Two documents sit in most bank risk functions and rarely speak to each other. The first is a board-approved risk appetite statement and the second is a third-party risk management framework. Neither one tells a vendor manager what to do about a critical core processor carrying three unresolved control findings into its second quarter.
Third party risk appetite is the control that closes that distance. It expresses how much third-party risk an institution accepts in exchange for the value outsourcing delivers, stated precisely enough that someone can act on it without convening a committee.
What follows covers what third-party appetite governs, how it differs from tolerance and limits, how to translate an enterprise statement into vendor-level thresholds, which indicators make those thresholds measurable, and how adherence reaches a board risk committee.
Learn more from our complimentary risk control self assessment datasheet to see more about this topic.

Appetite, Tolerance, and Limits Are Three Different Controls
Appetite is directional and largely qualitative and states the kind of third-party risk the institution is willing to carry and the kind it is not. Tolerance is the measurable band around that direction, the range of variation accepted before action is required. A limit is the hard stop, the point past which a position cannot go without formal escalation. Here is how the constructs separate for a critical technology provider:
| Construct | What it expresses | Who owns it | Example for a critical vendor |
|---|---|---|---|
| Risk appetite | Qualitative direction and the risk types accepted | Board or board risk committee | The institution accepts dependency on external providers for core processing, and accepts no unresolved high-severity security findings in critical relationships |
| Risk tolerance | The measurable band around that direction | Second-line risk function | High-severity findings in critical vendors remediated within 60 days, with up to two open at any time |
| Risk limit | The hard stop requiring escalation | Board risk committee, monitored by second line | No more than 30 percent of critical business services concentrated with a single provider |
| Key risk indicator | The measured signal against the band | First line, reported by second line | Count and ageing of open high-severity findings by vendor tier, reported monthly |
Why Enterprise Appetite Statements Break Down at the Vendor Layer
Enterprise appetite statements fail at the third-party layer for three recurring reasons, and all three are structural:
Vocabulary
A statement expressed as a tolerance for annual operational loss gives a vendor manager nothing to measure a supplier against.
Missing criticality
Appetite for a payments provider and appetite for a marketing agency should differ by an order of magnitude.
Absent trigger
Many statements describe a posture without naming the event that constitutes a breach.
Translating Enterprise Appetite into Third-Party Thresholds
Start with the enterprise statement and identify the clauses that third-party dependency can affect, such as:
- Operational resilience
- Data confidentiality
- Regulatory compliance
- Customer harm
Next, define criticality. The 2023 Interagency Guidance on Third-Party Relationships directs a banking organization to analyse the risks associated with each third-party relationship and to tailor its risk management practices to the organization's size, complexity, and risk profile.
Criticality tiers are how that principle becomes operational, and they are the point where an appetite statement connects to the third-party risk management programme already in place. Most institutions land on three or four tiers that they set tolerance for, such as:
- Business-service dependency
- Data sensitivity
- Customer-facing exposure
- Substitutability
Finally, attach an indicator and an owner to every threshold. The programme should be able to answer, for any threshold in the statement, which system produces the number, who reviews it, and on what cadence.
Setting Thresholds and Key Risk Indicators for Third-Party Exposure
Key risk indicators translate thresholds into numbers the programme can watch between reviews. The useful ones come from data institutions already hold.
Findings and remediation ageing
Open findings by severity and tier, with days outstanding against the remediation window in the tolerance band.
Assurance currency
The share of critical vendors with current independent assurance reports, current financial statements, and current insurance certificates.
Performance and service breaches
Contractual service level breaches by tier, counted over a rolling period.
Concentration position
Critical business services mapped to providers, expressed as a share of services dependent on any single provider.
Fourth-party exposure
The number of critical relationships where material subcontractors are identified, assessed, and contractually disclosed.
Each indicator needs three attributes to be worth reporting:
- A defined breach trigger
- A named owner
- A source system that produces it without a manual data pull
Concentration and Fourth-Party Exposure
Concentration in a third-party context means dependency on a small number of providers for services the institution cannot readily replace. It differs from credit concentration, and it is measured against business services.
