Framework

Third-Party Risk Framework™

Manage risk from third parties across the full relationship lifecycle.

Overview

Third-party risk arises from vendors, suppliers, outsourcers and partners. This framework manages it across the relationship lifecycle, from tiering and due diligence to monitoring and exit.

Business problem

Critical dependence on vendors creates concentration and continuity risk that goes unmanaged when third parties are not tiered, vetted and monitored.

Purpose

Manage risk from third parties across the full relationship lifecycle.

Who it's for
  • CROs
  • Procurement
  • Operational-risk teams
  • Business owners
Components
  • Inventory & tiering
  • Due diligence
  • Contractual controls & SLAs
  • Ongoing monitoring
  • Concentration & fourth-party risk
  • Exit & continuity
Governance Structure
  • Procurement and business owners manage relationships; the second line oversees; critical vendors are reported to the Risk Committee.
Maturity Levels (shared spine)
L1

Fragile

Maturity level 1 of the shared Outliers risk spine — Fragile.

L2

Functional

Maturity level 2 of the shared Outliers risk spine — Functional.

L3

Disciplined

Maturity level 3 of the shared Outliers risk spine — Disciplined.

L4

Strategic

Maturity level 4 of the shared Outliers risk spine — Strategic.

L5

Resilient

Maturity level 5 of the shared Outliers risk spine — Resilient.

Roadmap
Step 01
  • Inventory and tier third parties
Step 02
  • Risk-based due diligence
Step 03
  • Embed contractual controls
Step 04
  • Monitor performance and risk
Step 05
  • Plan exits and continuity
Deliverables
  • Third-party risk register
  • Due-diligence questionnaire
  • Vendor monitoring pack
Policies & documents
  • Third-party risk policy
  • Due-diligence standard
  • Vendor exit & continuity standard
Metrics & KRIs
  • Critical vendors without exit plan
  • Overdue due diligence
  • Concentration flags
  • Vendor incidents
Board oversight questions
  • Which third parties are critical, and what is our exposure?
  • Where are we concentrated or single-sourced?
  • Do critical vendors have exit and continuity plans?
  • How do we monitor vendor risk over time?

Across the ecosystem

Knowledge graph · 3 relations

operationalised by
ResourceThird-Party Risk PolicyResourceVendor Due-Diligence QuestionnaireResourceThird-Party Risk Register