top of page

Search Results

510 results found with an empty search

Blog Posts (112)

  • Beyond Third Parties: Eight Actions to Tackle Fourth‑ and Nth‑Party Risk

    If you spend enough time in third party risk, you’ll notice something unfair. Your third parties have their own third parties, and when those downstream providers fail, your organization still feels the impact, even though you never signed a contract with them. This leads to a common question: “How are we supposed to manage those third parties?” The short answer is that you don’t manage them directly. Instead, you focus on reducing the risks that come with these extended relationships. Fourth- and nth-party risk means knowing where these downstream dependencies are, how their failures could disrupt your services or affect your customers, and making sure your TPRM program identifies, analyzes, and reduces those risks where it matters most. Who is a 4th or nth party? In third party risk management (TPRM), “third party” usually means any external organization or supplier under contract to deliver a product, service, or process. That is the part everyone is used to tracking. A “fourth party” is any provider your third party relies on. These can be cloud platforms, sub‑processors, subcontractors, and upstream suppliers that sit behind the scenes but can still disturb your operations, affect your customers, or negatively impact your compliance posture when something goes wrong. “Nth‑party risk” is the more general term for the additional layers beyond that, including the third parties supporting those fourth parties and further out in the chain. Taken together, this extended chain of third, fourth, and nth parties is part of what many practitioners now refer to as extended enterprise risk, the risks that arise across the wider network of external relationships that support your organization’s products and services. Why fourth- and nth-party risks are getting attention Fourth- and nth-party relationships are getting more attention because shared dependencies are now easier to see. For example, one cloud platform, KYC provider, or infrastructure service can affect several third parties at once, turning a single incident into a disruption across multiple services. Regulators and boards are also asking more specific questions about sub‑processors, concentration risk, and resilience. Once you accept that fourth and nth‑party relationships can materially affect your organization, the next question is what to do about it in practice. You cannot manage every downstream provider directly, but you can absolutely design a TPRM program that properly addresses fourth‑ and nth‑party risk. Here are eight practical actions you can take to help your organization more effectively identify, analyze, and mitigate those extended‑ecosystem risks. 1: Determine How Far You Will Go If you try to map your whole supply chain, you’ll end up with too much information and little value. It’s usually better to set clear criteria for what’s in scope, like access to customer data, critical services, or when the same downstream provider is used by several third parties. Start by deciding how deep you are willing to go. A reasonable standard for many programs is your direct third parties, plus their critical sub‑processors and major shared platforms that would materially affect your business if disrupted. Make sure your final decision is reviewed and documented. If someone asks why a certain downstream provider is included or not, you should be able to explain it easily. 2: Know How to Identify Your 4th And Nth Parties After you decide how deep to look, the next step is finding those downstream entities. Some third parties will give you a clear list of sub-processors, but many will not. A practical way to do this is to gather information from several sources: SOC 2 Type II reports, especially the system description and subservice organization sections. External risk intelligence tools that map hosting providers, DNS, IP ranges, and technology stacks. Public trust centers and compliance pages that list sub‑processors or infrastructure partners. Regulatory or industry disclosures that reference key providers. Internal insight from Architecture, Security, and Operations teams that already know which shared platforms sit underneath important services. You are not trying to build an exhaustive inventory. You are trying to identify the downstream relationships that can materially impact your operations, customers, compliance, or reputation. 3: Think In Terms of Fourth‑Party Failure and Concentration When you look past your direct third parties, it helps to break fourth-party risk into two simple questions. Fourth‑party failure risk Start with a single third party and ask, “What if one of their critical fourth parties fails?” For that third party: Which fourth‑party providers are critical to the service they deliver to you? What parts of your operations stop working if one of those fourth parties has an outage or incident? How quickly would the third party detect and communicate that issue to you, and who owns the response on your side? What options exist if that fourth party is unavailable for an extended period (alternate providers, workarounds, manual processes)? This approach keeps the focus on a specific relationship: your third party, their key fourth party, and how it affects your organization. Fourth‑party concentration risk Then step back and ask, “How many of our third parties rely on the same fourth parties?” Across your third party portfolio: Which fourth‑party providers appear repeatedly in different third party relationships? How many critical services in your inventory ultimately depend on the same fourth‑party cloud, KYC, payments, or messaging provider? Are there specific fourth‑party entities that, if impaired, would create issues across multiple third parties at once? Here, you’re mapping shared fourth-party dependencies across your third parties . The result should be a short list of fourth-party providers and the services or third parties they support, so leadership can see where the biggest exposures are. By looking at fourth-party failure risk for each third party and concentration risk across your whole portfolio, you get a clearer view of where extended-ecosystem risk is acceptable and where you need to focus more attention. 