Annual Report Example Third-Party Risk Management

Published  . 0 views
↓ Download
Annual Report Example Third-Party Risk Management
1 / 1
Annual Report Example Third-Party Risk Management - slide 1 of 23 Annual Report Example Third-Party Risk Management - slide 2 of 23 Annual Report Example Third-Party Risk Management - slide 3 of 23 Annual Report Example Third-Party Risk Management - slide 4 of 23 Annual Report Example Third-Party Risk Management - slide 5 of 23 Annual Report Example Third-Party Risk Management - slide 6 of 23 Annual Report Example Third-Party Risk Management - slide 7 of 23 Annual Report Example Third-Party Risk Management - slide 8 of 23 Annual Report Example Third-Party Risk Management - slide 9 of 23 Annual Report Example Third-Party Risk Management - slide 10 of 23 Annual Report Example Third-Party Risk Management - slide 11 of 23 Annual Report Example Third-Party Risk Management - slide 12 of 23 Annual Report Example Third-Party Risk Management - slide 13 of 23 Annual Report Example Third-Party Risk Management - slide 14 of 23 Annual Report Example Third-Party Risk Management - slide 15 of 23 Annual Report Example Third-Party Risk Management - slide 16 of 23 Annual Report Example Third-Party Risk Management - slide 17 of 23 Annual Report Example Third-Party Risk Management - slide 18 of 23 Annual Report Example Third-Party Risk Management - slide 19 of 23 Annual Report Example Third-Party Risk Management - slide 20 of 23 Annual Report Example Third-Party Risk Management - slide 21 of 23 Annual Report Example Third-Party Risk Management - slide 22 of 23 Annual Report Example Third-Party Risk Management - slide 23 of 23
Description: Annual Report Example Third-Party Risk Management Board Reporting Annual Report Contents Part I Vendor Risk Report: Executive summary Report details: Vendor inventory Vendor risk exposure Vendor risk events Critical vendor inventory and

Related Topics

Download Presentation

"Annual Report Example Third-Party Risk Management" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Annual Report Example Third-Party Risk Management Board Reporting<br>
slide2. Annual Report Contents Part I – Vendor Risk Report:
Executive summary
Report details:
Vendor inventory
Vendor risk exposure
Vendor risk events
Critical vendor inventory and performance
Critical vendor issues
Critical vendor issue details
Other significant issues and events
New and emerging risks Part II – TPRM Program Report:
Executive summary
Metrics and results:
Process metrics
Operational metrics
Compliance metrics
TPRM program maturity analysis
Improvement roadmap Annual Report Contents 2<br>
slide3. Vendor Risks Annual Board Report: Part I<br>
slide4. Risk Exposure: 

Over the past year, the organization's overall exposure to vendor risk has increased. This is attributable to multiple factors, including the addition of several new high-risk and critical vendors that pose cybersecurity, compliance, and operational risks. There was also a significant increase (53%) of vendors risk rated as moderate. This increase is a result of multiple new operations, finance, and human resources projects requiring vendor support.    Additionally, after implementing improved TPRM risk assessments, previously unidentified risks related to vendor artificial intelligence, fourth and nth parties, and vendors’ TPRM practices were identified, requiring recalibration of the level of vendor risk exposure. Although inherent vendor risks have increased compared to the previous year, the subsequent mitigation of recently identified or known risks has been mostly effective, resulting in residual risk levels that are well within the organization’s acceptable risk appetite. New and Emerging Risks: 

Artificial intelligence (AI) is becoming more common in vendor offerings and may already be integrated into products and services we currently use. In some cases, AI can present significant data security, privacy, and other risks. Previous vendor risk assessments didn’t identify where AI risk may exist. Although TPRM has recently updated processes and questionnaires to address AI concerns specifically, there may be unidentified existing risks that can’t be immediately identified or remediated due to limited TPRM and SME capacity. Significant Risk Issues or Events:

