Third parties
Third-Party Compliance Risk Management
How to assess vendors, agents, contractors and partners before and during a relationship.
Why this matters
How to assess vendors, agents, contractors and partners before and during a relationship.
Risk-tier the relationship
Consider the service, data access, payment authority, customer contact, geographic reach, subcontractors, regulatory role and difficulty of replacement. Due diligence should match the risk.
Pre-contract review
Review ownership, reputation, licenses, sanctions exposure, security and privacy practices, financial stability, policies, insurance, incidents and use of subcontractors where relevant.
Contract controls
Contracts may address compliance duties, audit rights, reporting, data handling, records, training, approvals, incident notification, subcontracting and termination.
Ongoing monitoring
Track renewals, attestations, incidents, performance, regulatory changes, ownership changes and unresolved findings. High-risk vendors require more than an onboarding questionnaire.
Exit planning
Understand data return or deletion, record access, transition support, outstanding investigations and the effect of termination on customers or regulated services.
Questions to document
- Which obligations and processes are in scope?
- Who owns the activity and who independently reviews it?
- What record demonstrates that the activity operated?
- What happens when the control fails or circumstances change?
Related planning tools
Use the local planning tools to turn the concepts into a structured working note.