Two documents sit in most bank risk functions and rarely speak to each other. The first is a board-approved risk appetite statement and the second is a third-party risk management framework. Neither one tells a vendor manager what to do about a critical core processor carrying three unresolved control findings into its second quarter.

Third party risk appetite is the control that closes that distance. It expresses how much third-party risk an institution accepts in exchange for the value outsourcing delivers, stated precisely enough that someone can act on it without convening a committee.

What follows covers what third-party appetite governs, how it differs from tolerance and limits, how to translate an enterprise statement into vendor-level thresholds, which indicators make those thresholds measurable, and how adherence reaches a board risk committee.

Learn more from our complimentary risk control self assessment datasheet to see more about this topic.

Compliance officers are looking to integrate risk appetite into third-party risk governance frameworks.

Appetite, Tolerance, and Limits Are Three Different Controls

Appetite is directional and largely qualitative and states the kind of third-party risk the institution is willing to carry and the kind it is not. Tolerance is the measurable band around that direction, the range of variation accepted before action is required. A limit is the hard stop, the point past which a position cannot go without formal escalation. Here is how the constructs separate for a critical technology provider:

ConstructWhat it expressesWho owns itExample for a critical vendor
Risk appetiteQualitative direction and the risk types acceptedBoard or board risk committeeThe institution accepts dependency on external providers for core processing, and accepts no unresolved high-severity security findings in critical relationships
Risk toleranceThe measurable band around that directionSecond-line risk functionHigh-severity findings in critical vendors remediated within 60 days, with up to two open at any time
Risk limitThe hard stop requiring escalationBoard risk committee, monitored by second lineNo more than 30 percent of critical business services concentrated with a single provider
Key risk indicatorThe measured signal against the bandFirst line, reported by second lineCount and ageing of open high-severity findings by vendor tier, reported monthly

Why Enterprise Appetite Statements Break Down at the Vendor Layer

Enterprise appetite statements fail at the third-party layer for three recurring reasons, and all three are structural:

Vocabulary

A statement expressed as a tolerance for annual operational loss gives a vendor manager nothing to measure a supplier against.

Missing criticality

Appetite for a payments provider and appetite for a marketing agency should differ by an order of magnitude.

Absent trigger

Many statements describe a posture without naming the event that constitutes a breach.

Translating Enterprise Appetite into Third-Party Thresholds

Start with the enterprise statement and identify the clauses that third-party dependency can affect, such as:

  • Operational resilience
  • Data confidentiality
  • Regulatory compliance
  • Customer harm

Next, define criticality. The 2023 Interagency Guidance on Third-Party Relationships directs a banking organization to analyse the risks associated with each third-party relationship and to tailor its risk management practices to the organization's size, complexity, and risk profile.

Criticality tiers are how that principle becomes operational, and they are the point where an appetite statement connects to the third-party risk management programme already in place. Most institutions land on three or four tiers that they set tolerance for, such as:

  • Business-service dependency
  • Data sensitivity
  • Customer-facing exposure
  • Substitutability

Finally, attach an indicator and an owner to every threshold. The programme should be able to answer, for any threshold in the statement, which system produces the number, who reviews it, and on what cadence.

Setting Thresholds and Key Risk Indicators for Third-Party Exposure

Key risk indicators translate thresholds into numbers the programme can watch between reviews. The useful ones come from data institutions already hold.

Findings and remediation ageing

Open findings by severity and tier, with days outstanding against the remediation window in the tolerance band.

Assurance currency

The share of critical vendors with current independent assurance reports, current financial statements, and current insurance certificates.

Performance and service breaches

Contractual service level breaches by tier, counted over a rolling period.

Concentration position

Critical business services mapped to providers, expressed as a share of services dependent on any single provider.

Fourth-party exposure

The number of critical relationships where material subcontractors are identified, assessed, and contractually disclosed.

