Third-party risk management (TPRM): a practical guide for Australia

Third-party risk management (TPRM): a practical guide for Australia

Insights • July 14, 2026 • 34-minute read

Key Takeaways

  • Third-party risk management (TPRM) is essential for organisations relying on suppliers, as vendor failures can lead to significant breaches and liabilities.
  • Establishing a TPRM program involves creating a risk register and sorting your vendors into Tiers that align with how critical they are to your operations.
  • Effective ongoing vendor management includes regular assessments based on risk tiers and monitoring for changes.

Third-party risk management (TPRM) is how you stop your suppliers from becoming your problem. Every vendor you rely on, every cloud platform, every payroll provider, every firm that touches your data, is a way your organisation can be breached – with the fines and fallout falling on you, not the supplier.  

Third-party risk management is the work of finding those risks and keeping them in check.  

This is for leaders responsible for third-party risk management. You already know what third-party risk management is and why it’s important. This guide shows you how to build and maintain effective third-party risk management in your organisation. It covers: how to work out whether you need a formal third-party risk management program at all, build the register, ask the right questions before you sign, get the contract right and stay on top of vendors once they’re in. As a key supplier to APRA-regulated financial institutions, we meet some of the most stringent regulations against third-party suppliers in Australia. So, what follows is shaped by what an assessor actually looks for, not just what the standards say. 

This section takes you through all the steps involved in designing an effective third-party risk management program. But it’s also designed to meet you where you’re at in the process. So, if you already have a risk management program and are here to validate specific aspects of it, you can skip to the relevant section without missing a beat. If you’re starting from nothing, read it top to bottom, because each stage assumes the one before it is in place. 

  

Do you need a third-party risk management program?

Certainly, every organisation that depends on any amount of suppliers has third-party risk. But building a formal third-party risk management program (to the standards of regulated, high-risk sectors, at least) is a significant investment. So, before you begin your risk management uplift, the first question you should ask is whether you actually need a third-party risk management program. Some organisations are legally required to have one. Others would be better off spending their time, resources and effort elsewhere.  

Not sure which camp you fall under? The list below sorts that out. Read down it and stop at the line that describes you. 

 

  • You are an APRA-regulated financial institution (a bank, insurer or super fund). TPRM is mandatory, with CPS 230 and CPS 234 requiring it. The requirements section is your starting point. 
  • You are a material service provider to an APRA-regulated entity. If your services support a critical operation, or expose the entity to material operational risk (handling customer data is a common trigger), their APRA obligations reach you – and you’ll be assessed against the full criteria. Pay closest attention to the due diligence and contract sections. 
  • You hold personal information and rely on third parties to handle it. Under the Privacy Act, the responsibility for that data stays with you when you pass it on, meaning you need both due diligence and contractual controls.  
  • A serious chunk of your operations depends on outside suppliers. Your risk here is operational before it’s regulatory. One vendor going dark can grind operations to a halt. That’s a risk you can’t afford – so the full spectrum of TPRM applies to you. 

These branches stack as well. A typical super fund is regulated, holds personal information and runs critical operations through external vendors all at the same time. So, it inherits every obligation at once. If more than one of these criteria applies, your TPRM program has to clear the highest bar. 

What if none of these apply? In that case, a formal TPRM program may be premature. Standing up a heavyweight program before the risk justifies it is a waste of resources. Those are resources you could (and should) be spending on building the controls that would actually move the needle and reduce risk exposure in your organisation. But that doesn’t mean you can disregard TPRM entirely. Here are some best practices for staying on top of your third-party risk.  

Hold a basic supplier list. Ensure you have an up-to-date view of your suppliers. Include what data and systems they can access, and how.  

Run light due diligence on anyone touching sensitive data. Ask a few simple questions before onboarding: do they encrypt data at rest and in transit, do they have a breach notification process and who else (fourth parties) can see your information through them. You don’t need a formal audit framework here, just enough to know they’re not a black box. 

Keep track of changes to your organisation. Changes like a contract with a bank, an expansion into regulated territory and a new product that starts collecting customer data mean you’ll need to act quickly to implement TPRM controls. Third-party risk management is required in these circumstances for good reason. And the gap between the moment you need to implement TPRM and when you actually do is the most exposed your organisation can be. 

