From compliance to capability: the evolving role of third-party risk management in strengthening organisational resilience
DOI:
https://doi.org/10.3846/bm.2026.2502Abstract
The financial sector is highly dependent on ICT third-party service providers for the delivery of critical business processes. The Digital Operational Resilience Act (DORA), which came into force on 17 January 2025 and applies to all European Union financial institutions, has significantly increased the regulatory and managerial relevance of third-party risk management (TPRM) as a core component of organisational resilience governance. As TPRM evolves as a strategic capability within non-financial risk management, understanding expected regulatory and organisational developments within a 3- to 5-year horizon is essential for strengthening resilience and supporting effective management decision-making. This study examines expert perspectives on the future development of ICT TPRM in the Baltic banking industry. It is based on thirteen semi-structured interviews with professionals involved in ICT third-party governance and risk management, analysed using qualitative content analysis. The findings suggest that while core TPRM principles will remain stable, managerial focus will shift towards execution quality, organisational maturity, and embedding resilience thinking into governance processes. Experts expect greater standardisation, enhanced board-level visibility, expanded oversight of fourth and Nth parties, and increased use of automation and analytical tools. TPRM is transitioning from a compliance-driven function towards a strategic management capability supporting organisational resilience through improved transparency, accountability, and higher execution quality.
Keywords:
third-party risk management, ICT third-party risk, risk governance, financial sector, organisational resilienceHow to Cite
Buch, C. (2024, April 10). Financial integration in the Baltics: Lessons in resilience and transformation. https://www.bankingsupervision.europa.eu/press/speeches/date/2024/html/ssm.sp241004~9588c58d39.en.html
Buttigieg, C. P., & Zimmermann, B. B. (2024). The digital operational resilience act: Challenges and some reflections on the adequacy of Europe’s architecture for financial supervision. ERA Forum, 25(1), 11–28. https://doi.org/10.1007/s12027-024-00793-w
Crisanto, J. C., Ehrentraud, J., Fabian, M., & Monteil, A. (2022). Big tech interdependencies – a key policy blind spot. Bank for International Settlements. https://www.bis.org/fsi/publ/insights44.pdf
Ellex. (2025). Baltic Fintech Legal Outlook 2025. https://ellex.legal/wp-content/uploads/2025/02/baltic-fintech-legal-outlook-2025.pdf
Enria, A. (2023, June 20). The role of banks in mitigating systemic risks arising in the non-bank financial sector. https://www.bankingsupervision.europa.eu/press/speeches/date/2023/html/ssm.sp230620~ecce24f124.en.html
European Banking Authority. (2019). Final report on EBA guidelines on outsourcing arrangements (EBA/GL/201902). https://www.eba.europa.eu/sites/default/files/documents/10180/2551996/38c80601-f5d7-4855-8ba3-702423665479/EBA%20revised%20Guidelines%20on%20outsourcing%20arrangements.pdf
European Banking Authority. (2025). The EBA launches consultation on its draft Guidelines on third-party risk management with regard to non-ICT related services. https://www.eba.europa.eu/publications-and-media/press-releases/eba-launches-consultation-its-draft-guidelines-third-party-risk-management-regard-non-ict-related
Gai, K., Qiu, M., & Sun, X. (2018). A survey on FinTech. Journal of Network and Computer Applications, 103, 262–273. https://doi.org/10.1016/j.jnca.2017.10.011
Gellert, G. A., Borgasano, D., Palermo, R., Gellert, G. L., & Kelly, S. P. (2025). Third-party access cybersecurity threats and precautions: A survey of healthcare delivery organizations. Applied Clinical Informatics, 16(5), 1518–1530. https://doi.org/10.1055/a-2713-5725
Giacchero, A., & Moretti, J. (2021). A possible holistic framework to manage ICT third-party risk in the age of cyber risk. Risk Management Magazine, 16(1), 30–42. https://doi.org/10.47473/2020rmm0082
Harju, A., Schaëfer, K., Hallikas, J., & Kähkönen, A.-K. (2024). The role of risk management practices in IT service procurement: A case study from the financial services industry. Journal of Purchasing and Supply Management, 30(2), Article 100899. https://doi.org/10.1016/j.pursup.2024.100899
Kolo, F. H. O., Joseph, S. A., Ogunmolu, A. M., Ejiofor, V. O., & Oyekunle, S. M. (2025). Mitigating cybersecurity risks in financial institutions through strategic third- party risk governance frameworks. Journal of Engineering Research and Reports, 27(5), 173–193. https://doi.org/10.9734/jerr/2025/v27i51501
Korneev, V., Dziubliuk, O., Tymkiv, A., Antkiv, V., & Kucherenko, N. (2023). Banking sector stability and economic development: Assessment of risks and efficiency. Economic Affairs, 68(3), 1683–1692. https://doi.org/10.46852/0424-2513.3.2023.33
Mavlutova, I., Spilbergs, A., Verdenhofs, A., Natrins, A., Arefjevs, I., & Volkova, T. (2022). Digital transformation as a driver of the financial sector sustainable development: An impact on financial inclusion and operational efficiency. Sustainability, 15(1), Article 207. https://doi.org/10.3390/su15010207
Operational Riskdata eXchange Association. (2025). Top Risk Review H1 2025. https://orx.org/resource/top-risk-review-h1-2025
Operational Riskdata eXchange Association. (2026). Third party risk management practices. https://orx.org/resource/third-party-risk-management-practices
Saveljeva, J. (2025, June 15–19). Third-party risk in research: A literature review. In Proceedings of the 35th European Safety and Reliability Conference and the 33rd Society for Risk Analysis Europe Conference (pp. 267–274). Stavanger, Norway. https://doi.org/10.3850/978-981-94-3281-3_ESREL-SRA-E2025-P8074-cd
The European Parliament, & The Council of the European Union. (2022). Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (2022, December 14, No. 32022R2554). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
Vashisht, S., Sarva, M., & Mundi, H. S. (2022). Risks measurement in banking: A bibliometric and content analysis. International Social Science Journal, 72(246), 955–977. https://doi.org/10.1111/issj.12371
Wittlin, J., Ossowska, A., & Sawicka, K. (2026). Is DORA an opportunity for more balanced distribution of third-party risk management assurance responsibilities between banks, regulators and technology providers? Information & Communications Technology Law, 35(1), 109–116. https://doi.org/10.1080/13600834.2025.2514385
Downloads
Published
Conference Event
Section
Copyright
License

This work is licensed under a Creative Commons Attribution 4.0 International License.
