Third-party risk management: from questionnaires to continuous evidence
Why questionnaire-based vendor assessment fails, what DORA, NIS2, NYDFS and the SEC now expect, and how to build a tiered TPRM programme on continuous evidence.
Most third-party risk programmes are questionnaire programmes. A spreadsheet goes out, the answers come back, someone files them, and the vendor counts as assessed for another year. The process is real. The assurance it produces is mostly on paper.
Why the questionnaire stopped being enough
Four structural limits, and a better questionnaire fixes none of them.
- Self-reported. The vendor writes the answers, nobody verifies them, and the incentive runs one way. No supplier describes its own patching as slow.
- Point-in-time. An answer given in March describes March. The vendor's estate changes every week; the assessment changes once a year.
- Unverifiable at scale. Checking one vendor's claims properly takes days. Across several hundred vendors the checking stops, and the questionnaire becomes a record that a question was asked.
- Blind past the first tier. Your vendors' own suppliers are where a large share of incidents start, and a questionnaire almost never reaches them.
The result is a programme that produces documentation rather than warning. When a supplier is compromised, most organisations hear about it from the supplier, a customer or the news — not from their own oversight.
What regulators now ask for
The major regimes in the US and the EU point the same way: overseeing a supplier is the buyer's job, and it continues after the contract is signed.
| Instrument | Who it binds | What it asks |
|---|---|---|
| DORA, Article 28 | EU financial entities | Stay “fully responsible” for obligations when using ICT providers; keep a register of every ICT arrangement; due diligence before contracting; exit strategies for critical or important functions |
| NIS2, Article 21(2)(d) | EU essential and important entities | Supply chain security, including the security of relationships with each direct supplier and service provider |
| NYDFS, 23 NYCRR 500.11 | New York DFS-regulated entities | Written policies covering identification and risk assessment of providers, minimum practices, due diligence, and periodic assessment based on the risk each presents |
| SEC, Regulation S-K Item 106 | SEC registrants | Disclose whether you have processes to oversee and identify cyber risks from third-party service providers, and how the board oversees cyber risk |
| Interagency guidance, June 2023 | US banks (OCC, Federal Reserve, FDIC) | Risk management across the third-party relationship life cycle, proportionate to the risk each relationship presents |
One clause in DORA shows where this is heading. Article 28(7) requires that a contract can be terminated for “circumstances identified throughout the monitoring of ICT third-party risk”. That only works if monitoring exists and can find something. An annual questionnaire does not produce that kind of evidence between cycles.
If you are the supplier rather than the buyer, the same instruments reach you through your customers' contracts. That side of the question is covered in what NIS2, DORA and SEC Reg S-P demand of your vendors.
Tier by impact before assessing anything
The most common design error is treating every vendor alike. The office-supplies vendor and the provider hosting your core platform do not deserve the same scrutiny, and pretending they do guarantees the scrutiny is shallow everywhere.
Tier on impact, not spend. The question is not what you pay a vendor. It is what happens if they go down, are breached, or lose your data.
| Tier | Definition | Oversight |
|---|---|---|
| A — Critical | Holds customer data at scale, or an outage stops a regulated or core activity | Continuous monitoring, a contractual minimum rating, quarterly review, a tested exit plan |
| B — Important | A material operational dependency, limited sensitive data | Continuous monitoring, alerts on degradation, annual review |
| C — Standard | Business services, no sensitive data, replaceable | Monitoring, escalated by exception |
| D — Minimal | No system access, no data, easily replaced | A check at onboarding only |
Tier A should include every vendor supporting what DORA calls a critical or important function, because those carry the exit-strategy duty. Tiering once to that standard saves re-drawing the line for each regulator.
Continuous evidence, and where questionnaires still belong
External monitoring observes each vendor's internet-facing posture every day, independently, without asking the vendor for anything. What it adds:
- Evidence rather than assertion. An expired certificate or an exposed service is observed, not claimed.
- Change detection. The useful signal is usually decline. A vendor whose posture slips over six weeks is telling you something no questionnaire will.
