Modernization is essential; lowering standards is not
Modernizing the financial services TPRM approach should mean transforming the execution of risk management and oversight, not lowering risk management standards.
This means that while TPRM must evolve, the policy and regulatory foundation that underpins it must remain sound. In fact, successful modernization will depend on maintaining existing regulatory safeguards so that the entire financial services ecosystem, including new and established third parties, remains aligned to a clear set of common outcomes.
That distinction matters because the objective is to make modernization durable. Effective risk management is a driver of innovation because it supports meaningful and lasting partnerships, giving firms the confidence to adopt new capabilities at scale rather than in fragmented or brittle ways.
What modernization should mean: speed and stronger capabilities
Modernizing the execution of TPRM should not focus solely on streamlining and efficiency. While streamlining is a core objective, modernization should also mean advancing risk management capabilities so that TPRM can keep up with how third‑party services (and risks) actually operate today.
A prudent modernization agenda can be organized around three pillars: Execution (streamline how oversight is performed); Insight (strengthen risk identification and monitoring); and Regulation (promote a pragmatic and effective regulatory framework).
Those pillars translate into a practical set of principles that guide what “good” looks like in a world where third‑party relationships are deeper, more dynamic, and more interconnected than ever.
- Streamline and digitize execution.
Modernization should move TPRM away from manual, document-based assessments to standardized, automated, and machine-readable approaches (e.g., control evidence in consistent digital formats, including transparent “ingredient lists” for software and AI components), enabling oversight that can keep pace with technology and reducing unnecessary friction for both financial institutions and third parties. - Build deeper insight and real‑time visibility to reduce disruption.
If disruption is inevitable, then resilience depends on improving prevention and mitigation through real‑time monitoring capabilities and quicker validation of control effectiveness – so oversight reduces reliance on point‑in‑time snapshots. - Prioritize resources toward what matters most.
Prioritization of resources is paramount for both financial institutions and third parties, so that expert effort – and deeper diligence and collaboration, including clearer transparency into a third party’s resilience plans – is focused where risks are greatest and adjusted as those risks evolve. - Reduce the attack surface through better data practices.
Modernization should reduce exposure by advancing industry data principles that minimize data shared by default, strengthen validation of data retention and destruction, and adopt data‑sharing methods that allow financial institutions to maintain control of their data while third parties deliver services.
In other words, modernization is not just about moving faster; it is about moving smarter so oversight can keep up with how services operate today and in the future. Strong guardrails and consistent standards are essential to that evolution, creating the trust and resilience that enable innovation to scale. In an ecosystem defined by continuous change, risk management cannot be episodic. TPRM needs to move at machine speed.
Engagement, urgency, and shared execution
No single institution can solve this alone. Delivering change will require engagement, investment, and action across the entire financial services ecosystem – financial institutions, third parties, and regulators – because third‑party risk is created and mitigated across institutional boundaries.
Engagement should ultimately focus on reducing friction that doesn’t improve outcomes, while increasing transparency and consistency where it matters most, especially as supply chains become more complex and third‑party AI usage becomes more prevalent.
- For financial institutions: Operationalize continuous, evidence-based assurance and enhanced data practices with third parties. We should no longer rely solely on point-in-time reviews to understand risk.
- For third parties: Provide greater transparency and make trusted evidence readily available, through robust automation. Demonstrating effective controls should become routine business practice, not an annual exercise.
- For policymakers: Support new approaches to risk validation and third‑party oversight that enable innovation while maintaining accountability – including addressing systemic risk through direct regulatory oversight of critical third parties – strengthening resilience without added burden or reduced standards.
This vision is not ours alone; it reflects a shared view shaped through sustained engagement with industry leaders on what we need to build toward. We will continue supporting our clients and the broader economy, and we plan to engage more widely to help bring this vision to life.
The bottom line
Scaling responsible innovation does not require abandoning today’s regulatory safeguards; it requires modernization focused on the right outcomes. If we modernize processes or policy without addressing the fundamental shift in risk dynamics, we invite fragility and disruption, not resilience and lasting growth.
The urgency is rising as the consequences of inaction become more tangible and pressing. The opportunity is equally clear: We must modernize third-party risk management so innovation and safeguards advance together, enabling meaningful economic benefit that lasts.