← Operational risk: fundamentals, controls, and decisions
05 / 6 · 35 MIN

Change and external dependencies

Assess change lifecycle, provider concentration, and continuity and exit horizons.

Concept and mechanism

A change modifies exposure from design through service retirement. Automating a task can reduce manual error while introducing rule, data, or configuration errors at greater scale. Assessment should follow the new mechanism and test exceptions rather than only the normal path. After implementation, observe outcomes and differences from expectations. For patching, distributing a package does not prove the corrected version is active. Verify the running service and expected effect before closing risk. The NIST preventive-maintenance abstract supports this lifecycle but replaces neither product-specific instructions nor authorization to run commands on a real application.

Guided application

For external services, map dependencies beyond the direct contract. Two providers can use the same DNS, identity, or infrastructure, leaving a shared failure mode. The December 2023 FSB toolkit offers proportionate tools for managing these relationships; it does not replace legislation. Assess criticality, substitutability, and concentration with evidence. A six-month planned exit does not demonstrate continuity during a four-hour disruption tolerance. These are different horizons requiring viable plans. The July 2025 ECB cloud guide clarifies supervisory expectations without creating new legal obligations. The project should involve operations, risk, and provider owners to confirm tasks, costs, data, and recovery criteria.

IN PRACTICE

Example: providers A and B share identity services. Rehearsal should assess that failure, while the months-long exit plan remains separate from the hours-long response.

Common pitfalls

Automation treated as eliminated risk; package treated as active remediation; two contracts treated as isolation; long exit treated as immediate continuity.

Related topics: Scope, governance, and accountability · Risk assessment and control effectiveness · Events, near misses, and response

Take this idea with you

Validate actual change effects and dependencies within service-relevant timeframes.

Create account

Reference: Enhancing Third-Party Risk Management and Oversight: A toolkit · DR operational risk professional assessment2026.10