What it covers
Third-party risk management (TPRM) is the set of governance arrangements, policies and controls through which a bank oversees its dependence on parties outside its own legal entity: cloud and other information and communication technology (ICT) providers, software vendors, data centres, market-data feeds, and outsourced business processes. As banks have concentrated services with a small number of specialised suppliers, a failure, exit or disruption at one provider can propagate quickly into the bank's own operations. TPRM aims to keep that exposure visible, contractually controlled and, where possible, substitutable.
Typical TPRM activities include maintaining a register of arrangements, performing due diligence and risk assessment before contracting, negotiating audit and access rights, setting exit and substitutability plans, and monitoring concentration where many firms rely on the same provider. Arrangements that support critical or important functions attract the most rigorous treatment.
Relevance to resolution
TPRM matters for resolution because operational continuity depends on it. When an authority applies a resolution tool, the failing bank must keep running the services that underpin its critical functions — payments, custody, IT platforms — throughout the weekend and beyond. Many of those services are provided by third parties or by intragroup service companies. If contracts allow a provider to terminate or suspend delivery on the basis of the bank's entry into resolution, or if there is no plan to novate or continue the arrangement, the resolution strategy can stall. TPRM therefore feeds directly into operational continuity in resolution and into the resolvability assessment: unmanaged third-party dependence is a recognised impediment to resolvability.
Legal basis
TPRM is shaped by several overlapping instruments rather than a single provision. Under the Digital Operational Resilience Act (Regulation (EU) 2022/2554), Articles 28 to 30 set out requirements for managing ICT third-party risk, including contractual content and oversight of critical ICT providers. General internal-governance obligations, including sound arrangements for outsourced activities, flow from Article 74 of the Capital Requirements Directive (2013/36/EU). Supervisory expectations are elaborated in the EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), which are guidance rather than legislation. Resolution authorities draw on these frameworks when assessing whether third-party dependence threatens continuity.
Practical relevance
For a bank, robust TPRM is part of demonstrating resolvability: mapping which providers support critical functions, ensuring contracts survive resolution, and holding credible exit plans. For investors and analysts, weaknesses in third-party and ICT dependency are a source of operational and resolution risk that may not appear in capital metrics. The discipline connects the day-to-day supervision of outsourcing with the resolution planning framework, so the two views of the same dependencies stay consistent.