Glossary · Term

Third-party risk explained

Third-party risk means the risks arising from external service providers, partners or suppliers.

At a glance
Meaning
Risks arising from third parties
Examples
Cloud providers, IT service providers, suppliers
How it is steered
Assessment, contracts, monitoring (the TPRM lifecycle)
Relation to NIS2
Part of supply chain security
Updated
June 2026
Editorial team
Compliance Compass

What is third-party risk?

Third-party risk is the concrete risk that arises from each individual external service provider, partner or supplier. Where Supply chain security is the overarching programme and the Supply chain describes the overall structure, third-party risk turns the focus on the individual case: how large is the risk of this one particular provider? A security incident or an outage at a service provider can become your own problem straight away – when sensitive data sits there, for example, or when the provider works inside your systems through remote access.

Why it keeps growing in importance

Organisations outsource more and more – cloud, software, IT operations, whole business processes. Part of the risk moves outside with them, while the responsibility for it stays put. Keeping control means knowing your service providers, assessing their level of security and keeping an eye on the relationship for as long as it runs.

Steering third-party risk

In practice this follows a lifecycle, known as third party risk management (TPRM) – from selecting a provider to ending the relationship:

In concrete terms: An online retailer wants to connect a new payment service provider. Before the go-ahead, the provider fills in a security questionnaire, produces a current certificate and accepts a 24-hour duty to report incidents. Only then is the contract signed, and the status is reassessed every year. That way the risk of this one provider is decided deliberately instead of being taken on unnoticed.

Third-party risk and NIS2

NIS2, which has applied since 18 October 2024, requires you to steer these risks actively – as the operational core of Supply chain security and embedded in your Risk management. Ignoring third-party risks does not only invite security incidents: Article 34 sets a minimum ceiling of EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may set higher amounts.

Further reading: Directive (EU) 2022/2555 (EUR-Lex)

Frequently asked questions

What is third-party risk?

Third-party risk is the concrete risk that arises from a single external service provider, partner or supplier. It turns real when that provider handles sensitive data or works inside your systems through remote access and is compromised there. Unlike supply chain security, which is the overarching programme, third-party risk deliberately looks at the individual case: how large is the risk of this one particular provider?

How do you steer third-party risk?

Third-party risk is steered along a lifecycle, known as third party risk management (TPRM). In practice that means assessing critical partners for their level of security before the contract is signed, writing security requirements into the contract (and, where personal data is processed, into a data processing agreement under Article 28 GDPR), monitoring that level continuously rather than once, and returning or deleting every access right and every data set cleanly when the contract ends.

Why does third-party risk matter for NIS2?

The NIS2 Directive, which has applied since 18 October 2024 and binds you through the transposing law of your Member State, obliges entities in scope expressly to steer supply chain and service provider risks as an operational part of their risk management measures. Ignoring third-party risks costs more than security incidents: Article 34 sets minimum ceilings of EUR 10 million or 2 % of total worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, and Member States may set higher amounts.

Supply chain

Assess every provider one at a time

Compliance Compass makes the risk of every single provider visible – from the security questionnaire through the rating to the annual reassessment. That way you decide each third-party risk deliberately instead of taking it on unnoticed.