Dependency without contingency is a strategic weakness. Two thousand years before modern resilience frameworks and ISO standards, Julius Caesar seems to have understood this principle better than most. During the Alexandrian war for instance, when his enemies contaminated part of the city’s water supply to destroy his troop through thirst, he responded in typical Caesar-like fashion. He dug wells in the area he controlled to secure water for his troops. The interesting thing about Caesar is that he almost always had a plan B.
Today, as financial regulators worldwide are increasingly focused on reducing third-party risks across the financial sector (see FFIEC in the US, OSFI in Canada, DORA in the EU and FCA in the UK) by mandating financial institutions to adopt diverse resiliency measures, I thought it prudent to review the resiliency techniques used by the Roman General. In this article, I will be using the gallic campaign as a case study for that purpose. I will attempt to show that Caesar’s third-party risk management techniques, composed of three key pillars, are more relevant today than ever before.
1. Due Diligence and Ongoing Monitoring
“Alea iacta est.” – The die is cast.
Although Julius Caesar is often associated with that phrase, he was no gambler when it came to military strategy. He chose his allies and providers carefully, then monitored whether they continued to perform. His alliance with the Remi and the Aedui tribes illustrate this point. Before relying on the Remi for military intelligence, Caesar questioned their envoys, tested the specificity of the information they provided, and required tangible assurances. With the Aedui, one of his grain suppliers, Caesar monitored performance against their promised obligation. When deliveries failed to arrive, he summoned their leaders, challenged the delay, and investigated the causes. In modern terms, Caesar understood that due diligence gets you into a relationship, but ongoing monitoring tells you whether you should stay in it. That logic closely mirrors OSFI B-10 Section 2.2.2 on due diligence and ongoing monitoring.
2. Multisourcing and Geographical Redundancy
“Sed fortuna… parvis momentis magnas rerum commutationes efficit.” – Fortune… can produce large changes with very slight forces.
Caesar left little to chance as he understood that small disruptions could produce catastrophic consequences. His supply model relied on layered redundancy: local procurement and requisition, Roman provincial support, and distributed winter quarters. Early in the Gallic campaign, he combined local sourcing with provisions from Roman-controlled provinces, reducing dependence on any single community, route, or geography. Later, by stationing legions among different Gallic tribes during the winter, he spread the provisioning burden across multiple territories. That model was not risk-free. The Ambiorix revolt showed that geographic redundancy could create security vulnerabilities. Still, this redundancy model reduced supply concentration risks by avoiding total reliance on one local provider. In modern terms, Caesar’s approach mirrors OSFI B-10’s logic on concentration risks and resilience: critical operations should not depend on just one provider or one geography.
3. Internal Contingency Capabilities
“Ut est rerum omnium magister usus.” – Experience is the teacher of all things.
Caesar knew from experience that a resilient strategy could not rely solely on the performance of third parties. He, therefore, built internal contingency capabilities that could keep operations moving when providers failed. In Gaul, fortified camps and operational hubs allowed him to store supplies and protect critical assets. When planned provisioning was insufficient, foraging gave the army a last-resort internal backup for food, water and fodder. Most impressively, Caesar also had contingency capabilities for natural barriers that threatened operational movement. His engineers built a bridge over the Rhine in just 10 days allowing him to counter-attack German tribes. In modern terms, Caesar understood that true resilience requires internal fallback capacity, tested response options, and continuity planning. This approach mirrors the same logic reflected in OSFI B-10’s expectations on business continuity and exit planning.
In summary, Caesar’s Gallic campaign offers more than a historical analogy; it offers a practical lesson in third-party resilience. He did not treat allies, suppliers, or local communities as static dependencies. He assessed them before relying on them, monitored whether they continued to perform, diversified his sources of supply, and maintained internal fallback capabilities when external support failed. Julius Caesar’s third-party contingency playbook is clear; resilience must be carefully engineered. Financial regulators worldwide seem to agree with this sentiment as reflected by the recent shift towards stricter third-party oversight emphasizing due diligence, ongoing monitoring, concentration risk management, business continuity, and exit planning across the third-party lifecycle.
“Veni, Vidi, Vici.” – I came, I saw, I conquered.
For today’s financial business leaders, the implication is clear. Like Caesar’s legions, the institutions that will win in the 21st century are those that know where they have critical dependencies, and that have planned alternatives before disaster strikes. Third-party risk management can no longer remain a procurement exercise or compliance checklist. It must become a strategic operating discipline tied to regulatory confidence, and continuity of service. In an environment where one provider or one geography can disrupt critical operations, resilience is no longer optional. It is a competitive advantage.
Reference
Caesar, Julius. The Conquest of Gaul. Translated by S. A. Handford, revised by Jane P. Gardner, Penguin Classics, 1982.



