Resources / Information Security and Data Privacy / Third-Party and Supply Chain Risk
For regulated organisations
Third-Party and Supply Chain Risk
A practitioner's guide to third-party and supply chain risk in regulated organisations: the regulatory frameworks now in force across the UK, the EU, Australia and New Zealand, and the governance, due diligence, contractual and monitoring discipline a genuine third-party risk programme requires.
|
Important note This guide is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Contents
Introduction
Verizon’s 2025 Data Breach Investigations Report recorded third-party involvement in 30% of breaches, up from 15% in the previous year. That is the clearest signal yet that attackers are exploiting supplier relationships because those relationships often carry trusted access into better-defended organisations.
The logic is straightforward. A large regulated organisation invests heavily in its own perimeter, monitoring and incident response capability. A smaller supplier may hold the same sensitive data or carry the same trusted access without the same depth of control maturity. If the supplier is compromised, the trust relationship can give the attacker a route into the organisation’s environment. The access was not designed to treat the attacker as a threat, because the attacker is using a route the organisation opened itself.
This is not a new risk. Organisations have always depended on external suppliers. What has changed is the depth of that dependency.
Core banking platforms, cloud infrastructure, payments processing, identity verification, customer-facing digital services and cybersecurity monitoring itself now routinely sit with third parties in regulated organisations, often several layers deep.
The operational dependency is real, and it means a supplier failure is not a supplier's problem. It is the regulated entity's problem in full, regardless of where the failure originated.
Regulators across the UK, the EU, Australia and New Zealand have converged on that principle. You cannot outsource your accountability. You can outsource a function, but the obligation to manage the risk that comes with it stays exactly where it always was. This guide sets out what that means in practice: the regulatory frameworks that now apply, and the governance, due diligence, contractual and monitoring discipline that a genuine third-party risk programme requires.
It is written for compliance professionals, risk managers and programme managers building or strengthening a third-party risk function, and it draws on experience managing vendor relationships and procurement governance inside regulated financial services organisations. A note on terms: ‘third party’, ‘vendor’, ‘supplier’ and ‘service provider’ are used interchangeably throughout. A fourth party is a subcontractor or provider your supplier relies on to deliver the service. It remains part of your risk picture even though you do not contract with it directly.
Chapter One: Why This Risk Now Sits With the Board
Two risks, one accountability
Dependence on a third party creates two distinct categories of exposure. The first is operational: the supplier fails to deliver, becomes unavailable, or suffers a disruption that cascades into the organisation's own ability to serve customers. The second is security: an attacker compromises the supplier and uses that trusted access to reach the organisation's own systems and data. Both are live risks for most regulated organisations. Both remain the regulated entity's problem, whichever party actually failed.
Supply chain attacks have grown more sophisticated for a specific reason. Rather than attacking a well-defended organisation directly, an attacker compromises a smaller supplier with legitimate, trusted access to the target. The compromise can sit undetected for months, because the access was never designed to be scrutinised. When it surfaces, the damage is frequently worse than a direct attack, precisely because the attacker was operating inside a relationship built on trust rather than suspicion.
Why the existing controls usually fall short
Most regulated organisations already have some form of supplier oversight. The problem is what it was built for. Oversight has typically been designed around the large, named, obviously critical arrangements: the core banking platform, the payments processor, the data centre provider. It was not built for the long tail.
The long tail is where unmanaged risk often sits. A large financial services organisation can easily have hundreds of suppliers with some form of access to its systems or data. Many of those relationships were set up by individual business units without central visibility. Many have not been reviewed since onboarding. Some were never formally assessed, because they arrived as a convenient cloud tool rather than a procurement decision.
Even where due diligence happened properly at the outset, it was usually a single point-in-time exercise: a questionnaire completed, filed, and left alone. A supplier's security posture does not stay fixed. Key personnel leave. Its own suppliers introduce new exposure. A certification that was valid at onboarding lapses quietly, and nobody notices until it matters.
Regulators have responded to exactly this weakness. The frameworks covered in the next chapter do not stop at due diligence on day one. They require ongoing monitoring, documented oversight, tested exit plans, and named board-level accountability for the risk. For most organisations, that is a genuine step change from what was in place before these standards existed.
