Technology 

Beyond Your Four Walls: Why Third-Party Risk Management Is No Longer Optional

Suppliers, cloud providers, external partners. Modern organizations depend on third parties more than ever before. But as supplier networks expand, so do the risks that can affect operational resilience, security, and reputation. We sat down with Michaela Lenochová from Deloitte to discuss why Third-Party Risk Management (TPRM) has moved to the top of the C-suite agenda, how regulations such as DORA and NIS2 are changing expectations, and what it actually takes to regain control over an increasingly complex third-party ecosystem.

TPRM is still a bit of an acronym soup for many. How do you explain Third-Party Risk Management in plain English?

Simply put: it’s no longer enough to monitor only what happens within your own four walls. TPRM is about understanding and managing the risks that come with external service providers, suppliers, and business partners. Today, almost every organization relies on third parties to support important, and increasingly critical, business processes. The moment you outsource an activity, however, you also introduce dependencies and risks that need to be understood and managed. You need visibility not only into what your suppliers do for you, but also into what could happen to your own business if one of them fails.

What does “managed services” look like day-to-day in TPRM?

It means the client retains full ownership and authority over risk decisions while delegating agreed operational activities to a specialized team. Depending on the agreed service scope, we can support the entire third-party lifecycle, from onboarding and due diligence through continuous monitoring, remediation oversight, incident management support, and offboarding. Clients can also complement the core service with additional components, such as advanced supply-chain screening, targeted support for regulatory requirements including DORA or NIS2, ESG-related assessments, in-depth third-party audits, or contract reviews. The model is modular, so the level of support can be tailored to the organization’s regulatory environment, third-party portfolio, maturity, and internal capacity.

Outsourcing isn’t new. Why is TPRM suddenly getting so much spotlight right now?

The topic itself isn’t new, but the stakes have changed dramatically. TPRM is no longer primarily a compliance topic. It has become a business resilience issue. Organizations aren’t just outsourcing background administrative activities anymore. Third parties increasingly support business-critical operations, technology infrastructure, data processing, logistics, cloud services, and other capabilities that organizations depend on every day. At the same time, organizations are becoming increasingly dependent on a relatively small number of major cloud and technology providers, while the adoption of AI and other emerging technologies is creating new types of third-party relationships and dependencies. Add increasing regulatory expectations and a growing number of supply-chain and cyber incidents, and TPRM becomes a topic organizations simply cannot afford to ignore.

quote icon

We don't just design a framework, implement a technology platform, or provide operational support in isolation. We can help clients across the entire journey, from understanding their current environment and designing the target TPRM model, through technology implementation and integration, to ongoing operational delivery and continuous improvement.

author name Michaela Lenochová, manager, Deloitte

How does Deloitte specifically help organizations tackle this?

Our value comes from combining advisory, technology implementation, and managed services. We help organizations design their TPRM framework, implement the supporting technology, and, through our Operate model, take over agreed operational components of the TPRM process. Deloitte’s specialized team can act as an extension of the client’s internal team supporting operational activities, coordination, and day-to-day communication with third parties. This allows the client to retain ownership of risk decisions and strategic oversight while reducing the administrative burden, improving risk visibility, and making more efficient use of internal resources.

Why are companies pushing the boundaries of outsourcing so aggressively?

It comes down to efficiency, specialization, cost optimization, and staying competitive. In a globalized market, it rarely makes sense for an organization to build every capability internally. Specialized external providers can often deliver capabilities faster, provide access to expertise that would be difficult to maintain in-house, and support greater scalability. But every efficiency gain comes with a trade-off: greater reliance creates greater dependency. If a critical supplier experiences a major disruption and you don’t understand that dependency or have appropriate contingency measures in place, the supplier’s problem can very quickly become your own.

How are regulations like DORA and NIS2 reshaping this landscape?

They are making third-party risk management increasingly explicit from a regulatory perspective. DORA introduces detailed requirements for managing ICT third-party risk in the financial sector. NIS2 extends cybersecurity risk-management and supply-chain security requirements across a much broader range of essential and important entities, including organizations in sectors such as energy and certain manufacturing industries.

For financial institutions, operating in a highly regulated environment is nothing new. For many organizations in other sectors, however, the level of attention now expected around third-party and supply-chain risk represents a significant change. Having a policy on paper is no longer enough. Organizations need to demonstrate that third-party risks are identified, assessed, monitored, and managed effectively in practice.

