Third-Party Technology Governance
Govern third-party technology dependencies from materiality and selection through concentration, resilience, and exit
Continue readingSelection and contracting are only the start. Compliance oversight should continuously answer whether the provider is meeting the obligations the organization actually relies on, whether risk has materially changed, whether findings are closing, and whether evidence would support a regulator, auditor, customer, or executive review.
Substantively reviewed . This revision removes the superseded Federal Reserve SR 13-19 framing, adopts the current 2023 interagency guidance, and incorporates the Basel Committee's December 2025 principles for sound management of third-party risk.
Use the Third-Party Technology Governance guide for business ownership, materiality, selection, due diligence, concentration, contractual strategy, and exit planning. Use this page after onboarding to operate the monitoring and evidence lifecycle.
The oversight function should maintain a traceable link from each material obligation to the provider, service, evidence source, review cadence, exception path, and decision owner. The goal is not to collect the largest possible evidence package; it is to know which facts support continued reliance on the provider.
Build the oversight register from the specific relationship. Sources can include the signed contract, service levels, data-processing terms, security addenda, business-continuity commitments, audit rights, internal policy, risk-acceptance conditions, customer obligations, and applicable regulatory requirements.
| Field | Example | Why it matters |
|---|---|---|
| Obligation | Provider maintains agreed authentication control for privileged support access | States the behavior being relied on |
| Basis | Contract section, policy, regulatory requirement, risk acceptance | Explains why it must be monitored |
| Evidence | Attestation, configuration evidence, audit report, test result, ticket, log | Defines proof before review starts |
| Cadence | Continuous, monthly, quarterly, annual, event-triggered | Prevents arbitrary evidence collection |
| Owner | Business, security, privacy, compliance, resilience, contract owner | Creates an escalation target |
| Threshold | Missing evidence, control failure, repeated SLA miss, material incident | Defines when monitoring becomes a decision |
The 2023 U.S. interagency guidance emphasizes lifecycle risk management tailored to the banking organization's size, complexity, risk profile, and the nature of each relationship. It explicitly superseded the Federal Reserve's earlier general outsourcing guidance. Monitoring should therefore be risk-based rather than a universal annual questionnaire.
Every material finding should identify the affected service, risk, source evidence, provider action, internal compensating controls, owner, due date, status, and acceptance authority. Avoid closing a finding because the provider supplied a plan; close it when evidence shows the risk has been reduced to the approved state.
When remediation is not immediate, document the residual risk and time-bound compensating controls. Repeated extensions should trigger a new decision about continued reliance, architecture, contract leverage, alternate suppliers, or business acceptance.
For regulated financial entities in scope of DORA, third-party ICT risk is part of the entity's own ICT risk-management framework. Outsourcing the service does not outsource the financial entity's responsibility under the regulation.
Provider notifications should not live in a procurement mailbox. Define how an external event becomes an internal security, privacy, resilience, legal, compliance, customer, or executive escalation.
Periodic review remains useful, but event-driven reassessment catches the changes most likely to make old diligence misleading. Trigger reassessment for material incidents, major architecture changes, new data classes, increased privileged access, acquisition or ownership change, financial deterioration, critical subcontractor change, geographic relocation, service expansion, repeated control failures, significant regulatory action, or growing concentration.
The Basel Committee's December 2025 principles for sound management of third-party risk broaden the focus beyond traditional outsourcing and establish a common baseline for banks and supervisors. The Basel operational-resilience material also emphasizes mapping critical operations and third-party dependencies, testing disruption scenarios, and maintaining contingency and exit strategies.
Useful management or board reporting highlights:
Counts such as “percent of questionnaires complete” can be operationally useful, but they are weak executive risk measures unless they reveal a decision-relevant gap.
The regulatory examples here are scoped to their source regimes. Apply entity-specific legal, contractual, privacy, security, and sector requirements separately.
Follow the next implementation topic without returning to search.
Govern third-party technology dependencies from materiality and selection through concentration, resilience, and exit
Continue readingUse the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.