Chapter Two: The Regulatory Framework
Third-party risk obligations now sit inside a defined regulatory framework in each of the jurisdictions this guide covers. The frameworks share a common logic: identify what matters, assess it proportionately, contract for it properly, monitor it continuously, and be ready to exit it. They differ in structure, and knowing which obligations actually apply to your organisation is the starting point.
The regulatory summary below is deliberately selective. It focuses on obligations that affect third-party and supply chain risk management. It is not a full statement of each regime, and current regulator materials should be checked before relying on implementation dates, templates or supervisory reporting mechanics.
DORA: the EU financial sector
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied in full to in-scope EU financial entities since 17 January 2025. It reaches banks, insurers, investment firms, payment institutions and electronic money institutions directly, and it reaches non-EU ICT providers indirectly, because any contract with an in-scope entity must meet DORA's requirements regardless of where the provider is based.
The third-party provisions sit primarily in Chapter V, including Articles 28 to 44. For financial entities, the practical work starts with the Article 28 register of information, the assessment and management of ICT concentration risk, and the Article 30 contractual requirements. Arrangements supporting critical or important functions attract a materially more prescriptive set of contractual and oversight requirements than other ICT arrangements, so a defensible classification of the supplier portfolio is a prerequisite, not an afterthought.
Before entering any new ICT arrangement, financial entities must conduct due diligence proportionate to the risk, and that due diligence must explicitly assess concentration risk: whether the organisation is becoming overly dependent on a single provider, or a small number of interconnected ones, and whether a viable alternative exists. The analysis has to be documented, not simply asserted.
For arrangements supporting critical or important functions, DORA's contractual requirements are prescriptive: a clear description of the services, data location and portability, incident notification obligations, audit rights, subcontracting provisions, and an exit strategy. The requirement for a genuinely documented exit plan is one of DORA's most consequential practical changes. Many organisations that had never seriously worked through what happens if a critical supplier fails or is acquired now have to.
Critical ICT third-party providers designated under DORA are subject to direct EU-level oversight, but that designation does not transfer any obligation away from the financial entities that use them. If a designated provider sits in your supplier register, your own due diligence, contractual protections and exit planning still apply in full. The relevant supervisory information should be checked against the current ESA materials rather than treated as a fixed list.
APRA CPS 230: Australia
Prudential Standard CPS 230 Operational Risk Management has applied from 1 July 2025, with remaining transitional and amended requirements taking effect according to APRA’s implementation timetable. It replaced the earlier outsourcing and business continuity standards with a materially broader regime. It applies to APRA-regulated entities, including authorised deposit-taking institutions, general and life insurers, and superannuation trustees.
Where the previous standards focused on formally designated outsourcing arrangements, CPS 230 covers all material service providers, defined deliberately broadly as any provider the entity relies on for a critical operation, or which poses a material operational risk. That scope catches providers many organisations would not previously have thought of as an outsourcing arrangement at all.
CPS 230 requires regulated entities to identify their critical operations, identify their material service providers, and maintain a service provider management policy covering due diligence, contracting, ongoing monitoring and exit arrangements. Fourth-party risk is addressed explicitly: entities must have an approach to managing the risk arising from their suppliers' own supply chains, and material fourth parties must be identified and included in the material service provider register. If a fourth party fails and the entity's direct supplier cannot deliver as a result, the regulated entity remains responsible.
For contracts already in place when CPS 230 commenced, APRA allowed transitional timing: the requirements apply from the earlier of the contract’s next renewal date or 1 July 2026. Organisations should treat any legacy material service provider arrangement that has not been uplifted by the relevant date as a remediation priority, rather than as work still comfortably ahead of deadline.
APRA has also made targeted amendments for certain non-traditional service provider arrangements, such as arrangements with central banks, payment schemes, and clearing and settlement facilities, where standard contractual terms may not be realistically negotiable. The relief is narrow: it applies only to specified contractual requirements and only where the arrangement falls within APRA’s stated categories and conditions. The remaining CPS 230 obligations, including risk management, register and business continuity requirements, continue to apply.
