---
term: "Third-party risk management"
category: "Governance and model risk"
url: https://agenticopenfinance.com/glossary/third-party-risk-management
source: AgenticOpenFinance glossary
---

# Third-party risk management

> Managing the risks of relying on outside providers across the relationship, from due diligence to exit.

Third-party risk management is the discipline of identifying and controlling the risks that come from relying on outside providers, across the life of the relationship. The US banking agencies' interagency guidance describes stages of planning, due diligence, contract negotiation, ongoing monitoring and termination, and in the European Union DORA sets rules for ICT third-party risk. An agent built on another firm's model or tools is a third-party relationship, and the firm stays responsible for the outcome.

Related terms: [Model risk](https://agenticopenfinance.com/glossary/model-risk.md), [Model inventory](https://agenticopenfinance.com/glossary/model-inventory.md), [Provider (AI Act)](https://agenticopenfinance.com/glossary/ai-provider.md), [Change management](https://agenticopenfinance.com/glossary/change-management.md)
