About this slide presentation Customize this PowerPoint as you see fit Use these slides to help train your team about key aspects of third-party risk Keep this file saved where the team can easily access it The Third-Party Risk Management
"About this slide presentation Customize this" is the property of its rightful owner. Permission is granted to
download and print the materials on this website for personal, non-commercial use only, and to display it
on your personal computer provided you do not modify the materials and that you retain all copyright
notices contained in the materials. By downloading content from our website, you accept the terms of this
agreement.
Presentation Transcript
01
About this slide presentation Customize this PowerPoint as you see fit
Use these slides to help train your team about key aspects of third-party risk
Keep this file saved where the team can easily access it<br>
02
The Third-Party Risk Management Lifecycle<br>
03
Guiding the Lifecycle Documentation & reporting, oversight & accountability and independent review are peripheral to, but an integral part of the third-party risk management lifecycle.
Who will perform oversight on your third parties?
Policies, programs, procedures, control evidence and reports
Reporting is essential
Bring in internal audit teams to keep your organization honest Supporting Elements<br>
04
Determine the scope of relationships that should and should not be a part of this lifecycle.
Define what a vendor/third party/provider is to you
Scoping is essential in getting the best of your third-party risk management resources Scoping<br>
05
A strong risk assessment process is vital to a comprehensive third-party risk management program.
In order to understand the risk a vendor poses to your organization, you must understand the relationship
Evaluate all considerations of outsourcing
Understand the most amount of risk the engagement could pose, and how critical they are (or will be) to your organization Inherent Risk and Criticality Assessment Stage 1<br>
06
Due Diligence and Residual Risk Determination Due diligence is one of the most important activities in third-party risk management.
Support RFPs
Conducted for new engagements and periodically for existing engagements
Collect, review and assess applicable vendor information and controls
Determine the remaining risk Stage 2<br>
07
Vendor Selection and Contract Management Choose the best vendor and go through the process for administering sound written agreements with third parties.
Negotiation
Change Management
Ongoing Maintenance Source: Venminder Stage 3<br>
08
Keep abreast of a vendor’s performance and well-being throughout the engagement and continued periodic assessments.
Verify vendors still meet expectations
Identify areas of concern
Discover contract gaps, poor vendor trends and declining service levels Ongoing Monitoring Stage 4<br>
09
If the vendor relationship has come to an end:
Ensure exit strategy requirements are met
Notify the vendor of contract non-renewal Termination<br>
10
Key Themes to Consider at Every Single Step Board involvement Checkbox mentality is unacceptable Risk assessment needs to be kept up-to-date Documentation<br>
11
Best Practices and Mistakes to Avoid Stick to the basics – don’t be influenced by regulatory uncertainty
Study new regulations
Be responsive to new regulations
Invest in education and industry resources
Continue to grow the maturity of your third-party risk management
Keep policy and program updated
Use enforcement actions as a lens through which to view your business Wait till the examiners find fault
Nothings broken / don’t fix it
Collect documents without analysis
Inadequate or no budget approval
Prisoners of non-compliant vendors
Unidentified risk<br>