New Zealand: BS11, the FMA Standard Condition, and what comes next
New Zealand's framework for third-party and operational risk in financial services currently rests on two instruments. The Reserve Bank's BS11 Outsourcing Policy applies to registered banks and requires them to retain the legal and practical ability to control and execute their critical functions if an outsourcing arrangement fails.
It also requires banks to ensure the RBNZ can supervise, and if necessary resolve, the bank without that ability being compromised by an outsourcing relationship. The four major banks, all subsidiaries of Australian parents, achieved full compliance with the current version of BS11 in December 2023, after a multi-year implementation programme that ran into the hundreds of millions of dollars across the sector.
The Financial Markets Authority's Standard Condition on Business Continuity and Technology Systems has applied to certain FMA-licensed financial services providers since 1 July 2024. It requires licensed entities to maintain adequate current and future IT capability to support critical operations, to hold documented and tested business continuity plans, and to notify the FMA within 72 hours of a material operational disruption.
New Zealand does not yet have a single, cross-sector operational resilience standard equivalent to DORA or CPS 230. That is changing. As part of the phased implementation of the Deposit Takers Act 2023, the Reserve Bank is developing dedicated standards on operational resilience and outsourcing for deposit takers. Current Reserve Bank materials indicate that most DTA standards are expected to be issued before they take effect under the wider DTA regime, which is planned to commence on 1 December 2028. Readers should check the Reserve Bank’s current roadmap and consultation materials before relying on the implementation timetable.
In the meantime, because the major NZ banks are also APRA-regulated through their Australian parents, CPS 230's requirements already flow through to the New Zealand operations of those groups in practice, even though CPS 230 itself has no direct jurisdiction here. For non-bank deposit takers and other FMA-licensed entities without an Australian parent, the FMA Standard Condition remains the operative NZ obligation until the DTA Outsourcing Standard takes effect. The direction of travel, across all three jurisdictions, is the same: broader scope, more prescriptive contractual expectations, and clearer board accountability.
Key obligations at a glance
| Area | DORA (EU financial sector) | APRA CPS 230 (Australia) | NZ (BS11 / FMA / DTA Outsourcing Standard) |
|---|---|---|---|
| Scope | All ICT arrangements for in-scope EU financial entities; reaches non-EU ICT providers through contract terms | All material service providers to APRA-regulated entities, broader than the former outsourcing standards | Banks: BS11. Certain FMA-licensed entities: Standard Condition. Deposit takers: future DTA Outsourcing Standard from 1 December 2028 |
| Supplier register | Register of all ICT contractual arrangements, produced to the competent authority on request, categorised by criticality | Register of all material service providers, submitted to APRA, including material fourth parties | BS11 requires documented outsourcing agreements; Standard Condition requires a documented BCP covering IT dependencies |
| Due diligence | Required before any new ICT arrangement, proportionate to criticality, must assess concentration risk | Required before engaging any material service provider, proportionate to materiality | Required under BS11 for outsourcing arrangements; Standard Condition requires adequate IT risk management |
| Contractual requirements | Prescriptive for critical or important functions: services, data location, notification, audit, exit, subcontracting | Required for all MSP arrangements, with a narrow 2026 exemption for non-traditional providers | BS11 requires contracts to preserve the bank's control and the RBNZ's supervisory access |
| Fourth parties | Subcontracting of critical functions requires notification and approval; concentration risk from subcontracting must be assessed | Material fourth parties must be identified and included in the MSP register | BS11 addresses subcontracting of critical functions; it must not impair RBNZ oversight |
| Exit strategy | Mandatory documented exit plans for critical or important functions, with data portability and transition assistance | Exit strategy required for all MSPs; entity must show it can source an alternative or bring the function in-house | BS11 requires the ability to unwind outsourcing without losing control of critical functions |
| Concentration risk | Explicit obligation to assess and document, considering viable alternatives | Must be considered in service provider management; undue reliance to be avoided | Particularly relevant for NZ banks relying on Australian parent group services |
Chapter Three: Building the Programme
Third-party risk management is not a compliance exercise you complete once. It is an operating discipline that has to be built into how the organisation procures, contracts with, monitors and eventually exits its suppliers. The organisations that do this well have made it part of standard operating procedure, not a parallel workstream that runs alongside the business rather than through it.