When you look under the hood, what types of risks are companies actually running into?

There isn’t one single culprit. We frequently see concentration risk, for example, excessive reliance on one provider, technology, or geographic region, alongside cybersecurity threats, data privacy risks, financial instability, operational disruption, reputational risk, regulatory exposure, and ESG-related concerns. However, one of the biggest challenges isn’t a specific risk category. It is the lack of a structured and proportionate approach. Many organizations still don’t have a clear, consolidated view of their third-party ecosystem. Teams can spend enormous amounts of time sending questionnaires, following up by email, maintaining spreadsheets, and collecting documentation without necessarily gaining a clear understanding of the actual risk posed by each third party. Add limited internal capacity, poor data quality, fragmented ownership, and difficulties obtaining information from suppliers, and making informed and timely risk decisions becomes increasingly challenging.

What actually turns a supplier into a “high-risk” entity?

Criticality and dependency are key factors, but they are not the only ones. A supplier providing a relatively simple service with no access to sensitive information will have a very different risk profile from a core cloud provider, critical IT service provider, or primary logistics partner. The risk profile can depend on several factors: the criticality of the service, access to sensitive data or systems, regulatory relevance, subcontracting arrangements, geographic exposure, financial stability, and the availability of alternative providers. Imagine that one logistics provider is responsible for 90% of your product distribution. Even if the service itself appears straightforward, the level of dependency means that a disruption could have an immediate impact on your revenue and operations.

Who actually counts as a “third party”? Is it just IT and tech vendors?

Not at all. Broadly speaking, a third party can be any external organization or individual with whom the company has a business relationship. That could include cloud and IT providers, logistics companies, professional advisers, marketing agencies, consultants, cleaning and facility services, individual freelancers, or even brand influencers. The important point is that risk isn’t defined by the supplier’s title or industry. It depends on factors such as what service they provide, what data or systems they can access, what processes depend on them, and what the impact would be if that relationship were disrupted.

When an incident inevitably hits a supplier, what is the game plan?

The first priority is to understand the impact and contain the issue. Depending on the severity of the incident, this may involve activating incident or crisis management procedures, implementing business continuity measures, engaging alternative providers, and taking steps to protect operations and customers. Once the immediate situation is stabilized, the organization should understand what happened and why. That root-cause analysis should then feed back into the TPRM framework, whether through stronger monitoring, different contractual requirements, additional controls, alternative sourcing strategies, or changes to the way similar third parties are assessed.

Do clients usually call Deloitte proactively, or only once a problem has already emerged?

We see both. Sometimes the trigger is an audit finding, a supplier incident, a regulatory requirement, or another event that exposes weaknesses in the existing approach. But we are also seeing organizations becoming increasingly proactive. They recognize the regulatory direction of travel, see their third-party ecosystems becoming more complex, and want to strengthen their TPRM capabilities before an incident forces them to act. That is ultimately where organizations want to be: moving from reactive third-party risk management to proactive resilience management.

At what point does an organization need a formal, systematic TPRM setup?

It is less about company headcount and more about the scale, criticality, and complexity of the third-party portfolio. When an organization is managing hundreds or thousands of suppliers through spreadsheets, emails, and disconnected processes, teams can easily spend more time on administration than on understanding actual risk. The tipping point often comes when supplier information is fragmented across departments, different teams apply different assessment approaches, there is no consolidated view of critical dependencies, and internal capacity can no longer support the growing workload. A systematic TPRM approach helps introduce proportionality. Not every third party requires the same level of scrutiny. The objective is to identify where the greatest risks and dependencies are and focus resources accordingly.

Final question: The market is full of consulting firms and GRC tools. What sets Deloitte’s TPRM approach apart?

It comes down to our end-to-end partnership model. We don’t just design a framework, implement a technology platform, or provide operational support in isolation. We can help clients across the entire journey, from understanding their current environment and designing the target TPRM model, through technology implementation and integration, to ongoing operational delivery and continuous improvement. By combining regulatory and risk expertise, leading technology, and hands-on operational delivery, we help organizations move beyond treating Third-Party Risk Management as a compliance exercise. Done well, TPRM becomes an integral part of how an organization understands its dependencies, protects its operations, strengthens resilience, and makes informed business decisions beyond its own four walls.

Would you like to learn more? Read the webpage!

Risk management

Upcoming events

Seminars, webcasts, business breakfasts and other events organized by Deloitte.

    Show morearrow-right