Third-party errors hit operational flow
,

Third-party errors hit operational flow

Third party errors have hit the operational flow of over eight in ten businesses (84 per cent), according to a pole of executive risk committees. Impacts include operational disruptions, financial or reputational loss and increased scrutiny from regulars – sometimes leading to regulatory action (34 per cent), according to the researcher Gartner. On the rise The…

Third party errors have hit the operational flow of over eight in ten businesses (84 per cent), according to a pole of executive risk committees.

Impacts include operational disruptions, financial or reputational loss and increased scrutiny from regulars – sometimes leading to regulatory action (34 per cent), according to the researcher Gartner.

On the rise

The use of third parties for vital business operations is on the rise. But the researcher found that many businesses have become more dependent on such suppliers for services that perform core business operations – thereby increasing the risk of loss.

In response, organisations have increased their use of enterprise risk management (ERM) since 2016 to mitigate these new risks. “Just doing more isn’t enough because the characteristics of third-party risk undermine the effectiveness of a typical ERM setup,” Chris Matlock, vice president, research in the Gartner legal, risk and compliance practice, said.

That is because ERM struggle to elevate the right issues because it does not focus on a management set of issues. “ERM leaders are not clearly defining which issues must be acted on first, and they are not typically preparing their audiences well to take tangible steps on the issues they surface,” the report said.

Not focused

The researcher suggests taking three measures to combat such losses.

First, since third-party risks are high-volume and varied, they can be hard to identify. Risk managers should focus on identifying and understanding the ones that affect the whole enterprise.

Second, risk managers must work with risk owners throughout the business to create a holistic view of those risks. “In practice, this means facilitating direct thought-partnership between risk co-owners with ERM adding expertise and aligning actions, as opposed to ERM acting as a central co-ordinator of all risk information and mitigation,” the report said.

Finally, risk managers should narrow the focus on third-party emerging risks so that they track only those issues that are critical to the business.

IRM offers the supply chain risk management certificate for those planning to skill up in this area. See our website for more information.





← Previous

<strong>Mixed messages over business confidence</strong>
Surveys are showing mixed messages over business confidence making it difficult to predict investment trends.…






Next →

Whitepaper: EU’s Digital Operational Resilience Act: Your Guide to ICT Risk Management
The EU’s Digital Operational Resilience Act (DORA), due to be enforced in 2023/24, introduces EU-wide…

7 OCTOBER 2026

Key elements of a mature programme risk capability

Hosted by Vinay Shrivastava. Vinay's presentation will cover lessons he has learned over the course of his career. These insights will be shared using the principles of ISO31000 risk management.

Find out more

8 OCTOBER 2026

Pre-deployment agentic risk management

Delivered by Adam Grainger, the outcome of this session is to be able to support an agentic implementation with effective pre-deployment risk identification and mitigation.

Find out more

14 OCTOBER 2026

AI Transforming Enterprise Risk Management Activities

Risk management has changed considerably over the years, with new frameworks, standards and expectations shaping the way organisations manage risk. However, many of the day-to-day activities within Enterprise Risk Management (ERM) functions have remained much the same.

Find out more

Advertisement