# SP-042 Third Party Risk Management

Status: active. Release 26.02. Modified 2026-02-09. Licence: CC BY-SA 4.0.

Scope: Architecture pattern for managing security risk from third party vendors, service providers, and supply chain dependencies. Covers vendor security assessment (SOC 2 Type II, ISO 27001, penetration testing), risk tiering and classification, due diligence workflows, contract security requirements, continuous monitoring, fourth party (sub-processor) risk, incident notification obligations, exit planning, and cyber...
Use when: Any organisation using cloud services, SaaS platforms, or outsourced IT services. Regulated industries with explicit supply chain risk requirements (financial services under DORA/PRA SS2/21, healthcare under HIPAA, government under FISMA).
Not when: Organisations with no external vendor dependencies (extremely rare).

## Controls (23, NIST SP 800-53 ids)
- Critical (6): SR-02, SR-03, SR-05, SR-06, SA-04, SA-09
- Important (14): CA-07, CA-02, PM-09, PM-14, CP-02, AC-03, AC-06, SC-07, SC-08, SC-28, IR-06, IR-08, PS-07, RA-03
- Standard (3): RA-05, PL-02, SR-04

## What each critical control mitigates (6)
- SR-02 Supply Chain Risk Management Plan: T-42-006
- SR-03 Supply Chain Controls and Processes: T-42-001, T-42-003, T-42-009
- SR-05 Acquisition Strategies, Tools, and Methods: T-42-001, T-42-003, T-42-009, T-42-012
- SR-06 Supplier Assessments and Reviews: T-42-001, T-42-005, T-42-011
- SA-04 Acquisition Process: T-42-004, T-42-010, T-42-011, T-42-012
- SA-09 External System Services: T-42-001, T-42-002, T-42-007, T-42-009

## Threats and the controls that mitigate them (12)
- T-42-001 Supply chain compromise — Attacker compromises a trusted vendor to gain access to the target organisation's systems, data, or network via the established trust relationship (SolarWinds, MOVEit, Kaseya model): SR-03, SR-05, SR-06, SA-09
- T-42-002 Data breach via third party — Vendor with access to sensitive data suffers a breach, exposing the organisation's customer PII, financial data, or intellectual property through the vendor's compromised systems: SA-09, SC-08, SC-28, AC-06
- T-42-003 Fourth party concentration failure — Multiple critical vendors depend on the same underlying infrastructure provider, creating correlated failure risk that is invisible at the direct vendor assessment level: SR-03, SR-05, CP-02
- T-42-004 Vendor insolvency or exit — Critical vendor ceases operations, enters administration, or terminates the relationship, leaving the organisation unable to access its own data or maintain business-critical services: CP-02, SA-04, PM-09
- T-42-005 Questionnaire theatre — Vendor provides security assessment responses that describe policy intent rather than operational reality, creating false assurance that conceals material security weaknesses: CA-02, CA-07, SR-06
- T-42-006 Shadow vendor relationships — Business units procure SaaS and cloud services outside the TPRM process, creating unassessed third party relationships with unknown data access and security posture: PM-09, SR-02, AC-03
- T-42-007 Delayed incident notification — Vendor suffers a security incident affecting the organisation's data but delays notification beyond regulatory timelines, preventing timely response and mandatory breach reporting: IR-06, IR-08, SA-09
- T-42-008 Excessive third party access — Vendor maintains persistent privileged access beyond what is required for service delivery, expanding the attack surface and enabling lateral movement if the vendor is compromised: AC-03, AC-06, SC-07
- T-42-009 Sub-processor change without notification — Vendor changes a material sub-processor (hosting provider, data processor) without notifying the organisation, introducing unassessed fourth party risk: SR-03, SR-05, SA-09
- T-42-010 Data lock-in and portability failure — Vendor stores data in proprietary formats with no viable export mechanism, making exit impossible without data loss and creating permanent vendor dependency: CP-02, SA-04, SC-28
- T-42-011 Regulatory non-compliance via vendor — Vendor fails to maintain required certifications or compliance standards (SOC 2, ISO 27001, PCI DSS), creating inherited non-compliance for the organisation: CA-07, SR-06, SA-04
- T-42-012 Uninsured vendor liability — Vendor without adequate cyber insurance suffers a major incident but lacks financial capacity to fund breach response, notification, remediation, or compensatory damages: PM-09, SA-04, SR-05

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-042/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-042/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 26 KB: /api/v1/patterns/SP-042
- Page for people: /patterns/sp-042/
- Related: SP-034 Cyber Resilience; SP-036 Incident Response; SP-029 Zero Trust Architecture; SP-028 Secure DevOps Pipeline

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
