Third-Party Arrangement
A third-party arrangement is any business relationship between an organization and an outside entity that provides goods, services, or performs activities for it. These arrangements can be established by formal contract or through less formal means, and they range from outsourced services to consulting engagements and referral or payment arrangements. Because the outside party carries out functions on the organization's behalf, the arrangement can expose the organization to risks it must manage.
A third-party arrangement is any business relationship between an organization and an external entity, established by contract or otherwise, under which that entity provides goods or services or performs activities relevant to the organization. In financial services contexts, the term commonly encompasses outsourced services, use of independent consultants, referral arrangements, and merchant payment processing, among other forms. The term describes the relationship itself rather than the specific risk domains it may implicate; a given arrangement may carry information security, operational, financial, compliance, or other exposures depending on its nature, and the term alone does not specify which apply. It should be understood as broader than a formal outsourcing contract, since arrangements may exist 'by contract or otherwise,' and note that regulatory expectations for identifying and managing such arrangements vary across jurisdictions and sectors rather than following a single global standard.
Why it matters
The concept of a third-party arrangement matters because it defines the outer boundary of what an organization must identify before it can assess or manage any related risk. If a relationship is not recognized as a third-party arrangement in the first place, it typically falls outside inventory, due diligence, and monitoring processes entirely. Because these arrangements can be established 'by contract or otherwise,' organizations that scope their programs only to formal outsourcing contracts risk overlooking referral arrangements, independent consultants, or merchant payment relationships that nonetheless carry exposure.
The breadth of the term is also its central challenge. A third-party arrangement describes the relationship itself, not the specific risks it implicates; a given arrangement may carry information security, operational, financial, compliance, or other exposures depending on its nature. Treating all arrangements as equivalent tends to over-burden low-risk relationships while under-scrutinizing high-risk ones, which is why many programs tier arrangements by their function and criticality rather than by contract form alone.
Regulatory expectations for identifying and managing third-party arrangements vary across jurisdictions and sectors rather than following a single global standard. In financial services in particular, supervisory guidance frames these relationships broadly, but the specific obligations that attach depend on region, sector, and the nature of the activity being performed. Organizations operating across multiple regimes should not assume that satisfying one jurisdiction's expectations satisfies another's.
Who it's relevant to
Inside Third-Party Arrangement
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Arrangement.
