Skip to main content
Category: Third-Party and Supply Chain

Third-Party Performance Management

Simply put

Third-party performance management is the ongoing practice of tracking and evaluating how well outside parties, such as vendors, suppliers, and contractors, deliver against what an organization expects of them. It is closely related to third-party risk management, which focuses on identifying, assessing, and controlling the risks that these external relationships create. The evidence available describes the broader discipline of monitoring third parties rather than performance management as a standalone concept, so the specifics of any given program will depend on the organization's objectives and the contractual arrangements in place.

Formal definition

Third-party performance management generally refers to the structured, continuous monitoring and assessment of external parties engaged to perform outsourced business functions, evaluating their delivery against defined expectations across the relationship lifecycle. It typically operates within a broader third-party risk management (TPRM) framework, which the evidence describes as the continuous process of identifying, analyzing, and controlling risks presented by third parties, and which incorporates workflows to assess, onboard, and monitor a third-party network. Performance management and risk management are related but distinct activities: the former is oriented toward whether a third party meets service, quality, or delivery standards, while the latter is oriented toward identifying and reducing the risks the relationship poses. The evidence provided does not define third-party performance management as a discrete term, so the precise scope, metrics, and accountability structures will vary by organization, sector, contract, and jurisdiction, and depend on professional judgment. This entry is educational and is not legal, audit, or compliance advice.

Why it matters

Organizations increasingly depend on external parties, such as vendors, suppliers, and contractors, to perform outsourced business functions. When a third party fails to deliver against expectations, the consequences can extend beyond the immediate relationship to affect service continuity, quality, cost, and the organization's own obligations to customers and regulators. Tracking how well third parties perform is therefore a practical concern for any organization that relies on outside parties to meet its objectives.

Performance management is closely related to, but distinct from, third-party risk management. The available evidence describes third-party risk management as the continuous process of identifying, analyzing, and controlling the risks that external relationships present. Performance management is oriented toward whether a third party meets service, quality, or delivery standards, whereas risk management is oriented toward identifying and reducing the risks the relationship poses. Treating the two as interchangeable can obscure gaps: a vendor may be delivering acceptable service while still introducing unaddressed risks, or may be low-risk yet underperforming against contractual commitments.

Because the evidence available describes the broader discipline of monitoring third parties rather than performance management as a standalone concept, the specifics of any given program will depend on the organization's objectives and the contractual arrangements in place. The scope, metrics, and accountability structures for evaluating performance vary by organization, sector, contract, and jurisdiction, and turn on professional judgment. This entry is educational and is not legal, audit, or compliance advice.

Who it's relevant to

Procurement and vendor management teams
Teams responsible for engaging and overseeing vendors, suppliers, and contractors typically own the day-to-day work of tracking whether third parties deliver against agreed expectations. They generally translate contractual commitments into measurable standards and monitor delivery over the life of the relationship.
Third-party risk management functions
TPRM functions focus on identifying, analyzing, and controlling the risks that external relationships create, and often use workflows to assess, onboard, and monitor a third-party network. While their orientation differs from performance management, the two activities frequently share information and processes and are commonly coordinated.
Chief compliance and risk officers
Senior risk and compliance leaders generally have an interest in how third-party performance and risk are monitored, given the potential for third-party failures to affect the organization's own obligations. The extent of their involvement depends on the organization's structure, sector, and applicable requirements, which vary by jurisdiction.
The board and relevant committees
Boards and their committees typically hold an oversight role rather than an operational one. They may seek assurance that management has established adequate processes for monitoring significant third-party relationships, without themselves managing individual vendor performance. The specifics of any oversight expectation depend on the entity, sector, and jurisdiction.
Internal audit and assurance functions
Assurance providers may evaluate whether third-party monitoring processes are designed appropriately and operating as intended. Their role is generally to provide independent assurance over management's processes rather than to perform the monitoring itself.

Inside Third-Party Performance Management

Performance Standards and Service Levels
Defined expectations, typically documented in contracts or statements of work, against which a third party's delivery is measured. These may include service-level agreements (SLAs), key performance indicators (KPIs), and quality benchmarks. The specific standards vary by the nature of the relationship, the criticality of the service, and applicable regulatory expectations in a given jurisdiction and sector.
Ongoing Monitoring
The continuous or periodic collection and review of performance data throughout the life of the relationship, as distinct from point-in-time due diligence conducted at onboarding. Monitoring generally addresses whether the third party is meeting agreed standards and whether controls remain effective in operation, not merely as designed.
Risk-Based Tiering
The practice of calibrating the intensity of performance oversight to the residual risk a third party presents, so that critical or higher-risk relationships receive more frequent and rigorous scrutiny than lower-risk ones. Tiering methodologies differ across organizations and are typically informed by the entity's risk appetite.
Escalation and Remediation Processes
Defined pathways for addressing performance shortfalls, including corrective action plans, remediation timelines, and escalation to appropriate levels of management. These processes clarify who is accountable for triggering, tracking, and closing out identified issues.
Governance and Accountability Structure
The allocation of roles across relationship owners, procurement, risk and compliance functions, and, where relevant, board committees. Management typically owns the operational activity of managing and monitoring third parties, while the board or a designated committee generally exercises oversight of the overall program rather than individual relationships.
Reporting and Management Information
The aggregation and communication of performance results to decision-makers, often through dashboards, scorecards, or periodic reports. Reporting supports decisions on contract renewal, renegotiation, or exit and feeds into broader risk and assurance processes.
Contract Lifecycle and Exit Considerations
The linkage between performance outcomes and downstream decisions such as renewal, re-tendering, or termination, including contingency and exit planning where continuity of a service is important.