  

Third-party risk management requirements in Australia (CPS 230, CPS 234, Privacy Act)

Regulated organisations must be able to demonstrate adherence to their regulatory obligations on demand. Not once and never again, not just at audit time. On demand.  

For Australian organisations, three regulatory obligations stand out as the most consequential for third-party risk management. They are the Privacy Act, which applies to organisations across all sectors, and APRA CPS 230 and CPS 234, which apply to APRA-regulated organisations.    

For financial institutions that need to meet all three, it’s not as simple as creating one third-party risk management program and taking it from there. Each regulatory framework has its own language you need to understand. For example: APRA’s “critical operation” and “material risk” tests don’t map cleanly onto the Privacy Act’s definition of personal information, and the breach notification timelines don’t match either. Mismatches like that are why running them as one program is harder than it sounds. Understanding each regulatory requirement and its obligations means nothing gets lost in translation.  

Here’s a breakdown of these three key requirements. If APRA regulations don’t apply to your organisation, skip to the third one.  

  

APRA CPS 230

CPS 230 took effect on 1 July 2025, with transitional relief for contracts already in place running until the next renewal or 1 July 2026, whichever comes first. CPS 230 requires regulated organisations to maintain a register of material service providers, manage the risk each one carries across the entire life of the relationship and be ready to prove to APRA that you do.  

That last requirement is where many organisations get caught out. It’s not enough to have a semi-formal written policy that exists merely to satisfy the third-party risk management requirement, but won’t be of any use should any actual risks materialise. The only way to meet CPS 230 is by having evidence you can confidently hand over to a regulator. That’s why so much of the practical work later in this guide is about generating and keeping records. 

  

APRA CPS 234

CPS 234 runs alongside CPS 230 and governs information security. In short, CPS 234 mandates that every supplier has to meet your security standards, and that the onus is on your organisation to prove that they do.  

It has been live since 2019, so it should be familiar ground. Yet, its application to third-party risk still catches organisations out. CPS 234 covers every information asset the third-party manages, not only the ones wrapped in a formal outsourcing deal. This is where the evidence requirement hits hardest. Any vendor can claim to be secure – but that doesn’t mean they’re secure enough for your organisation – or at all.  

To understand these APRA regulations in more detail, check out our CPS 230 hub and CPS 234 hub. 

 

Privacy Act  

Even outside of APRA’s reach, the Privacy Act very likely applies to you. The Privacy Act applies to organisations with an annual turnover of more than AU $3 million. It also applies to health providers, those trading in personal data, credit reporting bodies, and organisations with federal government contracts, regardless of turnover. 

If the Privacy Act applies, it confirms your legal obligation when working with third-party suppliers who have access to your data.  

Passing data to a supplier doesn’t pass along your accountability for it. If you haven’t taken reasonable steps to choose, contract and oversee them properly, a breach on their end becomes a breach on yours. If they’re overseas or too small to be covered themselves, that exposure lands on you regardless of what the contract says. 

Under the current cross-border provisions, liability tracks the data rather than the contract. So, signing an agreement is not the same as confirming an offshore recipient handles personal information to Australian standards. If a vendor stores or processes data offshore, or leans on a sub-processor that does, that exposure lands on you.  

  

Third-party risk management and cyber insurance 

There’s also pressure that has nothing to do with regulators at all. Amid the rising volume of cyber incidents, more Australian organisations are turning to cyber insurance. With third-party leaks a common cause of breaches, cyber insurers increasingly want to see a functioning third-party risk management program before they will write or renew a policy.  

What an insurer uncovers about your third-party risk management feeds straight into your premium – or whether they’ll cover you at all. Allianz, one of the world’s largest insurers, specifically cites third-party risk management as  “a cornerstone in cyber insurance underwriting, fundamentally influencing pricing and risk through aggregation exposure and systemic risk.” 

To an underwriter, a thin program reads the same way it does to an APRA assessor: an unanswered question, and therefore a risk. 

Now you know what applies to your organisation and what your regulators expect, here’s how to create yours and put it into practice.  

