Written by a human
Weak links in the chain: A compliance guide to third-party risk
Learn how to spot third-party risk red flags early, from unestablished vendors to multi-vendor security gaps, and stay ahead of FCA, DORA, and SEC rules.
So, you’ve nailed the market research and secured the budget. Now comes the real test: evaluating potential suppliers.
In a world where a single vendor vulnerability can compromise your entire network, third-party risk minimization becomes your first line of defense. Standard risk management practices rightly place a heavy emphasis on comprehensive due diligence, yet many frameworks fail to leverage a crucial shortcut: filtering out immediate non-starters. Identifying these systemic risks early prevents teams from wasting weeks on unviable prospects.
This early-stage elimination typically centers on two main areas:
- Unestablished vendors
- The operational friction of managing multiple vendors simultaneously
Amid rising regulatory pressures, identifying these critical third-party risks allows evaluators to cut through vendor sales pitches to directly assess vulnerabilities.
Compliance considerations for third party risk rules
Since 2023, we have seen a significant focus on third party risk management from UK, EU, and U.S. regulators. This culmination could be due to an increased reliance on third party IT and tech systems, with many Tier 1 and enterprise-level financial institutions preferring to save on transformation investment projects and choose to buy, rather than build.
Bearing this upwards trend of regulatory activity in mind, the table below includes only a small portion of the extensive updates and announcements in recent years:
| Jurisdiction | Rule or regulation | Latest updates |
| UK | Material third parties arrangement | March 2026: The FCA, PRA, and Bank of England finalised a unified framework: firms must report all material third-party arrangements (both tech and non-tech) via a single platform, FCA Connect, and maintain an active registry including fourth-party supply chain mapping. |
| UK | Critical third parties regime | November 2024: Designated certain unregulated third-party technology providers (like major cloud networks) as ‘critical’ to the UK financial system. regulated firms using these providers must review their reliance on them. The designated critical tech providers themselves must now comply with direct audits, incident testing, and disruption disclosures mandated by the FCA/PRA. |
| EU | Digital Operational Resilience Act | January 2025: Mandates strict ICT third-party risk management strategies, standardized contract clauses, mandatory multi-firm threat testing, and direct oversight of Critical ICT Third-Party Providers (CTPPs). |
| EU | Sound management of third party risk | July 2025: Companies must build a single, consolidated third-party registry merging tech (DORA) and non-tech suppliers. Existing non-ICT vendor contracts must undergo a rigorous remediation process to insert mandatory audit, performance, and exit strategy clauses within the two-year window. |
| U.S. | SEC cybersecurity disclosure | 2024-2026: Publicly traded companies cannot treat third-party breaches as insulated. Legal and cybersecurity teams must establish contractual clauses requiring vendors to immediately escalate breaches, allowing the parent company to assess materiality and meet the SEC’s strict four-day disclosure window. |
Mapping the risks
Despite major differences in the laws themselves, the common denominator is the requirement for firms to assess, map, and monitor risks. Compliance teams must anticipate the likelihood of these risks occurring, as well as the potential impacts on not only their own services, but their customers and the wider supply chain.
We can split these risks into two major categories:
- The risks of working with multiple vendors at the same time
- The risks of working with new, unestablished vendors
The risks of working with multiple vendors at the same time
Working with multiple vendors is as common as it gets among regulated institutions, it can be rare to find a single supplier that meets all your needs. But we’d argue that contracting multiple vendors to solve one core problem should not be so normalized.
Weak links and poor security
From a data governance perspective, working with multiple vendors exponentially increases the level of risk that a company is exposed to.
When you onboard a single vendor, it is connected to its own sub-vendors and so on, creating an indirect link or a chain. This compounds the area of attack – each connection creates multiple points of vulnerability for attackers, through integration streams, data transfer channels, and day-to-day communication methods.
Without dedicated and ongoing security measures, there is no guarantee that your data is insulated, even if the breach is happening two or three levels away from your firm.
In July 2021, this nightmare became a reality for over 1,500 companies whose vendors all used one common admin tool. When this tool, Kaseya, suffered a ransomware attack, dozens of managed service providers were affected. This impact rippled downstream to their clients, affecting 1,500 businesses and their potentially sensitive data.
