In this article

Third Party Risk and Procurement in Banking: Cost vs. Control

Banks can reduce third-party risks by combining strong procurement oversight, automated risk scoring, and clear cybersecurity contracts. Lessons from major breaches highlight the need for ongoing monitoring and due diligence.

a man in a suit and tie looking at the camera
By Lewis Henderson, Director, Intelligence Communications

Published September 2, 2026

Third-party risk and procurement in banking

Banks and financial institutions rely on a complex network of third-party vendors to operate efficiently. Managing these relationships requires careful oversight to protect customer data, maintain compliance, and reduce operational risk. Procurement teams play a key role in embedding cybersecurity and regulatory controls into vendor selection and onboarding.

  • In this blog, we will explore best practices, lessons from past incidents, and practical strategies to strengthen procurement and risk management processes.

» Ensure your cybersecurity is up to standard with KELA

The Evolution of the Banking Ecosystem: From Fortress to Interconnected Network

Modern banking has shifted from a "closed fortress" model to a hyper-connected ecosystem. While this transformation allows for rapid innovation and cost-efficiency, it has created a profound reliance on external partners for critical infrastructure, changing the industry's risk profile.

The Structural and Tech Shifts

The transition to third-party reliance stems from a strategic pivot toward agility and the necessity of high-tier technical capabilities.

  • Focus on strategic specialization: Banks are divesting from non-core operational tasks to focus exclusively on financial product innovation and customer experience.
  • Infrastructure democratization: The move from on-premise servers to Cloud and SaaS models allows banks to access cutting-edge processing power without the heavy capital expenditure of building it themselves.
  • Efficiency and scalability: Utilizing specialized providers allows for "plug-and-play" scaling, enabling banks to handle massive data surges or new market entries without hiring thousands of internal staff.
Approximately 30% of all data breaches now involve a third party, with supply chain attacks roughly doubling between 2021 and 2025.

» Make sure you understand the difference between vulnerability, threat, and risk to strengthen your cybersecurity strategy

How Procurement Risk Management Differs

Procurement in banking is not a simple purchase-and-supply chain; it is an extension of the bank’s own regulatory perimeter.

  • Heightened liability: Banks are legally responsible for their vendors’ actions, meaning a third-party error is treated by regulators as an internal bank failure.
  • The trust mandate: Customer trust is a bank’s primary asset. A vendor data breach doesn't just lose money; it can trigger a systemic loss of confidence and "runs" on the institution.
  • Rigorous contractual safeguards: Unlike other sectors, bank contracts must include "right to audit" clauses, allowing regulators to inspect the vendor’s books directly.
  • Systemic importance: Because banks are part of the critical national infrastructure, their procurement failures can have a "domino effect" on the broader economy.

» Learn how supply chain threat intelligence strengthens your security posture

Challenges in Aligning Policy with Risk Frameworks

The primary struggle lies in moving from "check-the-box" compliance to a unified Enterprise Risk Management (ERM) approach.

  • The silo obstacle: Procurement teams often prioritize cost and speed, while ERM teams prioritize safety, creating internal friction and inconsistent vendor standards.
  • Visibility of sub-vendors: Banks struggle to track "fourth-party" risks, where their primary vendor outsources a service to an even less-vetted entity.
  • Fragmented data systems: Legacy internal systems often prevent a unified view of risk, making it difficult to verify if a supplier meets the bank’s latest security protocols in real-time.
  • Regulatory divergence: Global banks must align procurement with different (and often conflicting) risk frameworks across multiple jurisdictions.

» Here's everything you need to know about third-party risk management

Secure Your Supply Chain

KELA’s platform gives you real-time insights, continuous monitoring, and actionable intelligence to manage third-party security effectively.

Start for FREE
Learn more

Applying Third-Party Risk Management Across Key Banking Risk Domains

Procurement sits at the center of third-party risk management, translating policy and regulatory expectations into day-to-day vendor decisions that directly affect cybersecurity, compliance, and operational resilience across the bank.

Embedding Cybersecurity Controls in Vendor Selection and Onboarding

Procurement teams execute mission-critical TPRM measures during vendor selection and onboarding to strengthen supply chain resilience. A risk-based segmentation model is applied so due diligence is prioritized according to each vendor’s risk profile.

Cybersecurity due diligence and contractual controls:

  • Early cybersecurity due diligence for vendors handling sensitive data or requiring network access.
  • Contractual obligations mandating Multi-Factor Authentication and AES-256 encryption.
  • Formal accountability through Risk Acceptance approvals for any unmanaged risks.

