{"data":{"id":"SP-042","slug":"third-party-risk-management","title":"Third Party Risk Management","description":"Architecture pattern for managing security risk from third party vendors, service providers, and supply chain dependencies. Covers vendor security assessment (SOC 2 Type II, ISO 27001, penetration testing), risk tiering and classification, due diligence workflows, contract security requirements, continuous monitoring, fourth party (sub-processor) risk, incident notification obligations, exit planning, and cyber insurance verification. Addresses the structural challenge that most organisations now depend on hundreds of third parties, each representing an uncontrolled extension of the attack surface.","url":"https://www.opensecurityarchitecture.org/patterns/sp-042","metadata":{"release":"26.02","classification":"Governance and Risk","status":"active","type":"pattern","datePublished":"2026-02-09","dateModified":"2026-02-09","authors":["Vitruvius"],"reviewers":[],"provenance":"Driven by practitioner feedback on r/cybersecurity from bitslammer (Top 1% commenter) who identified that enterprise security teams cannot use external SaaS tools without completed TPRM due diligence — SOC 2 Type II, ISO 27001 certification, cyber insurance, and full vendor onboarding. This pattern documents the architecture that creates that requirement."},"diagram":{"svg":"/images/sp-042-third-party-risk-management.svg","png":""},"content":{"description":"Third party risk management (TPRM) is the discipline of identifying, assessing, monitoring, and mitigating security risks introduced by vendors, service providers, cloud platforms, software suppliers, and other external parties that have access to an organisation's data, systems, or networks.\n\nThe modern enterprise is a network of dependencies. A typical financial services organisation manages 500-1,000 third party relationships, of which 50-100 have access to sensitive data or critical systems. Each third party extends the organisation's attack surface beyond its direct control. The 2020 SolarWinds compromise, the 2023 MOVEit exploitation, and the 2024 CrowdStrike incident demonstrated that third party risk is not theoretical — it is the primary vector for systemic compromise.\n\nTPRM programmes fail for predictable reasons. Assessment is treated as a point-in-time checkbox during procurement rather than continuous monitoring. Questionnaire-based assessments (SIG, CAIQ, VSA) measure policy documentation rather than operational security. Risk tiering is based on contract value rather than data sensitivity and system criticality. Fourth party risk (your vendor's vendors) is invisible. Exit planning is deferred until the relationship is already in crisis.\n\nThis pattern defines a risk-proportionate TPRM architecture that addresses these failures. It covers the full vendor lifecycle from initial classification through due diligence, onboarding, continuous monitoring, incident response, and exit. The architecture is designed to be proportionate — a Tier 1 critical vendor with access to customer PII requires SOC 2 Type II, penetration test results, and cyber insurance verification; a Tier 4 office supplies vendor requires a basic questionnaire. Applying the same process to every vendor is how TPRM programmes collapse under their own weight.\n\nThe pattern maps to NIST 800-53 supply chain risk management (SR family), system and services acquisition (SA family), and planning controls, with additional mappings to assessment and authorisation controls that govern the ongoing assurance process.","keyControlAreas":["Third Party Classification and Risk Tiering (RA-03, PM-09, SR-02): Classify all third parties by data sensitivity (PII, financial, health, IP), system criticality (business-critical, important, standard), access type (network, data, physical, none), and substitutability (single source, limited market, commodity). Assign risk tiers: Tier 1 (critical — access to sensitive data or critical systems, hard to replace), Tier 2 (significant — access to internal systems or moderate data), Tier 3 (standard — limited access, easily replaceable), Tier 4 (minimal — no data access, commodity services). Each tier maps to a proportionate assessment depth and monitoring frequency. Maintain a complete third party inventory with owner, tier, contract expiry, and last assessment date.","Due Diligence and Security Assessment (SA-04, SA-09, SR-05, SR-06): Tier 1 requires: SOC 2 Type II report (or ISO 27001 certificate with statement of applicability), annual penetration test results (application and infrastructure), evidence of vulnerability management programme, incident response plan, business continuity/disaster recovery test results, cyber insurance certificate of currency, and completed security questionnaire (SIG Lite or CAIQ). Tier 2 requires: SOC 2 Type II or ISO 27001 certificate, penetration test summary, and security questionnaire. Tier 3 requires: Self-attestation questionnaire and evidence of basic security controls. Tier 4 requires: Confirmation of standard terms only. Assess before onboarding and at intervals proportionate to tier (Tier 1 annually, Tier 2 every 18 months, Tier 3 every 2 years).","Contract Security Requirements (SA-04, SA-09, PS-07): Embed security obligations in all vendor contracts proportionate to tier. Minimum clauses: data processing agreement (if personal data), security incident notification timeline (72 hours maximum for Tier 1, aligned with GDPR Article 33), right to audit (Tier 1 and 2), data return/destruction on termination, sub-processor notification and approval requirements, compliance with specified standards (SOC 2, ISO 27001, PCI DSS as applicable), insurance minimums, and liability allocation for security breaches. Use a standard security schedule that attaches to the commercial agreement rather than negotiating security terms ad-hoc per vendor.","Continuous Monitoring and Reassessment (CA-07, RA-05, SR-06): Point-in-time assessment is necessary but insufficient. Implement continuous monitoring proportionate to tier: Tier 1 — real-time security rating monitoring (BitSight, SecurityScorecard, RiskRecon), SOC 2 Type II report refresh annually, automated alerts on rating changes, quarterly review meetings. Tier 2 — security rating monitoring, annual attestation refresh. Tier 3 — biennial questionnaire refresh. Monitor for: public breach disclosures, significant rating drops, regulatory actions, financial distress indicators, leadership changes in security function. Trigger reassessment when monitoring signals degrade below threshold.","Fourth Party and Sub-Processor Risk (SR-03, SR-05, SA-09): Your vendor's vendors are your risk. Require Tier 1 vendors to disclose material sub-processors and notify before changes. Assess concentration risk — multiple critical vendors depending on the same cloud provider or infrastructure service creates correlated failure risk. Map critical fourth party dependencies: cloud hosting provider, identity provider, CDN, payment processor, key management service. Require contractual flow-down of security obligations to sub-processors. For SaaS vendors, assess whether they maintain SOC 2 coverage over their own sub-processor management.","Incident Response and Notification (IR-06, IR-08, SA-09): Define incident notification requirements per tier. Tier 1: notification within 24 hours of confirmed incident affecting your data or services, with root cause analysis within 72 hours and remediation plan within 7 days. Tier 2: notification within 48 hours, RCA within 5 business days. Maintain pre-agreed incident communication channels and contacts (not just a generic support email). Include your third party incident playbook in your own IR plan — who to contact, escalation path, communication to your customers, regulatory notification obligations. Test third party incident scenarios in tabletop exercises.","Access Management and Data Controls (AC-03, AC-06, SC-08, SC-28): Third party access to your systems must follow least privilege. Dedicated accounts (never shared credentials), MFA required, just-in-time access for maintenance windows, VPN or zero trust network access for remote connections. Segregate third party network access from internal employee access. Monitor and log all third party access with alerts on anomalous patterns. For data sharing: encrypt in transit (TLS 1.2+) and at rest, use dedicated secure transfer mechanisms (not email), apply data loss prevention controls, and maintain data flow inventories showing what data goes where.","Cyber Insurance Verification (PM-09, SA-04): Require Tier 1 and Tier 2 vendors to maintain cyber insurance with coverage proportionate to the relationship risk. Verify: policy type (cyber liability, errors and omissions, professional indemnity), coverage limits (minimum aligned to potential exposure), policy currency (certificate of insurance annually), coverage scope (data breach response, business interruption, regulatory defence, third party liability). Note that cyber insurance is not a control — it is a risk transfer mechanism. It does not prevent incidents but ensures the vendor can fund response and remediation. A vendor without cyber insurance who suffers a major breach may not survive to fulfil their remediation obligations.","Exit Planning and Data Return (CP-02, SA-04, SA-09): Plan exit before you need it. For Tier 1 vendors: document data return/destruction procedures, establish maximum data return timeline (30 days), verify data destruction certification, maintain alternative vendor shortlist, document migration runbook including data format and API compatibility. Test data portability before it becomes critical — extract a sample dataset and verify it imports to an alternative platform. For SaaS dependencies: ensure data export in standard formats (CSV, JSON, API), not proprietary. Contract should specify that the vendor will provide reasonable transition assistance at standard rates for a defined period after termination.","TPRM Programme Governance (PM-09, PM-14, PL-02): Assign TPRM programme ownership — typically procurement or vendor management with security providing assessment and monitoring. Maintain TPRM policy defining tier criteria, assessment requirements per tier, exception process, and escalation path. Report TPRM metrics to leadership: total vendors by tier, percentage assessed within policy, overdue assessments, average vendor security rating trend, open