The sudden financial decline and bankruptcy of a key technology partner and critical vendor, Totuoel, the provider of our new customer app MoneySaverz, has had operational and financial impacts on the organization. Negotiations are underway to purchase the app at the cost of $350,000, which is an unplanned expense. Due to intellectual property litigation and a judgment against Totuoel for specific code used in the app, the negotiations are stalled pending further legal interpretation from the court. Vendor Risk: Executive Summary 4<br>
slide5. Regulatory Overview and Risks: 
The Interagency Guidance on Third-Party Relationships (OCC, FDIC, and the Fed) took effect in June 2023, encompassing all business relationships within the scope of TPRM. The TPRM team introduced new requirements and updated processes to address all new vendor engagements. TPRM has collaborated with the Accounts Payable department for over a year to identify previous business relationships and bring them into compliance. However, the expanded scope of the guidance increased TPRM's workload by approximately 30%. The additional workload, combined with already stretched TPRM resources, has led to severe backlogs and the inability to bring all existing third-party relationships into compliance in a timely manner. Critical Vendor Issues:
Krakamura Cloud, the provider of corporate data storage and backup services, experienced multiple outages resulting in failed service level agreements (SLAs). The vendor didn’t provide sufficient evidence of issue remediation, leading to a breach of contract. An RFP is currently open to replace this vendor.
Totuoel, the technology partner for the MoneySaverz app, filed for bankruptcy in June due to financial decline and a legal ruling against them in an intellectual property lawsuit. Our organization holds the app's code in escrow, allowing us to maintain the application. We’re negotiating with Totuoel to purchase the app outright. Negotiations require additional legal counsel review due to Totuoel’s bankruptcy filing. The deadline for our offer expires on Jan 30, 2025.
Donut Security, the company that provides our data backup center security, experienced a security breach at our Fort Myers location. While no data was compromised, the facility suffered some vandalism. The breach occurred due to a lapsed access management control that allowed two individuals, who had been fired the previous day, to access the premises using active ID badges. However, they were caught within 20 minutes of entering the building. Donut conducted a full access management review, remediated the issue, and is paying for the repairs of damages to the entryway and front offices.
Note: Full details of critical vendor issues or events are included in a report appendix. Other Vendor Issues (Non-Critical):
NewEgg Business, our exclusive hardware supplier for network peripherals, had a fourth-party possibly violate the Uyghur Forced Labor Prevention Act (UFLPA). NewEgg has enlisted an independent supplier chain audit firm to determine what portion of manufacturing components were acquired in the Xinjiang region. Vendor Risk: Executive Summary Continued 5<br>
slide6. 42% year-over-year growth leading to increased workload for TPRM and SMEs, causing further backlog and straining limited resources.
Remediation actions:
Sourcing implementing cap on new suppliers through 2025 while they conduct study on possible opportunities to leverage existing suppliers
TPRM diligently continuing year-end vendor inventory cleanup – this involves identifying and closing out nonactive vendors
Request for additional TPRM resources was presented to finance and the board
Beginning Feb. 2025, overflow vendor risk reviews will be outsourced Vendor Inventory, Risk Exposure, and Risk Events Cybersecurity events decreased by 50%
BC/DR events decreased 17%
Vendor compliance events increased by 46%, contributing to the overall increase in vendor risk events in 2024:
This was primarily the result of a new SEC cybersecurity requirement that several vendors hadn’t yet implemented, resulting in audit or exam findings.

Remediation actions:
Continuing risk re-assessment and due diligence to identify risks that may result in a risk event
Improving contract templates to make requirements for the vendor more explicit and legally binding Cyber risk exposure increased since 2023 –more than half of moderate-risk and above vendors have elements of cyber risk
Compliance risk still substantial but decreased some from 2023
BC/DR risk associated with critical vendors has remained stable
Financial risk remains significant for engagements rated moderate and above
Offshore and concentration risks remain stable

Remediation actions:
There are no specific actions. Risks that make up the organization’s risk exposure profile result from the products and services we purchase from our vendors. 6<br>
slide7. Critical Vendor Inventory and Performance 7<br>
slide8. Critical Vendor Issues 8<br>
slide9. Holt and Bancroft (Law firm: Marketing compliance review) announced in February they were being acquired by Donal Legal International, an offshore private equity-backed firm operating in India, and the acquisition is to be finalized early in the third quarter. We have been informed that Holt and Bancroft will become their compliance operations division and is anticipated to remain in the U.S.

