Vision to Value

Third-party risk management: moving from traditionalist to strategist

As third-party networks grow, new approaches can help organizations manage complex risks at scale.


In brief
  • Third-party risk management (TPRM) is becoming more complex and interconnected. Cyber, operational and regulatory risks are outpacing traditional approaches.
  • Assessing risk earlier and evaluating dependencies across the third-party ecosystem can improve decisions and strengthen resilience.
  • Managed services can add dedicated skills, disciplined processes and flexible capacity as third-party risk changes.

Third parties are often essential for organizations to unlock growth, reduce costs and operate at scale. But as the third-party network expands, so does its potential exposure to cyber threats, disruption, data loss or reputational damage — and those risks can easily extend across an organization’s entire third-party network.

 

Many organizations still struggle to evaluate third parties efficiently and consistently. Traditional in-house third-party risk management (TPRM) programs often lack the visibility to identify risks early, understand their full impact and respond strategically.

 

Today, leading in TPRM requires a shift from standard compliance efforts toward a more proactive, deliberate approach. By rethinking the operating model — including the role of managed services —organizations can turn TPRM from a reactive function into a strategic capability. Here’s how.

The hard truth is businesses can no longer be reactive in this space. They need to utilize third parties at scale to drive greater efficiency while also proactively managing the risk that comes with those third parties.

Assess risk before the contract is signed

Too often, risk assessments occur after a third party has been selected or contracted. By then, organizations lose leverage to negotiate additional protections, put the right service-level agreements in those contracts — or ultimately walk away from the relationship if the risk is too great for the organization. Moving TPRM services earlier in the process gives risk and compliance teams timely insight about potential trade-offs before time, money and plans are committed.

Evaluate third-party interdependencies

When assessing a new third party, look beyond basic compliance and consider how one vendor could affect the entire organization. Consider such questions as:

  • What proprietary data and systems will the third party have access to?
  • What subcontractors and fourth parties does the vendor bring into the process?
  • What areas of the business would be affected by a third party’s cyber breach, operational failure or brand reputation issue?

Addressing these questions and more provides risk teams with a broader view of the full potential organizational impact of a third party. From there, they can determine which relationships have the greatest potential for risk, create relevant risk mitigation plans and assess if the value of the third party outweighs the possible complications.

Add flexible capacity

Risk and third-party management are always in motion. Assessing a new regulation, an acquisition, an incident or a wave of vendors can quickly strain in-house teams, particularly those that rely on traditional TPRM reviews.

A third-party risk managed services model can add technical skills, processes, speed and capacity that expand or contract as needs change, providing support that scales for in-house TPRM professionals. Ideal partners also will bring end-to-end support and a commitment to continuous innovation to adapt as risks or regulations shift.

Risk insight gap
68%
68%
The majority of organizations still take a traditional approach to risk management, with only about one-third consistently using risk insights in strategic business decisions.

Transition from risk traditionalist to risk strategist

In a risk environment that’s increasingly nonlinear, accelerated, volatile and interconnected, risk leaders can no longer rely on business as usual.

The organizations that are leading today have evolved from “risk traditionalists” to “risk strategists,” embracing a faster, more scalable approach, such as a managed services model, to manage third-party risk earlier, more efficiently and with greater confidence.

Summary 

Nearly all organizations rely on third parties to operate and grow, but those relationships can introduce risks — from data security and cyber exposure to brand reputation, financial impact and operational disruption. Third-party risk management managed services can provide technical skills, operating discipline and scalable support, helping organizations manage third-party risk with greater confidence while enabling growth. Leading organizations take a strategic approach that assesses risk early, evaluates dependencies across the third-party ecosystem and builds capacity to respond as conditions change.


About this article

Related articles

How can reimagining risk prepare you for an unpredictable world?

The 2025 EY Global Risk Transformation Study explores how Risk Strategists see disruption earlier, adapt faster and respond with more precision.

How AI navigates third-party risk in a rapidly changing risk landscape

Learn what the 2025 EY Third-Party Risk Management survey reveals about new AI-driven approaches to managing risks in a more volatile environment.