Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What happens when an EMI uses third-party providers…
Governance, Ownership & Risk

What happens when an EMI uses third-party providers without clear regulatory oversight?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Governance, Ownership & Risk

The EMI remains legally responsible to the client even when services are delegated to another provider. That means outsourcing does not transfer accountability, and supervisors can still inspect the provider and request audits through the EMI. If governance is weak, the arrangement can create compliance gaps, operational risk, and exposure to regulatory action because the service contract does not replace the legal obligations of the EMI.

An EMI can delegate processing, hosting, support, or other operational functions, but it does not delegate its statutory obligations. The regulatory relationship remains anchored in the EMI, so outsourcing changes the delivery model, not the duty to remain compliant, accountable, and supervised. That distinction matters most when the provider performs regulated activity or handles customer-facing processes.

Outsourcing also makes governance harder if roles, controls, and evidence are not explicitly defined. The EMI still needs to know what the provider is doing, which obligations remain with the EMI, and which controls must be demonstrably in place before the arrangement can be treated as acceptable.

Where oversight gaps usually appear

The main failure mode is assuming the contract itself creates control. In practice, weak oversight often shows up as unclear ownership of monitoring, incomplete audit rights, poor incident notification terms, and no tested exit or contingency path. If the provider can change systems, subdelegate work, or move data without meaningful challenge, the EMI can lose visibility into compliance exposure even though accountability stays unchanged.

Third-party dependence can also expand the blast radius of a control failure. A provider problem may become a regulatory problem if records, access logs, resiliency arrangements, or security controls are not available when supervisors ask for evidence. The issue is not just whether the provider is competent, but whether the EMI can still prove effective control over the outsourced activity.

What regulators and clients expect the EMI to be able to prove

The practical standard is evidence of governed outsourcing, not informal trust. The EMI should be able to show due diligence on the provider, contractual rights to inspect and audit, ongoing monitoring, clear service expectations, and a reasoned assessment of whether the outsourced function creates material operational or compliance risk. That expectation becomes stronger when the provider supports core client services or sensitive data handling.

For financial services practitioners, this is a good place to use the logic in EU Digital Operational Resilience Act (DORA) as a benchmark for disciplined third-party oversight. Where outsourcing touches regulated records, availability, access control, or incident response, the EMI should also look at control expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls and the governance functions in NIST Cybersecurity Framework 2.0.

Risk and Threat Considerations

Clear oversight matters because third-party arrangements can turn a routine service dependency into a compliance and resilience exposure. The risk increases when the EMI cannot see how the provider controls access, logging, subprocessing, change management, or incident escalation.

Failure mechanism: The EMI retains responsibility but loses effective control because the provider relationship is not backed by enforceable audit rights, continuous monitoring, and evidence retention. That can leave gaps between what the EMI believes is happening and what regulators or clients will expect to see.

Impact: The EMI can face supervisory findings, remediation orders, contractual disputes, service disruption, and avoidable regulatory action if it cannot demonstrate control over the outsourced activity.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
DORAICT third-party risk managementThird-party outsourcing in regulated finance directly affects oversight, resilience and supervisory expectations.
Recommendation — Apply ICT third-party controls to maintain oversight, auditability and exit readiness for material providers.
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingProvider oversight depends on reviewable logs and evidence when the EMI must prove control.
Recommendation — Require auditable evidence and review provider logs for material outsourced services.
NIST CSF 2.0GV.SC-01 — Supply Chain Risk ManagementThe question centers on governance of outsourced providers and the EMI's retained accountability.
Recommendation — Govern third-party dependencies with clear oversight, contractual controls and monitoring.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsSupplier relationships create the governance and assurance gap described in the question.
Recommendation — Define supplier security requirements, monitoring and responsibilities in the outsourcing arrangement.

Practitioner Guidance

What to verify: Confirm that the EMI can produce a complete outsourcing file for each material provider, including the risk assessment, contract, audit and inspection rights, incident notification terms, subprocessor visibility, and exit arrangements. If any one of those is missing, treat the arrangement as incomplete rather than merely undocumented.

Decision rule: If the provider performs a regulated or customer-impacting function, do not accept “the vendor has controls” as sufficient. The EMI should be able to evidence its own oversight, its own approvals, and its own ability to intervene.

Practitioner takeaway: The key test is not whether the EMI outsourced the work, but whether it can still govern, evidence, and defend the work as if its own regulatory accountability remains fully intact.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org