Key Risks:
Compliance: Risk intelligence identified that Donal Legal has been under investigation in the EU for compliance violations related to privacy and data protection
Reputation: Potential compliance violations have been widely reported in the media even though the EU’s investigation hasn’t yet concluded
Contractual: Donal informed customers of Holt and Bancroft that existing contracts won’t be honored, and new contracts are required with the parent entity
Financial: When the acquisition is finalized, existing fee structures will need to be renegotiated and prices will likely increase
Declining service and capacity: Holt and Bancroft notified that several legal team members are actively searching for new positions and two already left

 Next Steps:
Vendor Owner, Abebbi Bello, has reviewed the exit strategy and determined it will be possible to move business to another vendor. However, Donal Legal acquired the previously identified replacement vendor last year.
The vendor owner is actively working with Procurement on a new RFP. Three domestic firms have been identified as possible replacements.
TPRM is collecting due diligence information and documentation from Donal International for review, as Procurement is including them in the RFP. First Reported: March 2024
Latest Update: May 2024

The RFP closes on June 1. Results will be analyzed and shared with the risk committee and the board. (Note: The Procurement team is frustrated with Donal’s pressure tactics and failure to follow RFP requirements.)
A business relationship with Donal Legal is extremely unlikely as Donal Legal has also refused to provide several essential due diligence documents, such as a SOC 2 Type II or equivalent.

Emerging Risks:
Impact: Existing marketing compliance reviews are becoming backlogged, possibly delaying new product campaigns
Next Steps: The Internal Compliance team is actively looking for contractors to bring in-house to perform marketing compliance review work until a replacement firm can be engaged Critical Vendor Issue: Holt and Bancroft, Marketing Compliance 9<br>
slide10. Krakamura Cloud (corporate data storage and backup) had 4 outages during April and May that exceed acceptable SLA limits. The vendor failed to provide root cause analysis results and remediation plan by 06/15, as agreed upon by InfoSec, TPRM, and the vendor. The vendor owner reported declining response times from the vendor’s management.

Known Impacts: An outage on 05/10 caused an incomplete data backup, impacting Operations and Product teams. Manual workarounds were implemented, and data was restored within two business days.

Key Risks:
Operational: Delayed or missing data backup impacts Operations team's productivity and ability to generate operational stability reporting necessary for the SOC 2 Type II Audit
Financial: Legal determined that, due to SLA terms, contract termination for cause is acceptable but will result in a $250K early termination fee if it’s executed prior to 120 days of the contract expiration date, which is 09/16/26

 Next Steps:
Vendor Owner, Evan Wink, is reviewing exit strategies and plans to determine if vendor replacement is possible within 90 days (the contractual termination notice period). Findings will be reported to the Risk Committee on 06/21.
TPRM engaged legal counsel to prepare a breach of contract notice. This will be sent to the vendor if they fail to provide evidence of remediation by 06/30. First Reported: June 2024
Latest Update: New – no update 

Requested Actions from the Board: None at this time Critical Vendor Issue: Krakamura Cloud 10<br>
slide11. Tutuoel (MoneySaverz AP) has rapidly declining financial health. Risk intelligence alerted declining credit scores for three consecutive months. Annual due diligence revealed they won’t likely have enough cash to operate for more than six months. Additionally, Tutuoel must pay a legal judgment of over $1M in a disputed intellectual property case. Without a significant infusion of cash, there’s a high likelihood of Tutuoel filing for bankruptcy in the next 60-90 days.

Known Impacts: The MoneySaverz AP was integrated into our core processing ledger in January and launched to customers in March. To our knowledge, we’re the only existing customer of the MoneySaverz AP.

