CeFPro Connect

Event Q&A
Managing Dependency: Building Resilient Third-Party Risk Frameworks in an Interconnected World
As third-party ecosystems become increasingly complex, organisations must move beyond traditional supplier management towards a dependency-focused approach. This article explores best practices for accountability, integrated risk assessments, due diligence, lifecycle management, concentration risk and operational resilience, highlighting how firms can strengthen decision-making and remain resilient when critical suppliers fail.
Sep 14, 2026
Milena Maneva
Milena Maneva, Head of Business Continuity & Resilience EMEA, Cantor Fitzgerald & BGC Group
Tags: Operational and Non Financial Risk
Managing Dependency: Building Resilient Third-Party Risk Frameworks in an Interconnected World
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
  • Business owners must retain accountability for third-party risks and supplier relationships.
  • Integrated risk frameworks should focus on critical business services rather than individual risk disciplines.
  • Effective due diligence requires visibility of fourth parties and underlying dependencies.
  • Continuous monitoring, testing and early exit planning are essential for lifecycle management.
  • Organisations should assess dependency concentration, not just supplier concentration.
  • True resilience is demonstrated by the ability to operate when critical suppliers fail.

What are best practices for clearly defining and enforcing ownership and accountability across third-party risk management processes, particularly in complex, multi-stakeholder environments?

The first principle for me is very simple: the business that chooses to depend on the third party ultimately owns the risk.

A third-party risk function can provide governance, oversight and challenge but it should not become the owner of every supplier risk. The business owner needs to remain accountable for the relationship and, critically, understand what that dependency means for the service they are responsible for.

In complex organisations, cyber, technology, procurement, legal, operational risk, compliance and resilience will all have responsibilities. The danger is that everyone owns one part of the process but nobody owns the outcome.

That is why good practice comes down to clear accountability, defined decision rights and effective escalation. There should be no ambiguity about who can accept the risk, who owns remediation and who has the authority to act when a supplier moves outside the organisation's risk appetite or can no longer deliver a critical service.

And accountability needs to work under pressure, not just look good on a governance chart.

The real test is simple: when the supplier fails, do we know who makes the decision?

How can organisations effectively integrate technology, cyber, and operational risk assessments into a single, cohesive third-party risk framework without creating duplication or silos?

I think one of the biggest mistakes is starting with the individual risk disciplines rather than with what the organisation is trying to protect.

Cyber will naturally look at security controls. Technology risk will look at systems and architecture. Operational risk will consider process failure. Resilience teams will look at continuity and recovery. Those perspectives are all important but ultimately the organisation needs to understand what they collectively mean for its ability to continue delivering its critical services.

I would build a common view of the dependency:

Business service third party technology data people locations fourth parties recovery

That is where integration becomes valuable.

Integration does not mean forcing every function into one enormous assessment. It means bringing those different perspectives together to create one view of the dependency, one view of the potential business impact and clarity over the decisions that may need to be made.

A very simple question often cuts through a huge amount of complexity:

If this third party became unavailable tomorrow, what would stop, what would the impact be and how long could we tolerate it?

That moves the conversation away from individual risk scores and towards resilience.

What does robust, end-to-end due diligence look like in today’s environment, and how can firms address common gaps when dealing with layered or indirect supplier relationships?

For critical suppliers, due diligence has to go beyond whether the right policies and controls exist.

We need to understand financial viability, cyber posture, operational resilience, recovery capability, geographic exposure, technology dependencies and reliance on subcontractors. But increasingly, the biggest risks sit beneath the supplier we can see.

I often think of this as the dependency behind the dependency.

You may contract with one supplier but that supplier could depend on a cloud provider, data centre, software platform or specialist fourth party that also supports multiple other suppliers across your organisation.

That creates interconnected risk which may not be visible when relationships are assessed individually.

So due diligence should answer two questions:

·      Can this supplier meet our requirements?

·      And what does this supplier depend on to keep meeting them? 

For the most critical relationships, I also believe we need to move beyond assurance towards validation.

A supplier telling me they have a recovery plan gives me assurance. Demonstrating that they can recover within the timeframe my critical service requires gives me evidence.

