Analysis
Third-party risk: who actually owns it?
Why vendor risk falls between procurement, legal, and security — and an operating model that assigns real ownership without drowning in questionnaires.
TL;DR: Third-party risk fails organizationally before it fails technically: everyone touches it, nobody owns it, and the questionnaire ritual substitutes paperwork for judgment. The fix is an ownership split — business owns the risk, security owns the standard, procurement owns the gate, legal owns the terms — applied through tiers so the scrutiny lands where the blast radius is.
Why does third-party risk fall through the cracks?
Because it crosses four departments with four incentives. The business wants the vendor live this quarter. Procurement wants the process complete. Legal wants the liability capped. Security wants assurance nobody can actually give. The default resolution — route everything through a security questionnaire team — creates a bottleneck that assesses everything shallowly and owns outcomes it never chose. Meanwhile the incidents that matter keep arriving through exactly the channels the ritual misses: the remote-access tool, the file-transfer appliance, the software update, the fourth party nobody listed.
What does a workable ownership model look like?
Four roles, in writing. The business owner — whoever buys and uses the service — owns the risk: they sign the acceptance when a vendor falls short of standard, and the vendor appears on their risk report. Security owns the assessment methodology, performs or reviews assessments for higher tiers, and assigns the rating — advisory authority, honestly scoped. Procurement owns the gate: no contract executes without the tier-appropriate assessment complete — the single control that makes everything else real. Legal owns the clause library: notification windows, audit rights, sub-processor terms, exit provisions. The model's virtue is that when a vendor incident happens, the accountability conversation is short.
How do tiers keep the program sane?
Three or four tiers, defined by blast radius, not spend: what data does the vendor touch, what access do they hold, what breaks if they're down or breached? Critical tier (production access, sensitive data at scale, single points of failure): evidence-based assessment, external attestations reviewed rather than filed, continuous exposure monitoring, tested exit plans — DORA has made much of this mandatory for financial firms' critical ICT providers. Middle tiers: standardized assessment, contract standards, periodic refresh. Bottom tier: contract terms and inventory, nothing more. The tier assignment itself is the highest-leverage decision in the program; revisit it when usage changes, because vendors migrate upward silently.
What should leaders measure?
Not questionnaire throughput. The numbers that indicate a real program: percentage of critical-tier vendors with current evidence-based assessments; high-risk findings open past SLA with named business owners; concentration exposure (which single providers could halt operations); and time-to-notification in actual vendor incidents versus the contract's promise. And one cultural marker that predicts everything else: whether a business unit has ever actually not bought a vendor over security findings — a program where the answer is never is a program that documents risk rather than manages it.
Frequently asked questions
- Who should own third-party risk management?
- The workable model splits it: the business owner who buys the service owns the risk; security owns the assessment standard and the risk rating; procurement owns the process gate; legal owns the contract terms. What fails is 'security owns it all' — the team with the least authority over vendor selection holding all the accountability.
- Do security questionnaires actually reduce third-party risk?
- Marginally, at best. Questionnaires are self-attestation; they establish diligence and surface egregious gaps but verify little. Mature programs tier vendors and spend real scrutiny — evidence, external attestations, continuous monitoring, contract terms — on the critical tier.
- What belongs in vendor contracts for security?
- Breach notification within a defined window, security requirements by reference, audit or attestation rights, sub-processor transparency, data handling and return/destruction terms, and — for critical services — exit and continuity provisions. Regulations like DORA now mandate several of these for financial firms.
CISO Tribune Editorial
Editorial Desk
The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.