4: Understand How Your Third Parties Manage Their Third Parties Since you can’t manage all your third parties’ third parties, one of your best controls is making sure your third parties have strong TPRM practices themselves. This means asking if your third parties identify and rank their own third parties, separate critical providers from less important ones, do proper due diligence, and monitor those relationships over time. Third parties with mature TPRM programs are more likely to spot their own dependencies, catch issues early, and alert you to important problems. If your third party does a weak job managing its own supply chain, you inherit that weakness. If they are disciplined about risk tiers, due diligence, and ongoing monitoring, you gain a layer of protection and visibility you could not create on your own. 5: Build Visibility into the TPRM Lifecycle It’s easier to manage downstream risk when you include it in your existing processes, instead of tracking it separately in a spreadsheet. This can be as simple as asking the right questions or gathering key information at each stage of the lifecycle: Risk Assessment: Identify your critical products and services and focus on their sub processors. Due Diligence: Ask third parties about material sub‑processors and critical upstream services during due diligence. Record those entities in your third party/supplier record so they can be tracked over time. Contracting: Ensure clauses cover disclosure of critical sub-processors and notifications when they change. Monitoring: Update the record when sub‑processors change, new dependencies appear, or incidents affect key downstream providers. Exit: Capture what you learned about the third party’s downstream footprint and use it in future assessments. By including fourth- and nth-party oversight in your regular processes, you create consistent risk checkpoints and collect data that helps you make better decisions. 6: Contract For Downstream Control You might not have contracts with fourth- or nth-party entities, but you do have contracts with your third parties who rely on them. That’s where you have leverage. Useful terms include the requirement to disclose material sub‑processors, notice before changes, flow‑down obligations for security and resilience, incident notification when a sub‑processor issue affects your service, and independent assurance where appropriate. You obviously can’t dictate how someone else’s third party or supplier program operates. You can hold your third parties accountable for managing their own downstream relationships in line with your risk expectations. 7: Use Risk Alerts and Threat Intelligence for Key Downstream Providers You don’t need a contract with a downstream provider to keep an eye on public risk information about them. Risk alert services, external monitoring platforms, and threat intelligence feeds use public and open-source data, making them helpful for key nth-party relationships. For higher-impact downstream entities, you can monitor domains, infrastructure, leaked credentials, breach chatter, major vulnerabilities, and other warning signs. This monitoring won’t replace good third party management, but it gives you another way to spot issues with important shared providers. This is especially useful when a downstream provider supports several third parties in your environment. In these cases, a single alert can tell you more than multiple questionnaires. 8: Embed Downstream Risk into Governance Fourth- and nth-party risk management works best when it’s included in the same governance channels as your other key risks. This could mean including shared dependencies in outsourcing discussions, resilience reports, third party portfolio reviews, and contract playbooks. When it’s part of regular reporting and oversight, it becomes a normal part of your program instead of a special topic. Conclusion Fourth- and nth-party risk falls somewhere between your third parties’ responsibilities and your own. You can’t control every downstream provider, but you also can’t ignore how those relationships might affect your organization and your customers. The eight actions in this blog are designed to give you a practical starting point. If you pick a few and add them to your program, you’ll get better visibility into the downstream relationships that matter most and a more consistent way to manage their risks. You don’t have to solve everything at once. Focus on bringing the right extended relationships into view and handling them with processes you can explain, repeat, and improve over time. That’s what real progress on fourth- and nth-party risk looks like in a TPRM program. Author Bio Hilary Jewhurst Sr. Membership & Education Coordinator at TPRA Hilary Jewhurst is a seasoned expert in third party risk and risk operations, with nearly two decades of experience across financial services, fintech, and the nonprofit sector. She has built and scaled third party risk programs from the ground up, designed enterprise-wide training initiatives, and developed widely respected content that helps organizations navigate regulatory complexity with clarity and confidence. Known for turning insight into action, Hilary’s thought leadership and educational work have become go-to resources for professionals looking to mature their TPRM programs. She regularly publishes articles, frameworks, and practical guides that break down complicated risk topics into meaningful, accessible strategies. Hilary recently joined the Third Party Risk Association (TPRA) as a staff member, supporting industry-wide education, peer learning, and advancing best practices. She is also the founder of TPRM Success, a boutique consultancy that helps organizations strengthen their third party risk management capabilities through targeted training, tools, and strategic guidance.

