The role of internal audit in monitoring third-party risk
Insurers increasingly depend on external providers for cloud hosting, claims administration, payment processing, data analytics, cybersecurity, customer contact centers, and specialized technology. These relationships can improve efficiency and access to expertise, but they also create exposures that may sit outside the organization’s direct control. A vendor outage, weak access management practice, regulatory breach, or failure to protect policyholder data can quickly become an insurer’s problem.
Internal audit provides independent assurance that third-party relationships are governed with the same discipline applied to internal operations. Its role is broader than checking whether procurement files are complete or contracts contain standard clauses. Effective audit work examines how the organization identifies supplier risk, selects providers, monitors performance, responds to incidents, and exits relationships when necessary.
A strong third-party risk program also supports finance, operations, information security, compliance, and executive decision-making. Internal auditors connect these functions by assessing whether controls work across the entire vendor lifecycle and whether management receives reliable information before a weakness becomes a business disruption.
Why third-party oversight belongs in the audit plan
Outsourcing does not transfer accountability. Insurance companies remain responsible for meeting legal, regulatory, contractual, and customer obligations even when a service is delivered by a technology provider, administrator, broker, consultant, or offshore processing partner. Internal audit therefore needs visibility into the full network of material suppliers, subcontractors, and fourth parties.
The audit universe should reflect the effect a provider could have on critical business services. A small software vendor with privileged access to claims data may deserve more attention than a larger supplier providing a low-impact administrative service. Factors such as data sensitivity, transaction volume, operational dependency, geographic concentration, substitutability, and recovery time objectives help determine priority.
Internal audit should also consider concentration risk. Several vendors may rely on the same cloud platform, telecommunications carrier, payment network, or software component. A disruption at one common dependency can affect multiple services at once, making a simple vendor-by-vendor review insufficient.
Define a risk-based audit scope
The first step is to understand how management classifies third parties. Auditors should compare the supplier inventory with accounts payable records, contract repositories, procurement systems, business continuity documentation, and information security registers. Differences between these sources can reveal unapproved engagements, expired contracts, or providers that were never assessed under the formal program.
Risk assessment should cover the complete relationship lifecycle. Before onboarding, the organization should evaluate financial stability, regulatory standing, cyber controls, privacy practices, resilience, insurance coverage, ownership, and relevant litigation. During the relationship, monitoring should address service levels, incidents, control reports, complaints, data changes, subcontractor use, and material changes in the provider’s business.
Contract language is another important audit area. Agreements should define information security obligations, audit and inspection rights, notification timelines, data ownership, retention and destruction, business continuity expectations, service credits, regulatory access, and termination assistance. Internal audit does not negotiate every clause, but it can determine whether critical requirements are consistently included and enforced.
For organizations refining their procurement and oversight practices, these vendor management strategies can help connect project governance with third-party risk controls.
Test controls across the vendor lifecycle
Internal audit testing should move beyond policy review. A policy may require annual due diligence, quarterly performance reviews, or prompt incident escalation, yet actual evidence may show that assessments are late, exceptions are undocumented, or business owners cannot explain the provider’s current risk rating.
During onboarding, auditors can sample suppliers to verify that due diligence was completed before access or work began. They can inspect approval records, risk questionnaires, sanctions screening, financial reviews, data classification, and security assessments. For high-risk providers, testing may include independent assurance reports, penetration-testing summaries, recovery exercises, and evidence of employee background screening.
Ongoing monitoring requires a different set of procedures. Auditors can review key performance indicators, service-level failures, incident logs, issue registers, complaints, and management meeting minutes. They should check whether repeated failures lead to escalation, remediation plans, fee adjustments, or changes in the risk rating. A dashboard that reports only average service performance may conceal serious failures affecting a small but vulnerable customer segment.
Exit controls deserve equal attention. When a relationship ends, the insurer must retrieve or securely destroy information, revoke credentials, transfer knowledge, settle financial obligations, and confirm that critical services remain available. Internal audit can test whether termination plans are practical rather than merely documented in a contract.
Use evidence, data, and professional judgment
Third-party risk monitoring generates large quantities of information, but volume does not guarantee insight. Internal audit teams can combine contract data, procurement records, security alerts, access logs, service tickets, regulatory findings, payment activity, and business continuity results to identify patterns. For example, a vendor with recurring availability failures and rising unresolved incidents may warrant review even if its annual certification remains current.
Data analytics can help identify unusual relationships and control gaps. Useful tests include suppliers paid without an active contract, duplicate vendors, invoices above approved thresholds, missing due diligence dates, privileged accounts that remain active after staff departure, and providers whose risk ratings do not match the sensitivity of the data they handle.
Automation should support, rather than replace, auditor judgment. A risk score can prioritize work, but it may fail to capture a provider’s role in a critical claims process or a rapidly changing geopolitical exposure. Auditors should challenge the assumptions behind scoring models, verify the quality of source data, and discuss emerging risks with business and technology leaders.