 

How to build a third-party risk register and material service provider list

Going through all your vendors and assessing the implications for your risk posture can be a daunting task. That’s why the first move should be a triage. Separate the suppliers that genuinely matter from the ones that don’t pose any meaningful risk (such as small or rarely touched suppliers that don’t require access to your systems or data).  

The framework that helps you do this is identifying your material service providers. A material service provider is one you depend on for something critical, or one whose failure would actually land on your members or customers. In practical terms that means asking these two questions of all your vendors:  

If this supplier failed tomorrow, would something your members or customers rely on stop or badly degrade? 

Can they reach data or systems whose loss would actually hurt?    

The third parties that meet one or both of these criteria in that test require the highest scrutiny. These are the vendors you build your risk register around.     

A payroll provider sitting on employee records and a host running your member portal both clear that bar without argument. The firm servicing your printers does not, even though it may hold a login somewhere in your environment.  

The interesting cases are in the middle, and the discipline there is to make a justifiable decision and record your reasoning. Why? Because “we didn’t think they counted as material” isn’t a sentence you want to be saying to an assessor when asked about the vendor that just got breached. 

 

Your third-party risk register is what informs the rest of your third-party risk management program. It's also the first thing an assessor will want to see.  

It should be a comprehensive overview of your suppliers, with your material service providers clearly identified within it. Done well, it’s an unexciting, comprehensive record of every supplier, their relationship to you, how you work with them and what would happen if something went wrong. Done poorly, it becomes a record of the blind spots in your environment. And if one of those blind spots leads to a breach, you’re exposed to regulatory action. 

Here’s what you should include in your third-party risk register.  

  • Provider name, legal entity, and the fourth parties sitting behind them. Record the legal entity, not just the trading name. When the two differ, that’s who you have legal recourse against if something goes wrong. Your exposure doesn’t stop with your supplier though. Note any known fourth parties (subcontractors, sub-processors) the provider relies on to deliver the service to you. 
  • The service, and the critical operation it underpins. Name the operation rather than the category. “Cloud hosting” means nothing to an assessor, “cloud hosting for the member portal” explains exactly why the vendor is material.
  • The data and systems they can access. Be precise about sensitivity, since a vendor that can see member PII carries a different risk level than one that only sees anonymised logs.
  • Contract start, renewal and exit dates. Renewals double as natural review points, and exit dates are the ones nobody remembers until the day they need them.
  • The internal owner accountable for the relationship. One named person, not a team. If you spread ownership across a group, you’ve effectively assigned it to no one. Ensure a role change or departure is an automatic trigger for review, so ownership gaps don’t sit unnoticed.
  • Risk tier and the date of the last assessment. This is the first thing an assessor’s eye goes to, because an empty last-checked date gives the whole game away.
  • A documented exit plan. This is the most overlooked, yet potentially the most consequential aspect. Assessors will want to see not only your processes for offboarding material service providers, but that you’ve followed them. Even a single line, such as “Data returned by secure transfer, access cut within five days, destruction confirmed in writing” beats a blank field by a mile. 

Keep your register current. Listing the fields is the easy part. The real work is keeping every entry true as contracts roll over, owners change and vendors get acquired. That maintenance is what separates a register that survives an assessment from one that merely looks the part. 

A register six months out of date is worse than not having one. A non-existent third-party risk register doesn’t pretend to represent your risk posture, but a stale one actively misleads your stakeholders. 

  

How to tier vendors: a third-party risk assessment framework 

As the material service provider test suggests, not every vendor carries an equal amount of risk.  

If you hold the company that services your air-conditioning to the same standards as a cloud platform full of member records, you’ll only exhaust your team – and you might increase your chances of missing things that matter.  

That’s why it’s important to sort your vendors into tiers. A practical third-party risk management framework should be informed by two questions:   

  • How much damage would this supplier’s failure do?  
  • How sensitive is the data they can access?   

Your answers for each vendor determine their risk tier, and inform both the depth of your scrutiny and how often you return to it. Determining each vendor’s tier is the heart of any third-party risk assessment. It’s also what stops the rest of the work from becoming unnecessarily arduous.  

