Guide · Third-Party Risk
Third-Party Risk Management: Does It Cover the Parties Who Handle Your Goods?
The annual re-tiering of the third-party register is open on one screen and four other people need something from it before it closes. Information Security has a queue of renewals that cannot be signed until each provider has been through a security review, and two of those renewal dates are inside the next fortnight. Accounts Payable has been setting up new payees all quarter and wants to know which of them you consider in scope, because their onboarding form now has a field for it. Enterprise Risk needs the register summarised for the committee pack, in the tiering language the committee learned last year. And the insurance renewal has arrived with a schedule attached, asking for the list of parties who hold your property or handle it on your behalf.
Somewhere in the middle of that register, in the tier that gets reviewed least often, sit the companies that physically move, pack, store and consolidate everything your business sells. Some of them are on it because they send you an invoice. The ones that do not send you an invoice are not on it at all.
Third-party risk management covers every outside party a company relies on, and the most widely adopted shape of it — the five-stage life cycle in the June 2023 Interagency Guidance: Planning, Due Diligence and Third-Party Selection, Contract Negotiation, Ongoing Monitoring, Termination — was built in and for financial services, where the dominant exposures are data, money and service continuity. Applied to a physical supply chain, that framework is sound and the tooling underneath it is usually blind, because a register assembled from contracts and payment records cannot see a chain that is held together by custody. The parties who handle your goods are frequently engaged by somebody else in the chain, hold no agreement with you, appear in none of your systems, and carry the exposure that shows up at a border rather than in a data breach. That is the thinnest part of almost every TPRM portfolio, and it is thin for a structural reason rather than a careless one.
To be plain about our own scope before you read further: assessing that goods-handling slice — mapping it, verifying it, scoring it against the customs threat set, and driving the corrections to closure — is XFACTOR VERIFIED. The room that work lives in, where one supplier file answers whichever programme is asking this month, is XFACTOR COMMANDCENTER. Neither one is third-party risk management software in the enterprise sense, and neither is offered as a substitute for it.
What does third-party risk management actually cover?
The discipline has a clearer regulatory spine than most people outside financial services realise, which is worth knowing because it explains the shape of every tool sold into the category. On June 6, 2023 the Federal Reserve, the FDIC and the OCC issued the Interagency Guidance on Third-Party Relationships: Risk Management, replacing each agency's own prior guidance with a single life cycle: Planning; Due Diligence and Third-Party Selection; Contract Negotiation; Ongoing Monitoring; Termination. In Europe, the Digital Operational Resilience Act has applied since January 17, 2025 and requires in-scope financial entities to maintain a register of information covering their contractual arrangements with ICT third-party service providers. On the technology side, NIST published Special Publication 800-161 Revision 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations, in May 2022.
Read those three together and the centre of gravity is obvious. Banking supervision, ICT resilience and cyber supply chain — three regimes about information, money and service availability. The instruments the market built to serve them followed: the Standardized Information Gathering questionnaire from Shared Assessments, the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire, a SOC 2 report requested at renewal. All of them are competent instruments for what they were designed to establish.
One line in the Interagency Guidance points somewhere else entirely, and it is the line almost nobody operationalises. The guidance applies to any business arrangement between the organisation and another entity, by contract or otherwise — and it states that a third-party relationship may exist despite a lack of a contract or remuneration. That sentence is an instruction to inventory relationships you do not pay for and have not signed anything with. In a physical supply chain those relationships account for a substantial share of the parties handling your cargo, which makes that sentence considerably harder to satisfy than it first reads.
Why is the goods-touching part of the portfolio the thinnest part?
Ask where the register came from. In every programme I have looked inside, the answer has two sources: the contract repository and the accounts payable ledger. Both are excellent records of who a company has commercial relationships with, and a physical chain runs on something else entirely — a sequence of handovers, in which each party takes custody of the goods from the last one regardless of who engaged them.
Your supplier chooses the export packing facility. Your freight forwarder subcontracts the drayage leg at the origin port, and again at the destination. A container yard holds the box for whatever the dwell time turns out to be. A consolidation warehouse combines your cargo with four other shippers' freight before it moves. Each of those parties has your goods in their hands, unsupervised, for a period of time. Not one of them has a contract with you or sends you an invoice, so a contract-derived inventory does not report them as unassessed — it reports nothing at all, which reads on a dashboard as a clean portfolio.
Customs authorities scope it the other way, by touch rather than by agreement. The map CBP expects covers each party that has a hand in moving the goods at any point on the route — the manufacturing site, the export packing facility, the buying or selling agent, the forwarder and the NVOCC, the inland truck and rail legs, the warehouses and consolidation points, the container yard, the local drayage company, the ocean or air carrier, and the broker who files the entry. Lay that against a register built from payees and the difference is not a few rows.
Tiering then compounds the gap rather than catching it. Criticality models in general TPRM tools weight spend, data access, systems integration and revenue dependency, which are the right weights for the exposures the discipline grew up managing. A drayage company with a modest invoice, no systems access and no data lands in the lowest tier and is reviewed on the longest cycle, while holding an unaccompanied container on a public road. Nothing has gone wrong with the tool in that scenario; it has weighted the inputs it was designed to weight and returned a defensible answer to a question about a different kind of exposure.
The party that moved the goods and was never on the register
I was asked once to look at a third-party programme that was, by any reasonable standard, a good one. The register was current, the tiering had been through a committee, security reviews were closing inside their service levels, and the person running it knew her portfolio properly.
So we took one finished product and followed it in reverse, handover by handover, from her distribution centre to the raw material — half a day of work, and the only method I know that reliably shows what an inventory is missing. The contract manufacturer was on the register. The forwarder was on the register. Between them sat an export packing facility that repacked and palletised the goods for ocean freight, and a haulier that carried the sealed load to the port. The packing facility had been chosen by the manufacturer years earlier and appeared in no document anyone in that building had ever read. The haulier was engaged by the forwarder under the forwarder's own contract.
