Innovative technology is reshaping financial services, creating real potential to improve outcomes for consumers and businesses as well as supporting broader economic growth. At the same time, the pace of technological change is accelerating, and with it the scale and complexity of risk.

External service providers and business partners (“third parties”) sit at the center of this transformation. They are part of the fabric of financial services, powering core capabilities, enabling new products, helping firms meet rapidly evolving client needs, and supporting the deployment of emerging technologies across the financial sector.

As third-party relationships become more deeply embedded across financial services – expanding dependencies beyond traditional perimeters – effective and efficient third-party risk management (TPRM) becomes ever more important. The goal is to strike the right balance: Enable responsible innovation that delivers lasting economic benefit while maintaining trust in the financial system.

Prudent policy is central to achieving this outcome. The task for policymakers, regulators, financial institutions, and third parties is not to choose between innovation and safeguards – it is to ensure they advance together, so that innovation scales in ways that protects clients, strengthens market confidence, and supports the resilience of the broader economy. When implemented effectively, strong, consistent guardrails do not hinder innovation; they accelerate it.

A rapidly changing third‑party environment demands a new approach

The third-party service environment is evolving rapidly, driven by growing technological complexity, deeper interconnectedness, and increasing reliance on a small set of leading service providers. These dynamics increase the potential impact of disruption across the financial system and the complexity of managing risk for financial institutions, service providers, and business partners. Several pressures are converging at once:

  • Technology: Third-party ecosystems are becoming more complex as technology advances, integration deepens (e.g., SaaS and AI integration), and interdependencies grow.
  • Visibility: Traditional due diligence is often “point-in-time” even as third-party environments and risks evolve continuously, limiting the ability to proactively identify issues and mitigate potential incidents.
  • Data proliferation: Third-party service models involve growing volumes of data moving between organizations.
  • Resiliency: Concentration risk and deeper supply chain dependencies can amplify the impact of service disruptions, reinforcing the need for closer integration between TPRM and operational and cyber resilience.
  • Threats: Cyber attackers are growing more sophisticated with access to new, AI-enabled tools – significantly enhancing the identification, speed, and scope of exploitation – and further increasing the cost of maintaining the current oversight approach.
  • Competitiveness: Time to market for products and services is increasingly critical, requiring risk management processes that can keep pace with innovation. Slow, manual TPRM processes can hinder an institution’s ability to compete in a dynamic market and support broader innovation.

Taken together, these pressures point to a clear conclusion: legacy oversight models designed for slower cycles and simpler dependencies will increasingly lag the risks they are meant to manage, unless they evolve alongside the technologies and third-party ecosystems they oversee.

Meeting this challenge requires a more dynamic approach to TPRM. How can the industry continue to regularly update our capabilities to stay ahead of new and emerging risks? Industry-wide engagement, standards, and supportive policy will be critical to drive this transformation.

This reality has fueled industry and regulatory discussions about the state of TPRM and related burdens for both financial institutions and third parties – particularly where processes are manual, duplicative, or mismatched to the pace of change. How those burdens are addressed should be carefully calibrated to ensure progress is meaningful and durable.

In an ecosystem defined by continuous change, risk management cannot be episodic. TPRM needs to move at machine speed.

Dolly Singh

Modernization is essential; lowering standards is not

Modernizing the financial services TPRM approach should mean transforming the execution of risk management and oversight, not lowering risk management standards.

This means that while TPRM must evolve, the policy and regulatory foundation that underpins it must remain sound. In fact, successful modernization will depend on maintaining existing regulatory safeguards so that the entire financial services ecosystem, including new and established third parties, remains aligned to a clear set of common outcomes.

That distinction matters because the objective is to make modernization durable. Effective risk management is a driver of innovation because it supports meaningful and lasting partnerships, giving firms the confidence to adopt new capabilities at scale rather than in fragmented or brittle ways.

What modernization should mean: speed and stronger capabilities

Modernizing the execution of TPRM should not focus solely on streamlining and efficiency. While streamlining is a core objective, modernization should also mean advancing risk management capabilities so that TPRM can keep up with how third‑party services (and risks) actually operate today.

