Risk

Third-party risk in financial services: a maturity model

Third parties now underpin most customer-facing services. A structured maturity model helps banks focus assurance where it matters.

Third-party risk in financial services: a maturity model
4 October 2025 · 6 min read

Why third-party risk is now a board topic

Core banking, payments, cloud, customer support and even parts of compliance are frequently delivered by vendors. A material outage or data incident at a critical third party is a material incident for the bank. Regulators in Kenya and internationally increasingly expect formal third-party risk management, not informal relationship management.

The difficulty is volume. A mid-sized institution can have hundreds of suppliers. Treating all of them with the same questionnaire wastes effort and still misses the concentration risk in the top ten.

A simple maturity model

Level 1 — Inventory only: a list of vendors with contracts on file. Level 2 — Tiering: criticality rating based on data access, customer impact and substitutability. Level 3 — Risk-based assurance: questionnaires, certifications (ISO 27001, SOC 2, PCI DSS) and contractual rights calibrated to tier. Level 4 — Continuous monitoring: performance SLAs, security ratings, incident obligations and periodic re-assessment. Level 5 — Integrated: third-party risk feeds enterprise risk, operational resilience and board reporting.

Most institutions we assess sit between Level 2 and Level 3. The jump to Level 4 requires tooling and clear ownership, not only more spreadsheets.

What good looks like in practice

A living inventory owned by procurement and risk jointly. Exit and concentration analysis for the critical tier. Right to audit and evidence clauses that are actually exercised. Alignment with ISO 27001 Annex A supplier controls and with PCI DSS where card data is involved.

For security printing and telecom clients, third-party risk also covers production subcontractors and hosting partners that fall inside GSMA SAS scope — scheme requirements do not stop at the factory gate.

How AACL supports third-party risk programmes

We design tiering models, assurance programmes and board reporting for banks, payment firms and regulated manufacturers. Engagements can stand alone or sit inside a broader ISO 27001, PCI DSS or SMaaS retainer. Onsite in Kenya or remote worldwide.

To discuss this subject with our practitioners, write to info@aacl.co.ke.

WhatsAppSignalThreemaCall now