Where proportionate, test it. Exercise it. Challenge the assumptions. Understand whether recovery works against the scenarios that actually matter to your organisation.

A plan tells you what should happen. A test tells you what actually might.

What are the key elements of best-in-class lifecycle management for third-party risk—from onboarding and contracting through to continuous monitoring and exit strategies?

The risk profile you assess when you sign a contract is not necessarily the risk profile you will have two or three years later.

Suppliers change. Technology changes. Subcontractors change. Financial conditions change. Geopolitical exposure changes. And, importantly, your own dependency on that supplier can quietly increase over time.

I think about the lifecycle as:

Understand Assess Contract Monitor Test Respond Exit

At onboarding, understand criticality and dependency. Contractual requirements should then reflect that criticality, particularly around security, resilience, incident notification, recovery, audit rights, data and subcontracting.

Monitoring should be continuous and proportionate to risk. But for critical suppliers, monitoring alone is not enough. We also need to understand what happens when the control environment fails.

What happens if the supplier is unavailable for 24 hours? Three days? Several weeks?

Can we operate manually? What happens to customers and critical services? Do we have a genuine alternative? How quickly could we transition? And who has the authority to make that decision?

That is where third-party risk becomes operational resilience rather than supplier administration.

And exit planning needs to begin much earlier than many organisations think.

A contract can end relatively quickly. A dependency often cannot.

What proven approaches can organisations adopt to identify, measure, and mitigate concentration risk and supply chain vulnerabilities across increasingly interconnected third-party ecosystems?

This is one of the areas I think organisations need to challenge themselves most.

You can look diversified on paper and still be highly concentrated underneath.

You might have ten different suppliers but if eight ultimately rely on the same cloud platform, data centre, telecommunications provider, specialist technology or geographic region, you do not necessarily have the resilience you think you have.

That is why I would distinguish between supplier concentration and dependency concentration.

Supplier concentration tells you how much business you have with individual providers. Dependency concentration tells you where multiple critical services ultimately rely on the same underlying capability.

I would therefore map concentration across suppliers, fourth parties, cloud platforms, technology, geographic locations, infrastructure, specialist skills and, most importantly, critical business services.

Once those concentrations become visible, scenario testing becomes extremely powerful: What happens if this provider, technology or region becomes unavailable and several critical services are affected at the same time?

That is a very different resilience challenge from losing one supplier in isolation.

Not every concentration can or should be removed. Commercially, that would be unrealistic. The objective is to make concentration visible and intentional rather than hidden and accidental.

Once leadership understands the dependency and its potential impact, it can make a conscious decision: diversify, strengthen contingency, improve recovery capability, redesign the service or knowingly accept the exposure.

Ultimately, I don't see third-party risk as simply managing suppliers.

It is about managing dependency.

Knowing what we rely on, what sits underneath it, who is accountable for it and whether we can continue operating when that dependency fails.

Because ultimately, resilience is not demonstrated by how well we understand a supplier when everything is working.

It is demonstrated by what the organisation can still do when that supplier is not.

Milena Maneva Bio

Milena Maneva is a recognised resilience leader with over 16 years of experience across financial services, brokerage, legal, and real estate sectors. As Head of Business Continuity & Resilience, EMEA at BGC Group and Cantor Fitzgerald, Founder of ResilienceArc and Chair of the Institute of Strategic Risk Management (ISRM) London Chapter, she helps organisations navigate disruption, strengthen resilience and turn complex risks into strategic opportunities. A trusted advisor to senior leaders and boards, Milena specialises in business continuity, crisis management, risk governance and enterprise resilience. Recognised for her contributions to the resilience profession, Milena has also served as a judge for the FSTech Awards 2026, ISACA Global Achievement Awards 2026, Security & Safety Entrepreneur Awards (SSEAs) 2026 and the Recruiters Investing in Talent Awards. As organisations face increasing uncertainty, she remains focused on advancing resilience through thought leadership, innovation, and cross-industry collaboration, helping leaders build organisations that are prepared, adaptable and future-ready.

Milena Maneva
Sign in to view comments
You may also like...
ad
Related insights