A prudent modernization agenda can be organized around three pillars: Execution (streamline how oversight is performed); Insight (strengthen risk identification and monitoring); and Regulation (promote a pragmatic and effective regulatory framework).

Those pillars translate into a practical set of principles that guide what “good” looks like in a world where third‑party relationships are deeper, more dynamic, and more interconnected than ever.

  1. Streamline and digitize execution.
    Modernization should move TPRM away from manual, document-based assessments to standardized, automated, and machine-readable approaches (e.g., control evidence in consistent digital formats, including transparent “ingredient lists” for software and AI components), enabling oversight that can keep pace with technology and reducing unnecessary friction for both financial institutions and third parties.
  2. Build deeper insight and real‑time visibility to reduce disruption.
    If disruption is inevitable, then resilience depends on improving prevention and mitigation through real‑time monitoring capabilities and quicker validation of control effectiveness – so oversight reduces reliance on point‑in‑time snapshots.
  3. Prioritize resources toward what matters most.
    Prioritization of resources is paramount for both financial institutions and third parties, so that expert effort – and deeper diligence and collaboration, including clearer transparency into a third party’s resilience plans – is focused where risks are greatest and adjusted as those risks evolve.
  4. Reduce the attack surface through better data practices.
    Modernization should reduce exposure by advancing industry data principles that minimize data shared by default, strengthen validation of data retention and destruction, and adopt data‑sharing methods that allow financial institutions to maintain control of their data while third parties deliver services.


In other words, modernization is not just about moving faster; it is about moving smarter so oversight can keep up with how services operate today and in the future. Strong guardrails and consistent standards are essential to that evolution, creating the trust and resilience that enable innovation to scale. In an ecosystem defined by continuous change, risk management cannot be episodic. TPRM needs to move at machine speed.

Engagement, urgency, and shared execution

No single institution can solve this alone. Delivering change will require engagement, investment, and action across the entire financial services ecosystem – financial institutions, third parties, and regulators – because third‑party risk is created and mitigated across institutional boundaries.

Engagement should ultimately focus on reducing friction that doesn’t improve outcomes, while increasing transparency and consistency where it matters most, especially as supply chains become more complex and third‑party AI usage becomes more prevalent.

  • For financial institutions: Operationalize continuous, evidence-based assurance and enhanced data practices with third parties. We should no longer rely solely on point-in-time reviews to understand risk.
  • For third parties: Provide greater transparency and make trusted evidence readily available, through robust automation. Demonstrating effective controls should become routine business practice, not an annual exercise.
  • For policymakers: Support new approaches to risk validation and third‑party oversight that enable innovation while maintaining accountability – including addressing systemic risk through direct regulatory oversight of critical third parties – strengthening resilience without added burden or reduced standards.

This vision is not ours alone; it reflects a shared view shaped through sustained engagement with industry leaders on what we need to build toward. We will continue supporting our clients and the broader economy, and we plan to engage more widely to help bring this vision to life.

The bottom line

Scaling responsible innovation does not require abandoning today’s regulatory safeguards; it requires modernization focused on the right outcomes. If we modernize processes or policy without addressing the fundamental shift in risk dynamics, we invite fragility and disruption, not resilience and lasting growth.

The urgency is rising as the consequences of inaction become more tangible and pressing. The opportunity is equally clear: We must modernize third-party risk management so innovation and safeguards advance together, enabling meaningful economic benefit that lasts.

This material has not been reviewed, endorsed, or otherwise approved by, and is not a work product of, any research department of JPMorgan Chase & Co. and/or its affiliates. Information contained in this document has been obtained from sources, including those publicly available, believed to be reliable, but no representation or warranty is made by the document’s author or JPMorganChase as to the quality, completeness, accuracy, fitness for a particular purpose or non-infringement of such information. Sources of third-party information referred to herein retain all rights with respect to such data and use of such data by JPMorganChase herein shall not be deemed to grant a license to any third party. All information contained herein is as of the date referenced and is subject to change without notice.