Data leakage across vendors
Similarly, a single-vendor solution tends to keep data secure because there is typically only a single channel for the right information to travel between ecosystems. But an outsourcing set up with multiple vendors increases the number of data transmission points, again exponentially increasing the level of risk.
At each point of transfer, there is an opportunity for data to leak from the system – creating gaps that require increased oversight from procurement and supply chain teams.
Siloed data
Fragmented data is another key risk when more than one vendor is in play. Separate archives can slow retrieval time and waste precious storage, with analysts who deal with this issue often reporting duplicate entries among the different systems, too.
No matter how organised your team is, spreading the data across multiple vendors tends to create messy systems. If you require eDiscovery services, this makes the process of coordinating data retrieval for legal purposes extra hard. In fact, this very issue led to fines of over $2.5 million in a 2022 court case, with the judge putting it down to “technology competence and a slew of eDiscovery miscues”.
Accountability in the event of an error
With multiple vendors and unclear ownership, it can be difficult to work backwards from a risk event. Audit trails become harder to piece together, especially because different suppliers work on different systems, or when there is an overlap in responsibilities.
Many organizations enforce regular supplier reviews and map out risk journeys in a bid to maintain clear accountability trails. But without complete visibility into how, where and why data is transferred, these best practices can still fail.
The risks of working with unestablished vendors
Arguably worse than working with multiple vendors is the risk of choosing to contract new-to-market, unestablished vendors. In regulated industries particularly, these companies may lack the resources to deliver on their promises, or choose novel data management techniques that place your confidential information at risk.
And because evidence of claims can often be lacking for this type of company, validation and testing can significantly extend this phase of an RFP.
For example, unestablished vendors:
- Are entering the market for the first time and may not be able to fulfill contracts as efficiently (or at all) compared to suppliers that have stood the test of time
- Are likely relying on scant resources as they startup and scale, compared to enterprise level organizations
- May be relying on a founder exit strategy, which is likely to affect your level of service and compliance coverage as ownership transitions from one party to another
- May not be able to provide an adequate level of indemnity, signing away limitless indemnity if things go wrong, as they have nothing in the bank to lose
- Could be holding your data in less protected or encrypted places, leaving them more exposed compared with standard, secure data centers
In April 2024, each of these risks culminated in the high-profile collapse of an unestablished U.S. financial software provider. The business relied on non-standard recordkeeping that rendered their data management unreliable, and revealed a $60 to $90 million shortfall between what the vendor’s software ledger claimed existed and what was actually in the banks’ accounts.
When the business model deteriorated, the team also terminated a large portion of staff. This left Tier 1 banks without any customer service or technical support to untangle the infrastructure.
Of course, these risks are not necessarily present across all new vendors. But taking a ‘trust but verify’ approach means that any supplier in this category often requires more attention to fulfill third party risk and compliance responsibilities, elongating and potentially derailing the long-term business plans.
In an effort to avoid non-starters, some regulated businesses therefore choose to only accept contract bids from organizations with a minimum of five or 10 year’s worth of experience, unless they have the resources (and the patience) for an extra thorough evaluation.
How to evaluate potential third parties
Evaluating third-party data risks is never easy. But when you’re comparing physical data centers to the cloud, and security rules block you from seeing how they encrypt your data, it can feel downright impossible.
So, answering these four questions is a good place to start:
- Is the technology integrated, scalable, and future-proof?
If you’ll need to replace them down the line, or they rely on other third or fourth parties to deliver the solution, then you could be patchworking a solution, which tends to fray and break.
- Does the vendor have demonstrable experience and resources to manage your specific compliance needs?
Previous regulatory enforcement action has homed in on due diligence, including when Tier 1 banks have failed to ensure that their selected vendor had proven experience of managing data migrations at the scale and volume that its project required.
- Will you know where your critical data is stored, and can you access it when needed?
Ownership of the data space is important to maintain uptime, avoid added fees and also to prevent the introduction of third-and-fourth-party risks.
- What access to support is available?
Proven experience in delivering ongoing training and coverage in the event of emergency issues is key.
To help you find third parties that you can trust, our team has put together a detailed buying guide that goes into further depth on these four key questions. If you need to filter out incompatible vendors quickly, read our short guide on the 4 things to consider before you commit.