Both of those parties had sole custody of the finished goods, and both were invisible. They had not been deprioritised or scored low — they were absent from a register everyone had agreed was complete. The gap was never in her diligence. Her tooling inventoried the chain the only way it knew how, and the chain does not run on invoices.
What does a goods-chain third party have to be assessed against?
Once those parties are on the list, the second problem arrives, which is that the questions in a standard vendor security review do not reach anything that matters about them. In the threat step of the CBP five-step risk assessment, every party on the map is assessed against terrorism, contraband smuggling, human smuggling, agricultural and public safety threats, organized crime, and the conditions in a country or region that make any of those more likely. Underneath that sit the Minimum Security Criteria, which reach into physical access control, personnel screening, container and trailer inspection, seal handling, and how a conveyance is secured while it is in motion.
None of that is measured by asking whether a party encrypts data at rest or holds a current SOC 2. The two assessments are not competing versions of the same thing — they establish different facts about different exposures, and a company that trades physical goods internationally is carrying both. What is different about the goods-chain half is who eventually reads the file. A vendor security review is read internally. A supply chain security assessment is read by a customs authority, an accreditation validator, or a customer's audit team, and it is read against a published standard with an opinion about what constitutes sufficient evidence. The gap between an answer on a form and evidence that survives that reading is set out in the guide on what supplier verification actually verifies. How a scoring engine then weights all of it into a single figure, and what that figure can survive being asked about, belongs to supplier risk assessment software.
One more difference matters for planning. C-TPAT Partners are required to conduct a risk assessment at least annually to remain in the programme, and CBP has taken the written position that the assessment must conform to the company's own business model rather than adopt a generic, externally provided template. A single standardised questionnaire issued unchanged to every party in a chain fails that test on its face, whatever else it establishes.
Who gets asked when the register turns out to be incomplete?
What raises this above a backlog item is what the register turns into once a year. It stops being a working list and becomes a representation of the company — summarised into a committee pack, referenced in an audit response, attached to an insurance schedule, or quoted to a customer whose contract requires you to maintain a third-party risk programme. Somebody states that it is complete and current. In most companies that somebody is the person who built it.
Then a container is held, or a customer's audit team names a facility nobody recognises, or a certificate turns out to have lapsed at a party you cannot immediately identify. The meeting that follows is rarely about whether that party was risky. It moves within a few minutes to a harder question: what else is missing, and how would we know. At that point the register stops being evidence of control and becomes the thing under examination, and every other assurance built on top of it — the committee summary, the audit response, the customer answer — is standing on the same foundation.
The cost of that arrives as work rather than as a penalty: a manual reconstruction of the portfolio, on a deadline, done by the same people already carrying the renewals and the committee pack, for a programme that has been described in writing as complete. In thirty years I have watched that reconstruction happen more than once, and what it damages worst is not the calendar. Confidence in the register goes, and once that goes people begin keeping their own private version of it, which is how a company ends up maintaining two answers to the same question.
How do you close the goods-chain gap without rebuilding the programme?
The TPRM programme is not the problem and does not need replacing. What it needs is one slice of its portfolio inventoried by a different method, and that slice is smaller than people expect — it is the parties who handle, store, move or have access to the goods, not the whole register.
Take one product and trace it back from the point it reaches you to the raw material, writing down everyone who had custody at each handover, whether or not you pay them. Set that beside the rows already in the register and the missing parties surface on their own. Where a party declines to say who they subcontract to, that refusal belongs on the register as its own entry, with a date, an owner and a plan for what happens next, so the chain shows a known gap instead of a blank. Then assess the parties you found against the threat set that will actually be used to judge them, and keep the findings, the corrective actions and the expiry dates on a record that reopens itself when a certificate lapses. All of that runs inside the operating rhythm you already have. It adds no people to your team and nothing recurring to your calendar.
Doing that assessment is what XFACTOR VERIFIED is for. It maps the chain by custody rather than by contract, assesses each party against the customs threat set and the Minimum Security Criteria, writes the action plans, and produces the signed Master 5-Step Risk Assessment — mapping cargo flow and identifying business partners, conducting a threat assessment, conducting a vulnerability assessment, preparing an action plan, and documenting the risk assessment process. One assessment serves every programme you carry, because C-TPAT, PIP and AEO each rest on those same five steps to support a security profile, and the executive summary a Bill S-211 report requires under Canadian statute is built on the same underlying evidence. Keeping all of those obligations pointed at one file, on one set of dates, is XFACTOR COMMANDCENTER. The wider question of what any compliance platform has to carry end to end is in supply chain due diligence software.
Thirty years of client work is what I am arguing from here, and it carries a record I will state plainly: a 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum. I was never someone who gave the bare minimum to my clients. So when a register cannot name the company that has your container tonight, I would not call that portfolio assessed, however well the rest of it is run.
Free guide
Free guide: How to Evaluate Supplier Risk
Where real supplier exposure sits, what you can establish before you ever send a questionnaire, and what a record has to contain before an auditor, a customer or a customs officer will credit it. We'll email you the link.
Find out who is in your chain and not in your register.
See how XFACTOR VERIFIED maps and assesses the parties who handle your goods, or see what Procurement gets before a supplier is approved. Access is by request, and every request is reviewed personally.
The programs this maps to: C-TPAT · Bill S-211 · The departments this maps to: Procurement · Operations · Related reading: Supplier risk assessment software · Supplier verification software · Supply chain due diligence software · C-TPAT vs PIP vs AEO · The Master 5-Step Risk Assessment · The Minimum Security Criteria · Supplier due diligence