Compliance oversight

Turn third-party oversight into a living evidence process.

Selection and contracting are only the start. Compliance oversight should continuously answer whether the provider is meeting the obligations the organization actually relies on, whether risk has materially changed, whether findings are closing, and whether evidence would support a regulator, auditor, customer, or executive review.

Substantively reviewed . This revision removes the superseded Federal Reserve SR 13-19 framing, adopts the current 2023 interagency guidance, and incorporates the Basel Committee's December 2025 principles for sound management of third-party risk.

Clear division of work

Governance decides whether the relationship is acceptable; compliance proves it remains controlled.

Use the Third-Party Technology Governance guide for business ownership, materiality, selection, due diligence, concentration, contractual strategy, and exit planning. Use this page after onboarding to operate the monitoring and evidence lifecycle.

The oversight function should maintain a traceable link from each material obligation to the provider, service, evidence source, review cadence, exception path, and decision owner. The goal is not to collect the largest possible evidence package; it is to know which facts support continued reliance on the provider.

Obligation register

Translate contracts and applicable rules into monitorable statements.

Build the oversight register from the specific relationship. Sources can include the signed contract, service levels, data-processing terms, security addenda, business-continuity commitments, audit rights, internal policy, risk-acceptance conditions, customer obligations, and applicable regulatory requirements.

FieldExampleWhy it matters
ObligationProvider maintains agreed authentication control for privileged support accessStates the behavior being relied on
BasisContract section, policy, regulatory requirement, risk acceptanceExplains why it must be monitored
EvidenceAttestation, configuration evidence, audit report, test result, ticket, logDefines proof before review starts
CadenceContinuous, monthly, quarterly, annual, event-triggeredPrevents arbitrary evidence collection
OwnerBusiness, security, privacy, compliance, resilience, contract ownerCreates an escalation target
ThresholdMissing evidence, control failure, repeated SLA miss, material incidentDefines when monitoring becomes a decision
Continuous monitoring

Monitor changes that can invalidate the original risk decision.

Operational signals

  • Availability, support responsiveness, material SLA failures, capacity constraints, and recurring incidents.
  • Security incidents, material vulnerabilities, exposed credentials, ransomware events, control-plane failures, or data-loss events.
  • Recovery tests, restoration failures, business-continuity exercises, and unresolved resilience gaps.
  • Changes in service architecture, regions, data handling, critical subcontractors, or privileged support models.

Governance signals

  • Ownership, merger, financial-condition, litigation, regulatory, or sanctions developments relevant to the service.
  • Expired assurance reports or certifications that were relied on during approval.
  • New exceptions, overdue remediation, unapproved subcontracting, or material contract changes.
  • Growth in organizational dependence on the same provider or shared fourth party.

The 2023 U.S. interagency guidance emphasizes lifecycle risk management tailored to the banking organization's size, complexity, risk profile, and the nature of each relationship. It explicitly superseded the Federal Reserve's earlier general outsourcing guidance. Monitoring should therefore be risk-based rather than a universal annual questionnaire.

Assurance

Understand what each assurance artifact does—and does not—prove.

  • SOC reports: read the scope, period, system description, control objectives, exceptions, complementary user-entity controls, subservice-organization treatment, and auditor opinion. A clean opinion does not mean every control your organization needs was tested.
  • ISO certifications: verify the legal entity, certified scope, locations, services, standard/version, certification body, validity period, and any exclusions. Certification is not evidence that every contract-specific requirement operates.
  • Penetration or security testing: understand scope, date, environment, methodology, severity, unresolved findings, and whether the tested surface matches the service you consume.
  • Resilience evidence: distinguish a written continuity plan from a tested restoration or failover result. Look for scenario, dependencies, measured outcome, recovery integrity, and lessons learned.
  • Provider questionnaires: treat self-attestation as one evidence source. Escalate consequential claims that lack corroboration when the relationship's risk justifies it.
Findings and exceptions

Keep provider findings on the same accountability standard as internal findings.

Every material finding should identify the affected service, risk, source evidence, provider action, internal compensating controls, owner, due date, status, and acceptance authority. Avoid closing a finding because the provider supplied a plan; close it when evidence shows the risk has been reduced to the approved state.

When remediation is not immediate, document the residual risk and time-bound compensating controls. Repeated extensions should trigger a new decision about continued reliance, architecture, contract leverage, alternate suppliers, or business acceptance.

For regulated financial entities in scope of DORA, third-party ICT risk is part of the entity's own ICT risk-management framework. Outsourcing the service does not outsource the financial entity's responsibility under the regulation.

Provider incidents

Connect third-party incident intake to your own incident process.

Provider notifications should not live in a procurement mailbox. Define how an external event becomes an internal security, privacy, resilience, legal, compliance, customer, or executive escalation.

  1. Identify impact. Determine affected services, data, identities, integrations, business processes, jurisdictions, and customers.
  2. Preserve evidence. Record the provider's timeline, statements, indicators, affected components, containment actions, and updates without overwriting earlier versions.
  3. Assess internal obligations. Determine whether the event triggers the organization's own notification, materiality, contractual, insurance, or regulatory processes.
  4. Control exposure. Revoke or constrain access, rotate credentials, isolate integrations, invoke alternate processes, or fail over where warranted.
  5. Track remediation. Require root-cause and corrective-action evidence proportionate to the impact and use the event as a reassessment trigger.
Reassessment

Review when the risk changes, not only when the calendar says so.

Periodic review remains useful, but event-driven reassessment catches the changes most likely to make old diligence misleading. Trigger reassessment for material incidents, major architecture changes, new data classes, increased privileged access, acquisition or ownership change, financial deterioration, critical subcontractor change, geographic relocation, service expansion, repeated control failures, significant regulatory action, or growing concentration.

The Basel Committee's December 2025 principles for sound management of third-party risk broaden the focus beyond traditional outsourcing and establish a common baseline for banks and supervisors. The Basel operational-resilience material also emphasizes mapping critical operations and third-party dependencies, testing disruption scenarios, and maintaining contingency and exit strategies.

Reporting

Report unresolved dependency risk, not oversight activity volume.

Useful management or board reporting highlights:

  • Critical services dependent on providers with unresolved high-risk findings.
  • Material providers with expired or insufficient evidence.
  • Concentration in providers or fourth parties across critical services.
  • Provider incidents and whether recovery, notification, and remediation obligations were met.
  • Risk acceptances approaching expiration and repeated remediation extensions.
  • Exit or substitutability tests that failed or have never been performed.
  • Material changes that require a new governance decision.

Counts such as “percent of questionnaires complete” can be operationally useful, but they are weak executive risk measures unless they reveal a decision-relevant gap.

Put this guide to work

Turn Third-Party Compliance Oversight Guide into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.