remediation items, vendors with expired certifications. Conduct annual programme review including: tier classification accuracy, assessment process efficiency, monitoring effectiveness, and lessons from any third party incidents."],"assumptions":"The organisation uses external vendors, cloud services, and third party software. A procurement or vendor management function exists. The organisation has data classification and system criticality definitions. Regulatory requirements mandate supply chain risk management (financial services, healthcare, government, critical infrastructure).","typicalChallenges":"Assessment fatigue — Tier 1 due diligence on every vendor regardless of risk. Questionnaire theatre — vendors provide policy documents that do not reflect operational reality. Point-in-time assessment treated as continuous assurance. Fourth party risk invisible because vendors will not disclose their sub-processors. Exit planning deferred because it implies the relationship will fail. TPRM team understaffed relative to vendor population (500+ vendors, 2-person team). Vendors resisting right-to-audit clauses. SOC 2 Type I presented as equivalent to Type II. Cyber insurance verification not part of standard onboarding. Shadow IT creating unmanaged third party relationships.","indications":"Any organisation using cloud services, SaaS platforms, or outsourced IT services. Regulated industries with explicit supply chain risk requirements (financial services under DORA/PRA SS2/21, healthcare under HIPAA, government under FISMA). Organisations processing personal data under GDPR (data processor obligations). Organisations that have experienced a third party security incident. Any entity whose customers ask for SOC 2 Type II reports or completed security questionnaires.","contraIndications":"Organisations with no external vendor dependencies (extremely rare). Very small teams where all services are built and operated internally with no cloud or SaaS usage.","threatResistance":"Addresses supply chain compromise by requiring security assessment before vendor onboarding and continuous monitoring during the relationship. Reduces fourth party concentration risk through sub-processor disclosure and dependency mapping. Ensures incident response capability through contractual notification obligations and tested playbooks. Provides financial resilience through cyber insurance verification. Enables clean exit through pre-planned data return and migration procedures."},"examples":{"Financial Services (DORA/PRA Compliance)":["Classify all ICT third party service providers per DORA Article 28 criticality criteria","Register of information for all ICT services maintained and reported to supervisory authority","Concentration risk analysis: identify critical functions supported by single cloud provider","Exit strategies for critical ICT services tested annually, including data portability verification","Subcontracting chain monitored: cloud provider changes trigger reassessment under PRA SS2/21"],"Healthcare (HIPAA Business Associates)":["All vendors accessing PHI classified as business associates with executed BAAs","SOC 2 Type II required for all Tier 1 business associates (EHR, claims processing, cloud hosting)","Annual penetration test results reviewed for vendors processing PHI","Breach notification clause: 24-hour notification for any PHI exposure, aligned with HIPAA Breach Notification Rule","Data return verification on termination: certified destruction of all PHI within 30 days"],"Enterprise SaaS Procurement":["Security assessment integrated into procurement workflow — no PO issued without completed TPRM checklist for tier","Automated security rating monitoring for all Tier 1 and 2 vendors via SecurityScorecard/BitSight","Standard security schedule appended to all vendor contracts, pre-approved by legal and security","Quarterly review of Tier 1 vendors: security rating trend, open findings, certification currency","Shadow SaaS discovery via CASB and expense report analysis — 40% of SaaS relationships found outside procurement"],"Critical Infrastructure Operator":["OT vendor access managed through jump hosts with session recording and time-limited credentials","Hardware and firmware supply chain verification for SCADA components and PLCs","Vendor remote access via dedicated VPN with separate network segment — no lateral movement to corporate","Cyber insurance minimum £10M for all Tier 1 vendors supporting operational technology","Annual tabletop exercise simulating vendor compromise affecting safety-critical systems"],"Developing Areas":["Continuous third-party monitoring is displacing point-in-time assessment as the primary assurance mechanism, but the methodology is immature. External security rating services (BitSight, SecurityScorecard) provide observable signals but measure only internet-facing posture -- they cannot assess internal controls, incident response capability, or data handling practices. The gap between what continuous monitoring can see (exposed services, certificate hygiene, DNS configuration) and what matters (access controls, encryption, backup integrity) means ratings are directional indicators, not definitive risk measures.","Nth-party (sub-contractor) risk