Here’s an example of a typical vendor risk tier framework.  

  • Tier 1 (critical). Tier 1 vendors support a critical operation or hold sensitive member or customer data. They require full due diligence before coming on board, and formal contractual controls. Re-assess their risk at least once a year.  

Examples of tier 1 vendors include: cloud providers that host systems with customer PII, your hardware maintenance provider for critical on-premises systems. 
  

  • Tier 2 (important): Tier 2 vendors play a meaningful role in your operations or have some data access, but aren’t critical to your organisation. They require standard due diligence, and should be reviewed every one to two years. 

Examples of Tier 2 vendors include CRM, HR, marketing, accounting and internal collaboration tool vendors.
  

  • Tier 3 (low): Tier 3 vendors have limited access to systems, no access to sensitive data, and can be easily replaced if required. They require light checks, and should be reviewed at renewal or when something material changes. 

Examples of tier 3 vendors include: office cleaners and facilities managers, and suppliers of non-critical office equipment such as furniture, stationery and snacks.  

Get your Tiers right, and everything else gets easier, because the effort you spend on each vendor now matches the risk it carries.  

But often, knowing what tier your vendors belong in is easier said than done. There will be nuance to your vendors’ roles that requires careful consideration and justification. Take some of the examples above. An office cleaner typically sits in Tier 3, but they get bumped up to tier 2 if they’re given unsupervised after-hours access to your premises. And if they’ve got unsupervised access to highly sensitive areas like your server or comms room, they become Tier 1. Similarly, email marketing software may sit in Tier 2, but if it’s used to deliver urgent or mandatory customer communications, it becomes Tier 1.  

Tiering everything as critical out of caution, means burying the team under low-value assessments while the genuinely dangerous vendors get handed the same questionnaire as the office stationery supplier. Over-tiering, prudent as it may seem, is its own kind of failure. A third-party risk management program that treats everything as urgent loses any way to flag what actually is. 

The two-question test is simple by design, but it only works if you answer it honestly.  

A common mistake organisations make is treating a comfortable, long-term relationship as low risk when subjectively it isn’t. Tier on consequence and access, never on familiarity – a vendor you’ve used happily for a decade is still Tier 1. Treat each vendor as you would if they were a completely new supplier you know nothing about other than the cold hard facts about the services they provide and the systems they can access.  

 

How to run vendor due diligence: the questions to ask

Vendor due diligence comes down to the questions you ask before you commit. How many questions you need answered, and how far you push them, should scale with how much risk the vendor carries. A tier 1 provider should face the whole set of questions below. On the other hand, a tier 3 supplier gets the essentials and nothing more.  

The error to avoid here is treating any of it as form-filling. The aim of third-party due diligence is to produce a body of evidence you’d be comfortable putting in front of an assessor. A questionnaire the vendor filled in about themselves that nobody fact-checked shouldn’t pass that bar.  

The questions fall into five groups. A Tier 1 provider should get all five, and the rest of your vendors should only get the appropriate questions.  

Security.

Do they hold ISO 27001 or SOC 2? And, just as important as the certifications themselves, what does the certificate actually cover? A scope that takes in the head office but not the product you’re buying is worth far less than the badge suggests. So, validate your vendor’s certifications by reading the scope statement. 

When were their security controls last tested by someone independent? Will they show you the report, or at least a summary?  

How do they run and report incidents, and how quickly will they tell you when one reaches your data? A named standard, a recent test date and a defined notification window is what answers this question – vague promises don’t. 

 

Data and sovereignty.

What data will they actually hold? Where does it physically sit? Who can reach it and from which country? This is where the data sovereignty question comes into play, and the answer should be more than a simple “it’s in Australia”. Why? Because, for example, a provider can keep data in a Sydney facility while handing support access to staff overseas. At that point, your data has effectively left the country even though the disk never moved. Under the Privacy Act, both where the data rests and who can reach it matter for data residency requirements. Yet, some vendors still skip past the second one as if it doesn’t – don’t make that your problem.  

  

Financial and operational.