Inventory and classification
You cannot manage what you cannot see. The starting point is a complete, accurate inventory of every supplier with access to the organisation's systems or data, or on which the organisation depends for a critical operation. Most organisations discover real gaps the first time they do this properly. Business units have set up relationships with no central visibility. Legacy arrangements have gone unreviewed for years. Teams have adopted cloud services without procurement or security involvement at all. The supplier base that emerges from a genuine inventory exercise is almost always larger than the one on record.
Once the inventory exists, suppliers need to be classified by risk, based on two factors: how critical the supplier's function is to the organisation, and how sensitive the data it accesses or holds actually is. A supplier providing a minor administrative function with no data access is a fundamentally different risk from one processing customer payments or hosting customer records, and the two should not receive the same level of scrutiny.
That classification drives everything downstream: how deep the due diligence goes, what the contract has to contain, how often the relationship is reviewed, and how visible it needs to be to senior management and the board. Most programmes use a tiered structure, with tier one covering the highest-risk, most critical suppliers and resources concentrated accordingly.
The classification exercise itself needs input from across the organisation, not just from risk or procurement. The people who know which suppliers matter operationally are usually the business owners. Building the tiering around that knowledge produces a more useful result than one built purely on abstract criteria.
Due diligence before onboarding
Due diligence has to happen before the relationship begins, not after. A supplier that cannot demonstrate adequate security and operational standards should not be given access to the organisation's systems or data. The principle is simple. The discipline required to hold to it under procurement time pressure is not.
The depth of assessment should track the risk tier. A tier one supplier with access to large volumes of sensitive data supporting a critical function warrants a thorough review: security certifications, a detailed control-area questionnaire, potentially an on-site or independent audit, and some visibility into the supplier's own supply chain. A lower-tier supplier can reasonably receive a lighter-touch assessment.
The core areas any significant assessment should cover are: information security controls and certifications; data protection policies and practice; incident response and breach notification procedures; business continuity and resilience arrangements; financial stability; the supplier’s own subcontracting arrangements; and regulatory compliance relevant to the services provided.
Certification is useful evidence, not proof. An ISO 27001 or SOC 2 certificate shows the supplier has a documented, audited management system. It does not confirm that the specific controls relevant to your relationship are adequate, or that the certification scope covers the services you will actually use. The assessment needs to test the specifics.
Financial stability is the area most consistently underweighted. A supplier under financial pressure may cut corners on security investment, defer necessary maintenance, and ultimately fail altogether. For any supplier supporting a critical function, an assessment of financial health, including credit ratings and available public financial information, belongs in the due diligence process alongside the security review.
Contractual protections
The contract is the primary mechanism for enforcing what the organisation actually needs from a supplier relationship. It does not guarantee a good outcome, but an inadequate one makes it very difficult to hold a supplier to account when something goes wrong. The specific content required depends on the applicable regulatory framework and the nature of the relationship, but good practice across any significant third-party relationship should include:
- –
Scope of services and performance standards, defined clearly enough to hold the supplier to account for a shortfall.
- –
Data protection and security obligations, matching the organisation's own standard, with a Data Processing Agreement wherever the supplier processes personal data as a processor.
- –
Incident notification, on a timeframe that gives the organisation genuine headroom against its own regulatory notification clock, not one that matches it.
- –
Audit rights, whether exercised through questionnaires, third-party audit reports, or direct assessment, with evidence that the right is actually used, not just held on paper.
- –
Subcontracting and fourth-party management, including notification, and where appropriate prior approval, before a subcontractor with data access is engaged.
- –
Business continuity and resilience commitments, with recovery time and recovery point objectives that align to the organisation's own tolerance, not the supplier's default.
- –
Data return and deletion obligations at termination, consistent with the applicable data protection framework.
- –
Exit provisions, covering transition assistance, knowledge transfer, and realistic timeframes for moving away from the supplier.
Exit provisions are the most consistently neglected of these, and among the most important. Negotiating them into an existing relationship is far harder once the organisation is already dependent and switching costs have risen. The greatest leverage sits at renewal, or when the supplier is seeking an extension. Organisations that leave exit terms for later, when the relationship is well established, will find themselves negotiating from a much weaker position.
