Skip to main content
Category: Foundational Concepts

Third-Party Arrangement

Also known as: Third-Party Relationship, Outsourced Arrangement
Simply put

A third-party arrangement is any business relationship between an organization and an outside entity that provides goods, services, or performs activities for it. These arrangements can be established by formal contract or through less formal means, and they range from outsourced services to consulting engagements and referral or payment arrangements. Because the outside party carries out functions on the organization's behalf, the arrangement can expose the organization to risks it must manage.

Formal definition

A third-party arrangement is any business relationship between an organization and an external entity, established by contract or otherwise, under which that entity provides goods or services or performs activities relevant to the organization. In financial services contexts, the term commonly encompasses outsourced services, use of independent consultants, referral arrangements, and merchant payment processing, among other forms. The term describes the relationship itself rather than the specific risk domains it may implicate; a given arrangement may carry information security, operational, financial, compliance, or other exposures depending on its nature, and the term alone does not specify which apply. It should be understood as broader than a formal outsourcing contract, since arrangements may exist 'by contract or otherwise,' and note that regulatory expectations for identifying and managing such arrangements vary across jurisdictions and sectors rather than following a single global standard.

Why it matters

The concept of a third-party arrangement matters because it defines the outer boundary of what an organization must identify before it can assess or manage any related risk. If a relationship is not recognized as a third-party arrangement in the first place, it typically falls outside inventory, due diligence, and monitoring processes entirely. Because these arrangements can be established 'by contract or otherwise,' organizations that scope their programs only to formal outsourcing contracts risk overlooking referral arrangements, independent consultants, or merchant payment relationships that nonetheless carry exposure.

The breadth of the term is also its central challenge. A third-party arrangement describes the relationship itself, not the specific risks it implicates; a given arrangement may carry information security, operational, financial, compliance, or other exposures depending on its nature. Treating all arrangements as equivalent tends to over-burden low-risk relationships while under-scrutinizing high-risk ones, which is why many programs tier arrangements by their function and criticality rather than by contract form alone.

Regulatory expectations for identifying and managing third-party arrangements vary across jurisdictions and sectors rather than following a single global standard. In financial services in particular, supervisory guidance frames these relationships broadly, but the specific obligations that attach depend on region, sector, and the nature of the activity being performed. Organizations operating across multiple regimes should not assume that satisfying one jurisdiction's expectations satisfies another's.

Who it's relevant to

Third-Party Risk and Procurement Teams
These teams rely on a broad and accurate definition of third-party arrangements to build a complete inventory. Scoping the term too narrowly to formal contracts risks excluding referral arrangements, consultants, or payment relationships that exist 'by contract or otherwise,' leaving gaps in the population that later assessment and monitoring processes never reach.
Compliance and Regulatory Affairs Functions
Because supervisory expectations for identifying and managing third-party arrangements differ across jurisdictions and sectors, compliance teams must map how the term is scoped under each regime that applies to them. This is especially relevant in financial services, where guidance commonly frames third-party relationships broadly to include outsourced services, independent consultants, referral arrangements, and merchant payment processing.
Business and Relationship Owners
Owners who engage external consultants, referral partners, or service providers need to recognize when a relationship constitutes a third-party arrangement so that it enters the organization's risk processes. Since the term itself does not specify which risk domains apply, owners are often best positioned to describe what the external entity actually does, which informs how the arrangement is characterized and prioritized.

Inside Third-Party Arrangement

Contractual Relationship
The formal agreement between the organization and an external party that defines the scope of goods or services provided, the rights and obligations of each side, and the terms governing the engagement. A third-party arrangement centers on this direct relationship rather than on the broader multi-tier supply network.
Parties Involved
The organization and the external entity, which may be characterized as a vendor, supplier, service provider, or business partner depending on the nature of what is exchanged. These roles are distinct and should not be treated as interchangeable when defining the arrangement.
Scope of Services or Goods
The specific deliverables, functions, data access, or operational responsibilities covered by the arrangement. Precisely bounding this scope helps determine which risk domains, information security, financial, operational, geopolitical, or ESG, are relevant to the engagement.
Risk Tiering
The classification of the arrangement by criticality and inherent risk, which in many programs drives the depth of due diligence, contractual controls, and the frequency of ongoing monitoring applied.
Governance and Oversight Terms
Provisions addressing performance expectations, audit and assessment rights, service levels, and how the relationship is monitored over its lifecycle. Depending on the arrangement, these may extend to expectations regarding the external party's own downstream (fourth-party or Nth-party) relationships, though visibility typically diminishes beyond the first tier.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Arrangement.