Are they solid enough to carry the length of the contract? A vendor who folds eighteen months into a three year contract is an operational risk.  And most organisations that fold show signs of it well before the writing’s on the wall. You need to demonstrate you know the risk of this happening up front.  

What continuity and recovery commitments do they make? And have those ever been put to the test, or are they aspirational figures in a slide deck? A recovery target nobody has rehearsed is a hope, not a number. 

  

Fourth-parties.  

Which of their own suppliers touch your data or your service? Will they name them, and will they push your requirements down the chain? This is the group most programs leave out. After all, you often hire third parties because you want someone to own the work without getting into the specifics of how it gets done. But this mentality is the difference between current and outdated practice. Your vendor’s vendors are part of your exposure whether you can see them or not. And the only window where you have leverage to drag them into view is before you sign. A vendor risk assessment that ends with the supplier you work with stops one link short of where the risk often lives. A data breach that reaches you through a sub-processor you never knew about is still your breach in the eyes of your regulators. 

  

Exit.  

How does your data come back or get destroyed when the deal ends? And how fast can you actually walk away? Don’t make this a bridge you’ll only cross if and when you’re actively trying to leave. Their answer will tell you what unwinding the relationship will cost you. A vendor that can’t describe how you would exit is telling you, in advance, exactly how stuck you will be. 

  

Considerations to keep in mind during vendor due diligence. 

To ensure your due diligence works as the regulators intend it to, do these two things: 

First, weigh the answers rather than just collecting them. The point of due diligence is to get the full picture and surface any gaps, not tick every box. A single confident yes backed by a current independent report outranks ten yeses backed by nothing.  

Second, keep what you gather. This evidence is the same material an assessor will later ask to see, so a due diligence process that leaves an audit-ready record behind it saves you reassembling everything under pressure down the track. 

  

Vendor contract clauses that satisfy CPS 230

A supplier contract should tell you everything you need to prove to a regulator that the vendor satisfies CPS 230’s third-party risk management requirements. Once you’ve signed the contract, what’s in it protects your liability should the unexpected happen. The due diligence you do to prove the information in it is how you decide whether to sign.  

When it comes to third-party risk, APRA has been explicit that vetting a vendor up front is no longer sufficient on its own. The protections must be written into the agreement itself. The moment the ink dries, all you can do is ask nicely and hope your vendor rep doesn’t send you on a wild goose chase. For any material provider, these are the clauses your third-party risk management policy should treat them as non-negotiable: 

  

  • Exit provisions. How the relationship winds down, how your data returns or is destroyed, and how continuity holds through the handover. CPS 230 expects any offboarding process to be a smooth one no matter the circumstances. 
  • Incident notification. When something goes wrong, understand what they have to tell you and within what timeframe. Define it up front, so “promptly” doesn’t become “whenever suits them” at the worst possible moment.
  • Sub-processor disclosure. Every vendor has to name the fourth parties they rely on and seek your consent before adding new ones. Without it, the fourth-party visibility you fought for in due diligence expires the day after signing.
  • Audit and assurance rights. Ensure your entitlement to evidence that the vendor’s security controls work as they say they do, and as your compliance requirements mandate. This should come from independent reports, rather than an internal vendor claim. This is the clause some vendors resist the hardest. However, their resistance isn’t your defence against regulatory scrutiny. 
  • Continuity and recovery commitments. Expect defined recovery targets, paired with the right to test them. A recovery commitment you are not permitted to test is a recovery commitment you have no reason to believe.
  • Data residency. Get confirmation of where the data lives and who may reach it, offshore access included. Anchor this to the sovereignty answers from your due diligence so the contract enforces what the vendor told you. 

Every vendor classified as a material service provider needs each one of these clauses in their contract. Remember the golden rule: if a supplier failure impacts your ability to deliver services to your customers, would a regulator accept that you did enough to prevent it? This is exactly what your contract terms should make clear.  

Downtime as a result of a cloud provider switching its service off before your new provider switches on. A data breach linked to a fourth party you didn’t know about. A delayed incident notification that doesn’t give you enough time to meet your NDB scheme reporting obligations. If your vendor’s expectations aren’t spelled out in the contract, they’re your problem.  