Concentration risk
Concentration risk arises when an organisation becomes overly dependent on a single supplier, or a small number of interconnected ones, for something critical to its operations. If that supplier fails, is acquired, is compromised, or simply exits the market, there is no viable alternative available in the time the organisation actually has.
This risk is particularly acute in technology supply chains. Many regulated organisations rely on a small number of major cloud providers, a single core platform, or a shared managed security provider used across large parts of the sector. A failure at any of those does not affect one organisation. It can affect many organisations at the same time, when alternative capacity is hardest to find. Regulatory focus on critical ICT providers makes that concentration visible at a sector level.
Managing this in practice requires an honest assessment of substitutability. For some categories of supplier, genuine alternatives exist and switching, while costly, is realistic. For others, the supplier holds something genuinely difficult to replicate: proprietary technology, unique market access, or scale no comparable provider can currently match. The organisation needs to know, supplier by supplier, which situation it is actually in, and build its risk posture, and its exit planning, around the honest answer rather than the comfortable one.
Chapter Four: Ongoing Management
Due diligence at onboarding and a well-constructed contract are the foundation. They are not sufficient on their own. A third-party risk programme needs ongoing discipline: regular review, monitoring proportionate to risk, and a structured way of handling change and incidents when they occur.
Regular review and reassessment
Review frequency should track the supplier's risk tier. Tier one suppliers supporting critical functions should be reviewed at least annually; lower tiers can be reviewed less often, but every relationship needs a defined review interval, not just an onboarding assessment that is never revisited.
A proper review covers whether the supplier's performance against agreed service levels has held up, whether any security incidents have occurred since the last review, whether certifications remain current, and whether there has been a material change to ownership, financial position or key personnel.
It should also test whether the services or data involved have changed, and whether the contractual provisions still meet the current regulatory standard. The review needs a documented outcome and a date for the next one. A review with no documented output is not a review. It is a meeting.
Periodic review is not the same as continuous monitoring, and for tier one suppliers and those supporting critical functions, some form of continuous or near-continuous monitoring is appropriate: automated security rating tools tracking the supplier's external posture, monitoring of public disclosures, and contractual notification obligations for significant change.
Managing changes in the relationship
Supplier relationships are not static. The supplier may be acquired. Key personnel leave. A new subcontractor is engaged with access to the organisation's data. The technology platform changes. Any of these can shift the risk profile and warrant reassessment.
A contract can require the supplier to notify the organisation of material change, but contracts do not enforce themselves. The ongoing management process needs a mechanism to catch these changes when they happen, whether through supplier notification, market monitoring, or the annual review, and to trigger reassessment when it matters.
Mergers and acquisitions involving suppliers deserve particular attention. An acquiring entity may bring a different security posture, a different regulatory footprint, and a new set of subcontractors into a relationship the organisation thought it understood. A change-of-control clause, giving the organisation the right to renegotiate or exit on acquisition, is a meaningful protection worth insisting on.
Incident response involving third parties
When a supplier suffers a security incident or operational failure, the regulated entity has to respond as well as the supplier. That response needs to be defined in advance, not improvised while the incident is live.
Notification is the first requirement, and the contract needs to give the organisation enough time to assess its own obligations before its regulatory clock runs out. Where personal data is involved, the UK GDPR’s 72-hour notification window to the supervisory authority runs from when the controller becomes aware of a personal data breach, not from when the supplier completes its own investigation. A slow or vague supplier notification clause erodes time the organisation cannot get back.
Where the event meets the definition of a major ICT-related incident under DORA, the financial entity’s own DORA reporting duties apply. Under APRA CPS 230, regulated entities must notify APRA as soon as possible, and no later than 24 hours after becoming aware of a disruption to a critical operation, or no later than 72 hours after becoming aware of a material operational risk incident more broadly.
The response also has to address operational continuity: if the supplier is unavailable, what happens to the function it supports? That answer belongs in the business continuity provisions of the contract and the organisation’s own resilience planning, worked through in advance. Discovering it for the first time during a live incident is one of the most avoidable failures in this area.
