Third-party risk management
Managing the risks of relying on outside providers across the relationship, from due diligence to exit.
Third-party risk management is the discipline of identifying and controlling the risks that come from relying on outside providers, across the life of the relationship. The US banking agencies' interagency guidance describes stages of planning, due diligence, contract negotiation, ongoing monitoring and termination, and in the European Union DORA sets rules for ICT third-party risk. An agent built on another firm's model or tools is a third-party relationship, and the firm stays responsible for the outcome.
Agent Minute explains this term on 18 January 2027.
Related terms
Model riskThe potential for adverse consequences from decisions based on model outputs, including misuse of a sound model.Model inventoryA firm-wide record of the models in development or in use, with enough detail to understand their risks.Provider (AI Act)Under the AI Act, whoever develops an AI system or model, or has it developed, and places it on the market under its name.Change managementControlling changes to a model or agent so each change is assessed, approved, recorded and reversible.