- Coverage at scale. Monitoring four hundred vendors costs about what monitoring forty does. Verifying four hundred questionnaires does not.
- A dated record. Each vendor's rating over time is the kind of evidence a supervisor, an auditor or an Item 106 disclosure can rest on.
A rollout sequence
- Build the real vendor list. Procurement, accounts payable and the asset inventory will disagree. Reconciling them usually turns up third parties no single system knew about. For a DORA entity, it is also the starting point for the register of information.
- Tier hard. If a third of your vendors come out as critical, the tiering is wrong.
- Baseline Tier A and B externally before telling vendors anything, so the first picture is unmanaged.
- Put thresholds in contracts at renewal. A minimum rating, a remediation window, a right to monitor and a notification duty. Most programmes skip this step, and most need it.
- Give every alert an owner. An alert with no owner and no deadline is noise that teaches people to ignore the console.
- Report the portfolio, not the incidents. Boards need distribution and trend by tier, not last month's findings.
Fourth parties and concentration
A vendor list that looks diversified often is not. Map the dependencies behind your Tier A and B vendors and many of them converge on the same few cloud hosts, payment processors or managed service providers. An incident at one of those is a correlated failure across your portfolio, not an isolated vendor problem.
DORA makes this explicit: before contracting, a financial entity has to assess whether an arrangement adds to ICT concentration risk. Outside DORA the duty is less explicit, but the exposure is the same, and it is invisible to a programme that stops at the first tier.
What to report to the board
- Share of Tier A and B vendors under continuous monitoring — the target is all of them
- Distribution of vendor ratings by tier, quarter on quarter
- Vendors below their contractual threshold, and for how long
- Median time from alert to vendor acknowledgement
- Fourth-party concentration: dependencies shared by more than five Tier A vendors
Note what is missing: the number of questionnaires sent. It measures activity, not risk, and reporting it upward rewards the wrong programme.
Related reading
- Security questionnaires vs security ratings
- What is a cyber security rating?
- Third-party risk management for Indian BFSI — the same method under the RBI outsourcing Directions.
Read from the published text: Regulation (EU) 2022/2554, Article 28, and Directive (EU) 2022/2555, Article 21, on EUR-Lex; 23 NYCRR 500.11 on dfs.ny.gov; 17 CFR 229.106 on the eCFR; and OCC Bulletin 2023-17 on occ.gov.
Every instrument cited here was verified against the issuing regulator's own notification on .Questions this page answers
- What does DORA require for third-party risk?
- Article 28 of DORA keeps a financial entity fully responsible for its obligations when it uses ICT third-party providers. It requires a register of information covering every ICT arrangement, due diligence and a concentration-risk assessment before contracting, termination rights that include circumstances found through monitoring, and tested exit strategies for services supporting critical or important functions.
- What does NYDFS Part 500 require for third-party service providers?
- Section 500.11 requires written policies covering how providers are identified and risk-assessed, the minimum cybersecurity practices they must meet, the due diligence used to evaluate them, and periodic assessment based on the risk each presents. The guidelines should address access controls including multi-factor authentication, encryption, notice of cybersecurity events, and contractual representations and warranties.
- Do SEC registrants have to disclose third-party cyber risk?
- Yes. Item 106 of Regulation S-K requires registrants to describe their processes for assessing, identifying and managing material risks from cybersecurity threats, including whether they have processes to oversee and identify such risks from third-party service providers, and to describe the board’s oversight of cyber risk. A dated record of vendor posture is the kind of evidence that disclosure can rest on.
- Should every vendor be assessed to the same standard?
- No — tier first. Verifying one vendor’s claims properly takes days, so assessing several hundred uniformly means assessing none of them properly. Tiering by what a vendor can reach, and what happens if it fails, decides where depth is worth paying for. Every vendor supporting a critical or important function belongs in the top tier.
- Do security ratings replace vendor questionnaires?
- No. External monitoring cannot see internal controls, staff vetting or recovery capability. It replaces the questionnaire as a census: continuous monitoring covers the whole vendor estate for hygiene and early warning, and deep questionnaires or audits are kept for the critical tier, informed by what the monitoring has already shown.