Third-Party Relationship
A third-party relationship is any business arrangement between an organization and an outside entity, whether formalized by a written contract or established through some other arrangement. These outside entities can include service providers, vendors, supply-side and demand-side partners, independent consultants, referral arrangements, and other external parties an organization relies on to pursue its objectives, access expertise, or improve efficiency.
A third-party relationship encompasses relationships with external entities arising from any business arrangement between an organization and another party, by contract or otherwise. Recognized examples include, but are not limited to, service providers, vendors, supply-side and demand-side partners, outsourced services, use of independent consultants, referral arrangements, and merchant payment arrangements. In supervisory usage, such as U.S. interagency guidance, the term is scoped to the organization's direct relationships and anchors the third-party risk management life cycle across stages including planning, due diligence and selection, contracting, ongoing monitoring, and termination. As defined here, the term identifies the relationship itself and does not, on its own, extend to fourth-party or Nth-party relationships beyond the direct arrangement, nor does it prescribe the specific risk domains (for example, information security, financial, operational, or geopolitical) that a given program must evaluate; those are addressed by separate risk management processes. Regulatory expectations for identifying and managing such relationships vary by jurisdiction and sector.
Why it matters
The third-party relationship is the foundational unit of analysis in third-party risk management: it defines the scope of what an organization must identify, assess, and monitor. Because these relationships can be established by contract or through less formal arrangements, organizations frequently rely on external entities, service providers, vendors, supply-side and demand-side partners, independent consultants, referral arrangements, and others, to attain strategic objectives, access expertise, or improve efficiency for a particular activity. When such relationships are not comprehensively inventoried, exposures can go unmanaged simply because the underlying arrangement was never recognized as a third-party relationship in the first place.
Supervisory guidance treats the relationship as the anchor for a structured risk management life cycle. In U.S. interagency guidance issued to banking organizations, the third-party risk management life cycle spans stages including planning, due diligence and selection, contracting, ongoing monitoring, and termination, with risk management principles applicable to each stage. Framing the relationship in this way emphasizes that risk management is not a one-time onboarding exercise but a continuous obligation across the life of the arrangement.
It is important to note what the term does and does not do on its own. Identifying a third-party relationship establishes the direct arrangement between an organization and an external entity, but it does not by itself extend visibility to fourth-party or Nth-party relationships beyond that direct arrangement, nor does it prescribe which specific risk domains, such as information security, financial, operational, or geopolitical risk, a program must evaluate. Those are addressed through separate risk management processes, and expectations for identifying and managing these relationships vary by jurisdiction and sector.
Who it's relevant to
Inside Third-Party Relationship
Common questions
Answers to the questions practitioners most commonly ask about Third-Party Relationship.