Key Risks:
Operational: The MoneySaverz AP was integrated into our core processing ledger. Although the code for our use of the app is in escrow, bankruptcy would likely prevent any product updates or improvements. Integration required a 6-month effort and significant resources. Replacing the AP with a similar one would be difficult.
Financial: Legal and finance are exploring the possibility of purchasing the entire application, including all programming coding, for exclusive use. Current estimates are $150-300K of unplanned expenses. An unplanned expense for AP maintenance and improvements is likely, though not currently estimated.
Reputation: Customer adoption of the AP has been strong; discontinuing it now could have reputational or customer satisfaction issues.

Next Steps:
Vendor Owner, Lionel Bean, is reviewing exit strategies and holding discussions about financial health and purchasing MoneySaverz AP
Legal is drafting an offer for purchase for board review and decision in June First Reported: May 2024
Latest Update: New – no update 

Requested Actions from the Board: Awareness Critical Vendor Issue: Tutuoel: MoneySaverz AP 11<br>
slide12. Note: NewEgg isn’t critical; it’s risk rated as moderate. However, this potential violation requires the board's attention, as there’s growing concern over human rights abuses in the Xinjiang region.

NewEgg Business is our exclusive hardware supplier for network peripherals. A new supply chain audit of this supplier revealed a fourth party's possible violation of the Uyghur Forced Labor Prevention Act (UFLPA). NewEgg informed us that, as of April, the fourth-party vendor, Dounitec, has been unable to provide a full account of all manufacturing component origins. They’ve terminated the contract but are still working on an audit to determine if there have been violations. NewEgg is enlisting an independent supply chain audit firm to determine what portion of manufacturing components were acquired from a manufacturer in the Xinjiang region.

Activists are calling out corporations that abuse supply chains through the “Inside Out” campaign, which actively targets the supply chains of Fortune 500 companies.

Key Risks:
Compliance: Breach of NewEgg contract if violations did occur
Reputation: Impact the brand and reputation if violations did occur and became public
Financial: Potential short-term customer loss

Next Steps:
NewEgg to complete an independent supply chain audit
TPRM to review the situation with Enterprise Risk, Legal, and Public Relations Other Vendor Issues and Risks 12<br>
slide13. Vendor-provided artificial intelligence (AI) is becoming more common in vendor offerings and may already be integrated into products and services we currently use. 
In some cases, AI can present significant data security, privacy, and other risks. Previous vendor risk assessments didn’t identify where AI risk may exist. Although TPRM has recently updated processes and questionnaires to address AI concerns, it's crucial to note that there may be unidentified existing risks that cannot be immediately identified or remediated due to limited TPRM and SME capacity. 
The potential impact of these unidentified risks underscores the importance of our ongoing efforts. New and Emerging Risks 13<br>
slide14. Third-Party Risk Management Program Update Annual Board Report: Part II<br>
slide15. In this annual TPRM board report, 29 individual metrics will be analyzed to measure the TPRM program's effectiveness, operational efficiency, capacity, and internal compliance. The report highlights critical successes, improvement opportunities, and risks requiring remediation, as part of an annual assessment of the health and stability of the organization's TPRM.

Program highlights:
The TPRM team achieved significant success in the past year, demonstrating its commitment to strengthening TPRM practices.

Notable projects and initiatives include:
Effective mitigation of all open audit and exam findings
Concluded large-scale inventory clean-up initiative
Updating and improving TPRM risk assessments
Integrating vendor AI risk and vendor TPRM (fourth party) management activities
Enhancing vendor owner education
Implementing performance and risk management processes
Increasing the number of contracts reviewed for required terms
Implemented functionality within the TPRM system to add automation to multiple processes

Overall, the TPRM team's accomplishments reflect their dedication to fostering a robust and resilient TPRM framework and their proactive approach to addressing emerging risks. Unfortunately, many of these notable advancements are essentially neutralized by core processes in decline due to severely limited capacity of a TPRM team, currently down to a single team member.

TPRM's resource constraints result from the organization's hiring freeze, in place since January 2024. This issue has been reported in TPRM monthly board reports since February 2024 and included as an agenda item in the last four bi-monthly risk committee meetings.