Common questions

Answers to the questions practitioners most commonly ask about Third-Party Performance Management.

Is third-party performance management the same as third-party risk management?
No, though the two are related and often coordinated. Performance management typically focuses on whether a third party is delivering against contractual service levels, quality standards, and value expectations. Third-party risk management focuses on the risks a relationship introduces to the organization, such as regulatory, operational, financial, information security, or reputational risk. A vendor can meet performance targets while still presenting elevated risk, and vice versa. In many organizations these are distinct but complementary activities, with performance data often serving as one input into risk assessments. The precise division of responsibility depends on how an entity structures its procurement, vendor management, and risk functions.
Does strong third-party performance management mean the organization can rely on the vendor's own controls and reduce its own oversight?
Not necessarily. Monitoring a third party's performance does not transfer accountability. In many jurisdictions and under various regulatory expectations, an organization generally remains accountable for outsourced activities and for the outcomes delivered to its customers or stakeholders, regardless of how the work is performed. Good performance results may reduce the intensity of certain monitoring, but they do not eliminate the organization's own oversight, assurance, or compliance obligations. The appropriate level of ongoing oversight generally depends on the criticality of the service, the risk profile of the relationship, and applicable regulatory requirements, which vary by jurisdiction and sector.
How should performance metrics and key performance indicators be defined for a third-party relationship?
Metrics are typically most useful when tied to defined contractual obligations, service level agreements, and the outcomes the organization actually cares about, rather than to volume alone. Many programs distinguish leading indicators that may signal emerging problems from lagging indicators that confirm results after the fact. The set of metrics generally reflects the criticality and risk profile of the relationship, so that a critical or high-risk vendor receives more comprehensive measurement than a low-risk one. Clarity on data sources, measurement frequency, and who is accountable for each metric helps avoid disputes. This is an operational activity generally owned by management or a vendor management function, not by the board.
How can an organization verify performance data reported by the third party itself?
Self-reported data can be a legitimate input, but relying on it exclusively creates a verification gap. Organizations often supplement vendor-reported figures with independent checks such as the organization's own transaction or system data, periodic reviews or audits where contractual rights permit, third-party assurance reports, customer or user feedback, and site or process reviews for higher-risk relationships. The appropriate degree of verification generally scales with the criticality and risk of the service. Any assurance work performed by an internal audit or independent assurance function is typically kept organizationally separate from the management activity of managing the relationship, consistent with the roles of the respective lines of defense.
What should happen when a third party underperforms against agreed standards?
Programs commonly define an escalation and remediation pathway in advance rather than improvising after a problem arises. This often includes documented performance reviews, corrective or performance improvement plans with defined timeframes, and clearly identified contractual remedies where they exist, such as service credits, cure periods, or termination rights. Escalation thresholds help determine when an issue moves from routine management to senior management attention, and, for material matters affecting critical services or significant risk, to relevant committees or the board consistent with their oversight roles. The specific remedies available depend on the contract terms and applicable law in the relevant jurisdiction.
How should performance management be adjusted across different types of third parties?
A single, uniform approach applied to every vendor is generally inefficient and may leave critical relationships under-monitored while over-monitoring low-impact ones. Many organizations use a tiered or risk-based approach that calibrates the frequency, depth, and formality of performance oversight to the criticality of the service and the risk the relationship presents. Critical or high-risk third parties, such as those supporting essential operations or handling sensitive data, typically warrant more rigorous metrics, more frequent review, and stronger governance involvement. The classification criteria and thresholds depend on the organization's own risk appetite and any applicable regulatory expectations, which vary by sector and jurisdiction.

Common misconceptions

Third-party performance management is the same as onboarding due diligence.
Due diligence generally occurs before or at the point of engagement to assess suitability, whereas performance management is an ongoing activity across the relationship lifecycle. The two are related but distinct: strong onboarding does not substitute for continued monitoring of whether performance and controls remain effective in operation over time.
The board is responsible for managing third-party performance.
Managing individual third-party relationships is typically a management function, owned by relationship owners with support from procurement, risk, and compliance. The board or a designated committee generally provides oversight of the program as a whole rather than performing operational monitoring. Attributing operational duties to the board, or oversight duties to management, blurs an accountability distinction that governance frameworks tend to keep separate.
Meeting contractual SLAs means all third-party risk is under control.
SLAs typically measure a defined set of service outcomes and do not necessarily capture the full range of risks a third party may present, such as compliance, resilience, or conduct risks. Performance measured against agreed standards addresses residual exposure only within the scope of those standards; other risks may require separate assessment and monitoring.

Best practices

Calibrate the frequency and depth of performance monitoring to the risk tier of each relationship, focusing more intensive oversight on critical and higher-risk third parties in line with the organization's stated risk appetite.
Define performance standards, SLAs, and KPIs clearly in contracts before the engagement begins, and ensure they reflect the outcomes and controls that actually matter to the organization rather than generic metrics.
Assign explicit ownership for each relationship and distinguish it from independent risk and compliance oversight, so that operational management and assurance responsibilities are not conflated.
Establish documented escalation and remediation pathways with defined timelines and accountable owners, and track issues through to closure rather than treating identification as the end point.
Provide decision-makers with concise, risk-based management information that links performance results to renewal, renegotiation, and exit decisions, and escalate material matters to the appropriate committee.
Treat performance management as a continuous process distinct from onboarding due diligence, revisiting standards and monitoring approaches as the relationship, service, or regulatory expectations change.