Contingency Corner: Third-Party Risks
Third-Party Risks
Where third-party risk comes from
Most organizations vet a vendor once, at the start of the relationship, and never look again. Risk usually shows up later, after the contract is signed and the relationship has become routine. Common sources include:
- Vendors or agents with undisclosed ownership ties to government officials or politically exposed persons
- Contractors who subcontract work to parties your organization has never reviewed
- Local partners operating under different labor, safety, or environmental standards than your own
- Suppliers with weak data security practices who handle sensitive information on your behalf
- Logistics or transport providers with a history of safety incidents or regulatory violations
Building a vendor vetting program
A workable program does not need to be elaborate, but it does need to be consistent. Organizations operating in emerging markets should:
- Screen every new vendor or partner against sanctions lists, adverse media, and beneficial ownership records before signing
- Set vetting requirements based on risk tier, so a low-risk supplier is not held to the same standard as a partner with government access
- Build contract language that requires vendors to meet your compliance and safety standards, not just their own
- Re-screen key vendors on a set schedule rather than only at onboarding
- Maintain a single, current record of vendor risk status that is accessible to procurement, compliance, and security teams alike
Frequently asked questions
How is third-party risk different from bribery and corruption risk? Bribery risk is one specific category within the broader third-party risk picture. Third-party risk also covers labor practices, data security, safety standards, and operational reliability, all of which can affect your organization even without any corrupt conduct involved.
Do we need to vet every vendor the same way? No. A tiered approach, where the depth of due diligence scales with the vendor’s access, spend, and risk profile, is more sustainable than applying one standard checklist to every relationship regardless of size.
Interested in strengthening your organization’s security and contingency posture? Contact our team.