Third-Party Risk Management (TPRM) in the Brazilian Regulatory Context: BACEN and LGPD

TPRM extends risk management to the supplier chain. In Brazil, BACEN and LGPD make continuous monitoring of third-party posture a compliance requirement.

· #TPRM · #vendor risk · #BACEN · #LGPD

Third-Party Risk Management (TPRM) is the discipline of identifying, assessing, and monitoring the risks that suppliers, service providers, and partners introduce into an organization throughout the entire relationship. In the cyber domain, TPRM recognizes that a third party's security posture becomes part of the exposure of the very organization that contracts it.

An organization's security boundary no longer coincides with the perimeter it controls directly. Cloud providers, payment processors, integrators, software-as-a-service platforms, and support providers maintain access to data, systems, and credentials. Each of these relationships widens the attack surface beyond the organization's own assets. Third-party risk management is the structured response to this reality, and in Brazil it has ceased to be a recommended practice to become a regulatory requirement.

Why the Attack Surface Includes the Supplier Chain

An adversary seeks the path of least resistance. When an organization's direct controls are robust, the compromise vector frequently shifts to a supplier with privileged access and an inferior security posture. The compromise of a single provider with connectivity to multiple customers can propagate across its entire portfolio, which gives these relationships a concentration risk.

This dynamic has three consequences for exposure management:

Monitoring the external posture of suppliers is, therefore, an integral part of any attack surface management (ASM) program. The surface relevant to the organization's risk comprises the exposed assets of its critical suppliers to the extent of the access and integration they maintain.

Brazilian Regulatory Requirements

The Financial Sector: The Cybersecurity Regulation of the CMN and the BCB

The Brazilian cybersecurity framework for the financial sector establishes explicit requirements regarding the contracting of data processing and storage services and of cloud computing, including the institution's responsibility for the diligence of its providers. CMN Resolution No. 4,893/2021 governs the cybersecurity policy of institutions authorized to operate by the Central Bank and the requirements for contracting these services. Joint resolutions and related regulations of the Central Bank extend equivalent principles to other regulated segments, such as payment institutions.

The elements that this framework makes enforceable, with respect to third parties, consistently include:

The joint reading of these requirements points to an expectation that goes beyond the assessment at the moment of contracting. The duty to monitor the service throughout the relationship implies continuous monitoring of the provider's posture, beyond a point-of-entry verification. It is advisable to consult the current text of the resolutions applicable to the specific segment, given that the framework is updated periodically.

LGPD: Processors, Sub-Processors, and Accountability

The General Data Protection Law (Law No. 13,709/2018) structures the processing of personal data around the figures of the controller — the party that decides on the processing — and the processor — the party that carries out the processing on behalf of the controller. When a processor subcontracts part of the activity, the figure of the sub-processor arises, and the chain of responsibility extends.

Two points of the law are decisive for TPRM:

Accountability is joint and several in relevant scenarios. LGPD provides that the processor is jointly and severally liable for damages caused when it fails to comply with the obligations of the legislation or when it has not followed the lawful instructions of the controller. The controller, in turn, answers for the processing decisions. The practical consequence is that the selection and supervision of a processor form part of the controller's duty of diligence.

Security is an obligation of both. The law imposes on the processing agents the adoption of security measures capable of protecting personal data. This obligation falls on both processor and controller, which makes the processor's security posture a legitimate and necessary object of verification on the part of the party that contracts it.

The National Data Protection Authority enforces compliance with these obligations and holds sanctioning powers. The demonstration of diligence over the chain of processors is, thus, an element of compliance that the organization needs to be able to evidence.

Point-in-Time Assessment and Continuous Monitoring

The consolidated practice of third-party risk management was born supported by questionnaires. The supplier answers a security form at the contracting phase, the organization files the responses, and the relationship proceeds. This approach presents structural limitations that render it insufficient in the face of current requirements.

The security questionnaire captures a self-declaration referring to an instant. It describes what the supplier states about its posture at the moment it responded. The effective security posture, however, varies continuously: certificates expire, services are published with inadequate configuration, assets are exposed by mistake, credentials leak. A questionnaire answered at the start of the contract says nothing about the state of the supplier six months later.

Continuous monitoring of the supplier's exposure observes the third party's external posture on a recurring basis, from its publicly observable surface, without depending on self-declaration. This observation evidences the current state of the supplier's posture and signals degradations as they occur. The two approaches are complementary and fulfill distinct functions:

The combination of the two meets the regulatory expectation of monitoring throughout the term of the contract and sustains the demonstration of diligence both before the Central Bank and before the ANPD. An organization that merely files questionnaires holds evidence of compliance at the moment of contracting; an organization that monitors continuously holds evidence of compliance at any moment it may be required.

Structuring a Defensible TPRM Program

A third-party risk management program equal to the Brazilian framework is organized around a few operational principles:

CSURFACE's third-party risk solution was designed to sustain this program, continuously observing the external posture of suppliers and integrating that view into the attack surface management of the contracting organization. The objective is to allow the organization to maintain, at any moment, current evidence of the diligence exercised over its third-party chain — the standard that BACEN and LGPD, each in its own domain, have made enforceable.

Frequently Asked Questions

What does Brazilian legislation require in relation to third-party risk?

In the financial sector, the cybersecurity framework of the CMN and the Central Bank requires prior verification of the provider's capacity, contractual provision for access to information, and monitoring of the service throughout the term of the contract. LGPD, applicable to any sector, holds both controller and processor accountable for the security of personal data and provides for joint and several liability in cases of non-compliance, which makes diligence over processors part of compliance.

Is a security questionnaire sufficient to meet the requirements?

The questionnaire documents commitments and covers internal aspects that escape external observation, although it captures a self-declaration referring to a single instant. The regulatory expectation of monitoring the service throughout the contract points to the need for continuous monitoring of the supplier's posture, which independently and recurrently verifies the current state of its exposure.

What distinguishes continuous monitoring from point-in-time assessment?

The point-in-time assessment describes what the supplier declares at a specific moment. Continuous monitoring observes the supplier's external posture on a recurring and independent basis, evidencing the current state of its surface and signaling new exposures as they arise. The two approaches are complementary.

How does third-party risk relate to the attack surface?

Suppliers with access to data and systems extend the organization's attack surface. Their exposed assets become part of the contracting party's risk to the extent of the access they maintain. For this reason, third-party monitoring is part of attack surface management. Consult the glossary for the technical terms cited.

Pronto para ver isso aplicado ao seu cenário?

Agendar Demonstração