The evolving regulatory landscape and increasing complexity of vendor relationships compounded limitations. For instance, the Interagency Guidance on Third-Party Relationships, effective in 2023, now encompasses all business relationships, leading to a 30% increase in the total vendor inventory, which now includes marketing partnerships, consultants, and external HR services.

Here’s how these resource constraints and capacity issues are impacting the TPRM team and the organization:
A significant decrease in timely completion of risk re-assessments, increasing regulatory risk
Time to complete vendor due diligence is now, on average, seven weeks vs five weeks in 2023
Resulted in longer onboarding times, preventing organization from realizing the benefits of vendor engagement in a timely manner
Non-approved policy exceptions (individuals violating policy) increased
Regular TPRM oversight routines (reporting, meetings, and consulting with vendor owners) are diminished or eliminated TPRM Program Update – Executive Summary 15<br>
slide16. Risk assessment rates are currently at 84%, which is below the target rate of 95%, but stable compared to last year’s 83%.

The 2024 counts now reflect the inclusion of all business arrangements that were previously out of scope. Many of these engagements did not have accompanying risk assessments. New assessments for these relationships are currently underway as part of an inventory calibration project with a target completion date of Q2 2025.

Timely risk re-assessment is a best practice and a regulatory expectation. In 2024, 65% of all re-assessments were completed on time. The drop in risk re-assessment rates is attributed to limited TPRM capacity. TPRM Process Metrics In 2024, 96% of vendor engagements completed risk-based due diligence, surpassing the 95% target. Due diligence is labor-intensive, requiring the participation of the TPRM team, vendor owner, and SMEs. This high completion rate is crucial for validating vendor risk practices and controls, leading to better TPRM for the organization.

Completion of due diligence before contract execution ensures identified issues are remediated before entering the business relationship. This policy requirement wasn’t consistently enforced until mid-2024.

In Q3, TPRM provided additional education to specific business units not in compliance with this policy and started tracking and reporting violations to the risk committee. As a result, by the end of the year, 96% of all contracts were executed only after confirming completion and issues were addressed. Contract reviews help determine a vendor’s commitment to mitigating risks through terms and conditions such as the right to audit, indemnification, insurance, cybersecurity, and business continuity.

In Q1, TPRM and Legal created a list of necessary/preferred terms to include in vendor contracts, as appropriate and feasible. This allowed vendor owners to identify missing items or gaps in prospective contracts, requiring negotiation before involving Legal.

In 2024, 58% of contracts were reviewed. TPRM hasn’t set a target for this metric due to uncertainty about what is feasible. Further analysis is needed. Due to other priorities of TPRM and Legal, there are no current initiatives to conduct a formal analysis or set a target. The objective is year-over-year improvement. 16<br>
slide17. In 2022, formal vendor performance management requirements and processes were implemented.

All critical and high-risk vendors must undergo a formal performance review at least once per quarter.

In 2023, only 78% of all required vendors received these reviews. However, in 2024, the number of vendors receiving these reviews increased to 92%.

This increase can be attributed to TPRM’s vendor owner education efforts and consulting with individuals and business lines to establish appropriate performance metrics and reporting. These efforts are ongoing and managed on a case-by-case basis. TPRM Process Metrics Continued It’s important to consistently monitor vendor risks to identify new or changing risks and address them effectively. In the past, these monitoring efforts have been irregular and reactive.

The absence of evidence of ongoing monitoring was highlighted as an issue in the last regulatory examination (Q2 2023).

To address this issue, the TPRM team implemented a professional risk intelligence alerts and monitoring platform (Venmonitor) and worked directly with vendor owners to register vendors for monitoring. In 2024, vendor owners were able provide evidence of risk monitoring for 86% of the required vendors. Open issues at risk or past due: In 2024, 11% of identified issues were at risk or past due, which is double the desired target of <5% and represents a slight increase from 2023. A root cause analysis is currently ongoing to understand the increase.

Critical and high-risk vendors with open issues: In 2024, 14% of high-risk or critical vendors had an open issue, up from 9% in 2023. Enhanced performance management and risk monitoring have led to the identification of more issues.