  • 5 Tips on Continuous Monitoring

    Staying on top of third party risks doesn’t stop at onboarding. Ongoing monitoring is crucial for ensuring your third parties remain compliant and resilient over time. Review the infographic below for actionable tips to enhance your continuous monitoring strategy. Interested in learning more about Continuous Monitoring? Check out our Free TPRM 101 Guidebook: https://www.tprassociation.org/guidebook Download the infographic:

  • Keeping Pace with Regulatory Change in Third Party Risk Management (TPRM)

    A decade ago, most third party risk programs followed a simple routine: assess the third party's risk level, perform adequate due diligence, review the contract, and check in once a year. While this approach is still used, it no longer meets today’s broader expectations for resilience, cybersecurity, privacy, supply chain oversight, and artificial intelligence, putting your business at risk of non-compliance or disruption. In 2026, TPRM is governed by a much broader mix of frameworks and regulations, including the Digital Operational Resilience Act (DORA), the Network and Information Systems Directive 2 (NIS2), the General Data Protection Regulation (GDPR), the Corporate Sustainability Due Diligence Directive (CSDDD), and the UK critical third parties regime. These requirements may highlight different risk concerns, but they often affect the same parts of a TPRM program: third party classification, due diligence, contract terms, monitoring, issue management, and exit planning. More Frameworks Now Affect TPRM The biggest change is not a single regulation, but the increase in frameworks that now apply to third party oversight. DORA requires financial firms to manage third party IT risk through governance, testing, concentration risk management, and record keeping. NIS2 broadens cybersecurity and supply chain requirements, making third party risk a key part of incident response and operational governance. Privacy and supply chain rules add complexity. GDPR continues to guide how organizations manage third parties handling personal data. CSDDD and Germany’s Supply Chain Due Diligence Act (LkSG) also drive organizations to examine risks, including human rights and environmental risks, beyond direct suppliers. Key takeaways Managing third party risk now means meeting broader standards for resilience, cybersecurity, privacy, and supply chain oversight. One process change may need to address multiple frameworks at once. Operational Resilience Has Raised the Standard Operational resilience rules continue to emphasize the importance and urgency of third party oversight. DORA requires firms to identify critical providers, manage concentration risk, include oversight and exit terms in contracts, and maintain detailed records. NIS2 also strengthens supply chain security and incident readiness, treating third party failures as broader issues. The UK’s critical third party regime adopts a similar approach for financial services, allowing direct oversight of providers whose disruption could affect many firms or the wider market. The bottom line: if a third party supports a critical service, regulators expect more than just a one-time review. Key takeaways Critical third parties require heightened scrutiny as new regulations and resilience rules emphasize operational dependencies and disruption risk. Third party classification, contracts, continuity, and documentation must adapt to resilience standards. Overlapping Rules from Different Jurisdictions Create Practical Challenges One challenge for TPRM teams is that third party oversight often goes beyond a single country’s rules. For example, a U.S. organization may begin with local requirements but find extra obligations if it serves customers in the EU or UK, supports regulated firms there, or uses third parties that do. This means the same third party might need different review steps based on location, customer type, or service model. To manage this complexity, organizations should prioritize requirements that carry the highest regulatory or business risk and look for opportunities to harmonize controls where possible. Establishing a baseline set of global controls, then layering on local or high-priority requirements, can help ensure compliance without duplicating effort. When faced with conflicting rules, consult with legal, compliance, or risk experts to determine which requirements should take precedence. Multiple regulatory requirements often create challenges as organizations grow. A TPRM program built for one country might struggle when the company expands to new markets or supports clients in other jurisdictions. DORA can even apply to non-EU providers serving EU financial firms; NIS2 covers organizations offering services in the EU, and the UK’s rules affect non-UK providers serving UK financial companies. Key takeaways Expanding your business across borders often brings overlapping regulatory requirements. TPRM needs adaptable due diligence and oversight for global third parties. Less Frequent Reviews Are Hard to Justify Annual assessments are useful, but less convincing when third party risk changes during the year. DORA and NIS2 both emphasize ongoing oversight and incident readiness. Not every organization needs to implement automated monitoring or redesign risk re-assessment schedules; however, critical third parties, major subcontractor changes, concentration points, and significant incidents should be addressed between formal reviews. Key takeaways Point-in-time reviews leave gaps when third party risk changes quickly, making it harder for your organization to respond to emerging threats. Higher-risk third parties require ongoing monitoring year-round. AI Highlights Weaknesses in Older TPRM Processes Artificial intelligence (AI) is now providing clear indicators of where older TPRM tools fall short. Standard questionnaires developed a few years ago might cover security and privacy but probably miss basic questions about AI use, data inputs, model governance, and how important changes are explained. This means organizations are trying to assess new risks with outdated templates. Regulations make this even more challenging. AI-related requirements can come from specific AI rules, privacy laws, model risk standards, or industry supervision, depending on the country and use case. As a result, the same third party may need different levels of review based on its services and where it operates. Key takeaways AI risks increasingly surface in third party relationships that older processes may overlook. Cross-border third parties need flexible, AI-specific due diligence and contracts. A Few Things Organizations Can Do Now Most organizations do not need to completely rebuild their TPRM programs. By strengthening the parts facing new regulatory pressures, you can meet evolving requirements and keep your business protected. Current frameworks all point toward better visibility into third parties and dependencies, stronger documentation, clearer governance, and more up-to-date oversight, delivering the assurance your organization needs. Here are a few practical steps that can help: Update your list of critical third parties and confirm which regulations apply based on service, location, customer type, and data exposure. Prioritize requirements that carry the highest regulatory or business risk and look for opportunities to harmonize controls where possible. Review your questionnaires and contract templates to ensure they cover resilience, subcontractor visibility, AI use, incident response, and exit support as needed. Set up monitoring triggers for Critical and high-risk third parties, such as major incidents, subcontractor changes, declining performance, sanctions updates, or concentration points affecting critical services. Ensure that changes or updates to your processes are documented, including the rationale for those changes. TPRM programs are always evolving, and recent changes mean many organizations must now align with overlapping expectations from DORA, NIS2, GDPR, CSDDD, and local rules for how third parties are chosen, contracted, monitored, and, if needed, exited. This is harder in multi-jurisdiction environments and with AI-enabled services, where the same third party can fall under several rule sets at once. Organizations that keep a clear view of critical third parties and jurisdictions, keep their questionnaires and contracts up to date on resilience and AI, and add reliable monitoring triggers, should be able to keep up without rebuilding their program every year. Author Bio Hilary Jewhurst Sr. Membership & Education Coordinator at TPRA Hilary Jewhurst is a seasoned expert in third party risk and risk operations, with nearly two decades of experience across financial services, fintech, and the nonprofit sector. She has built and scaled third party risk programs from the ground up, designed enterprise-wide training initiatives, and developed widely respected content that helps organizations navigate regulatory complexity with clarity and confidence. Known for turning insight into action, Hilary’s thought leadership and educational work have become go-to resources for professionals looking to mature their TPRM programs. She regularly publishes articles, frameworks, and practical guides that break down complicated risk topics into meaningful, accessible strategies. Hilary recently joined the Third Party Risk Association (TPRA) as a staff member, supporting industry-wide education, peer learning, and advancing best practices. She is also the founder of TPRM Success, a boutique consultancy that helps organizations strengthen their third party risk management capabilities through targeted training, tools, and strategic guidance.

