Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Managing Third Party Risk

ASecurity

Structures vendor and third-party risk assessment with due diligence, monitoring, and concentration analysis. Use when assessing vendor risk, conducting third-party due diligence, or monitoring outsourcing risk.

22 stars
0 votes
0 copies
0 views
Added 9/20/2026
businessgosecurity

Works with

cli

Security Analysis

A100/100

Scanned 9/20/2026

Install to Claude Code

$npx -y skills add lev-os/agents --skill managing-third-party-risk --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Managing Third Party Risk?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Managing Third Party Risk
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/lev-os-managing-third-party-risk/badge)](https://www.skillsdirectory.com/skills/lev-os-managing-third-party-risk)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: managing-third-party-risk
description: Structures vendor and third-party risk assessment with due diligence, monitoring, and concentration analysis. Use when assessing vendor risk, conducting third-party due diligence, or monitoring outsourcing risk.
tags:
  - management
  - risk-management
  - risk
metadata:
  author: casemark
  practice_areas:
    - Risk Management
    - Enterprise Risk
    - Market Risk
  document_types:
    - Management Report
  skill_modes:
    - Management
    - Coordination
---
# Managing Third Party Risk

Structures vendor and third-party risk assessment with due diligence, monitoring, and concentration analysis.

## When To Use

- Onboarding a new vendor, outsourcing partner, or critical service provider
- Performing periodic re-assessment of existing third-party relationships
- Evaluating concentration risk across vendor portfolios (e.g., single cloud provider, dominant counterparty)
- Responding to a third-party incident, control failure, or regulatory finding
- Preparing for regulatory examinations that cover outsourcing and vendor management (OCC, FFIEC, EBA guidelines) [VERIFY jurisdiction-specific rules]

## Inputs To Gather

- **Vendor inventory**: Complete list of third parties including name, service category, contract value, contract term, and business owner
- **Criticality classification**: Whether the vendor supports a critical business function, handles sensitive data, or has customer-facing exposure
- **Due diligence package**: SOC 2 / ISO 27001 reports, financial statements, business continuity plans, insurance certificates, and any prior audit findings
- **Regulatory requirements**: Applicable guidance (e.g., OCC Bulletin 2013-29, DORA, APRA CPS 230) [VERIFY which frameworks apply]
- **Existing risk ratings**: Prior tiering, residual risk scores, and open remediation items
- **Concentration data**: Revenue share per vendor, geographic overlap, technology dependency mapping, fourth-party (subcontractor) disclosures

## Workflow

1. **Tier the vendor population**
   - Assign each third party to a risk tier (Critical / High / Medium / Low) based on data sensitivity, operational dependency, regulatory exposure, and substitutability
   - Critical-tier vendors trigger full due diligence; low-tier vendors require abbreviated assessment

2. **Conduct due diligence**
   - Collect and review SOC reports, financials, BCP/DR plans, and cybersecurity questionnaires
   - Flag gaps: missing reports, qualified audit opinions, declining financial ratios, unresolved findings
   - For critical vendors, assess fourth-party risk — identify key subcontractors and their controls

3. **Score inherent and residual risk**
   - Rate each vendor across dimensions: operational, financial, cyber/information security, regulatory/compliance, reputational, and geopolitical
   - Apply mitigating controls (contractual protections, SLA penalties, escrow, audit rights) to arrive at residual risk
   - Document risk acceptance rationale when residual risk exceeds appetite

4. **Analyze concentration risk**
   - Map vendor dependencies to business lines and geographies
   - Identify single points of failure: one vendor serving multiple critical functions, heavy reliance on one jurisdiction, shared technology stack
   - Calculate concentration metrics (e.g., top-5 vendor spend as % of total outsourced spend)

5. **Build monitoring and escalation framework**
   - Define KRIs per tier: SLA breach rate, financial health triggers, incident frequency, audit finding closure rate
   - Set review cadence: quarterly for critical, annually for high, biennial or event-driven for medium/low
   - Establish escalation paths: who is notified when a KRI breaches threshold, what triggers contract re-negotiation or exit planning

6. **Document and report**
   - Produce a third-party risk register with current tier, residual score, open issues, and next review date
   - Prepare board/committee-level summary: aggregate risk heatmap, concentration dashboard, material exceptions

## Output

- **Third-party risk register**: Vendor name, tier, inherent/residual risk scores, key findings, remediation status, next review date
- **Concentration analysis**: Dashboard showing spend concentration, geographic concentration, and fourth-party overlap
- **Due diligence summary per vendor**: Controls assessment, gap list, and recommended mitigants
- **Executive risk report**: Heatmap of vendor risk by category, trend vs. prior period, material exceptions requiring escalation
- **Monitoring plan**: KRI definitions, thresholds, review cadence, and escalation matrix

## Quality Checks

- Every critical-tier vendor has a completed due diligence file dated within the applicable review cycle [VERIFY required frequency per regulation]
- Concentration thresholds are defined and tested — no single vendor exceeds the board-approved limit without documented risk acceptance
- Risk scores use a consistent methodology across all vendors; scoring criteria are documented and repeatable
- Fourth-party dependencies are identified for all critical vendors; gaps are flagged rather than omitted
- Regulatory mapping is current — confirm the applicable supervisory guidance matches the entity's charter, jurisdiction, and license type [VERIFY]
- All open remediation items have assigned owners, target dates, and status tracking
- Mark any data point sourced from vendor self-attestation (vs. independent audit) with [VERIFY]

Attribution

lev-oslev-os
View sourceMore from lev-os →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Solution Architect

Designs system architecture, component specifications, and technical integration strategy. Use when: designing solutions, system architecture, technology stack, or integration approaches.

192 votes

Akorchak:Venture Assessment

Generate a comprehensive VC investment assessment report for a company

72 votes

Stock Analysis

Analyze stocks and cryptocurrencies using Yahoo Finance data. Supports portfolio management (create, add, remove assets), crypto analysis (Top 20 by market cap), and periodic performance reports (daily/weekly/monthly/quarterly/yearly). 8 analysis dimensions for stocks, 3 for crypto. Use for stock analysis, portfolio tracking, earnings reactions, or crypto monitoring.

6511 votes

Just Fucking Cancel

Find and cancel unwanted subscriptions by analyzing bank transactions. Detects recurring charges, calculates annual waste, and helps you cancel with direct URLs and browser automation. Use when: 'cancel subscriptions', 'audit subscriptions', 'find recurring charges', 'what am I paying for', 'save money', 'subscription cleanup', 'stop wasting money'. Supports CSV import (Apple Card, Chase, Amex, Citi, Bank of America, Capital One, Mint, Copilot) OR Plaid API for automatic transaction pull. Out...

6511 votes

Telegram Compose

Compose rich, readable Telegram messages using HTML formatting via direct Telegram API. Use when: (1) Sending any Telegram message beyond a simple one-line reply, (2) Creating structured messages with sections, lists, or status updates, (3) Need formatting unavailable via Clawdbot's Markdown conversion (underline, spoilers, expandable blockquotes, user mentions by ID), (4) Sending alerts, reports, summaries, or notifications to Telegram, (5) Want professional, scannable message formatting wit...

6511 votes
View all in business →