Blog

Getting the Risk Data Right – TPRM’s Biggest Challenge

In third party risk, issues around data – data security and data privacy - often hold center court. In the wake of the recent onslaught of cyber attacks and data breaches, as well as the enhanced and new regulatory efforts to contain them, third party risk managers can often find themselves spending a lot of time talking about data.

But are they focusing on one aspect of the businesses’ data, at the expense of improving their own? Today, third party risk management (TPRM) executives are being asked to help shape their corporate data strategies, while their approach to their own risk data can be painfully out-of-date.

Two recent surveys show that while vendor risk issues may be a high priority for organizations’ finance teams, the way data is used within the risk management discipline falls considerably behind how other parts of the business may be using data to help deliver on the firm’s strategic goals.

Read More

Topics: third party risk management, third party governance, tprm, supplier risk, vendor risk, cyber risk, cybersecurity regulation, cyber resiliance, cybersecurity, data quality checks, vendor database, compliance data, risk-scoring, internal audit, regulation, Data Security & Privacy, data risk

Third Party Risk - A Unique Kind of Operational Risk

Third party risk management is on a journey. A journey that is being accelerated and guided by increased regulatory attention.

Read More

Topics: operational risk, third party risk, risk-scoring, enterprise risk, performance scoring, third party relationships, reputational risk, regulatory risk, regulatory compliance, risk and compliance, supplier risk, Financial Services, vendor risk, occ compliance, Risk Management Framework, performance management program, third party supplier

Third party scorecards: Making an improved culture of collaboration a reality

Scorecards that measure the performance of suppliers and vendors that a company contracts with have been a business tool embraced by procurement for some time now.

However, there’s an evolution underway. Increasingly businesses are recognizing that a holistic third party scorecard that also embeds risk and compliance metrics, can not only help drive continuous improvements in vendor performance, but can also help reduce the risk that third party engagements may bring to the enterprise. What’s more, scorecards can also be leveraged as a collaborative tool to help raise the collective bar of the third party ecosystem – especially in areas such as IT security.  Operational risk, Information Security and Compliance are all now stepping up to the scorecard plate.

Read More

Topics: third party risk, risk-scoring, performance scoring, third party relationships, reputational risk, organization risk, regulatory risk, regulatory compliance, data privacy, Data Security & Privacy, information security, risk and compliance

Evaluating Third Party Risk and Performance

Best practice approaches to risk and performance scoring and automated workflow

As businesses have evolved and matured, so too has their approach to third parties. In the past, companies focused more on transactional ‘supplier’ relationships, typically for raw materials or ‘parts’. However, today third party relationships form a much deeper and far-reaching part of the strategic and operational ecosystem of any Global 2000 organization.

DOWNLOAD THE WHITE PAPER

Read More

Topics: third party risk management, risk and compliance, tprm, business complexity, scale, compliance risk, Global 2000, business change, business scale, third parties, white paper, risk-scoring, performance scoring, automated workflows, risk dashboard

Empowered Third Party Due Diligence: Aravo and Dow Jones Risk & Compliance

With continued bribery and corruption enforcement actions high on the agenda of the regulators, companies should be looking to raise the bar on the due diligence of their third parties, both at onboarding and as part of a continuous monitoring process.

Read More

Topics: third party risk management, Dow Jones, due diligence, risk and compliance, Anti-Bribery and Anti-Corruption, regulatory risk, governance, ABAC, audit, workflows, risk-scoring, reporting