visibility is the most significant blind spot in TPRM programmes. DORA and PRA SS2/21 mandate sub-processor visibility for critical ICT services, but practical enforcement is limited. Most Tier 1 vendors resist disclosing their full sub-processor chain, and the concentration risk from multiple critical vendors depending on the same cloud provider (AWS, Azure, GCP) or infrastructure service remains difficult to map and nearly impossible to mitigate without architectural diversity that increases cost and complexity.","AI-assisted vendor risk assessment is emerging as a response to the scale problem -- hundreds of vendors requiring assessment with limited analyst capacity. LLM-powered tools can parse SOC 2 reports, extract control findings, compare against organisational requirements, and generate risk summaries, reducing initial assessment time by an estimated 60-70%. However, the accuracy of automated assessment is unvalidated at scale, and the risk of hallucinated compliance findings in AI-generated assessments creates a new category of assessment error.","Software supply chain transparency through vendor-provided SBOMs is a regulatory requirement in progress (EU Cyber Resilience Act, US Executive Order 14028) but practical adoption is minimal. Fewer than 10% of commercial software vendors provide machine-readable SBOMs with their products, and those that do often deliver incomplete or inaccurate bills of materials. The tooling to consume, validate, and act on vendor SBOMs -- matching components to known vulnerabilities, detecting licence conflicts, verifying provenance -- is available but not integrated into standard TPRM workflows.","Concentration risk measurement is gaining regulatory attention but lacks standardised methodology. Regulators want to know what happens if a major cloud provider or critical SaaS platform suffers a prolonged outage, but measuring concentration requires mapping dependency chains across hundreds of vendors, identifying single points of failure, and modelling correlated failure scenarios. No commercial TPRM platform provides automated concentration risk analysis, leaving organisations to build ad-hoc dependency maps that are outdated within months."]},"references":[{"title":"NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management Practices","url":"https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final","note":"Comprehensive C-SCRM guidance integrating supply chain risk into enterprise risk management."},{"title":"DORA — Digital Operational Resilience Act (EU Regulation 2022/2554)","url":"https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554","note":"EU regulation mandating ICT third party risk management for financial entities. Articles 28-30 cover third party risk, Article 31 covers the oversight framework."},{"title":"PRA SS2/21 — Outsourcing and Third Party Risk Management","url":"https://www.bankofengland.co.uk/prudential-regulation/publication/2021/march/outsourcing-and-third-party-risk-management-ss","note":"UK PRA supervisory statement for banks, insurers, and PRA-designated investment firms on outsourcing and third party arrangements."},{"title":"ISO 27036 — Information Security for Supplier Relationships","url":"https://www.iso.org/standard/82905.html","note":"Four-part standard covering supplier relationship security: overview, requirements, ICT supply chain, and cloud services."},{"title":"SIG (Standardized Information Gathering) Questionnaire","url":"https://sharedassessments.org/sig/","note":"Industry-standard vendor security questionnaire maintained by Shared Assessments. SIG Core (full) and SIG Lite (abbreviated) versions."},{"title":"CAIQ (Consensus Assessments Initiative Questionnaire) v4","url":"https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4","note":"Cloud Security Alliance questionnaire for cloud service provider assessment. Maps to CCM v4 controls."},{"title":"SOC 2 Type II — Trust Services Criteria","url":"https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2","note":"AICPA attestation report covering security, availability, processing integrity, confidentiality, and privacy over a period of operation (typically 12 months)."},{"title":"NIST CSF 2.0 — Supply Chain Risk Management Category (GV.SC)","url":"https://www.nist.gov/cyberframework","note":"CSF 2.0 elevates supply chain risk management to a dedicated category under Govern, with 10 subcategories."},{"title":"BitSight / SecurityScorecard — Security Rating Services","url":"https://www.bitsight.com/","note":"External security rating platforms providing continuous monitoring of third party security posture based on observable internet-facing signals."},{"title":"UK NCSC Supply Chain Security Guidance","url":"https://www.ncsc.gov.uk/collection/supply-chain-security","note":"UK National Cyber Security Centre guidance on assessing and managing supply chain risk, including 12 principles for supply chain security."