Third-party risk management
Third-party risk management is how a firm selects, contracts with, monitors and exits outside providers, and manages the risks it takes on by relying on them.
Third-party risk management (TPRM) is the discipline of selecting, contracting with, monitoring and exiting outside providers, and managing the risks a firm takes on by relying on them, from cloud platforms and payment processors to data vendors and outsourced service centers. The premise regulators share is that using a provider moves the work, not the accountability. The US banking agencies' final interagency guidance on third-party relationships, issued on 6 June 2023 by the Federal Reserve, the FDIC and the OCC, organizes the discipline around a life cycle: "planning, due diligence and third-party selection, contract negotiation, ongoing monitoring, and termination." It replaced each agency's earlier guidance, and the OCC's bulletin lists its 2013 and 2020 guidance among the documents rescinded.
In the EU, DORA sets the rules for ICT providers in Chapter V of Regulation (EU) 2022/2554. Financial entities must keep a register of information on all contractual arrangements for ICT services (Article 28(3)), include mandatory contract terms and plan exits, and the most important ICT providers can be designated critical and overseen by the European Supervisory Authorities. For services outside ICT, the EBA published final guidelines on the sound management of third-party risk related to non-ICT services on 18 September 2026; once they apply, they will repeal its 2019 guidelines on outsourcing arrangements.
Two habits separate working programs from paper ones. The inventory is tiered by criticality, because a provider supporting a critical or important function needs deeper diligence than an office supplier. And regulatory change feeds the program: when a rule adds contract terms or reporting fields, every affected contract and register row needs an owner and a date, which is where a regulatory change impact assessment earns its place. The worked example in the impact assessment template traces one DORA change through contracts and the register.
This entry is general information, not legal advice.
Sources
- Federal Reserve, FDIC and OCC, Agencies issue final guidance on third-party risk management (6 June 2023) accessed 30 Sep 2026
- OCC Bulletin 2023-17, Third-Party Relationships: Interagency Guidance on Risk Management accessed 30 Sep 2026
- Regulation (EU) 2022/2554 (DORA), EUR-Lex accessed 30 Sep 2026
- EBA, Guidelines on the sound management of third-party risk related to non-ICT services (final report, 18 September 2026) accessed 30 Sep 2026