Post-incident review has value even where the incident caused no significant disruption. Understanding how the supplier actually handled it, what caused it, and what remediation followed feeds directly back into the organisation's ongoing risk assessment, and often into a change in contractual requirements or oversight intensity for that supplier going forward.
Exit management
Exit is consistently the most neglected part of third-party risk management, and consistently the hardest to manage well when it becomes necessary. The time to plan for it is before it is needed, not once it is.
Exit can be organisation-driven, where the supplier underperforms or the relationship no longer fits the strategy, or it can be forced by events outside the organisation's control: financial failure, an unwelcome acquisition, a compromise that makes the relationship untenable, or a straightforward market exit. For any tier one supplier, any of these scenarios could cause significant disruption without a plan already in place.
A working exit plan addresses what alternative sources of the service exist, whether the organisation has the internal capability to perform the function itself if needed, the realistic transition timeline, what data has to be returned and in what format, and what transition assistance the supplier is contractually obliged to provide. The plan should be tested, at minimum through a tabletop exercise, so gaps surface on paper rather than during an actual transition under pressure.
DORA requires documented exit plans for critical and important functions. CPS 230 requires regulated entities to demonstrate they can actually exit a material service provider arrangement, not simply assert that they could. Both regulators will ask about this during supervision, and ‘we have not needed to think about it yet’ is not an acceptable answer for a critical relationship.
Chapter Five: Governance and Accountability
Third-party risk is a governance issue, not purely an operational one. The board and executive team need to understand the organisation's material dependencies, the risks those dependencies carry, and whether the oversight programme managing them is actually working.
Board and executive oversight
The board does not need visibility into every supplier relationship. It does need to understand the concentration of critical dependencies, the material risks arising from them, and the health of the oversight programme itself.
Board reporting should cover the size and composition of the supplier portfolio, the tier one suppliers and the critical functions they support, any significant incidents in the period, the outcomes of due diligence and periodic review, identified concentration risks, and any regulatory observations relating to supplier management.
DORA is explicit on this point: financial entities must establish governance arrangements with named senior management responsibility for ICT third-party risk, and the board must approve the third-party risk policy and be kept informed of significant developments. This is not a second-line matter that can run without board visibility.
In Australia, the Financial Accountability Regime creates personal accountability for executives responsible for operational risk and service provider management. Combined with CPS 230’s requirements, that means third-party risk can no longer be treated as a purely operational detail sitting below the level that carries personal consequence.
The three lines and supplier risk
Third-party risk management works best when the three lines of defence model is applied with discipline rather than nominally. The first line is the business unit that owns the relationship day to day: accountable for escalating performance issues and ensuring the supplier continues to meet its obligations, and closest to the relationship even though central functions set the wider framework.
The second line is risk, compliance and procurement: setting policy, maintaining the supplier register, conducting or overseeing due diligence, reviewing contractual provisions, and reporting to senior management and the board on the overall state of supplier risk. The third line is internal audit, providing independent assurance that the controls exist and actually operate as intended, covering the completeness of the register, the quality of due diligence, contractual compliance, the adequacy of monitoring, and exit planning.
The most common failure pattern in this area is a well-designed second-line policy that the first line does not consistently follow under time pressure: a new supplier is engaged before the security assessment is complete, the assessment eventually happens and finds issues, but by then the supplier is already embedded and hard to unwind. Embedding the requirement into procurement governance itself, so that contract execution or payment approval is gated on a completed assessment, is far more effective than relying on policy awareness alone.
Metrics and reporting
A programme that cannot be measured cannot be managed. Useful metrics include the total number of suppliers in the register and their tier distribution, the proportion of tier one and tier two suppliers with current due diligence on file, the number of suppliers whose contractual provisions fall short of the current standard and the plan to close that gap, the number and outcome of supplier incidents in the period, the number of reviews completed against those overdue, and the status of exit plans for critical suppliers.
The register itself is a living document, not a project deliverable. It needs to be maintained as relationships form, change and end. An out-of-date register is not simply an audit finding. It is a genuine gap in risk management, because the organisation cannot oversee a relationship it has lost track of having.