Each indicator needs three attributes to be worth reporting:

  • A defined breach trigger
  • A named owner
  • A source system that produces it without a manual data pull

Concentration and Fourth-Party Exposure

Concentration in a third-party context means dependency on a small number of providers for services the institution cannot readily replace. It differs from credit concentration, and it is measured against business services.

The 2023 Interagency Guidance treats dependency on a single provider for multiple activities as a consideration when assessing operational resilience, and it directs banking organizations to evaluate a third party's use of subcontractors according to the risk that arrangement poses to the institution.

Industry-level concentration compounds the exposure. Core processing, payment rails, and cloud infrastructure are where community and regional institutions most often discover they hold an unstated limit at 100 percent.

The fix is a limit expressed at the service level, supported by contractual disclosure of material subcontractors for every tier-one relationship. Institutions that have centralised third-party vendor management usually find the service-level view easier to assemble.

Board, Risk Committee, and the Three Lines

Under the 2023 Interagency Guidance the board holds ultimate oversight responsibility for the banking organization operating in a safe and sound manner and in compliance with applicable law. The guidance adds that directors should be aware of, and may approve or delegate approval of, contracts involving higher-risk activities.

The three lines divide the rest cleanly:

  • The first line owns the relationship and operates inside the thresholds, which means the relationship manager has to know them.
  • The second line sets and maintains the thresholds, aggregates the indicators, and challenges first-line decisions that sit at the edge of the band.
  • Internal audit (the third line) tests whether the framework works as documented, including whether breaches were escalated when they occurred.

Name the forum for a tolerance breach and the forum for a limit breach and set a maximum elapsed time between detection and notification.

Monitoring Breaches and Reporting Appetite Adherence

A board pack that meets the standard shows position against each threshold by tier, breaches opened and closed in the period with remediation status, concentration position for critical services, and direction of travel across several quarters.

Thresholds govern only when the indicators behind them are measured continuously. An annual vendor review cycle produces an outdated snapshot. Continuous monitoring closes that window, which is why appetite work and investment in third-party risk monitoring software tend to arrive together.

Reconciliation disputes consume the committee time that should go to decisions. Governance, risk, and compliance platforms address this by holding assessment, monitoring, and reporting data in one place.

Predict360's third-party and vendor risk management module, for example, runs vendor assessments from a library of more than 750 standardized templates. The platform's Power BI reporting engine as provides a single source of truth.

Frequently Asked Questions

What is the difference between risk appetite and risk tolerance?

Appetite states which risks the institution accepts and which it does not. Tolerance is the measurable band around that direction, expressing how much variation is acceptable before action is required. A risk limit is stricter than both, functioning as a hard stop that cannot be crossed without formal escalation and a documented decision by the accountable committee.

How do you measure third party risk appetite?

Measurement works through key risk indicators tied to each threshold. Common indicators include open high-severity findings and their ageing by vendor tier, currency of independent assurance reports for critical vendors, service level breaches over a rolling period, concentration of critical business services by provider, and identification of material subcontractors.

Does the 2023 Interagency Guidance require a third-party risk appetite statement?

No. The 2023 Interagency Guidance on Third-Party Relationships sets risk-based expectations across the relationship life cycle and describes board oversight responsibilities without prescribing an appetite statement or a specific format. Separately, the OCC's heightened standards at 12 CFR Part 30 Appendix D require banks with average total consolidated assets of $50 billion or more to maintain a risk appetite statement with qualitative components and quantitative limits as part of their risk governance framework.

How often should a third-party risk appetite statement be reviewed?

Annual review aligned to the enterprise risk appetite cycle is common practice, with interim revision triggered by material change. Events that warrant an off-cycle review include a significant new critical relationship, a merger that changes the vendor portfolio, a material breach of a limit, a supervisory finding on third-party governance, or a change in the services a critical provider delivers.

Streamline Risk Management

The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.

Request Demo
  • Cloud-Based
  • Risk Repository
  • Assess Risks
  • Real-time Monitoring