View All

Other Pages (393)

  • VENDOR-HOSTED EVENTS | TPRA

    Learn about and register for events outside of the TPRA that are applicable to TPRM. Vendor-Hosted Events The TPRA promotes the industry of third party risk, which includes events conducted by other third party risk-related groups and organizations. Check back here regularly to see our list of vendor-hosted events. If you would like to promote your next third party risk-specific event, please complete the form below . Disclaimer: TPRA does not endorse or sponsor the products/services of one particular organization; however, we do communicate training opportunities for the benefit of the community. Filter by Organization Select Organization Filter by Event Type Select Event Type Filter Download Global Resilience Federation (GRF) In-Person Conference 9th Annual Summit on Security & Third-Party Risk Wednesday, October 21, 2026 Orlando, FL Networking and Education on Critical Third-Party and Cybersecurity Issues, for Mutual Resilience The conference features dozens of speakers on third-party risk management, cloud security, emerging cybersecurity threats, and AI/machine learning threat mitigation and management. Attendees will gain an understanding of how some of the largest and most sophisticated organizations in the world are managing risk, and leave the conference better armed to defend their company, regardless of its size or the status of its risk mitigation program. Register Tenchi Security In-Person Conference Tenchi Conference 2026 Wednesday, November 4, 2026 Tangara Palace Hotel, São Paulo, Brazil The fourth edition of the Tenchi Conference is set to be even bigger and more impactful, featuring renowned speakers and new panels led by seasoned executives in Third-Party Cyber Risk Management (TPCRM). Under the theme “TPCRM: The New Era of Inside-Out,” this year’s edition will explore a new perspective on third-party risk - shifting from reactive approaches to a more integrated, continuous, and inside-out strategy. Building on last year’s success, this global leading event dedicated to Third-Party Cyber Risk will once again bring together CISOs, Board Members, Cybersecurity Professionals, GRC Experts, and DPOs from leading organizations across global industries. Expect a full day of in-depth discussions and a dynamic agenda exploring TPCRM best practices, risk mitigation strategies, and enhanced security across multiple industries. The agenda is currently being carefully curated and will be revealed soon. Watch the highlights from last year’s edition: https://www.tenchisecurity.com/en/company/events Invitation is personal and non-transferable – subject to confirmation. And to end the day on a high note, you’re invited to a special Happy Hour featuring a surprise performance - the perfect opportunity to expand your network and connect with industry leaders. Have insights or real-world experience in TPCRM? Apply to speak at the Tenchi Conference 2026 and share your perspective with a highly qualified audience – plus the opportunity to win a trip to RSA Conference 2027*. We are looking for 30-minute sessions featuring relevant cases or innovative approaches. *See more information and submit your proposal here: https://forms.gle/nen5uQpb1ZQpMMbR6 . Register Submit an External Event TPRA Practitioner Members can submit upcoming events they'd like displayed on this page using the form below. Some events may also be shared via our monthly events emails and/or quarterly newsletter. TPRA does not post on-demand/recorded events to this page. TPRA Vendor Members can submit their upcoming events through the Vendor Member Submissions form . Submitter Information First name* Last name* Email* Event Information Event Title* Event Host* Event Type* Event Description* Event Date* Event Time (please include time zone)* Link to learn more and/or register for the event* Anything else we should know? Submit

