Skip to content

Journey: Third-Party Onboarding

A material outsourcing arrangement, from proposal to approved engagement under lifecycle governance.

Fictional example.


The proposal

The bank intends to move core banking platform hosting to a cloud infrastructure provider. The provider already supplies two other services to the group.


Week 1 — The party already exists

Third party TP-2026-0018 is already registered, with two existing engagements:

EngagementServiceCriticality
ENG-2026-0042Development and test environmentsMedium
ENG-2026-0057Marketing analytics platformLow

The party carries no risk rating

Two existing engagements at Medium and Low criticality say nothing about the new one.

One legal entity, three radically different risk propositions. Rating the party would force a single answer that is wrong for at least two of them.

Party-level facts already recorded: certifications held with validity dates, entity registration, relationship owner.


Week 1 — The engagement

Engagement ENG-2026-0041:

FieldValue
ServiceCore banking platform hosting
Business serviceCore Banking
OwnerHead of Technology Sourcing
Contract termThree years
Renewal notice180 days before expiry

Week 2 — Criticality determination

The business dependency question, answered independently of any regulator.

Determination: Critical.

"The service supports the Core Banking business service. An outage exceeding four hours breaches the impact tolerance stated in BIA-2026-0003."

Requires tprm.assess.

Criticality links to the BIA, not to a subjective scale

Grounding criticality in the stated impact tolerance from the business impact analysis means the determination is testable rather than a matter of opinion.


Week 2 — Regulatory classification

A different test with different criteria.

Classification: Material outsourcing, proposed and confirmed, with the framework code and rule version recorded.

Requires tprm.classify.

Criticality and classification are separate judgements

Your internal view of business criticality and the regulator's definition of materiality are different tests. An arrangement can be operationally low-criticality and regulatorily material, or the reverse.

Recording them separately means you can hold both truthfully and explain the difference when asked.


Weeks 3 to 6 — Due diligence

A questionnaire run is issued: 84 questions.

Provider response includes a service organisation control report and a penetration test summary.

Review finds two issues:

IssueDetail
Control report scopeExcludes the disaster recovery region this engagement will use
Exit planNot tested since the arrangement's scope expanded

A questionnaire is testimony, not assurance

The provider's responses are what they told you. The value is as an input to the risk assessment and as a record of what was represented.

The control report scope gap was found by reading the report, not by reading the questionnaire response — which had answered the question affirmatively.


Week 7 — Risk assessment

Drawing on the criticality determination, the classification, the questionnaire and the independent assurance supplied.

ElementValue
Inherent riskCritical
Provider controlsIndependently assured, with the scope gap noted
Exit planDocumented; not recently tested
ConcentrationThird engagement with this provider; two support important business services
Residual riskMedium

Two canonical findings are raised in the shared findings register with the source Third-Party Risk:

FindingSubject
FND-2026-0088Provider control report scope excludes the DR region used by this engagement
FND-2026-0089Exit plan not tested since the scope expansion

TPRM maintains no separate issue log.


Week 8 — The decision

Submitted by the Technology Sourcing Analyst. Decided by the Head of Third-Party Risk.

The analyst who prepared it could not decide it

Segregation of duties on the decision stage. And tprm.decide is never auto-granted — a Tenant Administrator holds tprm.manage and still cannot make this decision.

Decision: Approve with conditions.

ConditionTracked asOwnerDue
Provider control report extended to cover the DR regionACT-2026-0261Head of Technology Sourcing90 days
Exit plan retestedACT-2026-0262Head of Operational Resilience120 days
FieldValue
Review date12 months, set deliberately
Reassessment frequency12 months, guidance only
ResidualMedium, within appetite

Approve with conditions is the decision that actually gets made

Real arrangements are rarely fully compliant on day one and rarely bad enough to refuse. Recording it as a distinct outcome with tracked conditions is what stops it degrading into an unconditional approval nobody follows up.


Day 90 — The first condition

ACT-2026-0261 is complete and verified. The provider's control report has been extended.


Day 120 — The second condition

ACT-2026-0262 is overdue. The exit plan retest has not happened.

What surfaces automatically:

EffectWhere
Overdue action signalOn RSK-2026-0033, the concentration risk linked to this engagement
Workbench itemIn the Head of Operational Resilience's queue

The conditional approval did not quietly become an unconditional one.

Day 142. The exit plan is retested. The test identifies that migration back in-house would take 14 weeks against a stated 8-week expectation. The condition is closed and a new finding is raised on the exit plan assumption.


Month 11 — Review approaching

Alert policies fire at 30 days before the review date:

TriggerRecipients
engagement_review_dueEngagement owner, Head of Third-Party Risk

The GRC Calendar shows the review date.

The review date was set, not derived

Reassessment frequency is guidance. OrviQ does not compute a review date from it.

An engagement with no review date reports none — correctly saying nobody has scheduled a review, rather than showing a plausible derived date nobody committed to.


Month 12 — Reassessment

Reassessment advances next_review_date. It overwrites nothing.

New records added:

RecordChange from prior
Criticality determinationUnchanged at Critical; new row
Regulatory classificationUnchanged at Material; new row
Questionnaire runNew run; 84 questions
Risk assessmentResidual moves Medium to Low-Medium, reflecting the extended control report scope

History preserved:

Record typeEntries after 12 months
Criticality determinations2
Regulatory classifications2
Risk assessments2
Questionnaire runs2
Engagement decisions1

Every prior row is superseded, not replaced. The question "what was our assessment of this arrangement at onboarding?" has a dated answer.


What the journey demonstrates

PrincipleWhere
The party carries no risk ratingWeek 1 — three engagements, three profiles
Criticality and classification are separate testsWeek 2
A questionnaire is testimony, not assuranceWeeks 3 to 6
Findings go in the shared registerWeek 7
tprm.decide is never auto-grantedWeek 8
Preparers cannot decideWeek 8
Conditions are tracked records, not decision notesDays 90 and 120
An overdue condition surfaces as a risk signalDay 120
Review dates are set, not derivedMonth 11
Assessments are insert-onlyMonth 12

OrviQ Enterprise Governance, Risk & Compliance Platform