Compliance Insights

2 min read

Identifying and managing the critical risks of third-party providers

Prior to the 1990s, a reference to third-party risk management (TPRM) in a financial institution (FI) meant you were talking about oversight of outsourced technology providers — whether they were financially viable, reputable, reliable, and had adequate privacy and information security safeguards. Cybersecurity controls weren’t part of these earlier discussions, since the word cybersecurity didn’t even enter the English lexicon until 1989. Decisions to engage outsourced technology providers were often broadly distributed throughout a FI, and attempts to compile a complete listing of an institution’s third-party technology providers were often futile. 

Much has changed in three decades. Today, it is commonly understood that third-party providers to FIs include a broad array of technology and other service providers (although the lack of a universal definition does complicate compliance efforts) and that identifying and managing the risks of these providers require a coordinated and continuous effort. And while long-recognized risks remain important, many other risks, such as concentration risk, also require attention. Given the risk landscape and the realization that large financial institutions may have close to 50,000 suppliers,  it is little wonder that TPRM is a global industry and regulatory priority. 

Download now to read the full issue and learn about the common risks third-party service providers face.

Want to hear more?

We invite you to listen to our latest Risky Women Radio Radio podcast episode, where Protiviti leaders provide deeper commentary, share real-world perspectives and discuss how organizations are navigating these evolving challenges.

Together, the paper and podcast offer a comprehensive view—combining data-driven analysis with practitioner dialogue—to help compliance leaders make informed, strategic decisions for the months ahead. 

2025 Top Compliance Priorities Mid-Year Check-In

Risky Women Podcast

Kimberley Cole welcomes Protiviti’s Carol Beaumier and Bernadine Reese for a mid-year check-in on 2025 compliance trends, covering artificial intelligence, financial crime and operational resilience in today’s evolving risk landscape.

Listen Now

Insights on the Global Compliance Landscape

Learn more
Loading...