These terms are easiest to get at the start and can be painful to retrofit later, which is exactly why thorough due diligence is crucial before you even think about signing a contract. A gap you spot during due diligence becomes a clause you can negotiate before signing. The same gap found afterwards becomes a renegotiation where switching cost and friction become the vendor’s leverage.  

There are some limited exceptions. APRA’s April 2026 amendments acknowledge (and accept) that some of these clauses will be out of reach for specific providers. Such providers include reserve banks, stock exchanges, trade clearing services, settlement platforms and payment schemes. But treat these vendors as the rare exemptions that they are, not a precedent to slack off when negotiating every vendor’s contract.  

For the ordinary run of commercial vendors the list above is the floor, not the ceiling, and “they wouldn’t agree to it” is a reason to question whether they belong as your Tier 1 material service provider.  

  

Ongoing vendor risk management: how to monitor suppliers after onboarding

Many organisations put more effort into winning new customers than they do retaining existing ones. This is why your supplier risk management obligations don’t end once you sign on the dotted line. Instead, that’s where they begin.  

 A vendor who looked perfectly safe at onboarding can gradually become riskier over time without you noticing. It might be because they get acquired, they shift their (and therefore your) data to a new region, they sneak in a sub-processor or they get breached.  

 This is why vendor risk management and third-party monitoring needs to be an always-on, ongoing activity rather than a single check at the gate.  

  

Your vendor’s assigned tier should set how often you review them: 

  • Tier 1 vendors require a formal re-assessment at least yearly, on top of a continuous watch on security posture and incidents impacting them. For these vendors, a full year between reviews is already a stretch. 
  • Tier 2 vendors need a review every one to two years, and again at renewal, which is a natural checkpoint that shouldn’t go unnoticed.  
  • Tier 3 vendors should be reviewed at renewal or after a material change. While this should be a lighter review than that of the tiers above – it’s not nothing. 

When should you conduct an off-cycle re-assessment? If the vendor has a breach or incident, changes ownership, changes where they keep your data, adds a sub-processor or misses a service commitment. All of these situations should automatically trigger a review of their risk in line with your third-party risk management policy. This is true even if it doesn’t seem long before their next regularly scheduled review.  

The trigger list is where teams tend to underinvest. Yet, it’s often what stops your most consequential risks from materialising. An annual review handles slow drift fine. But it’s useless against a merger that closed in March when their review is booked for November. Document your non-negotiable review triggers in advance and bind them to the contract’s notification clause. That way, the vendor is contractually obliged to play ball if your program calls for a re-assessment. That’s a preferable outcome to finding out about material changes at your regular review 6 months later – or worse, on the news.  

Here’s the hard part in all of this. You’ve built collaborative, long-term relationships with some of your vendors. And those most trusted vendors are likely to be your Tier 1 service providers. How do you avoid vendor bias creeping in? Adopt a zero-based thinking approach. No matter who the vendor is, how long you’ve worked together or how intertwined they are with your organisation, they’ll need to meet the same bar you set new potential suppliers you don’t know. The only way to do this is by being absolute and prescriptive with what you require to effectively manage your third-party risk. Remember to dot every I and cross every T. If the vendor meets that bar, happy days. If they don’t, you’ll need to have a hard but mandatory conversation.  

  

Supplier risk management: governing change across your vendor base

 The only constant in life is change. And for an APRA-regulated financial services organisation, no change should go unnoticed. But how do you stay on top of every change, let alone weigh the risk before it reaches your customers?  

 Small changes are manageable. Yet when those changes stack up, as they’re likely to do when your organisation depends on a large number of suppliers, they often stretch manual change tracking processes beyond their limits. And when a regulator asks how you keep track of every change that impacts your customers, that’s a problem.  

There’s a sustainable, scalable solution. But it involves something too many organisations still dread: putting named owners to vendor risk. Ownership is what turns a notification into an action instead of a missed email. First, give every register entry a named owner inside the business. That person is accountable for keeping on top of any changes your supplier makes that has implications for your third-party risk.  

Once you’ve put these change owners in place, your organisation as a whole will be fully equipped to see what changes are coming, what they mean and what (if anything) you’ll need to do about them. 

