What is third-party risk management?

Third-party risk management explained: the lifecycle, why fourth parties matter, and how Australian regulation treats supplier oversight.
CYBORIUM article header reading Your risk does not stop at your perimeter, over a connected node graphic.

Third-party risk management is the practice of identifying, assessing and monitoring the risk a supplier introduces to an organisation, before contract and throughout the relationship. It covers security, operational resilience, financial stability, regulatory exposure and concentration risk.

What is third-party risk management?

Third-party risk management is the practice of identifying, assessing and monitoring the risk a supplier introduces to an organisation, before contract and throughout the relationship. It covers security, operational resilience, financial stability, regulatory exposure and concentration risk.

How does it differ from vendor due diligence?

Due diligence is a point-in-time assessment carried out before contracting. Third-party risk management is the continuing discipline that follows: monitoring performance, reassessing when circumstances change, and managing the relationship through to exit. Due diligence is a stage within it.

What is fourth-party risk?

Fourth-party risk is the risk introduced by your suppliers own suppliers. A provider may be resilient while depending on a single cloud region, payment processor or subcontractor whose failure would still stop your service. Mapping these dependencies is part of a complete assessment.

Concentration risk is the related problem. Several suppliers that look independent can share one underlying platform, so a single outage removes what appeared to be redundancy.

How does Australian regulation treat third-party risk?

APRA Prudential Standard CPS 230, in force since 1 July 2025, requires regulated entities to manage risks from material service providers, including maintaining a register and assessing the ability to continue critical operations through disruption. The Security of Critical Infrastructure Act imposes related supply chain obligations on responsible entities.

Published figures on the cost of incidents are collected on the Australian statistics page, each with a named and dated source.

It treats it as the entity’s own risk, not the supplier’s. APRA CPS 230 requires regulated entities to identify material service providers, manage the risks those arrangements carry, and maintain the ability to keep critical operations running within tolerance when a provider fails. APRA CPS 234 requires the same entity to assess the information security capability of any third party managing its information assets. Neither standard accepts a contract clause as evidence on its own, which is why fourth-party concentration and exit arrangements now appear in evaluation criteria rather than only in the contract.

Sources

Where to read more

See vendor and supplier risk management, what is vendor due diligence, and virtual vendor relationship management.

Also relevant: the benefits of cybersecurity procurement services and software bills of materials in Australian procurement.

Share this analysis