Enterprise risk & controls · Core
Third-party risk
Also called: vendor risk
ELI5
Risk introduced through suppliers, partners, outsourcers or other external parties.
Used in conversation
“Can we separate the likelihood of third-party risk from its potential impact?”
Pitch context
You will see “Third-party risk” in board papers, contracts, policies, risk registers and compliance reports when the discussion reaches enterprise risk & controls.
Why it matters: In enterprise risk & controls, a loose definition can change rights, obligations, approval, disclosure or enforceability.
Caution
Meaning, enforceability and required process vary by jurisdiction and agreement; this definition is not legal advice.
Sources & evidence · 3
Direct term-level sources and supporting source families.
- OECD — G20/OECD Principles of Corporate Governance 2023Direct source · institutional · checked 2026-08-16
- National Institute of Standards and Technology — Computer Security Resource Center GlossaryDirect source · primary · checked 2026-08-16
- U.S. Securities and Exchange Commission — EDGAR and filing resourcesSupporting source family · primary · checked 2026-08-16