCURRENT
Regulation and standards

The authorities shaping third-party risk practice

A maintained reading library for the rules, supervisory expectations, and technical standards that change how organizations inventory, assess, monitor, govern, and exit third-party relationships.

Final
May 4, 2022
U.S. government technical guidance

NIST SP 800-161 Rev. 1 Update 1

Foundational NIST guidance for integrating cybersecurity supply-chain risk management into enterprise risk management. It covers strategy, policy, risk assessment, acquisition, supplier oversight, controls, and risk response across organizational levels and the system life cycle.

National Institute of Standards and Technology · United States; broadly adopted as voluntary guidance outside federal use

Final
July 7, 2026
U.S. government technical guidance

NIST SP 1326

An implementation-oriented guide for conducting due-diligence research on ICT suppliers and products before acquisition or during an existing relationship. Its assessment components are foreign ownership, control, or influence; provenance; resilience; foundational cyber practices; and supply-chain tiers.

National Institute of Standards and Technology · United States; usable as voluntary guidance by public- and private-sector acquirers

Final and current
June 5, 2023
Joint U.S. banking supervisory guidance

2023 Interagency Third-Party Risk Management Guidance

Joint supervisory guidance covering the full third-party relationship life cycle: planning, due diligence and selection, contract negotiation, ongoing monitoring, and termination. It emphasizes proportionality, governance, inventory, critical-activity identification, documentation, independent review, and oversight of subcontractors where appropriate.

Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corporation, and Office of the Comptroller of the Currency · United States banking organizations supervised by the issuing agencies

In force and applicable
December 26, 2022
European Union regulation

Digital Operational Resilience Act (DORA)

A harmonized digital-operational-resilience regime for EU financial entities. Chapter V requires ICT third-party risk to be managed within the ICT risk framework and includes strategy, contractual, concentration, register-of-information, criticality, exit, and oversight provisions.

European Parliament and Council of the European Union · European Union financial sector and in-scope ICT third-party arrangements

2019 final report remains listed as applicable; replacement third-party-risk guidelines for non-ICT services were under review after a consultation that closed October 8, 2025
February 24, 2019
European supervisory guidelines

EBA/GL/2019/02

Applicable EBA guidance defining outsourcing, identifying critical or important functions, and setting expectations for governance, records, pre-outsourcing analysis, due diligence, contracting, access and audit rights, security, subcontracting, monitoring, concentration, exit strategies, and supervisory cooperation. The EBA has been updating the framework to align non-ICT third-party risk with DORA.

European Banking Authority · EU credit institutions, investment firms, payment institutions, and electronic-money institutions within the stated scope

Current rule in effect; HHS separately proposed strengthened cybersecurity requirements on January 6, 2025
February 19, 2003
U.S. federal regulation

HIPAA Security Rule and business-associate requirements

The Security Rule requires covered entities and business associates to protect electronic protected health information with administrative, physical, and technical safeguards. Organizational requirements include written business-associate arrangements, satisfactory assurances, flow-down obligations to subcontractors, incident reporting, and required documentation.

U.S. Department of Health and Human Services, Office for Civil Rights · United States covered entities and business associates subject to HIPAA

In force; supplemented by October 21, 2025 DFS guidance on managing third-party service-provider risk
October 31, 2023
New York State financial-services regulation

NYDFS Cybersecurity Regulation

Part 500 requires a risk-based cybersecurity program for covered entities. Section 500.11 requires written policies and procedures for third-party service providers with access to information systems or nonpublic information, including identification, risk assessment, minimum practices, due diligence, periodic assessment, and relevant contractual protections.

New York State Department of Financial Services · New York DFS-regulated covered entities

Current active version as of July 18, 2026
June 10, 2024
Global payment-card industry security standard

PCI DSS v4.0.1

The current PCI DSS baseline for protecting account data. Requirement 12.8 addresses management of third-party service-provider relationships, including due diligence, agreements, clear responsibility allocation, a maintained provider list, and at least annual monitoring of provider compliance status.

PCI Security Standards Council · Organizations whose payment-card obligations require PCI DSS compliance and their relevant third-party service providers

In force from July 1, 2026
April 29, 2026
Australian prudential standard

APRA CPS 230

CPS 230 requires APRA-regulated entities to manage operational risk, maintain critical operations through disruption, and manage risks arising from service providers through policy, formal agreements, monitoring, and accountable governance.

Australian Prudential Regulation Authority · APRA-regulated banks, insurers, private health insurers, and registrable superannuation entity licensees

Current statement effective December 31, 2024; March 2026 update takes effect March 18, 2027
March 30, 2021
United Kingdom prudential supervisory statement

PRA SS2/21

SS2/21 sets expectations for governance, materiality, pre-contract assessment, due diligence, contracts, data security, access and audit rights, subcontracting, monitoring, business continuity, concentration, and exit across outsourcing and third-party arrangements.

Bank of England Prudential Regulation Authority · PRA-regulated firms in the United Kingdom

In force; application depends on national transposition and entity scope
December 26, 2022
European Union directive

NIS2 Directive

NIS2 establishes cybersecurity risk-management and incident-reporting obligations for covered entities. Article 21 expressly includes supply-chain security and security-related aspects of relationships with direct suppliers and service providers.

European Parliament and Council of the European Union · EU Member States and essential or important entities within the directive's scope as implemented in national law

Published standard under systematic review as of July 15, 2026
July 31, 2021
International information-security standard

ISO/IEC 27036-1:2021

Part 1 establishes the concepts and framing for information and communication technology supplier relationships, including risks that arise when organizations acquire products and services or participate in supply chains.

International Organization for Standardization and International Electrotechnical Commission · Voluntary international standard unless adopted through contract, policy, certification scope, or regulatory expectation