Skip to content

Third-Party Risk

Third-party risk is a form of operational risk and includes the risk that arises from relationships with third-party providers such as suppliers, contractors and other business partners.

Regulators are concerned about the types of risks that third parties and, in turn, firms could be exposed to.

Our Third-party Risk course will help your team understand the various third-party risks and how to manage them.

  • 30 Minutes
  • For all staff
  • Based on best-practice risk management frameworks and suitable for global audiences.

Learning objectives

  • Appreciate why third-party risk has become so important
  • Recognise risks companies face in their third-party population and specific threats presented
  • Identify the key features of third-party risk management (TPRM)
  • Appreciate the regulatory landscape and key terminology used in third-party risk management (TPRM)
  • Distinguish between the stages of the third-party risk management (TPRM) lifecycle
  • Create a business continuity, termination strategy and exit plan for material outsourcing relationships

    What can you expect your employees to learn?

Welcome

  • Learning objectives
  • How to complete this course

What is third-party risk?

  • Understanding risk exposure: Types of risks

Third-party risk management (TPRM)

  • You decide: Whose responsibility is it?
  • Key roles

Understanding the international regulatory landscape

  • You decide: What are the requirements?

Key terms within TPRM

  • Practical examples

The TPRM lifecycle

  • Scenario: Holly's fintech solution

What is a TPRM policy?

  • Additional features of a TPRM policy

Planning a smooth exit

Importance of business continuity & operational resilience

Benefits of TPRM

Summary

Affirmation

Assessment

Start your compliance e-learning journey with a free trial

Our no-obligation free trial gives you access to our libraries and compliance platform. 

Ready to start your free trial? Complete the form, and a member of the Skillcast team will be in touch with further details.

Your questions, answered

How does conduct risk differ from compliance risk?

Conduct risk focuses on behaviour and outcomes, how actions affect customers and markets -  while compliance risk relates to failing to meet legal or regulatory requirements. Conduct risk is broader and more subjective, often tied to culture and ethics.

Who is responsible for managing conduct risk within a firm?

While senior leadership sets the tone, managing conduct risk is a shared responsibility across all levels, from front-line staff to compliance teams. Everyone plays a role in identifying and mitigating risky behaviour.

Can conduct risk exist in non-financial sectors?

Yes. Although the FCA regulates financial services, conduct risk principles apply across industries. Any business that interacts with customers or influences markets can face conduct-related challenges.

How can technology help reduce conduct risk?

Tools like automated monitoring systems, AI-driven analytics, and e-learning platforms can help detect risky patterns, reinforce ethical behaviour, and ensure consistent training across teams.

How often should proliferation financing risk assessments be updated?

Best practice suggests reviewing risk assessments annually or whenever there are significant changes in business operations, customer profiles, or geopolitical developments.

Why is risk scoring important for my business?

Identifying potential risks around your business is not enough. Tracking how your company manages them helps you implement policies to prevent them. The best way to get started is with a risk scoring matrix.

What is a risk scoring matrix?

A risk scoring matrix helps identify the level of risk for specific activities, such as personal data. By measuring the likelihood of something happening against how serious the consequences would be, it helps you see which areas to focus on. And what policies or procedures to put in place.