Appearance
Journey: Third-Party Onboarding
A material outsourcing arrangement, from proposal to approved engagement under lifecycle governance.
Fictional example.
The proposal
The bank intends to move core banking platform hosting to a cloud infrastructure provider. The provider already supplies two other services to the group.
Week 1 — The party already exists
Third party TP-2026-0018 is already registered, with two existing engagements:
| Engagement | Service | Criticality |
|---|---|---|
ENG-2026-0042 | Development and test environments | Medium |
ENG-2026-0057 | Marketing analytics platform | Low |
The party carries no risk rating
Two existing engagements at Medium and Low criticality say nothing about the new one.
One legal entity, three radically different risk propositions. Rating the party would force a single answer that is wrong for at least two of them.
Party-level facts already recorded: certifications held with validity dates, entity registration, relationship owner.
Week 1 — The engagement
Engagement ENG-2026-0041:
| Field | Value |
|---|---|
| Service | Core banking platform hosting |
| Business service | Core Banking |
| Owner | Head of Technology Sourcing |
| Contract term | Three years |
| Renewal notice | 180 days before expiry |
Week 2 — Criticality determination
The business dependency question, answered independently of any regulator.
Determination: Critical.
"The service supports the Core Banking business service. An outage exceeding four hours breaches the impact tolerance stated in
BIA-2026-0003."
Requires tprm.assess.
Criticality links to the BIA, not to a subjective scale
Grounding criticality in the stated impact tolerance from the business impact analysis means the determination is testable rather than a matter of opinion.
Week 2 — Regulatory classification
A different test with different criteria.
Classification: Material outsourcing, proposed and confirmed, with the framework code and rule version recorded.
Requires tprm.classify.
Criticality and classification are separate judgements
Your internal view of business criticality and the regulator's definition of materiality are different tests. An arrangement can be operationally low-criticality and regulatorily material, or the reverse.
Recording them separately means you can hold both truthfully and explain the difference when asked.
Weeks 3 to 6 — Due diligence
A questionnaire run is issued: 84 questions.
Provider response includes a service organisation control report and a penetration test summary.
Review finds two issues:
| Issue | Detail |
|---|---|
| Control report scope | Excludes the disaster recovery region this engagement will use |
| Exit plan | Not tested since the arrangement's scope expanded |
A questionnaire is testimony, not assurance
The provider's responses are what they told you. The value is as an input to the risk assessment and as a record of what was represented.
The control report scope gap was found by reading the report, not by reading the questionnaire response — which had answered the question affirmatively.
Week 7 — Risk assessment
Drawing on the criticality determination, the classification, the questionnaire and the independent assurance supplied.
| Element | Value |
|---|---|
| Inherent risk | Critical |
| Provider controls | Independently assured, with the scope gap noted |
| Exit plan | Documented; not recently tested |
| Concentration | Third engagement with this provider; two support important business services |
| Residual risk | Medium |
Two canonical findings are raised in the shared findings register with the source Third-Party Risk:
| Finding | Subject |
|---|---|
FND-2026-0088 | Provider control report scope excludes the DR region used by this engagement |
FND-2026-0089 | Exit plan not tested since the scope expansion |
TPRM maintains no separate issue log.
Week 8 — The decision
Submitted by the Technology Sourcing Analyst. Decided by the Head of Third-Party Risk.
The analyst who prepared it could not decide it
Segregation of duties on the decision stage. And tprm.decide is never auto-granted — a Tenant Administrator holds tprm.manage and still cannot make this decision.
Decision: Approve with conditions.
| Condition | Tracked as | Owner | Due |
|---|---|---|---|
| Provider control report extended to cover the DR region | ACT-2026-0261 | Head of Technology Sourcing | 90 days |
| Exit plan retested | ACT-2026-0262 | Head of Operational Resilience | 120 days |
| Field | Value |
|---|---|
| Review date | 12 months, set deliberately |
| Reassessment frequency | 12 months, guidance only |
| Residual | Medium, within appetite |
Approve with conditions is the decision that actually gets made
Real arrangements are rarely fully compliant on day one and rarely bad enough to refuse. Recording it as a distinct outcome with tracked conditions is what stops it degrading into an unconditional approval nobody follows up.
Day 90 — The first condition
ACT-2026-0261 is complete and verified. The provider's control report has been extended.
Day 120 — The second condition
ACT-2026-0262 is overdue. The exit plan retest has not happened.
What surfaces automatically:
| Effect | Where |
|---|---|
| Overdue action signal | On RSK-2026-0033, the concentration risk linked to this engagement |
| Workbench item | In the Head of Operational Resilience's queue |
The conditional approval did not quietly become an unconditional one.
Day 142. The exit plan is retested. The test identifies that migration back in-house would take 14 weeks against a stated 8-week expectation. The condition is closed and a new finding is raised on the exit plan assumption.
Month 11 — Review approaching
Alert policies fire at 30 days before the review date:
| Trigger | Recipients |
|---|---|
engagement_review_due | Engagement owner, Head of Third-Party Risk |
The GRC Calendar shows the review date.
The review date was set, not derived
Reassessment frequency is guidance. OrviQ does not compute a review date from it.
An engagement with no review date reports none — correctly saying nobody has scheduled a review, rather than showing a plausible derived date nobody committed to.
Month 12 — Reassessment
Reassessment advances next_review_date. It overwrites nothing.
New records added:
| Record | Change from prior |
|---|---|
| Criticality determination | Unchanged at Critical; new row |
| Regulatory classification | Unchanged at Material; new row |
| Questionnaire run | New run; 84 questions |
| Risk assessment | Residual moves Medium to Low-Medium, reflecting the extended control report scope |
History preserved:
| Record type | Entries after 12 months |
|---|---|
| Criticality determinations | 2 |
| Regulatory classifications | 2 |
| Risk assessments | 2 |
| Questionnaire runs | 2 |
| Engagement decisions | 1 |
Every prior row is superseded, not replaced. The question "what was our assessment of this arrangement at onboarding?" has a dated answer.
What the journey demonstrates
| Principle | Where |
|---|---|
| The party carries no risk rating | Week 1 — three engagements, three profiles |
| Criticality and classification are separate tests | Week 2 |
| A questionnaire is testimony, not assurance | Weeks 3 to 6 |
| Findings go in the shared register | Week 7 |
tprm.decide is never auto-granted | Week 8 |
| Preparers cannot decide | Week 8 |
| Conditions are tracked records, not decision notes | Days 90 and 120 |
| An overdue condition surfaces as a risk signal | Day 120 |
| Review dates are set, not derived | Month 11 |
| Assessments are insert-only | Month 12 |