External assurance reports can be valuable evidence, especially when a provider supplies a SOC report, ISO certification, penetration-test summary, or regulatory examination result. However, reliance must be evaluated carefully. The report’s scope, review period, control objectives, exceptions, complementary user entity controls, and service locations may not align with the insurer’s actual needs.
| Audit focus | Evidence to examine | Warning signs | Useful outcome |
|---|---|---|---|
| Supplier inventory | Contracts, purchase records, application registers | Unlisted or duplicate providers | Complete and accurate third-party population |
| Due diligence | Risk assessments, screening, financial reviews | Late approvals or unsupported ratings | Risk-based onboarding decisions |
| Contract controls | Agreements, amendments, legal reviews | Missing audit rights or weak notification terms | Clear accountability and enforceable protections |
| Service performance | KPIs, complaints, incidents, service reports | Repeated failures without escalation | Timely remediation and better oversight |
| Resilience | Recovery tests, exit plans, dependency maps | Untested recovery assumptions | Greater continuity and substitutability |
| Data protection | Access reviews, encryption evidence, certifications | Excessive access or unclear retention | Reduced privacy and cyber exposure |
Report findings in business terms
Internal audit reports are most useful when they explain how a third-party weakness affects insurance operations. A finding should connect the control gap to a plausible consequence, such as delayed claims payments, inaccurate financial reporting, regulatory criticism, exposure of protected information, or an inability to serve policyholders during an outage.
Ratings should reflect impact and urgency rather than the number of missing documents. A minor documentation lapse may be less important than a technically compliant process that cannot detect unauthorized access to a core policy administration system. Clear criteria help management understand why an issue matters and which risks require executive attention.
Recommendations should have accountable owners, realistic deadlines, and measurable completion criteria. Internal audit should distinguish between management’s acceptance of risk and genuine remediation. Closing an issue because a new policy was approved is not sufficient if the control has not operated long enough to produce reliable evidence.
Issue tracking should continue after the report is issued. Auditors can validate corrective actions through targeted follow-up, review updated metrics, or incorporate unresolved matters into future audits. Persistent delays may indicate inadequate resources, unclear ownership, competing priorities, or a risk appetite that has not been formally acknowledged.
Build cooperation without compromising independence
Third-party risk is a shared responsibility. Procurement may own supplier selection, information security may assess technical safeguards, legal may review contracts, compliance may interpret regulatory requirements, and business owners may monitor service delivery. Internal audit should understand each role and identify gaps between them.
A coordinated model reduces duplicate questionnaires and conflicting risk ratings. It can also produce a common control framework that allows evidence to be reused across functions. Internal audit should remain independent from management decisions, however. It can advise on control design and emerging risks without becoming the owner of the vendor program or approving individual suppliers.
Communication with the board and audit committee should focus on themes and concentrations. Useful reporting may show the number of critical providers, overdue assessments, open high-risk findings, material incidents, dependency clusters, and suppliers lacking tested exit plans. Trends often provide more insight than a single annual snapshot.
The most mature organizations treat third-party assurance as an ongoing conversation. Internal auditors meet with operational leaders, technology teams, finance professionals, and risk specialists to understand changes in products, regulation, and service models. Professional events such as IASA Conference can support that exchange by bringing insurance executives and solution providers together around accounting, technology, risk management, and operational priorities.
Prioritize practical improvements
Internal audit can help management strengthen oversight by focusing on a manageable set of actions that improve visibility and accountability. The following priorities are especially valuable for insurers with complex supplier networks:
- Maintain one authoritative inventory that identifies critical services, data types, providers, subcontractors, owners, and renewal dates.
- Apply tiered due diligence so high-impact suppliers receive deeper assessment, more frequent monitoring, and stronger contractual protections.
- Link vendor performance, cyber events, complaints, financial indicators, and continuity testing to a common risk dashboard.
- Test exit strategies and recovery arrangements for providers supporting claims, policy administration, payments, customer service, and financial reporting.
- Escalate repeat control failures to senior management and the audit committee instead of allowing temporary exceptions to become permanent practice.
These measures work best when they are integrated into existing governance rather than treated as a separate compliance exercise. Procurement systems, contract management tools, security platforms, and enterprise risk reporting should exchange enough information to support timely decisions.
Internal audit can also evaluate whether the program is keeping pace with new delivery models. Artificial intelligence services, embedded insurance platforms, application programming interfaces, managed cloud environments, and specialized data providers may introduce risks that older vendor questionnaires do not capture. Audit criteria should evolve as the insurer’s operating model changes.
Third-party risk oversight protects more than systems and contracts. It supports accurate reporting, reliable customer administration, regulatory confidence, and the insurer’s ability to deliver on its promises. When internal audit combines independence with operational understanding, it can identify weak signals, challenge unsupported assurance, and help leaders direct resources toward the relationships that matter most.
Insurance organizations should review their supplier governance through the lens of critical services, customer impact, and resilience. Use the next audit cycle to test one high-risk provider, trace its controls from onboarding through exit, and turn the evidence into decisions that strengthen accountability across the enterprise.