Third parties

Third-Party Compliance Risk Management

How to assess vendors, agents, contractors and partners before and during a relationship.

Why this matters

How to assess vendors, agents, contractors and partners before and during a relationship.

Risk-tier the relationship

Consider the service, data access, payment authority, customer contact, geographic reach, subcontractors, regulatory role and difficulty of replacement. Due diligence should match the risk.

Pre-contract review

Review ownership, reputation, licenses, sanctions exposure, security and privacy practices, financial stability, policies, insurance, incidents and use of subcontractors where relevant.

Contract controls

Contracts may address compliance duties, audit rights, reporting, data handling, records, training, approvals, incident notification, subcontracting and termination.

Ongoing monitoring

Track renewals, attestations, incidents, performance, regulatory changes, ownership changes and unresolved findings. High-risk vendors require more than an onboarding questionnaire.

Exit planning

Understand data return or deletion, record access, transition support, outstanding investigations and the effect of termination on customers or regulated services.

Questions to document

  • Which obligations and processes are in scope?
  • Who owns the activity and who independently reviews it?
  • What record demonstrates that the activity operated?
  • What happens when the control fails or circumstances change?

Related planning tools

Use the local planning tools to turn the concepts into a structured working note.

Educational limitation: This page explains general concepts. It does not determine legal duties, eligibility, coverage, tax treatment, immigration status or the correct action in a specific situation. Check current official sources and qualified advice where needed.