Automation through GRC platforms embeds these requirements directly into procurement workflows, reinforcing governance, traceability, and accountability across the vendor lifecycle.

» Stay in the loop for our upcoming GRC agents — Be among the first to engage with KELA's evolving autonomous agent ecosystem as it rolls out.

Aligning Procurement Governance With Regulatory Expectations

Procurement governance frameworks apply third-party risk management across the entire vendor lifecycle in line with OCC, FCA, and DORA requirements. A risk-based segmentation approach ensures controls match the risk and criticality of each vendor relationship.

Before engagement, procurement carries out structured due diligence to assess vendor financial stability, cybersecurity controls, and legal compliance. Contracts clearly define security responsibilities, incident response requirements, and audit rights, allowing both the institution and regulators to review records throughout the relationship.

High-risk and critical vendors are monitored on an ongoing basis, while low-risk vendors are subject to lighter oversight. DORA further strengthens this approach by requiring procurement to confirm that third parties meet defined standards for digital resilience and cybersecurity.

» Learn more: The power of KELA's cyber threat intelligence platform

Oversight of AML and KYC Outsourcing Arrangements

Procurement governance plays a critical role in outsourced AML and KYC arrangements by aligning risk, compliance, and legal functions around shared control standards. Contracts mandate confidentiality, liability, and data protection obligations while requiring verification of third-party AML and CFT policies.

Outsourced AML and KYC services are categorized as critical, triggering enhanced due diligence and ongoing monitoring in line with EBA guidelines. Oversight includes audits and compliance reviews focused on:

  • Customer Identification Program requirements
  • Customer Due Diligence accuracy
  • Data integrity and confidentiality controls
Take Note: Contracts often require that data be returned or securely destroyed upon termination, typically documented with a formal certificate of destruction to confirm compliance.

Protecting Customer and Transactional Data in High-Risk Services

A defined risk-based procurement approach is applied when engaging cloud, analytics, and payment service providers. Cybersecurity capability is assessed during the intake phase, with controls scaled to the provider’s data access and processing scope. Key contractual protections include:

  1. Minimum encryption standards, such as AES-256, to protect data at rest and in transit.
  2. Enforced Multi-Factor Authentication for access to systems and data.
  3. Restrictions on data movement to limit unauthorized transfer or exposure.
  4. Clear data destruction procedures to ensure secure disposal at contract end
  5. Validation through recognized questionnaires to evidence control effectiveness.
  6. Contractual audit rights to support ongoing assurance.

This structure ensures customer and transactional data remains protected throughout the vendor relationship.

Collaboration Between Procurement and TPRM for Operational Continuity

Close collaboration between Procurement and TPRM ensures operational continuity and incident readiness for high-risk and critical vendors across the vendor lifecycle.

This collaboration focuses on three core areas:

  1. Contractual safeguards: Contracts require documented Business Continuity and Disaster Recovery plans, incident notification timelines, and remediation obligations.
  2. Due diligence and assessment: During onboarding, TPRM assesses vendor resilience and Incident Response capabilities.
  3. Continuous oversight: Ongoing monitoring validates adherence to SLAs, KRIs, and periodic BC and DR testing results.

» Here's everything you need to know about TPRM

Lessons From High-Profile Third-Party Incidents

Capital One, 2019

  • What happened: A former employee of Amazon Web Services exploited a misconfigured Web Application Server (WAF), exposing over 100 million customer records including personal and financial data. The breach occurred despite the bank outsourcing cloud infrastructure.
  • Lesson: Banks must enforce stricter risk assessments, validate cloud configurations, ensure credentials are managed and continuously monitor third-party services to ensure customer data remains protected even when using outsourced systems.

Industrial and Commercial Bank of China (ICBC), 2023

  • What happened: The U.S. arm of the world’s largest bank was hit by a LockBit ransomware attack triggered by an unpatched vulnerability (CitrixBleed) in a vendor’s gateway. The breach crippled ICBC’s ability to clear U.S. Treasury trades, forcing the bank to settle over $60 billion in transactions manually using USB sticks carried by messengers across Manhattan. To prevent a systemic collapse, the bank required a massive $9 billion capital injection to settle with BNY Mellon.
  • Lesson: Third-party software vulnerabilities can cripple even the most well-capitalized institutions. Patch management and rapid incident response are as critical as the initial vendor vetting process; a single unpatched "Citrix" or "NetScaler" product can bypass traditional perimeter defenses.

