Skip to content
Resilience agents
Risk, Trust & ResilienceResilienceThird-Party Intake, Criticality & Due Diligence

Third-Party Criticality Judge

Independently classifies third-party criticality and the important services it can disrupt.

Re-derives impact from customer harm, transaction volume, regulatory obligation, data, privileged access, substitutability, recovery time and dependency concentration rather than accepting spend or the sponsor's label. Borderline and out-of-appetite dependencies go to the resilience officer.

Authority

Approve within policy

Team role

Provides independent challenge

Handoffs

Named collaborators

The role

What it owns and where its authority ends

Desk

Third-Party Intake, Criticality & Due Diligence

Desk workflow

Relationship intake, then service and data mapping, then independent criticality, then risk-domain diligence, then evidence verification, then accountable approval.

Collaboration

Works within a defined desk workflow

Decision boundary

Approves only inside a defined policy and escalation boundary.

Systems and capabilities involved

  • Important business service map

  • Impact tolerance registry

  • Criticality rules engine

  • Dependency evidence request

Handoffs

What this role gives and receives

Capabilities offered

Judge third-party criticality

Assign criticality from service impact, dependency and substitutability evidence.

Receives:
Relationship intake, service map, tolerances, data and fallback facts
Returns:
Criticality tier, drivers, controls and escalation flags

Delegates

Fourth-Party Dependency Mapper

Resolve hidden subcontractor dependencies that can change criticality. Trigger: Service relies on material subcontractors or managed cloud infrastructure Returns: Fourth-party chain, shared dependencies and unresolved opacity.

Delegates

Third-Party Concentration Monitor

Measure aggregate exposure to the provider and underlying platforms. Trigger: Provider or technology appears across multiple important services Returns: Concentration measures, correlated failure paths and appetite status.

External handoff

Operational resilience officer

External handoff

Business service owner

External handoff

Risk acceptance committee

Context

What the role needs to do the work

Current work
Service facts, impact tolerances, dependency map and disputed tier drivers.
Prior interactions
Prior tier decisions, overrides and realized vendor incidents.
Policies and reference
Important business services, critical-function taxonomy and risk appetite.
Working method
Criticality, materiality and escalation rules.

Illustrative workflow

How the work moves

Starting point

A managed database provider supports card authorization and customer servicing.

  1. 01

    Map affected services, impact tolerances, access, recovery and substitution evidence.

  2. 02

    Commission fourth-party and concentration checks for the shared cloud dependency.

  3. 03

    Apply the criticality rubric and record the independent rationale.

Result

Critical relationship with enhanced diligence, exit testing and concentration review requirements.

Checks and boundaries

What must be tested or reviewed

  1. 01Classifies a low-cost identity provider as critical when failure blocks all digital channels.
  2. 02Does not make a marketing-data supplier critical solely because it handles a large record count.
  3. 03Escalates when substitutability is asserted but no tested alternative or data-portability path exists.

Human authority

  • Resilience officer rules on boundary cases
  • Risk committee accepts out-of-appetite criticality

Keep exploring