Module · Third-Party Risk Workbench

    Your fourth party is the one that takes you down.

    Most third-party programmes are questionnaire archives. Supervisors have stopped asking whether the questionnaire was returned and started asking whether the institution could keep operating without the provider. That is a resilience question, so it belongs in the same operating layer as everything else.

    The lifecycle

    Stage 01

    Intake

    Provider registered with service, data classes, jurisdictions and downstream dependencies captured at onboarding — not at renewal.

    Stage 02

    Criticality

    Assessed against important business services, not spend. A low-cost provider inside a payment path is critical.

    Stage 03

    Substitutability

    Time-to-replace, tested exit plan, and whether a credible alternative exists at institutional scale.

    Stage 04

    Concentration

    Fourth-party mapping surfaces the cloud region, the model provider and the settlement rail three vendors deep.

    Stage 05

    Continuous monitoring

    Provider posture, incident history and attestation currency tracked between reviews, not once a year.

    Stage 06

    Evidence

    Contract clauses, audit reports, penetration test summaries and AI attestations bound to the control they satisfy.

    Obligations it evidences

    DORA Articles 28–30

    Register of information, contractual requirements, critical-provider designation and exit strategies.

    OSFI B-10

    Third-party risk lifecycle, criticality assessment and concentration reporting.

    OSFI E-23

    Model and AI provider governance where the model is supplied rather than built.

    NIS2 Article 21

    Supply-chain security measures for essential and important entities.

    FFIEC / OCC 2023-17

    Third-party relationship lifecycle expectations for US banking organisations.

    EU AI Act Article 25

    Obligations along the AI value chain where a provider becomes a deployer.

    Feeds ORS third-party dimensionShares the CFIA dependency graphOne evidence vault, no parallel archive
    Scope a third-party programme