Chapter Six: Implementation Checklist
For organisations building or strengthening a third-party risk programme, the following sequence covers the core elements.
- –
Complete the supplier inventory. Identify every supplier with access to your systems or data, or on which you depend for a critical operation. Be thorough. It will be larger than expected.
- –
Classify and tier the supplier base. Categorise by criticality and data sensitivity. Concentrate oversight resources on the highest tiers, and document the classification criteria and outcomes.
- –
Run a gap analysis on existing due diligence. Identify which suppliers have adequate due diligence on file, which are out of date, and which have never been assessed. Prioritise remediation by tier.
- –
Review existing contracts. Assess whether current contracts cover security, notification, audit, exit and data protection adequately. Plan remediation at the next renewal, or sooner where the risk warrants it.
- –
Establish the due diligence process. Define what is required per tier, who conducts it, and the approval gate before a new supplier can be engaged. Embed it in procurement governance so it happens before onboarding, not after.
- –
Assess concentration risk. Identify material dependence on single providers, and whether a viable alternative exists. Document the assessment and escalate material findings to the board.
- –
Build and document exit plans. For tier one suppliers and other critical functions, set out what exit involves, how long it would take, and what the alternatives are. Test the plan.
- –
Establish the ongoing monitoring process. Define review frequency per tier, ownership, scope, and how outcomes are documented. Apply automated monitoring for higher-risk suppliers where it adds value.
- –
Define the incident response process for supplier-originated incidents. Ensure it covers regulatory notification triggers and operational continuity, not just the technical response.
- –
Report to the board. Establish a regular cadence covering the supplier portfolio, material risks, incident outcomes, and the state of the programme itself.
Conclusion
Third-party and supply chain risk has moved from a niche compliance concern to a material operational and security risk for regulated organisations. Regulators across the UK, the EU, Australia and New Zealand have raised their expectations to match.
The thread running through DORA, CPS 230 and the developing New Zealand framework is the same: accountability cannot be outsourced. The regulated entity remains responsible for what happens when a supplier fails, is compromised, or cannot deliver, and that accountability is not discharged by a questionnaire completed once at onboarding.
It requires an ongoing discipline: a complete and accurate register, due diligence proportionate to risk, contracts that reflect current regulatory expectations, monitoring that matches criticality, tested exit plans, and genuine board visibility of the material risks.
Most organisations sit somewhere in the middle of that journey: further ahead than the old standard required, not yet where the new one expects them to be.
The practical path is to start with the highest-risk relationships, build the process systematically from there, and keep the momentum going rather than treating this as a project with an end date.
The organisations that manage it well are the ones where third-party risk has become part of how the business thinks about procurement and supplier relationships, not a compliance function running in parallel to them.
The regulatory environment will keep tightening, and supply chain attacks will keep growing in sophistication. Managing this risk properly is not an optional extra sitting alongside the core business. It is a core part of running a regulated organisation responsibly.
Key takeaways
- ✓Third-party involvement in breaches doubled year on year according to Verizon's 2025 DBIR. Supplier risk is now a primary attack vector, not a secondary one.
- ✓Accountability cannot be outsourced. DORA, APRA CPS 230 and New Zealand's developing framework all converge on the same principle: the regulated entity remains responsible for what happens when a supplier fails.
- ✓APRA CPS 230's transition deadline for pre-existing material service provider contracts, the earlier of the next renewal date or 1 July 2026, has now passed. Any legacy contract not yet uplifted is a remediation priority.
- ✓A supplier register and risk tiering are the foundation. You cannot manage, monitor or exit a relationship you have not properly identified and classified.
- ✓Exit planning is the most consistently neglected control and the hardest to build under pressure. The time to document and test an exit plan is before it is needed, not during a live disruption.
- ✓Third-party risk is a governance matter. Board visibility, named executive accountability, and honest metrics separate a genuine programme from a compliance formality.
More from Information Security and Data Privacy
Information Security in Practice Data Privacy in PracticeRussel.Fielding
Practitioner knowledge on transformation, financial crime and AML, written from inside the machine. Free, current, no registration.
© 2026 Russel Fielding. All rights reserved.