  • Women Lead | WNTPRM

    This page is dedicated to showcasing the inspiring Women Leaders and their stories. Our goal for this program is to highlight and learn from women leaders in the field of Third Party Risk Management (TPRM) throughout various industries. Back Women Lead Program Welcome to the Women In TPRM (WNTPRM) "Women Lead" Program! This page is dedicated to showcasing inspiring Women Leaders by highlighting their stories. Our goal for this program is to learn from and be inspired by women leaders in the field of Third Party Risk Management (TPRM) throughout various industries. If you know of an inspiring Leader you think should be featured by WNTPRM, complete the form linked below! Apply Now Leader Spotlights Ritu Jethani Director, TPRM & ERM KPMG WNTPRM July 2026 Leader Spotlight July 1, 2026 Read More Sophia Corsetti Senior Product Marketing Manager ProcessUnity WNTPRM May 2026 Leader Spotlight May 1, 2026 Read More Maria Alhasoon VP Vendor Management Byline Bank WNTPRM February 2026 Leader Spotlight February 1, 2026 Read More Seema Gupta Business Information Security Officer HII- Mission Technologies WNTPRM June 2026 Leader Spotlight June 1, 2026 Read More Dr Angela Dogan Associate Director, Cybersecurity Assurance Kyndryl WNTPRM April 2026 Leader Spotlight April 1, 2026 Read More April Harrison Sr. Director of Marketing & Communications Trust Your Supplier WNTPRM January 2026 Leader Spotlight January 1, 2026 Read More Paige Johnson SVP, Director of Third-Party Risk Management Stellar Bank WNTPRM May 2026 Leader Spotlight May 13, 2026 Read More Verity Billson Group Head of Third Party Risk Management Experian WNTPRM March 2026 Leader Spotlight March 1, 2026 Read More Corina Reymer AVP, Information Security The Walt Disney Company / Partners Federal Credit Union WNTPRM December 2025 Leader Spotlight December 1, 2025 Read More LOAD MORE

  • TPRM JOBS | TPRA

    Explore jobs in third party risk management from organizations hiring TPRM professionals. New listings added regularly. Start your search today. TPRM Job Listings Searching for a TPRM-specific job? Check out the listings below from organizations looking for talented TPRM professionals! Note: TPRA reserves the right to remove any job listing for any reason and without communication to the contact. Post a Job Hagerty Senior Manager, TPRM View Job USA (Remote) Old National Bank Third Party Risk Lead View Job Several Locations Edward Jones Senior Third Party Risk Analyst View Job Tempe, AZ (Hybrid) KPMG US Lead Specialist, TPRM View Job San Diego, CA (Hybrid) Asurion Sr. Manager, TPRM View Job Nashville, TN (onsite) Vanta Senior Manager, Strategic Customer Success View Job USA (remote) Ichor Systems, Inc Senior Supply Chain Compliance Program Manager View Job Portland, OR (onsite) Certa.ai Solutions Architect View Job San Francisco, CA (remote) Early Warning Senior Manager, TPRM View Job Scottsdale, AZ PartsSource Inc Vendor Relations, Manager View Job Charlotte Metro Replit TPRM & Customer Trust Lead View Job Foster City, CA (Hybrid) Nscale Sr. Manager, Vendor Contract & Operations Management View Job Bellevue, WA (Remote) LOAD MORE

View All
bottom of page