Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should insurers govern third-party access once vendors…
Governance, Ownership & Risk

How should insurers govern third-party access once vendors and sub-vendors are in scope?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 6, 2026 Domain: Governance, Ownership & Risk

They should treat third-party access as a lifecycle control, not a contract clause. That means documenting who authenticates, what delegated rights exist, which identities are non-human, and how access is removed at termination. Without that chain, the organisation cannot prove that vendor access stops when the relationship ends.

Why Third-Party Access Becomes a Governance Problem Once Sub-Vendors Exist

Insurers usually discover that “vendor access” is not a single relationship but a chain of delegated trust. Once sub-vendors are in scope, the real question is who is allowed to create, use, approve, and remove access on behalf of whom, and whether the insurer can still evidence that control at every hop. That matters because access sprawl across service desks, managed services, outsourced operations, and software support can outlive the contract that created it. When the authority chain is unclear, termination becomes a record-keeping problem instead of a security control.

For governance teams, the issue is not only confidentiality. It is also accountability, revocation, and the ability to prove that access was limited to the intended purpose. The same delegated access model that speeds operations can also blur ownership of credentials, shared accounts, and non-human identities. In practice, many insurers encounter the breakdown only after a supplier change, service exit, or audit request forces them to reconstruct who actually had standing access and who could still act through downstream partners.

Useful reference material on machine and delegated identity risk is available in the OWASP Non-Human Identity Top 10.

How Insurers Should Operationalise Control Across Vendors and Sub-Vendors

The practical answer is to govern third-party access as a managed identity lifecycle, not as an annual procurement checkbox. Insurers need a clear record of the access chain: the prime vendor, any subcontractor or sub-vendor, the business purpose for access, the system or dataset being touched, and the identity type used to obtain it. That includes human users, service accounts, API keys, certificates, and other non-human identities where those are used to perform work. If the insurer cannot distinguish which access is person-based and which access is machine-based, it cannot reliably decide how it should be approved, monitored, or revoked.

A workable model usually depends on five linked decisions:

  • who owns the access on the insurer side;
  • which vendor role is allowed to request or approve it;
  • what subcontracted access is prohibited unless explicitly disclosed;
  • how the insurer validates that access is still necessary; and
  • what evidence proves removal when the relationship ends.

These decisions need to be reflected in onboarding, review, and offboarding processes, not just in the contract. That is because sub-vendor access often changes faster than contract language, and operational change can create stale entitlements even when the legal agreement is unchanged. Insurers also need to watch for shared credentials, standing access to production, and break-glass paths that were created for support but later become normal operating channels.

NIST’s control catalog remains useful where the question is about access governance and revocation discipline, particularly around account management and least privilege. The relevant public reference is NIST SP 800-53 Rev 5 Security and Privacy Controls.

Where this approach breaks down is when insurers treat the vendor as the only accountable party and never validate downstream identities or technical revocation paths.

Where Sub-Vendor Models Create the Hardest Edge Cases

Tighter control often increases operational overhead, so insurers have to balance traceability against support speed and outsourcing flexibility.

The most difficult cases are usually not the obvious ones. They include managed service providers that operate through nested subcontractors, software vendors that rely on hosted support personnel, and situations where a sub-vendor uses non-human identities that are not visible in the insurer’s own IAM tooling. There is also a governance distinction between temporary support access and delegated operational access: one may be acceptable with tight time bounds, while the other may require formal approval, periodic review, and stronger evidence of ownership.

Industry consensus is strongest on one point: if the insurer cannot identify the downstream party, it should treat the access as not fully governed. Where consensus is weaker is on how much technical visibility insurers should demand into a vendor’s internal sub-vendor chain. Some organisations require contractual disclosure and periodic attestation; others insist on direct inventory and log evidence for all privileged pathways. The right choice depends on the sensitivity of the system, the data involved, and how quickly access can be revoked in practice. The common mistake is to assume that a clean contract means a clean access model. In reality, the access path can remain active long after the paper trail looks complete.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and MITRE-ATTACK set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Sub-vendor access often relies on non-human identities and delegated credentials.
Recommendation: Requires visibility into machine identities so downstream access can be owned and revoked.
NIST CSF 2.0PR.AAThe question is about governing third-party access and revocation across suppliers.
Recommendation: Maps third-party access to lifecycle control, least privilege, and termination assurance.
CIS Controls v86Insurers need to manage vendor and sub-vendor accounts, rights, and removal.
Recommendation: Emphasises controlled provisioning, review, and deprovisioning of external access.
NIST SP 800-63IALWhere third parties act through named users, assurance is needed on who is being trusted.
Recommendation: Supports confidence in the identity behind delegated third-party access.
MITRE-ATTACKT1078Unremoved vendor or sub-vendor credentials create abuse potential through legitimate access.
Recommendation: Highlights how legitimate accounts become an attack path if access is not revoked.

Practitioner Guidance

What to prioritise: build an inventory that ties each third-party access path to a named business purpose, an accountable owner, and the exact identity used. If a sub-vendor cannot be mapped to that chain, it should be treated as an exception rather than routine access.

What to verify: confirm that termination is technically enforceable, not just contractually promised. Insurers should verify that privileged accounts, API credentials, certificates, and delegated approvals are actually removed or disabled when a vendor or sub-vendor relationship ends, and that evidence of removal can be produced later.

What practitioners underestimate: the revocation problem is often harder for non-human identities than for people, because machine access may be embedded in integrations, support tooling, or automation. The control is only as strong as the weakest downstream identity path.

Practitioner takeaway: if the insurer cannot explain the full downstream access chain in a way an auditor and an incident responder would both accept, the governance model is incomplete.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org