Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach

SEI Report
A resilience-based approach can help financial services organizations to manage cybersecurity risks from outsourcing and comply with federal regulations.
Publisher

Software Engineering Institute

Abstract

Outsourcing to third parties and the resulting dependency risks have become a leading consideration for financial services firms, drawing extensive management attention and regulatory scrutiny. This is particularly true for third party risks that arise from the use of information and communication technology (ICT), which may include data breaches, fraud, access to sensitive internal information, reputation impacts, or disclosure of intellectual property. These concerns are exacerbated by a pervasive and dynamic cybersecurity threat landscape. Attackers know that third party suppliers can be a weak link and target them accordingly.

Recent, high profile incidents involving the financial industry highlight the unexpected or unintended consequences that can arise when organizations outsource support and processing activities. This is particularly true for customer-facing services supported by outsourced information technology. Regulators have emphasized careful oversight of third party suppliers and have strongly urged senior management to more directly engage in this area of risk management. 

Cite This SEI Report

Haller, J., & Wallen, C. (2016, September 27). Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach. Retrieved August 10, 2026, from https://www.sei.cmu.edu/library/managing-third-party-risk-in-financial-services-organizations-a-resilience-based-approach/.

@techreport{haller_2016,
author={Haller, John and Wallen, Charles},
title={Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach},
month={Sep},
year={2016},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/managing-third-party-risk-in-financial-services-organizations-a-resilience-based-approach/},
note={Accessed: 2026-Aug-10}
}

Haller, John, and Charles Wallen. "Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, September 27, 2016. https://www.sei.cmu.edu/library/managing-third-party-risk-in-financial-services-organizations-a-resilience-based-approach/.

J. Haller, and C. Wallen, "Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 27-Sep-2016 [Online]. Available: https://www.sei.cmu.edu/library/managing-third-party-risk-in-financial-services-organizations-a-resilience-based-approach/. [Accessed: 10-Aug-2026].

Haller, John, and Charles Wallen. "Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 27 Sep. 2016. https://www.sei.cmu.edu/library/managing-third-party-risk-in-financial-services-organizations-a-resilience-based-approach/. Accessed 10 Aug. 2026.

Haller, John; & Wallen, Charles. Managing Third Party Risk in Financial Services Organizations: A Resilience-Based Approach. Software Engineering Institute. 2016. https://www.sei.cmu.edu/library/managing-third-party-risk-in-financial-services-organizations-a-resilience-based-approach/