Your third-party risk program should make the risk owner's job, and its expectations, straightforward. Straightforward enough that if an assigned risk owner were to leave your organisation, a new risk owner could immediately pick up where they left off - with zero coverage gaps.

Here’s what you should do to empower your risk owners to solve the challenges change presents – rather than become scapegoats for systemically poor risk management practices.  

First, write a clause into the contract that obliges the provider to tell you about material change before it happens, not once it is done. A vendor contractually bound to warn you before making a material change hands you a window to assess its impact on your organisation.   

Second, ensure that you have a framework to help you decide whether a given change warrants a fresh look at the vendor’s risk – and record the outcome back in the register. Not every change matters, a vendor relocating customer data is a material change worth assessing, them renaming a product isn’t. Not all changes are that straightforward though. So, your risk register should include clear decision guidance that makes it easy to tell every change apart.   

Without taking these steps, you’re letting change manage you rather than the other way around. That’s a weak point in your risk posture that assessors know to probe for.  

This is also the point where the register, the contract and the tiering stop being three separate sections and start working as a single system. The owner comes out of the risk register. The change notification comes out of the contract and your judgement about whether a change matters is informed by its Tier.   

Get all three right, and you have an agile third-party risk management program that stands up to regulatory scrutiny.  

  

Vendor offboarding: how to exit a supplier without leaving holes  

Breaking up is never easy. Whether you’re unhappy with their service, found a better alternative, or simply no longer need them – the exit can get awkward. But just because the conversation is uncomfortable doesn’t make your regulatory obligations less important.  

Ending a vendor relationship is where exposure most often gets left wide open, because the moment the decision is made everyone’s attention has already moved to whatever comes next. The access you granted doesn’t revoke itself, and the data you handed over doesn’t find its own way out. A forgotten login or a copy of your records still sitting on a former supplier’s servers can become a big problem later on. And the risk of that problem occurring is higher after offboarding precisely because the relationship has ended and no one’s keeping tabs on that vendor.  

So, give the exit the same rigour you gave the entry, a checklist, worked through to the end. Here’s what to do before officially considering a former supplier out of scope.  

  

  • Revoke every form of access: accounts, API keys, VPN, building and system access alike.   
  • Return or destroy the data: get your data back in a usable form, then secure written confirmation that their copies have been destroyed. The written confirmation is the part that matters for your audit trail, because “we assume they deleted it” isn’t a control. 
  • Close the loop on fourth parties: Confirm your supplier’s sub-processors have also done the above steps. Your data might sit somewhere outside your direct vendor’s control, and an exit that stops at the vendor leaves those copies live. 
  • Keep the records: the exit is a regulated event in its own right. Retain evidence of the offboarding for your audit trail and your CPS 230 exit obligations.  
  • Update your risk register: mark the provider as “exited”. Record their exit date and all the steps you completed.  

Until you’ve ticked these boxes, the vendor carries a risk that needs to be managed just as, if not more, carefully than suppliers you’re still working with.   

  

Third-party risk management gaps that lead to APRA assessment failures  

As a material service provider for APRA-regulated financial institutions, we sit on both sides of their third-party risk management expectations. 

That broad exposure to APRA’s third-party risk management requirements means we see where assessments can come undone. It’s typically the same gaps that surface when tested. If you’re new to third-party risk management or going on the journey for the first time, the gaps can be easy to miss. The good news is they’re easy to close once you do.   

So, we’ve done the hard part for you. These are the most common third-party risk management gaps that can cause you to fail an APRA assessment.  

A stale or incomplete register. Vendors missing, no owner against half the rows, last-assessed dates left blank. This is the most common gap and the most exposed, because the register is the first thing an assessor reads and its holes show at a glance.  

The fix: named owners and a periodic review cadence. This way, you’ve got people accountable for ensuring the register stays up-to-date between assessments –  instead of getting refreshed in a panic before one. 

Trusting attestations instead of evidence. Taking a vendor’s word that their security controls work can mean you’ll have nothing to give an assessor when they ask to see proof.  

