Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist
Insight . Intelligence . Accountability
A new wave of professionals is transforming Governance, Risk, and Compliance from a rigid framework into a dynamic force for trust, innovation, and resilience. Governance, Risk, and Compliance (GRC) has long been associated with boardrooms and bureaucracy—a domain reserved for executives and auditors. But that image is changing fast.
Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist
Dr Foluso Amusa, PhD — Founder & President, IGRCFP
3 August 2026
Outsourcing does not outsource accountability. Regulators have said this for years. Boards are only now starting to act as though they believe it.
Most institutions can produce a vendor risk register on request. Far fewer can answer, with confidence, a harder question: if our single largest third-party provider — the one processing KYC checks, or hosting core banking infrastructure, or running customer due diligence screening — suffered a serious operational failure tomorrow, what would happen to our customers, our regulatory obligations, and our board's ability to explain what happened? That question exposes the gap between third-party risk management as a procurement discipline and third-party risk management as a governance discipline, and it is the second version that regulators now expect.
The regulatory logic here is not new, but it has hardened. Across banking, insurance and increasingly non-financial regulated sectors, supervisors have made clear that an institution cannot outsource its accountability along with the activity itself. A failure at a critical outsourced provider is, from the regulator's perspective, a failure of the institution's own control environment — full stop. That framing puts third-party risk squarely inside the board's risk appetite conversation, alongside credit risk, market risk and financial crime risk, rather than treating it as a category owned three or four levels down the organisation.
The Extended Enterprise Has Outgrown Its Governance Model
The practical difficulty is that the modern institution's dependency web has grown faster than most governance frameworks have adapted. Core infrastructure increasingly sits with a small number of cloud providers, creating concentration risk that no single institution can diversify away on its own. KYC, screening and monitoring functions are routinely outsourced or augmented by third-party data and technology providers. Even governance functions themselves — internal audit co-sourcing, external MLRO support, compliance monitoring — now regularly involve external parties operating inside the institution's control environment. Each relationship is individually reasonable. Collectively, they represent a risk surface that a procurement-led due diligence process, run once at onboarding and revisited annually if at all, was never designed to manage.
A vendor risk register that gets updated once a year is not third-party risk management. It's an audit artefact.
Four Things That Separate Real Third-Party Governance from a Checklist
Effective third-party risk management rests on a small number of disciplines, consistently applied rather than periodically performed. First, due diligence at onboarding needs to be proportionate to criticality — a marketing vendor and a core banking processor should never go through the same template. Second, monitoring needs to be continuous rather than annual, with defined triggers — a security incident, a regulatory action, a change of ownership — that force an off-cycle reassessment. Third, contracts need genuine step-in and exit rights, tested in principle before they are needed in practice, not discovered to be inadequate during an actual failure. And fourth, and most often missing, critical third-party concentration needs to be reported to the board directly, in terms the board can act on — not buried in an operational risk appendix that gets nodded through.
None of this requires exotic tooling. It requires a board that treats its extended enterprise as part of its own control environment, because that is precisely how regulators, customers and — eventually — courts will treat it too.
This article reflects the author's professional view and is intended for general awareness. It does not constitute regulatory or legal advice.
Your email address will not be published. Required fields are marked with *
No recommended articles found.