- Meaning
- Risks arising from third parties
- Examples
- Cloud providers, IT service providers, suppliers
- How it is steered
- Assessment, contracts, monitoring (the TPRM lifecycle)
- Relation to NIS2
- Part of supply chain security
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is third-party risk?
Third-party risk is the concrete risk that arises from each individual external service provider, partner or supplier. Where Supply chain security is the overarching programme and the Supply chain describes the overall structure, third-party risk turns the focus on the individual case: how large is the risk of this one particular provider? A security incident or an outage at a service provider can become your own problem straight away – when sensitive data sits there, for example, or when the provider works inside your systems through remote access.
Why it keeps growing in importance
Organisations outsource more and more – cloud, software, IT operations, whole business processes. Part of the risk moves outside with them, while the responsibility for it stays put. Keeping control means knowing your service providers, assessing their level of security and keeping an eye on the relationship for as long as it runs.
Steering third-party risk
In practice this follows a lifecycle, known as third party risk management (TPRM) – from selecting a provider to ending the relationship:
- Assess: identify and rate the critical partners and their level of security before the contract is signed.
- Secure it contractually: write the requirements down, and where personal data is processed, in a Data processing agreement (DPA).
- Monitor: check continuously rather than once, and return or delete access rights and data cleanly when the contract ends.
In concrete terms: An online retailer wants to connect a new payment service provider. Before the go-ahead, the provider fills in a security questionnaire, produces a current certificate and accepts a 24-hour duty to report incidents. Only then is the contract signed, and the status is reassessed every year. That way the risk of this one provider is decided deliberately instead of being taken on unnoticed.
Third-party risk and NIS2
NIS2, which has applied since 18 October 2024, requires you to steer these risks actively – as the operational core of Supply chain security and embedded in your Risk management. Ignoring third-party risks does not only invite security incidents: Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.
Further reading: Directive (EU) 2022/2555 (EUR-Lex)
Frequently asked questions
What is third-party risk?
Third-party risk is the concrete risk that arises from a single external service provider, partner or supplier. It turns real when that provider handles sensitive data or works inside your systems through remote access and is compromised there. Unlike supply chain security, which is the overarching programme, third-party risk deliberately looks at the individual case: how large is the risk of this one particular provider?
How do you steer third-party risk?
Third-party risk is steered along a lifecycle, known as third party risk management (TPRM). In practice that means assessing critical partners for their level of security before the contract is signed, writing security requirements into the contract (and, where personal data is processed, into a data processing agreement under Article 28 GDPR), monitoring that level continuously rather than once, and returning or deleting every access right and every data set cleanly when the contract ends.
Why does third-party risk matter for NIS2?
The NIS2 Directive, which has applied since 18 October 2024 and binds you through the transposing law of your Member State, obliges entities in scope expressly to steer supply chain and service provider risks as an operational part of their risk management measures. Ignoring third-party risks costs more than security incidents: Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.