Most third-party risk management (TPRM) programs share a structural blind spot. They measure vendors along a single axis, risk, and then act as if a high score on that axis identifies which vendors could bring the business down. A vendor can be low-risk and still be the single point of failure that halts operations for days.
Risk vs. criticality
In most TPRM programs, “critical” is used loosely, often as a synonym for “high-risk.” But these are different questions that share similar vocabulary. Risk asks how likely a vendor is to cause harm and how exposed you are based on the vendor’s data access, security posture, financial health, and compliance gaps. Criticality asks a different question: if this vendor stopped delivering services tomorrow, how badly and how quickly would the business break?
Risk and criticality often move in different directions. A boutique analytics provider with weak controls and access to sensitive records may be high-risk, but its failure may not interrupt core operations. By contrast, a claims clearing house with strong controls, clean audits, and financial stability may appear low risk while still serving as the vendor whose outage stops the business. When a TPRM program scores only risk, it can focus too heavily on the first vendor and underweight the second.
Recent case studies
Two recent failures show the difference. In 2024, a cyberattack forced a healthcare technology company offline, disrupting claims, eligibility checks, prior authorizations, and remittance across the U.S. healthcare system. The Centers for Medicare and Medicaid Services created an emergency accelerated-payment program to help providers manage the cash-flow shock. Five months later, a faulty cybersecurity update crashed an estimated 8.5 million Windows devices worldwide, disrupting airlines, banks, hospitals, and emergency services. In both cases, the vendors were trusted, widely used providers, not obvious high-risk outliers. Their failures were not predicted by an inherent-risk score. They were failures of availability, concentration, and substitutability, which a risk-only lens is not designed to see.
The regulatory landscape
This is no longer just leading practice; it is increasingly written into law. The EU’s Digital Operational Resilience Act (DORA) came into application in January 2025 and frames third-party oversight around operational resilience and critical functions rather than risk alone. DORA requires financial entities to maintain a register of Information and Communication Technology (ICT) providers, build exit strategies that reduce single-provider reliance, and assess concentration risk. In November 2025, the European Supervisory Authorities designated an initial 19 Critical ICT Third-Party Providers, including major cloud platforms, for direct oversight. They were selected on systemic impact, substitutability, and interconnectedness, not on any single firm’s risk rating scale.
For any TPRM program, regulated or not, the message is straightforward: organizations need to know which third parties support important business services, how easily those providers can be replaced, and how operations would continue if one failed. These are questions of criticality and resilience, not risk alone.
Separating criticality from risk
This distinction changes what you measure, how you tier vendors, and where you focus oversight. Criticality should be scored on its own axis, based on business impact from disruption rather than likelihood of harm. The inputs are recovery-oriented and differ from a traditional risk questionnaire:
- Recovery tolerance. How long can the business function without the service before material impact?
- Substitutability. Does a viable alternative exist, and how long would it take to switch?
- Process dependency. How many critical processes route through this one vendor?
- Concentration and fourth-party exposure. Do other critical vendors depend on the same provider or its subcontractors?
- Incident history. Has the vendor shown it can detect, communicate, and recover from disruption?
Once risk and criticality are scored separately, the combination should drive oversight:
| Low Criticality | High Criticality | |
|---|---|---|
| High Risk | Diligence and remediation. Reduce exposure, but failure is survivable. | Highest priority. Remediate while building resilience, redundancy, and exit options. |
| Low Risk | Routine monitoring. Lightest touch. | The hidden danger zone. Clean on paper, catastrophic if it fails. Needs resilience planning regardless of risk score. |
Tiering should follow a combined view. The highest tier (high risk, high criticality) should receive the deepest oversight, including continuous monitoring, tested plans, recovery-time expectations, and resilience posture reporting. Because criticality changes as the business, vendor scope, and dependency landscape evolve, reassessments should be triggered by renewals, scope changes, incidents, and concentration shifts. The criticality view should be refreshed alongside the risk view.
From risk scoring to resilience
The real shift is from assessment to resilience. A risk score helps determine how much diligence a vendor requires; resilience oversight asks whether an organization can continue delivering important services when a critical vendor fails. Risk management still matters, but it answers a different question. Risk and criticality are separate measures. Treating them as one can hide the dependencies most likely to disrupt the business. Keeping them distinct, and acting on the integrated view, is what moves a program from documenting risk to building resilience.
How BDO Can Help
BDO helps organizations strengthen third-party risk management through a tailored, risk-based approach that spans the full relationship lifecycle. We can identify, assess, and address third-party risks by combining ongoing monitoring with technology-enabled insights. BDO supports organizations in enhancing compliance, improving operational resilience, and aligning risk management strategies to their specific objectives and risk appetite. Contact our Risk & Resilience team for a third-party risk assessment today.