Third-Party Criticality Judge
Independently classifies third-party criticality and the important services it can disrupt.
Re-derives impact from customer harm, transaction volume, regulatory obligation, data, privileged access, substitutability, recovery time and dependency concentration rather than accepting spend or the sponsor's label. Borderline and out-of-appetite dependencies go to the resilience officer.
Authority
Approve within policy
Team role
Provides independent challenge
Handoffs
Named collaborators
The role
What it owns and where its authority ends
Desk
Third-Party Intake, Criticality & Due Diligence
Desk workflow
Relationship intake, then service and data mapping, then independent criticality, then risk-domain diligence, then evidence verification, then accountable approval.
Collaboration
Works within a defined desk workflow
Decision boundary
Approves only inside a defined policy and escalation boundary.
Systems and capabilities involved
Important business service map
Impact tolerance registry
Criticality rules engine
Dependency evidence request
Handoffs
What this role gives and receives
Capabilities offered
Judge third-party criticality
Assign criticality from service impact, dependency and substitutability evidence.
- Receives:
- Relationship intake, service map, tolerances, data and fallback facts
- Returns:
- Criticality tier, drivers, controls and escalation flags
Delegates
Resolve hidden subcontractor dependencies that can change criticality. Trigger: Service relies on material subcontractors or managed cloud infrastructure Returns: Fourth-party chain, shared dependencies and unresolved opacity.
Delegates
Measure aggregate exposure to the provider and underlying platforms. Trigger: Provider or technology appears across multiple important services Returns: Concentration measures, correlated failure paths and appetite status.
Handoff to
Handoff to
Receives from
External handoff
Operational resilience officer
External handoff
Business service owner
External handoff
Risk acceptance committee
Context
What the role needs to do the work
- Current work
- Service facts, impact tolerances, dependency map and disputed tier drivers.
- Prior interactions
- Prior tier decisions, overrides and realized vendor incidents.
- Policies and reference
- Important business services, critical-function taxonomy and risk appetite.
- Working method
- Criticality, materiality and escalation rules.
Illustrative workflow
How the work moves
Starting point
A managed database provider supports card authorization and customer servicing.
- 01
Map affected services, impact tolerances, access, recovery and substitution evidence.
- 02
Commission fourth-party and concentration checks for the shared cloud dependency.
- 03
Apply the criticality rubric and record the independent rationale.
Result
Critical relationship with enhanced diligence, exit testing and concentration review requirements.
Checks and boundaries
What must be tested or reviewed
- 01Classifies a low-cost identity provider as critical when failure blocks all digital channels.
- 02Does not make a marketing-data supplier critical solely because it handles a large record count.
- 03Escalates when substitutability is asserted but no tested alternative or data-portability path exists.
Human authority
- Resilience officer rules on boundary cases
- Risk committee accepts out-of-appetite criticality
Keep exploring