THIRD PARTYCURRENT
News topic

Regulation & Standards

Current reporting and analysis with clear distinctions between primary-source facts, provider-reported claims, and Third Party Current interpretation.

Primary-source analysis

Federal Reserve guide makes information gaps a risk decision

The community-bank guide says unavailable due-diligence evidence should lead to alternative information, controls, or monitoring—not an unexplained pass or a silent stop in the review.

Primary-source analysis

DORA makes ICT concentration a pre-contract decision

Article 29 puts substitutability, repeated reliance on the same or connected providers, alternative solutions, and subcontracting risk into the assessment before critical ICT services are contracted.

Primary-source analysis

PRA SS2/21 makes outsourcing exit plans testable

For material outsourcing, the current supervisory statement treats exit as a planned, owned, costed, and risk-based test—not a clause that can wait for supplier failure.

Primary-source analysis

NIS2 makes supplier security part of the entity's controls

Article 21 puts supply-chain security inside the risk measures for essential and important entities. A supplier score cannot replace the entity's own relationship-specific controls.

Primary-source analysis

Interagency guidance makes relationship structure a risk fact

Federal banking agencies apply third-party risk principles across relationship types and structures. The operating record must explain how each arrangement works.

Primary-source analysis

NIST SP 800-161 makes supplier criticality a lifecycle decision

NIST's cyber supply-chain guidance does not reduce third-party risk to an onboarding questionnaire. It connects products, services, suppliers, system context, and risk response across the life of the relationship.

Standards Watch

ISO supplier-security standard enters systematic review

ISO/IEC 27036-1 remains the published supplier-relationship standard while its 2026 review determines whether the current edition should be confirmed, revised, or withdrawn.

Regulatory Analysis

CPS 230 puts service-provider resilience into force in Australia

APRA's operational-risk standard now requires regulated entities to connect material service-provider oversight with critical operations, formal agreements, monitoring, and continuity planning.

Analysis

NIST pulls supply-chain risk into the system planning record

SP 800-18 Revision 2 treats cybersecurity supply-chain risk planning as part of the broader system risk record, raising the importance of traceable ownership and evidence.

Market context

Coverage is attached to the companies, capabilities, and standards it affects so that market records change with evidence rather than headlines alone.