Third-Party Risk Management (TPRM)
A Guide for Financial Institutions
A Guide for Financial Institutions
Financial institutions are operating under increasingly detailed expectations for how third-party relationships are assessed, governed and monitored. In Europe, DORA and EBA guidance have strengthened requirements around ICT and outsourcing risk, while UK regulators have introduced their own expectations through the PRA and FCA. In the US, the Federal Reserve, FDIC and OCC have similarly issued interagency guidance on third-party relationships, setting expectations for risk management across the full lifecycle of outsourcing and supplier arrangements, with a strong emphasis on proportionate, risk-based oversight.
In the UK, PS7/26 introduces an additional requirement by mandating notification before entering or materially changing a material third-party arrangement, which means procurement decisions trigger formal regulatory processes that depend on complete and current risk documentation.
If a critical supplier becomes unavailable tomorrow, who in your institution holds documented accountability, and what evidence can be produced within 48 hours?
DORA (Digital Operational Resilience Act) – EU regulation, in force since January 2025, requiring financial entities to manage ICT and third-party risk, including oversight of critical technology providers.
EBA (European Banking Authority) – sets EU-wide guidelines on outsourcing arrangements, including how banks assess, contract with, and monitor outsourced service providers.
PRA (Prudential Regulation Authority) – the Bank of England body responsible for prudential supervision of UK banks, insurers, and major investment firms.
FCA (Financial Conduct Authority) – the UK’s conduct regulator for financial services firms.
PS7/26 (The PRA’s Policy Statement on Operational Incident and Third-Party Reporting) – published in March 2026, introduce mandatory notification before entering or materially changing a material third-party arrangement. Rules take effect 18 March 2027.
US Interagency Guidance on Third-Party Relationships: Risk Management. Joint guidance from the Federal Reserve, FDIC (Federal Deposit Insurance Corporation) and OCC (Office of the Comptroller of the Currency), setting expectations for how US banking organisations manage risk across the third-party relationship lifecycle.
Many institutions operate with TPRM frameworks broadly similar to those they used three years ago, while supplier risk has continued to evolve. In 2025, more than 40% of cyber incidents reported to the FCA involved a third party*, while most institutions still check their critical suppliers once a year. The gaps tend to appear in four places:
Classification models do not consistently incorporate newer risk dimensions such as GenAI dependency, fourth-party exposure, and geographic concentration. This results in supplier assessments that do not fully capture how services are delivered today.
What this looks like in practice
A bank outsources document processing to a BPO center in a region that is later affected by geopolitical disruption. The center stops operating and the bank’s processing is interrupted. Geographic concentration had been recorded at onboarding but never monitored afterwards, leaving the bank unable to show the exposure had been reassessed.
Supplier financial stability, ownership structures, and risk indicators are often checked manually and on fixed cycles. Supplier data is frequently fragmented across systems and formats, making it difficult to maintain a current view of exposure. As supplier ecosystems become more dependent on cloud, AI and complex downstream providers, monitoring needs to focus on material changes in exposure as they occur, rather than relying primarily on scheduled reviews.
What this looks like in practice
A data analytics vendor supporting credit decisions is found to have ownership links to a restricted entity. The onboarding assessment conducted several years earlier did not include beneficial ownership checks. Detection is delayed, exit is forced, and credit processing is disrupted.
Procurement, IT, and risk functions assess different aspects of supplier exposure. Without shared classification and aligned decision rights, no single view exists at the point a commercial commitment is made.
What this looks like in practice
A SaaS provider is onboarded for a customer-facing application. Procurement, IT, and risk complete separate assessments using different definitions of criticality. Onboarding is delayed, and concentration exposure remains unresolved at go-live.
Each institution typically conducts its own assessment of the same supplier, generating cost and supplier fatigue without proportionate risk reduction. Shared due diligence ecosystems are gaining adoption, with thousands of suppliers already in scope and a recent extension into pooled supplier audits. This raises a question institutions increasingly need to answer: which assessments should remain proprietary, and which can be sourced from a community.
What this looks like in practice
A mid-sized supplier serving dozens of banks is asked to complete a separate due diligence questionnaire by each one, covering largely the same ground. The supplier deprioritizes the slowest requesters, responses arrive late and inconsistent, and several institutions end up relying on assessments that are months out of date.
*Source: FCA, “FCA confirms new incident and third party rules to bolster resilience”, 18 March 2026 (fca.org.uk)
GenAI is changing TPRM primarily by changing what institutions need to understand about their suppliers. TPRM teams themselves still rely on human judgement for material decisions. The sharper question is how suppliers use GenAI within the services they provide: how models are trained and updated, what data flows into them, and what changes in model behavior mean for the institution relying on the output.
This affects two parts of the supplier relationship:
Without these, GenAI-related exposure is difficult to identify through standard cybersecurity or financial due diligence.
Our work with financial institutions on TPRM covers three connected operating capabilities that establish continuous supplier risk management across the supplier lifecycle. Rather than treating TPRM as a sourcing activity, risk assessment becomes an ongoing AI-supported procurement capability that informs sourcing whenever commercial decisions are made. This enables faster, better-informed sourcing awards. How Inverto Applies TPRM within Procurement
Designing the framework and governance
We work with risk, procurement, IT, and legal to define the risk dimensions, scoring methodology, and decision rights that determine how supplier risk is assessed and who is accountable at each stage. This includes alignment with applicable regulatory expectations across jurisdictions and ensures that the framework reflects current risk dimensions including GenAI dependency, fourth-party exposure, and concentration.
Segmenting suppliers and running TPRM as part of procurement’s daily business
We apply the framework across the supplier base to assign supplier tiering, map regional concentration and fourth-party dependencies, and continuously reassess supplier exposure as new information becomes available – decoupled from the sourcing event itself. GenAI-enabled monitoring supports daily screening of supplier signals across structured and unstructured data sources, allowing procurement teams to focus their attention on suppliers where material risk changes are detected. The output is an operating model that procurement, risk, and IT can run from a shared view, with the governance structure to support material decisions.
Fine-tuning risk assessment and mitigation in sourcing and contracting
With supplier risk already understood through continuous monitoring, well before a sourcing process starts, tenders and negotiations focus on calibrating the specific mitigations a deal requires, rather than beginning risk assessment from scratch.
This includes audit rights, subcontractor disclosure, notification timelines, and exit provisions. Where critical or market-dominant providers cannot offer the full set of protections an institution would normally require, the sourcing decision also needs to make the residual exposure explicit and establish proportionate mitigation and continuity measures.
José Carande Morgado
Managing Director
Kiren Pandya
Principal