Turn third-party oversight into a living evidence process.
Selection and contracting are only the start. Compliance oversight should continuously answer whether the provider is meeting the obligations the organization actually relies on, whether risk has materially changed, whether findings are closing, and whether evidence would support a regulator, auditor, customer, or executive review.
Substantively reviewed . This revision removes the superseded Federal Reserve SR 13-19 framing, adopts the current 2023 interagency guidance, and incorporates the Basel Committee's December 2025 principles for sound management of third-party risk.
Governance decides whether the relationship is acceptable; compliance proves it remains controlled.
Use the Third-Party Technology Governance guide for business ownership, materiality, selection, due diligence, concentration, contractual strategy, and exit planning. Use this page after onboarding to operate the monitoring and evidence lifecycle.
The oversight function should maintain a traceable link from each material obligation to the provider, service, evidence source, review cadence, exception path, and decision owner. The goal is not to collect the largest possible evidence package; it is to know which facts support continued reliance on the provider.
Translate contracts and applicable rules into monitorable statements.
Build the oversight register from the specific relationship. Sources can include the signed contract, service levels, data-processing terms, security addenda, business-continuity commitments, audit rights, internal policy, risk-acceptance conditions, customer obligations, and applicable regulatory requirements.
| Field | Example | Why it matters |
|---|---|---|
| Obligation | Provider maintains agreed authentication control for privileged support access | States the behavior being relied on |
| Basis | Contract section, policy, regulatory requirement, risk acceptance | Explains why it must be monitored |
| Evidence | Attestation, configuration evidence, audit report, test result, ticket, log | Defines proof before review starts |
| Cadence | Continuous, monthly, quarterly, annual, event-triggered | Prevents arbitrary evidence collection |
| Owner | Business, security, privacy, compliance, resilience, contract owner | Creates an escalation target |
| Threshold | Missing evidence, control failure, repeated SLA miss, material incident | Defines when monitoring becomes a decision |
Monitor changes that can invalidate the original risk decision.
Operational signals
- Availability, support responsiveness, material SLA failures, capacity constraints, and recurring incidents.
- Security incidents, material vulnerabilities, exposed credentials, ransomware events, control-plane failures, or data-loss events.
- Recovery tests, restoration failures, business-continuity exercises, and unresolved resilience gaps.
- Changes in service architecture, regions, data handling, critical subcontractors, or privileged support models.
Governance signals
- Ownership, merger, financial-condition, litigation, regulatory, or sanctions developments relevant to the service.
- Expired assurance reports or certifications that were relied on during approval.
- New exceptions, overdue remediation, unapproved subcontracting, or material contract changes.
- Growth in organizational dependence on the same provider or shared fourth party.
The 2023 U.S. interagency guidance emphasizes lifecycle risk management tailored to the banking organization's size, complexity, risk profile, and the nature of each relationship. It explicitly superseded the Federal Reserve's earlier general outsourcing guidance. Monitoring should therefore be risk-based rather than a universal annual questionnaire.
Understand what each assurance artifact does—and does not—prove.
- SOC reports: read the scope, period, system description, control objectives, exceptions, complementary user-entity controls, subservice-organization treatment, and auditor opinion. A clean opinion does not mean every control your organization needs was tested.
- ISO certifications: verify the legal entity, certified scope, locations, services, standard/version, certification body, validity period, and any exclusions. Certification is not evidence that every contract-specific requirement operates.
- Penetration or security testing: understand scope, date, environment, methodology, severity, unresolved findings, and whether the tested surface matches the service you consume.
- Resilience evidence: distinguish a written continuity plan from a tested restoration or failover result. Look for scenario, dependencies, measured outcome, recovery integrity, and lessons learned.
- Provider questionnaires: treat self-attestation as one evidence source. Escalate consequential claims that lack corroboration when the relationship's risk justifies it.
Keep provider findings on the same accountability standard as internal findings.
Every material finding should identify the affected service, risk, source evidence, provider action, internal compensating controls, owner, due date, status, and acceptance authority. Avoid closing a finding because the provider supplied a plan; close it when evidence shows the risk has been reduced to the approved state.
When remediation is not immediate, document the residual risk and time-bound compensating controls. Repeated extensions should trigger a new decision about continued reliance, architecture, contract leverage, alternate suppliers, or business acceptance.
For regulated financial entities in scope of DORA, third-party ICT risk is part of the entity's own ICT risk-management framework. Outsourcing the service does not outsource the financial entity's responsibility under the regulation.
Connect third-party incident intake to your own incident process.
Provider notifications should not live in a procurement mailbox. Define how an external event becomes an internal security, privacy, resilience, legal, compliance, customer, or executive escalation.
- Identify impact. Determine affected services, data, identities, integrations, business processes, jurisdictions, and customers.
- Preserve evidence. Record the provider's timeline, statements, indicators, affected components, containment actions, and updates without overwriting earlier versions.
- Assess internal obligations. Determine whether the event triggers the organization's own notification, materiality, contractual, insurance, or regulatory processes.
- Control exposure. Revoke or constrain access, rotate credentials, isolate integrations, invoke alternate processes, or fail over where warranted.
- Track remediation. Require root-cause and corrective-action evidence proportionate to the impact and use the event as a reassessment trigger.
Review when the risk changes, not only when the calendar says so.
Periodic review remains useful, but event-driven reassessment catches the changes most likely to make old diligence misleading. Trigger reassessment for material incidents, major architecture changes, new data classes, increased privileged access, acquisition or ownership change, financial deterioration, critical subcontractor change, geographic relocation, service expansion, repeated control failures, significant regulatory action, or growing concentration.
The Basel Committee's December 2025 principles for sound management of third-party risk broaden the focus beyond traditional outsourcing and establish a common baseline for banks and supervisors. The Basel operational-resilience material also emphasizes mapping critical operations and third-party dependencies, testing disruption scenarios, and maintaining contingency and exit strategies.
Report unresolved dependency risk, not oversight activity volume.
Useful management or board reporting highlights:
- Critical services dependent on providers with unresolved high-risk findings.
- Material providers with expired or insufficient evidence.
- Concentration in providers or fourth parties across critical services.
- Provider incidents and whether recovery, notification, and remediation obligations were met.
- Risk acceptances approaching expiration and repeated remediation extensions.
- Exit or substitutability tests that failed or have never been performed.
- Material changes that require a new governance decision.
Counts such as “percent of questionnaires complete” can be operationally useful, but they are weak executive risk measures unless they reveal a decision-relevant gap.
Current authorities used for this review.
- Federal Reserve SR 23-4 — Interagency Guidance on Third-Party Relationships: Risk Management.
- OCC Bulletin 2023-17 — Interagency Guidance on Third-Party Relationships: Risk Management.
- Regulation (EU) 2022/2554 — Digital Operational Resilience Act.
- European Banking Authority — DORA oversight resources and critical ICT third-party provider list.
- Basel Committee — Principles for the sound management of third-party risk, December 2025.
- Basel Committee — Operational resilience consolidated guidance.
The regulatory examples here are scoped to their source regimes. Apply entity-specific legal, contractual, privacy, security, and sector requirements separately.
Related resources
Turn Third-Party Compliance Oversight Guide into a decision-ready next step.
Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.