Sep 03 2026
Security

Q&A: How To Get Third-Party Risk Management Right in Finance

A ServiceNow leader shares insights into best practices for handling risk with multiple vendor partners in financial services.

In a highly regulated industry dealing with sensitive customer data such as financial services, third-party risk management is crucial. As adoption of artificial intelligence grows, organizations are expanding their partnerships, and TPRM must be a central part of their security strategy

“Five years ago, third-party risk was a compliance function. Send questionnaires, check boxes, renew annually. Today, effective programs look operationally embedded,” says Vasant Balasubramanian, group vice president and general manager of risk, AI control tower and ESG at ServiceNow. An alternative to periodic vendor audits, TPRM should be thought of as “continuous risk visibility,” which will help companies respond more quickly and proactively as risks evolve at AI-powered speed. 

Balasubramanian spoke with BizTech about how TPRM is changing financial services and how to improve best practices to keep up with the shifting risk landscape.

Click the banner below to learn more about managing third-party risk in finance.

 

BIZTECH: What makes third-party vendor relationships a vulnerability for banks and financial institutions? Are financial institutions particularly vulnerable? 

BALASUBRAMANIAN: Third-party relationships extend your operational perimeter without extending your control. A bank with world-class security can still be compromised through a vendor with weak access controls or poor patch management. Financial institutions face a perfect storm: intense regulatory scrutiny (you’re accountable for vendor security), a vast ecosystem of dependencies (payment processors, cloud providers, identity services) and high-value data that attracts sophisticated attackers. Increasing operational reliance on third parties also amplifies the complexity of delivering resilient services to their clients. While other sectors face similar pressures, financial services is distinct in the scale and velocity of the impact. A compromise can disrupt operations, impact millions of clients, impact the economy, trigger regulatory action and erode customer confidence — all within hours. 

READ MORE: What can financial institutions learn from NIST’s AI Risk Management Framework?

BIZTECH: How is the third-party risk landscape changing for financial services? Is AI having an impact? 

BALASUBRAMANIAN: The landscape has shifted fundamentally. Vendors are increasingly complex and cloud-native, with their own third-party dependencies. The supply chain is now a preferred attack vector. The velocity of change has outpaced traditional annual assessment cycles. 

On AI specifically, the risk isn’t theoretical. When financial institutions adopt AI for fraud detection or underwriting, it’s creating new vendor relationships that didn’t exist before: the model provider, the training data provider, the cloud infrastructure running interference. Because AI models are proprietary and opaque, you can’t audit them in the way you’d audit traditional vendors. You can’t see inside their black box. That’s a new category of risk financial services hasn’t had to manage before. Simultaneously, AI enables attackers to scale reconnaissance and vulnerability identification. Increasing adoption of AI by third parties exponentially amplifies all of these risks. 

The key shift institutions need to make is moving from periodic vendor audits to continuous risk visibility. This operational alignment of third-party risk enables organizations to respond more quickly and continuously in a world where risks evolve at accelerated speeds, including those driven by AI-powered threat actors and autonomous attack vectors.

Vasant Balasubramanian

Vasant Balasubramanian Group Vice President and General Manager of Risk, AI Control Tower and ESG, ServiceNow

BIZTECH: Many banks rely on third-party providers. How should organizations determine which vendors deserve the closest scrutiny?

BALASUBRAMANIAN: Start with criticality. If this vendor fails, gets breached or stops serving you, what happens to operations or customers? Map vendors into tiers: 

  • Tier 1 includes critical vendors such as payment processors and identity providers 
  • Tier 2 includes important vendors, but with alternatives 
  • Tier 3 includes operational conveniences 

Here's what makes this different in financial services: A Software as a Service company can migrate platforms in months. A bank’s core banking system, payment rails and settlement infrastructure are multiyear commitments. You’re locked in. Your Tier 1 vendors have structural leverage because replacing them is existential risk. For Tier 1, you need continuous oversight and active security dialogue. This includes employing continuous risk mitigation strategies such as independent risk scanning through public sources, backup processes and failover capabilities, and maintaining relationships with alternate vendors where possible. 

For hundreds of lower-tier vendors, rely on annual questionnaires and reputation monitoring. But recognize the asymmetry: Your most critical vendors are the hardest to change and the hardest to control. 

BIZTECH: What do financial institutions need to know about other risks, such as fourth-party risk? 

BALASUBRAMANIAN: Fourth-party (and nth-party) risk is a genuine challenge for financial institutions. Your most critical vendors, your payment processors and identity providers, are often the least transparent about their own vendor relationships. You can threaten to switch vendors, but that can take years and millions of dollars. You’re left managing risk you can’t fully control and can’t fully see. The question isn’t whether fourth-party risk exists. It’s how much residual risk you can accept when you have imperfect information. 

A realistic approach is tiered. For critical vendors, require disclosure of material fourth-party relationships and evidence that they’re managing their own vendors. Don’t require them to audit their entire ecosystem, but require visibility into dependencies that could impact you. 

DISCOVER: Risk management is an accelerant in finance.

For lower-risk vendors, manage fourth-party risk through incident response preparedness rather than preventive audits. And understand contractual leverage: Your contracts should require vendors to notify you of material incidents involving their vendors, but recognize that many vendors will push back on providing detailed subcontractor lists. Negotiate the balance that fits your risk tolerance. 

In this fast-paced environment, other continuous risk mitigation strategies should also be employed, such as independent risk scanning through public sources, backup processes and alternate vendors, to name a few. 

BIZTECH: What are some best practices banks and financial services institutions should follow when rethinking their approach to third-party risk management? 

BALASUBRAMANIAN: Start with visibility. Create an authoritative vendor tiering and inventory, and assess risk systematically rather than reactively. Supplement vendor questionnaires with independent security assessments (SOC 2, ISO 27001) and threat intelligence. Embed third-party risk into procurement by addressing it early in vendor evaluation, not as an afterthought. Most institutions are good at doing assessments. Where they struggle is proving the program actually reduces risk. The honest answer is that third-party risk management is partly defensive (reducing exposure) and partly about acceptance (knowing what you’re exposed to). If your goal is to eliminate third-party risk entirely, you’ll fail. There’s no such thing as zero risk. If your goal is to know your exposure and make deliberate choices about it, that's measurable. But it requires clarity on what you’re actually trying to achieve first. AI agents can be used here to autonomously, independently and continuously evaluate third parties at scale.

Tempura/Getty Images
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.