The fix: get independent assurance of security controls, and the right to audit them yourself, written into the contract, so the evidence already exists rather than being chased mid-assessment. 

No view of fourth parties. Knowing your direct suppliers cold and having no idea who stands behind them.  

The fix: request that your suppliers disclose sub-processors and subcontractors at the contract stage. Make sure you know them all before you sign anything.  

Ungoverned change. Your assessment of risk the vendor poses to you might have been accurate the day they came on board. But each time there’s a change on their side, that risk profile shifts.  

The fix: build a change notification requirement into the contract. Act on those notifications through a formal change review process, as laid out in the “governing change” section above. 

No plan for AI. There’s no assessment of how vendors use AI, including what your data trains, and what exposure that adds. This is the newest gap – many organisations that didn’t need a plan for AI use across their vendor landscape only a few years ago now do – and the one that’s moving the fastest.  

The fix: add AI-specific questions to due diligence. Ask: where does our data go, what does it train, who sees the output. Above all, treat a vendor feeding your data into a model as the material change it is.  

None of these gaps should shock you. Neither should finding them in your own third-party risk management program as you create or update yours. They are simply the ordinary ways good intentions fail to survive contact with scale and time. That’s exactly why you need to stay vigilant and check on them regularly.  

  

How Interactive can support your third-party risk management

As the material service provider that our APRA-regulated customers depend on to meet CPS 230 and CPS 234, we speak the regulators’ language.  

We’ve spent a great deal of time on the receiving end of the very process we’ve talked about in this guide. We’ve fielded the due diligence questionnaires, evidenced the controls and negotiated the necessary contract clauses.  

As a service provider, we also hold ourselves to the same third-party risk management standards as our APRA-regulated customers. 

What that means for our customers is an easier time proving adherence to APRA regulations. We offer: Audit-ready documentation across our entire environment – evidence your register can take as-is.  

  • Controls we can actually evidence – and the right for you to prove it. 
  • Contracts that already carry the exit terms. 
  • Incident notification assurances. 
  • Audit rights the contract section told you to demand.  

When you assess Interactive, you’re assessing a supplier who already knows, from constant first-hand experience, what an APRA assessment is looking for. 

Our strong APRA alignment aside, another reason we help our customers streamline their compliance requirement is a more simple one: our broad expertise and service offering help you reduce your vendor footprint. Because let’s be real, the fewer vendors you have, the easier it is to meet APRA obligations. Every vendor you add is another register entry, another due diligence round, another exit plan, another relationship to monitor and another thread an assessor can pull.  

But that doesn’t mean you should have to go without the capability and flexibility that a wide vendor network offers. Bringing your entire IT environment – cloud, data centre, on-premise hardware maintenance, managed IT services, network and cyber security – under one accountable Australian provider shortens your vendor list. That reduces your compliance burden, audit surface and governance load along with it.  

If you’d like an independent read of your third-party risk, Slipstream Cyber (an independent business of Interactive) can deliver that assessment. 

APRA’s regulations are designed to ensure Australia’s financial system remains unstoppable. Helping our customers stay unstoppable is our bread and butter. If CPS 230 is what brought you here, the most useful next step is a readiness review that looks at your program the way an assessor would, against the very gaps the section above lays out. This is where our team can help. Book a CPS 230 readiness review and we’ll show you where the gaps are before APRA does. 

Featured Insights

Insights • 34-minute read
Practical TPRM guide: build vendor registers, run due diligence, and meet CPS 230 & APRA obligations.
Insights • 28-minute read
Practical CPS 234 guide: APRA controls, testing expectations, and 72-hour breach notification rules.
Insights • 20-minute read
A practical CPS 230 guide: scope, obligations, audit approach, breach actions, incl. APRA’s 2026 amendments.
[wpforms id="15231"]
[wpforms id="14210"]
FORM HEADINF
Search by industry
  • All
  • Automotive and Logistics
  • Consumer Packaged Goods
  • Corporate
  • Financial Services
  • FMCG
  • Government
  • Healthcare
  • IT, Data and Software
  • Manufacturing
  • Media and Entertainment
  • Real Estate
  • Retail
  • Superannuation
  • Travel