TPRM glossary

Third-party vendor, every vendor is a third party; not every third party is a vendor

A third-party vendor is an external organisation that supplies goods or services to you under a commercial arrangement. The term overlaps with "third party" but is narrower: a third party is anyone outside your organisation whose failure reaches you, including parties you have no purchase order with.

Why the distinction is worth keeping

A vendor is someone you buy from. A third party is anyone outside your organisation whose failure lands on you — which includes vendors, and also includes parties with no purchase order: joint venture partners, agents and introducers, franchisees, resellers, and organisations you share data with without paying for the privilege.

The distinction bites at exactly one moment, and it is an expensive one. A register built by exporting the supplier list from finance is complete for spend and incomplete for risk, because the parties it omits are precisely the ones nobody has assessed. Scoping a programme as "vendor risk" and then reporting it as third-party risk coverage is a very common way to be wrong in a board pack.

First, second, third and fourth parties

The numbering confuses people because it is not one convention. In commercial usage the first party is you, the second party is your customer or counterparty, the third party is an external organisation you engage, and the fourth partyis your third party's supplier.

What matters more than the numbering is that risk transmits along the chain regardless of where your contract stops. Your obligations to customers and regulators do not become somebody else's because the failure happened two organisations away — which is the whole reason third-party risk management is a discipline rather than a procurement checkbox.

Common questions

What is the difference between a third party and a third-party vendor?
A third-party vendor supplies goods or services under a commercial arrangement. A third party is broader: anyone outside your organisation whose failure reaches you, including partners, agents, franchisees and data-sharing counterparties you do not pay. Every vendor is a third party; not every third party is a vendor.
What is third-party vendor management?
The end-to-end management of supplier relationships — onboarding, due diligence, contracting, performance and risk monitoring, and offboarding. Vendor risk management is the risk-focused subset of it, concentrating on what the relationship exposes you to rather than on how well the vendor performs commercially.
Who is a fourth party?
Your third party’s supplier — the hosting, payment, identity or support providers your vendor depends on. You have no contract with them, but their failure reaches you through the vendor you do contract with.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.