GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

HomeCybersecurity & GRC Career GuidesThird-Party Risk Skills

Third-Party Risk Skills

Get new GRC career guides by email. We publish most weeks. No spam, and we never sell or share your address with anyone.

Third-Party Risk Skills illustration

Third-party risk is the discipline of worrying about systems you do not run, staffed by people you cannot manage, at companies that have no obligation to tell you when something breaks. The regulator holds you responsible anyway. That gap is the whole job.

Tiering is the decision that determines everything else

Most programs fail at the first step, by treating every vendor the same. Sending an identical two hundred question assessment to a payroll processor holding employee bank details and to the company supplying the office coffee produces two things: a backlog, and a review queue nobody reads.

Tier on what the vendor can actually cost you. Does it touch regulated or personal data? Would an outage stop you serving customers? Does it have privileged access into your network? Is it hard to replace inside a quarter? A vendor scoring yes on the first and third of those deserves months of attention. One scoring no on all four deserves a short form and a renewal date.

Reading evidence properly

The most valuable and least taught skill here is reading a SOC 2 Type II report rather than filing it.

Three things matter and most reviewers miss all three. The opinion, because a qualified opinion means the auditor found something and said so. The exceptions in the testing section, which is where the actual findings live and where the report stops being marketing. And the complementary user entity controls, the list of things the report assumes you are doing at your end. If you are not doing them, the assurance you think you bought does not exist.

Then check the period covered. A report ending in June, reviewed the following May, leaves eleven months unexamined, and the bridge letter that is supposed to cover the gap is usually a single paragraph asserting nothing changed.

Questionnaires, and their limits

SIG, CAIQ and the various industry variants standardize the asking. They do not verify anything. A questionnaire is a self-assessment, which means it records what the vendor believes or wants you to believe.

Experienced reviewers treat the questionnaire as a way to find the questions worth asking on a call, then ask for the artifact. Not "do you perform background checks" but "show me the policy and tell me what you did about the last exception".

Concentration and fourth parties

Your vendors have vendors. When thirty of your suppliers all run on the same cloud region, you do not have thirty independent risks, you have one. Mapping that concentration is increasingly expected, and increasingly asked about in interviews, because a single provider outage now takes out whole sectors at once.

The AI supply chain has made this sharper. A vendor that has quietly added a model API into its product has changed what your data is exposed to, often without a contract amendment and usually without telling you.

Contracts and the exit

The leverage is at signature and nowhere else. Right to audit, breach notification within a stated number of hours, subprocessor change notice, data return and deletion on termination. After signature you are asking for favors.

Exit planning is the part everyone skips and auditors increasingly test. If this vendor failed on Monday, what happens? If the honest answer is that nobody knows, that is a finding waiting to be written.

Where the regulation is

In financial services, the EU Digital Operational Resilience Act sets requirements for ICT third-party risk including a register of contractual arrangements. US banking supervisors issued joint third-party risk guidance in 2023 that replaced the older agency-specific versions. In healthcare, HIPAA business associate agreements make the flow-down explicit. Naming the one that applies to your target employer is a straightforward way to sound like you have done this before.

Where to go next

Frequently Asked Questions

What are third-party risk management skills?

The ability to work out which suppliers can genuinely hurt you, assess them proportionately, read the assurance evidence they provide rather than merely filing it, get protections into the contract while you still have leverage, and monitor the relationship until it ends.

How do you tier vendors?

By impact rather than by spend. The useful questions are whether the vendor touches regulated or personal data, whether an outage would stop you serving customers, whether it has privileged network access, and how quickly it could be replaced. Sending every vendor the same long questionnaire creates a backlog and a queue nobody reads.

What should I look for in a SOC 2 report?

The opinion, since a qualified opinion means the auditor found something. The exceptions listed in the testing section, which is where real findings appear. The complementary user entity controls, which are the things the report assumes you are doing at your end. And the period covered, because a report can easily be most of a year out of date.

Are security questionnaires useful?

They standardize the asking but verify nothing, because a questionnaire is a self-assessment. Treat it as a way to identify which questions are worth pursuing, then ask for the underlying artifact rather than accepting the answer.

What is fourth-party or concentration risk?

The risk carried by your vendors' vendors, and the risk of many suppliers depending on the same underlying provider. Thirty vendors on one cloud region is one risk, not thirty. Regulators increasingly expect this to be mapped.

What contract terms matter most in third-party risk?

Right to audit, breach notification within a defined period, notice of subprocessor changes, and data return and deletion on termination. All leverage exists before signature. Afterwards you are asking for favors.

What regulations govern third-party risk?

DORA in EU financial services, including a register of contractual arrangements. The 2023 US interagency guidance on third-party relationships for banking organizations. HIPAA business associate agreements in healthcare. Sector matters more than geography here.

How has AI changed third-party risk?

A vendor that adds a model API to its product changes what your data is exposed to, frequently without a contract amendment and often without notification. Assessing whether a supplier uses AI, and on what data, is becoming a standard section of the review.

What jobs use third-party risk skills?

Third-party risk analyst and manager, vendor risk analyst, supplier assurance, operational resilience roles, and GRC analysts in financial services and healthcare where the regulatory expectations are most explicit.

More in this series

Written and reviewed by
Founder and Publisher, GRC Careers and AI Governance Jobs
  • Founder of ExecSearches and GRC Careers
  • Executive search across corporate, higher education, financial services, and nonprofit sectors
  • Focus on AI governance and GRC hiring
VP of Operations and GRC Practitioner
  • More than a decade in risk advisory and internal audit in financial services
  • Led SOX and regulatory audits for Citi, Goldman Sachs, Morgan Stanley, and McKesson
  • Public Accounting Certification, Cornell University