The 2023 Interagency Guidance treats dependency on a single provider for multiple activities as a consideration when assessing operational resilience, and it directs banking organizations to evaluate a third party's use of subcontractors according to the risk that arrangement poses to the institution.
Industry-level concentration compounds the exposure. Core processing, payment rails, and cloud infrastructure are where community and regional institutions most often discover they hold an unstated limit at 100 percent.
The fix is a limit expressed at the service level, supported by contractual disclosure of material subcontractors for every tier-one relationship. Institutions that have centralised third-party vendor management usually find the service-level view easier to assemble.
Board, Risk Committee, and the Three Lines
Under the 2023 Interagency Guidance the board holds ultimate oversight responsibility for the banking organization operating in a safe and sound manner and in compliance with applicable law. The guidance adds that directors should be aware of, and may approve or delegate approval of, contracts involving higher-risk activities.
The three lines divide the rest cleanly:
- The first line owns the relationship and operates inside the thresholds, which means the relationship manager has to know them.
- The second line sets and maintains the thresholds, aggregates the indicators, and challenges first-line decisions that sit at the edge of the band.
- Internal audit (the third line) tests whether the framework works as documented, including whether breaches were escalated when they occurred.
Name the forum for a tolerance breach and the forum for a limit breach and set a maximum elapsed time between detection and notification.
Monitoring Breaches and Reporting Appetite Adherence
A board pack that meets the standard shows position against each threshold by tier, breaches opened and closed in the period with remediation status, concentration position for critical services, and direction of travel across several quarters.
Thresholds govern only when the indicators behind them are measured continuously. An annual vendor review cycle produces an outdated snapshot. Continuous monitoring closes that window, which is why appetite work and investment in third-party risk monitoring software tend to arrive together.
Reconciliation disputes consume the committee time that should go to decisions. Governance, risk, and compliance platforms address this by holding assessment, monitoring, and reporting data in one place.
Predict360's third-party and vendor risk management module, for example, runs vendor assessments from a library of more than 750 standardized templates. The platform's Power BI reporting engine as provides a single source of truth.
Frequently Asked Questions
What is the difference between risk appetite and risk tolerance?
Appetite states which risks the institution accepts and which it does not. Tolerance is the measurable band around that direction, expressing how much variation is acceptable before action is required. A risk limit is stricter than both, functioning as a hard stop that cannot be crossed without formal escalation and a documented decision by the accountable committee.
How do you measure third party risk appetite?
Measurement works through key risk indicators tied to each threshold. Common indicators include open high-severity findings and their ageing by vendor tier, currency of independent assurance reports for critical vendors, service level breaches over a rolling period, concentration of critical business services by provider, and identification of material subcontractors.
Does the 2023 Interagency Guidance require a third-party risk appetite statement?
No. The 2023 Interagency Guidance on Third-Party Relationships sets risk-based expectations across the relationship life cycle and describes board oversight responsibilities without prescribing an appetite statement or a specific format. Separately, the OCC's heightened standards at 12 CFR Part 30 Appendix D require banks with average total consolidated assets of $50 billion or more to maintain a risk appetite statement with qualitative components and quantitative limits as part of their risk governance framework.
How often should a third-party risk appetite statement be reviewed?
Annual review aligned to the enterprise risk appetite cycle is common practice, with interim revision triggered by material change. Events that warrant an off-cycle review include a significant new critical relationship, a merger that changes the vendor portfolio, a material breach of a limit, a supervisory finding on third-party governance, or a change in the services a critical provider delivers.
The Predict360 Enterprise Risk Management Software ensures managers have complete visibility of enterprise risk on a single dashboard.
Request Demo- Cloud-Based
- Risk Repository
- Assess Risks
- Real-time Monitoring
- 1Appetite, Tolerance, and Limits Are Three Different Controls
- 2Why Enterprise Appetite Statements Break Down at the Vendor Layer
- 3Translating Enterprise Appetite into Third-Party Thresholds
- 4Setting Thresholds and Key Risk Indicators for Third-Party Exposure
- 5Concentration and Fourth-Party Exposure
- 6Board, Risk Committee, and the Three Lines
- 7Monitoring Breaches and Reporting Appetite Adherence
- 8Frequently Asked Questions