Is a third-party arrangement the same as a signed contract?
No. A contract is one component that may formalize a third-party arrangement, but the arrangement refers to the broader relationship through which an external party performs a function, provides a service, or delivers goods on the organization's behalf. Arrangements can exist through purchase orders, statements of work, master service agreements, or in some cases informal or handshake relationships that lack a comprehensive written contract. Treating the arrangement as coextensive with the signed contract can leave gaps where obligations, service levels, or risk controls are assumed but not documented.
Does having a third-party arrangement mean the organization has transferred its risk to the third party?
Not in most cases. Contracting a function to a third party may allocate certain responsibilities and liabilities, but the organization typically retains accountability for the outcome, particularly under many regulatory regimes that hold the contracting entity responsible for functions it outsources. Indemnification clauses, insurance, and service level provisions can shift some financial consequences, but they generally do not eliminate operational, reputational, or compliance risk. The extent of any transfer depends on contract terms, applicable law, and the jurisdiction and sector involved.
What should a third-party arrangement document capture beyond price and deliverables?
In many programs, the arrangement documentation is expected to address the scope of services, service levels and performance metrics, data handling and security obligations, subcontracting or fourth-party use, audit and access rights, business continuity expectations, breach and incident notification, and termination and exit provisions. The specific elements typically vary with the risk tier of the arrangement, so a low-criticality supplier arrangement may capture far less than one supporting a critical function.
How does the type of arrangement affect the level of due diligence applied?
Due diligence is typically scaled to the criticality and inherent risk of the arrangement rather than applied uniformly. Arrangements involving access to sensitive data, support of critical operations, or dependency with limited substitutability generally warrant deeper diligence and more frequent review, while lower-risk arrangements may receive a lighter assessment. Keep in mind that onboarding due diligence addresses a point in time and does not, on its own, cover ongoing monitoring across the life of the arrangement.
How should subcontracting or downstream dependencies within an arrangement be handled?
Because a third-party arrangement may permit the third party to rely on its own suppliers, the arrangement often needs terms addressing whether subcontracting is allowed, whether notification or approval is required, and how downstream obligations flow through. Visibility beyond the direct third party is frequently limited, so contractual flow-down provisions do not guarantee that fourth-party or Nth-party risks are actually observed or controlled. Programs typically supplement contract terms with mapping and monitoring where the risk warrants it.
How should a third-party arrangement address termination and exit?
Exit and termination provisions are often built into the arrangement so that the organization can transition or wind down the relationship without undue disruption. Depending on the criticality of the function, these may cover return or destruction of data, transition assistance, continuity of service during handover, and conditions for termination for cause or convenience. The presence of exit clauses does not by itself ensure a smooth transition; the practical feasibility of exit also depends on substitutability of the third party and any concentration or single-source dependencies involved.

Common misconceptions

A third-party arrangement is the same as supply chain risk management, so managing it covers the full supply network.
A third-party arrangement centers on the organization's direct contractual relationship with an external party. Supply chain risk management extends across multiple tiers and the physical and logistical flows of goods and services. Managing a direct arrangement typically provides limited visibility beyond the first tier and does not by itself address fourth-party or Nth-party risk.
Once the arrangement is signed after onboarding due diligence, the associated risk has been addressed.
Onboarding due diligence is generally point-in-time and can become stale as the relationship, the external party, or the risk environment changes. Many programs pair the arrangement with ongoing monitoring, because the initial assessment does not cover the full lifecycle of the relationship.
The terms vendor, supplier, service provider, and business partner all describe the same kind of arrangement.
These roles are distinct and reflect different exchanges of goods, services, or shared objectives. Treating them as synonymous can obscure which risk domains and contractual controls are relevant to a particular arrangement.

Best practices

Characterize each arrangement precisely by the role of the external party (vendor, supplier, service provider, or business partner) so the applicable risk domains and controls are correctly scoped.
Define and document the scope of goods or services in the arrangement, stating explicitly which risk domains, information security, financial, operational, geopolitical, or ESG, are and are not addressed.
Apply risk tiering to calibrate the depth of due diligence, the strength of contractual controls, and the frequency of ongoing monitoring to the criticality of the arrangement.
Complement point-in-time onboarding due diligence with ongoing monitoring, recognizing that initial assessments can become stale over the life of the relationship.
Include governance provisions such as audit and assessment rights, performance expectations, and, where relevant, terms addressing the external party's downstream relationships, while acknowledging that visibility typically diminishes beyond the first tier.
Keep the arrangement's scope distinct from broader supply chain risk management, and avoid assuming that managing a direct relationship covers fourth-party or Nth-party exposure.
Application Security Isn’t Optional Anymore.