}],"relatedPatterns":["SP-034","SP-036","SP-029","SP-028"],"relatedPatternNames":["Cyber Resilience","Incident Response","Zero Trust Architecture","Secure DevOps Pipeline"],"threats":[{"id":"T-42-001","name":"Supply chain compromise — Attacker compromises a trusted vendor to gain access to the target organisation's systems, data, or network via the established trust relationship (SolarWinds, MOVEit, Kaseya model)","mitigatedBy":["SR-03","SR-05","SR-06","SA-09"]},{"id":"T-42-002","name":"Data breach via third party — Vendor with access to sensitive data suffers a breach, exposing the organisation's customer PII, financial data, or intellectual property through the vendor's compromised systems","mitigatedBy":["SA-09","SC-08","SC-28","AC-06"]},{"id":"T-42-003","name":"Fourth party concentration failure — Multiple critical vendors depend on the same underlying infrastructure provider, creating correlated failure risk that is invisible at the direct vendor assessment level","mitigatedBy":["SR-03","SR-05","CP-02"]},{"id":"T-42-004","name":"Vendor insolvency or exit — Critical vendor ceases operations, enters administration, or terminates the relationship, leaving the organisation unable to access its own data or maintain business-critical services","mitigatedBy":["CP-02","SA-04","PM-09"]},{"id":"T-42-005","name":"Questionnaire theatre — Vendor provides security assessment responses that describe policy intent rather than operational reality, creating false assurance that conceals material security weaknesses","mitigatedBy":["CA-02","CA-07","SR-06"]},{"id":"T-42-006","name":"Shadow vendor relationships — Business units procure SaaS and cloud services outside the TPRM process, creating unassessed third party relationships with unknown data access and security posture","mitigatedBy":["PM-09","SR-02","AC-03"]},{"id":"T-42-007","name":"Delayed incident notification — Vendor suffers a security incident affecting the organisation's data but delays notification beyond regulatory timelines, preventing timely response and mandatory breach reporting","mitigatedBy":["IR-06","IR-08","SA-09"]},{"id":"T-42-008","name":"Excessive third party access — Vendor maintains persistent privileged access beyond what is required for service delivery, expanding the attack surface and enabling lateral movement if the vendor is compromised","mitigatedBy":["AC-03","AC-06","SC-07"]},{"id":"T-42-009","name":"Sub-processor change without notification — Vendor changes a material sub-processor (hosting provider, data processor) without notifying the organisation, introducing unassessed fourth party risk","mitigatedBy":["SR-03","SR-05","SA-09"]},{"id":"T-42-010","name":"Data lock-in and portability failure — Vendor stores data in proprietary formats with no viable export mechanism, making exit impossible without data loss and creating permanent vendor dependency","mitigatedBy":["CP-02","SA-04","SC-28"]},{"id":"T-42-011","name":"Regulatory non-compliance via vendor — Vendor fails to maintain required certifications or compliance standards (SOC 2, ISO 27001, PCI DSS), creating inherited non-compliance for the organisation","mitigatedBy":["CA-07","SR-06","SA-04"]},{"id":"T-42-012","name":"Uninsured vendor liability — Vendor without adequate cyber insurance suffers a major incident but lacks financial capacity to fund breach response, notification, remediation, or compensatory damages","mitigatedBy":["PM-09","SA-04","SR-05"]}],"controls":[{"id":"SR-02","name":"Supply Chain Risk Management Plan","family":"SR","emphasis":"critical"},{"id":"SR-03","name":"Supply Chain Controls and Processes","family":"SR","emphasis":"critical"},{"id":"SR-05","name":"Acquisition Strategies, Tools, and Methods","family":"SR","emphasis":"critical"},{"id":"SR-06","name":"Supplier Assessments and Reviews","family":"SR","emphasis":"critical"},{"id":"SA-04","name":"Acquisition Process","family":"SA","emphasis":"critical"},{"id":"SA-09","name":"External System Services","family":"SA","emphasis":"critical"},{"id":"CA-07","name":"Continuous Monitoring","family":"CA","emphasis":"important"},{"id":"CA-02","name":"Control Assessments","family":"CA","emphasis":"important"},{"id":"PM-09","name":"Risk Management Strategy","family":"PM","emphasis":"important"},{"id":"PM-14","name":"Testing, Training, and Monitoring","family":"PM","emphasis":"important"},{"id":"CP-02","name":"Contingency Plan","family":"CP","emphasis":"important"},{"id":"AC-03","name":"Access Enforcement","family":"AC","emphasis":"important"},{"id":"AC-06","name":"Least Privilege","family":"AC","emphasis":"important"},{"id":"SC-07","name":"Boundary Protection","family":"SC","emphasis":"important"},{"id":"SC-08","name":"Transmission Confidentiality and Integrity","family":"SC","emphasis":"important"},{"id":"SC-28","name":"Protection of Information at Rest","family":"SC","emphasis":"important"},{"id":"IR-06","name":"Incident Reporting","family":"IR","emphasis":"important"},{"id":"IR-08","name":"Incident Response Plan","family":"IR","emphasis":"important"},{"id":"PS-07","name":"External Personnel Security","family":"PS","emphasis":"important"},{"id":"RA-03","name":"Risk Assessment","family":"RA","emphasis":"important"},{"id":"RA-05","name":"Vulnerability Monitoring and Scanning","family":"RA","emphasis":"standard"},{"id":"PL-02","name":"System Security and Privacy Plans","family":"PL","emphasis":"standard"},{"id":"SR-04","name":"Provenance","family":"SR","emphasis":"standard"}],"controlFamilySummary":{"SR":5,"SA":2,"CA":2,"PM":2,"CP":1,"AC":2,"SC":3,"IR":2,"PS":1,"RA":2,"PL":1}}}