On-time issue remediation rate: Although the timely remediation rate remains relatively high at 91%, it has dropped from 96% in 2023. While the ideal scenario would be to remediate all issues on time, a more realistic target is set at >95%. 17<br>
slide18. Completing timely risk re-assessments is crucial for regulatory compliance and identifying new, evolving, or changing vendor risks.

In 2023, the timely completion rate was only 72%. In early 2024, the TPRM team implemented automated reminders, resulting in a slight improvement in Q1 and Q2. However, Q3 and Q4 saw a sharp decline due to the TPRM team's limited capacity to process assessments and clear backlogs.

The 2024 average rate was only 65%, a figure that poses significant regulatory, operational, and financial risks to the organization. This underscores the critical need for immediate action to address TPRM capacity and resource issues. TPRM Operational Metrics Once a vendor has provided all necessary information and documentation, the target due diligence completion time frame is 45 business days.
In 2023, the TPRM team consistently met this time frame, completing due diligence in 44 days. However, as the number of vendors requiring due diligence increased in 2024 and TPRM capacity decreased, the backlog grew, and the time to complete due diligence extended to approximately 52 days, adding two full weeks to the process.
Contract execution is dependent on due diligence completion, so delays in due diligence affect the organization's ability to realize the benefits of vendor engagement. The TPRM staff-to-vendor ratio, which should be about one full-time employee per 250 vendors, is crucial to maintain TPRM operations, meet regulatory compliance, and manage vendor risks. The vendor population of vendors risk rated as moderate accounts for 82% of the total vendor population.
The TPRM team has worked with a resource deficit since 2023 when the ratio was .32. A growing vendor population and decreased staff in 2024 further exacerbated the gap, resulting in a ratio of .29 employees for every 250 vendors.
TPRM presented the issue and business case for increased resources to both the board and risk committee, as the current staffing level is not sustainable. Continued TPRM capacity limitations increase compliance risk, financial risk, and the ability to provide adequate oversight. 18<br>
slide19. In rare cases, TPRM will make documented exceptions to specific policy requirements. A non-approved process exception is where a policy requirement is knowingly or unknowingly violated by an employee, without proper TPRM approval TPRM.
These exceptions include executing a contract before due diligence is complete, failing to complete an inherent risk assessment, or establishing a business relationship outside of the TPRM process. Justification is often that the TPRM process is too long or complicated.
In 2023, 18% of process exceptions were non-approved. TPRM’s re-education efforts, reporting, and escalation to management resulted in a sharp decline for the first half of 2024. Decreasing capacity to monitor and report resulted in the rate of non-approved exceptions averaged 14% at the end of 2024. This is well beyond the set target of <5%. TPRM Program Compliance Metrics To ensure compliance, vendor owners must have a strong understanding of roles, responsibilities, and requirements they must meet.
A root cause analysis in 2023 determined many TPRM issues and policy violations stem from a lack of robust vendor owner education and training.
In 2024, vendor owner education and training efforts were standardized and implemented. All new vendor owners must be trained within 30 calendar days of their start date. Existing employees who take on new vendor owner responsibilities must be trained within 14 calendar days.
This has been incredibly successful, as 92% of all vendor owners were trained by the end of 2024. This is just shy of the target goal of 95%. Timely remediation of all audit or exam issues is essential. The current target is 100% of issues are remediated on time.
The remediation rate in 2023 was only 60%, which is not acceptable.
As TPRM’s top priority in 2024, open audit and exam issues were 100% remediated either on time or in advance of the required remediation date. 19<br>
slide20. TPRM program maturity refers to the level of development, stability, and reliability of a TPRM program. It’s an important factor that determines the overall effectiveness of the program in managing third-party risks. Each year, the TPRM team includes an analysis of their program components measured against the scale below.
As of 2024, the TPRM program is in the Implemented stage. TPRM Program Maturity 20<br>
slide21. TPRM Program Components Score 21<br>
slide22. TPRM Program Components Score By Component and Process 22<br>
slide23. TPRM 2025 Roadmap 23<br>