Bank of America (via Ernst & Young / MOVEit), 2023

  • What happened: Tens of thousands of Bank of America customers had their personal data exposed not through a direct hack, but through a fourth-party vulnerability. The Cl0p ransomware group exploited a zero-day flaw in MOVEit file transfer software used by Ernst & Young (EY), a third-party consultant for the bank. This chain of exposure highlighted how data can be compromised through a vendor’s own software providers.
  • Lesson: Visibility must extend beyond the first tier. "Fourth-party" risk—the vendors of your vendors—is a massive blind spot. Contracts and risk assessments must account for how third parties handle data and what software they use to process it, as the bank remains the entity accountable to the customer.

» Understand the difference between leaked credentials and compromised accounts to better protect your organization

Best Practices for Aligning Procurement Speed, Cost, and Regulatory Control

Banks face constant pressure to move faster and reduce costs in procurement, while still meeting strict regulatory expectations. The key is not choosing one over the other, but aligning procurement practices with risk.

The following approaches help procurement teams move efficiently without weakening third-party controls across the vendor lifecycle.

Risk-Based Segmentation and Due Diligence

Risk-based supplier segmentation allows procurement to focus time and effort where it matters most. High-risk and critical vendors receive deeper due diligence, while low-risk vendors follow streamlined review paths.

This approach reduces unnecessary checks, shortens onboarding timelines, and can lower procurement effort.

Technology and Automated Workflows

Using dedicated TPRM tools within procurement workflows reduces manual effort and accelerates assessments. Automation supports standardized questionnaires, real-time risk monitoring, and faster issue identification.

This allows procurement teams to progress low-risk engagements quickly, while risk and compliance teams focus on vendors that present higher operational or regulatory exposure.

» Did you know? Cybercriminals now exploit generative AI

Standardized Contractual Safeguards

Embedding security and compliance clauses into contract templates at onboarding creates consistency and speeds up negotiations. Pre-approved language for audit rights, incident response, data protection, and regulatory access reduces legal back-and-forth.

This approach helps procurement move faster while ensuring regulatory requirements are applied uniformly across vendor relationships.

Cross-Functional Governance and Early Risk Involvement

Aligning procurement, TPRM, legal, and compliance early in the RFP and vendor selection process prevents late-stage delays. Early risk visibility allows issues to be addressed before contracts are finalized, reducing rework and escalation.

This governance model supports faster decision-making while maintaining strong regulatory and risk oversight.

» Confused? Here's our guide to navigating third-party cyber threats

How KELA Supports You

KELA gives you real-time visibility, ongoing monitoring, and practical intelligence to keep third-party security under control.

Contact Us

How KELA Cyber Can Strengthen Vendor Risk Oversight

KELA Cyber gives procurement and risk teams clear, real-time visibility into vendor exposure, cyber posture, and dark web threats. Automated risk scoring and vendor categorization help you focus on high-risk relationships. Integration with procurement workflows ensures timely assessments, while dashboards track compliance and key risk indicators.

Predictive algorithms flag potential risks before they materialize. With KELA Cyber, banks can confidently onboard and monitor vendors while reducing operational and reputational risk.

» Ready to begin? Contact us to learn more about our third-party intelligence

FAQs

Why is third-party risk management critical for banks?

Third-party vendors can introduce cybersecurity, operational, and compliance risks, making structured oversight essential for protecting data and maintaining trust.

How can procurement teams balance speed, cost, and regulatory requirements?

By using risk-based segmentation, automation, standardized contracts, and cross-functional governance to prioritize high-risk vendors while streamlining low-risk engagements.

How can banks protect sensitive customer and transactional data with vendors?

Banks should enforce encryption, Multi-Factor Authentication, data movement restrictions, clear destruction procedures, and contractual audit rights to ensure data safety.

How can operational continuity be maintained with critical vendors?

By including business continuity and incident response requirements in contracts, performing thorough onboarding assessments, and monitoring vendors regularly to detect and resolve issues quickly.



Related Articles

DORA Third Party Risk Management: Beyond Basic Compliance

DORA Third Party Risk Management: Beyond Basic Compliance

KELA Cyber Intelligence Center

September 2, 2026

4 Third Party Risk Management Frameworks Every CISO Needs

4 Third Party Risk Management Frameworks Every CISO Needs

KELA Cyber Intelligence Center

September 3, 2026

The Role of Risk Management in the Financial Services Industry

The Role of Risk Management in the Financial Services Industry

KELA Cyber Intelligence Center

September 4, 2026

NIST Third Party Risk Management: A Complete Strategic Guide

NIST Third Party Risk Management: A Complete Strategic Guide

KELA Cyber Intelligence Center

September 4, 2026