Blog Post

Third-Party Cyber Risk: A GRC Playbook for Tiering and Concentration

August 10, 2026

Table of Contents

Most vendor risk programs are built around an annual questionnaire and a criticality tier assigned at onboarding. Regulation has moved past both. Under DORA, which has applied to EU financial entities since January 2025, concentration risk must be assessed before a contract is signed rather than reviewed afterward, and a defined set of contractual provisions became mandatory and unwaivable for arrangements supporting critical functions.

The direction extends past financial services, because supervisors elsewhere are asking the same questions in less prescriptive language. What follows covers what changed, why criticality tiering misranks vendors, how concentration behaves as a portfolio property, and what to do when an assessment fails and you have no leverage.

What DORA Formalized

Three articles carry the third-party obligations, and each one converts a practice most programs performed loosely into something a supervisor inspects.

Concentration Assessment Moved Before the Contract

Assessing single-provider and cross-sector concentration is now required before entering a new arrangement rather than surfacing during an annual review. The sequencing matters, since a concentration finding discovered after signature has no remedy short of exit. Programs assessing vendors individually and never assessing the portfolio will find this the hardest requirement to retrofit.

Contract Terms Became Mandatory

A defined set of provisions applies to arrangements supporting critical or important functions, cannot be waived, and has to be inserted into contracts predating the regulation. Service description, subcontracting conditions, data and service locations, audit and access rights, and exit provisions all sit in that set. Renegotiating a live cloud contract to add audit rights is a commercial problem rather than a compliance exercise, which is why the requirement bites. Recording those terms against each arrangement rather than in the contract file alone is what makes an auditable register possible.

The Register Became a Filing

A register of every ICT contractual arrangement, distinguishing those supporting critical functions, is maintained and submitted to the national authority in a structured format. Nineteen providers have been designated critical ICT third parties under direct European supervisory oversight, so entities now need to know which of their vendors appear on that list. Maintaining this inside the risk register rather than a separate spreadsheet avoids the reconciliation problem that produces filing errors.

Criticality Tiering Misranks Vendors

Tiering by business criticality answers how much you depend on a vendor. It does not answer how much loss that dependence carries, and the two produce different orders.

Vendor analysis table listing individual providers with service category, event frequency score, annual likelihood and average annual loss
Ranking vendors by modeled loss rather than by frequency score reorders the list, since a low-frequency provider can carry more exposure than a high-frequency one.

Frequency and Impact Are Separate Axes

A provider scored low for event frequency can carry more modeled loss than one scored high, because the severity of an outage depends on what depends on it. Collapsing both into a single tier loses that, and the vendor a program deprioritizes on frequency grounds is sometimes the one holding the largest figure. Modeling the two separately is the only way the ordering comes out right, and risk-focused prioritization applies to a vendor population as readily as to a control set.

A Better Tier Uses Three Inputs

Dependence describes what stops working. Data exposure describes what leaves. Substitutability describes how quickly you could replace the provider, which determines whether exit is a real option or a document. A tier built on those three supports different treatment per vendor rather than the same questionnaire sent to everyone, and it reflects how supply chain risk distributes across a population.

Concentration Is a Portfolio Property

Vendor-by-vendor assessment cannot see concentration, because the exposure arises from the relationship between vendors rather than from any one of them. Four suppliers each assessed as acceptable can share a single hosting provider, a single identity platform or a single region.

Third-party financial exposure showing average annual loss and one-in-one-hundred-year loss attributable to third parties, split by event type
Separating third-party exposure from total exposure shows how much of the portfolio depends on providers the organization does not operate.

Third-Party Risk Sits in the Tail

Third-party events contribute modestly to expected annual loss and disproportionately to the extreme figure, because a shared provider failing affects everything depending on it at once. Programs reasoning about vendors through average loss therefore understate them, and the correlation that makes vendor concentration dangerous only appears when the tail is modeled. Scenario work covers this directly, since scenario-based quantification can model a single provider failing across everything that depends on it. Aggregation through a single supplier is the mechanism, and it has a well-documented precedent.

Fourth Parties Are Where Concentration Hides

Your vendor's dependencies are your dependencies, and questionnaires rarely reach them. Asking a supplier which providers support the service you buy, rather than whether they have a vendor management program, surfaces the shared infrastructure that no individual assessment reveals. Subcontracting terms in the contract are what make the answer enforceable later.

The Questionnaire Problem

Annual questionnaires persist because they are auditable rather than because they work. Three limitations are worth stating plainly.

  • Self-Reported: The respondent describes intended practice, and nothing in the instrument tests whether it operates.
  • Point in Time: A response valid in March says nothing about the migration that happened in July.
  • Uniform: The same document goes to a payroll provider and a hosting platform, so depth matches neither.

Replacing them entirely is rarely realistic, since a completed questionnaire is often a contractual requirement. Reducing their load is realistic, by accepting recognized certifications where they cover the ground, reserving bespoke questions for the tier where answers change a decision, and moving monitorable items to continuous checks. Applying continuous control monitoring to externally observable vendor signals covers part of the interval a questionnaire leaves open.

What to Do With a Failed Assessment

The uncomfortable case is a vendor that fails and cannot be replaced, which is where most programs quietly file the finding and move on. Three responses are legitimate. Compensating controls on your side of the boundary, contractual remedies that price the risk, and a documented accepted risk with an owner and a review date. Filing the finding without choosing one of the three is the option that fails an examination.

Exit Plans Are the Control Nobody Tests

Exit provisions appear in contracts and exit plans rarely exist in practice, which supervisors have started noticing. An empty exit strategy for a critical arrangement is simultaneously a filing error and a resilience problem, and the two get discovered together.

A tested plan answers where the data goes, how long migration takes, what runs in the interim and who authorizes the decision. Untested plans consistently understate the timeline, since the constraint is usually data extraction in a usable format rather than the technical migration. Substitutability assessed candidly at tiering time is what tells you whether a plan is worth writing or whether the relationship needs different treatment entirely.

Quantifying Vendor Exposure Changes the Conversation

A vendor discussion framed as a control deficiency invites a debate about questionnaire scoring. The same discussion framed as modeled loss attributable to that provider gives procurement something to negotiate with and gives the business a comparison against the cost of switching. Third-party risk assessed in currency also aggregates, which vendor-by-vendor ratings cannot do, and GRC teams using quantification tend to reach concentration conclusions their questionnaire programs never surfaced.

A Program Built on the Portfolio

Third-party risk management fails when it treats a vendor population as a list of individual assessments. Regulation now expects concentration analysis before contracting, mandatory terms in live agreements, a filed register and tested exit plans, and none of those are satisfied by a questionnaire cycle. Building the program around dependence, data exposure and substitutability, with exposure expressed in a unit that aggregates, produces something that answers both the supervisor and the board. Reporting it alongside the rest of the portfolio is what board-level quantified reporting makes possible. Kovrr's cybersecurity GRC approach keeps vendor exposure inside the same model as the rest of the portfolio.

To see modeled loss attributed to individual providers and aggregated across your vendor population, book a demo with our cyber risk experts.

Tomer Shoolman

Product Manager

Shalom Bublil

Kovrr Co-founder & Chief Product Officer

Third-Party Cyber Risk FAQs

Speak to an Expert
No items found.