Skip to main content
← All controls
SR-2 / A.15.1.1 / CIS-15.1 NIST SP 800-161 Rev 1

Is there a documented risk appetite for third-party risk (e.g. acceptable concentration, residual risk thresholds)?

Demonstrate that the organization has formally documented, approved, and operationalized risk appetite statements specific to third-party relationships, including quantitative thresholds for concentration, residual risk acceptance, and aggregate exposure.

Description

What this control does

This control requires the organization to formally define and document acceptable risk thresholds for third-party relationships. It establishes measurable limits such as maximum vendor concentration (percentage of critical vendors in a single industry or geography), residual risk scores that require executive escalation, and aggregate exposure ceilings. Without documented appetite, vendor selection and monitoring decisions become arbitrary, inconsistent across business units, and may accumulate systemic risk. The documented appetite should align with the organization's overall risk tolerance and guide vendor onboarding, ongoing assessments, and offboarding decisions.

Control objective

What auditing this proves

Demonstrate that the organization has formally documented, approved, and operationalized risk appetite statements specific to third-party relationships, including quantitative thresholds for concentration, residual risk acceptance, and aggregate exposure.

Associated risks

Risks this control addresses

  • Single-vendor concentration creates catastrophic business continuity exposure if that vendor experiences outage, bankruptcy, or security incident
  • Accumulation of high-residual-risk vendors without executive oversight leads to systemic organizational risk exceeding board-approved tolerance
  • Geographic or regulatory concentration exposes the organization to correlated failures from regional events, sanctions, or regulatory changes
  • Inconsistent risk acceptance decisions across business units result in vendors with unacceptable risk profiles gaining access to critical systems
  • Lack of quantitative thresholds prevents early warning when aggregate third-party risk approaches unacceptable levels
  • Absence of documented appetite enables individual procurement decisions to override organizational risk strategy
  • Undefined residual risk thresholds create liability exposure when incidents occur with vendors leadership never formally approved

Testing procedure

How an auditor verifies this control

  1. Request the organization's formal third-party risk appetite statement or policy document from senior risk management or third-party governance teams
  2. Verify the document includes quantitative thresholds such as maximum percentage of critical services from single vendor, maximum concentration by geography or industry, and numeric residual risk scores requiring escalation
  3. Obtain board or executive committee meeting minutes demonstrating formal approval of the risk appetite statement within the past 12-24 months
  4. Review the vendor inventory or third-party risk register to identify current concentration metrics (e.g., count of critical vendors, geographic distribution, industry clustering)
  5. Compare current vendor concentration data against documented appetite thresholds to verify the organization is operating within stated limits
  6. Select a sample of 5-8 vendor risk assessments completed in the past 12 months and verify residual risk scores were evaluated against documented thresholds
  7. Trace at least two instances where vendors exceeded risk appetite thresholds to verify escalation occurred per policy and decisions were documented by appropriate authority level
  8. Interview third-party risk management personnel to confirm they actively use the risk appetite statement in vendor selection, ongoing monitoring, and remediation prioritization decisions
Evidence required Collect the signed and dated third-party risk appetite policy or framework document, executive or board approval records, vendor inventory with concentration metrics (vendor count by criticality tier, geographic distribution, industry categorization), sample vendor risk assessment reports showing residual risk scores, and escalation records for vendors exceeding thresholds including executive approval or acceptance documentation.
Pass criteria A formally documented third-party risk appetite statement exists with quantitative thresholds for concentration and residual risk, has been approved by executive leadership or board within the past 24 months, current vendor portfolio operates within stated thresholds, and evidence shows the appetite is actively used in vendor risk decision-making with documented escalations when thresholds are exceeded.