top of page

Search Results

Search this site

115 results found with an empty search

  • TPRM 101: Risk Remediation

    Today’s video will cover Risk Remediation , the fifth section of the Pre-contact Due Diligence phase. It highlights the importance of documenting and mitigating risks discovered during third-party assessments, ensuring compliance with regulatory requirements, and maintaining good governance practices. The video also provides detailed strategies for documenting risks, creating mitigation plans, and ensuring effective communication and validation with third-party partners. Understand how to document, mitigate, and manage risks identified during vendor assessments—before finalizing agreements.

  • TPRM 101: Risk Identification

    This video will focus on Risk Identification , the fourth section of the Pre-Contract Due Diligence phase of the TPRM lifecycle. Learn how to uncover and categorize risks in a potential third-party relationship as part of the Pre-Contract Due Diligence phase.

  • How Third-Party Risk Management Helps Combat Vendor AI Risk: Mitigating New Risks With Established Processes

    Artificial intelligence (AI) is everywhere, and it’s transforming the way we live and work. It’s rapidly revolutionizing industries with its potential to solve complex problems, enhance decision-making, and improve efficiency. As such, the integration of AI into many products and services offered by third-party vendors to organizations is also becoming more widespread, many times without the organization’s awareness.    Understanding the Risks of Third-Party AI   AI is an impressive technology, but it also comes with significant risks, especially when it’s integrated into vendor products or services.    Let’s examine two of the most common risks of third-party AI usage:   Data security and privacy – AI systems need a significant amount of data to function efficiently. Therefore, it’s essential to protect the data from theft and misuse. AI systems may access different types of data such as:   Customer/consumer information and personal identifiable information (PII): This includes addresses, driver's licenses, passports, family members, financial or health information, social media or web use data, shopping behaviors, and more.   Sensitive company data:  This includes employee records, financial information, customer data, legal and compliance information, supply chain inventory, logistics, forecasting, and all types of intellectual property.   Compliance and legal – It’s vital to understand there are significant legal and compliance concerns related to the use of data and other assets when they’re accessed and processed with AI. The use of AI in data processing may be subject to numerous laws and regulations, including:  Health Insurance Portability and Accountability Act (HIPAA)   Children's Online Privacy Protection Act (COPPA)   Gramm-Leach-Bliley Act (GLBA)   Electronic Communications Privacy Act (ECPA)   California Consumer Privacy Act (CCPA)   Numerous state privacy laws   Additionally, there’s a risk of violating permissible use requirements preventing out of context, unrelated, or unfair use of data.   While these are two significant risks associated with AI, they’re not the only ones. Ethical risks, including bias and fairness, require attention, as do algorithm transparency, financial risk, and intellectual property risks. As AI technology becomes more widespread, the risks associated with it are also expanding.   Identifying AI Risk in Your Third-Party Vendor Portfolio   You likely have third parties who are currently using AI in their products and services. If you haven't done so already, it’s important to identify these third-party vendors and assess the specific AI risks they pose to your organization and customers.     It's crucial to update your third-party risk management (TPRM) framework and tools to include AI risks. However, many TPRM programs haven’t incorporated AI risks, and it’s important to address this issue now.    A practical, two-prong approach can ensure you’re identifying existing third-party AI risks and building the infrastructure to properly assess and mitigate them:   Getting started  – Develop a short questionnaire to help identify the products and services utilizing AI. Here are three suggested questions that can provide a wealth of information:   Has AI technology been used in the research, development, or production of any of your products or services?  It's worth noting that different types of AI carry different levels of risk. For instance, a vendor might use image recognition for research purposes, generative AI to create a system that interacts with customers directly, such as a chatbot, or machine learning to identify fraud across a series of transactions.   Are there any plans to incorporate AI in your products, services, or operations?  It's crucial to consider that your third-party vendor's adoption of AI can significantly impact your organization, even if they aren't currently using it today.   Do you have any policies on employee use of AI?  Inquire whether your third-party vendor has any limitations or prohibitions regarding the workers' usage of AI for work-related assignments. With the increasing popularity of generative AI systems such as ChatGPT, it’s essential to understand how your vendor is supervising the utilization of such technologies among their employees, especially if the AI-based service uses the data input to train its model.   Begin with your critical and high-risk vendors and work your way down the list. This simple approach can help you determine where additional due diligence and risk reviews are needed.   Updating your TPRM framework  – It's not enough to identify third-party vendors with AI; you’ll also need proper tools and processes to ensure they have adequate AI risk management practices and controls, and that risks are well-managed and monitored throughout the contract. This means incorporating AI risk across your entire TPRM framework. Here are key areas to review and update:   Incorporate AI-related questions in the inherent risk assessment   Update vendor questionnaires to include AI-related questions   Identify the types of due diligence documentation you’ll request as evidence of AI controls   Review and update standard contract language to address AI risks   Consider how AI will be factored into third-party performance monitoring and management   Consider how AI will be factored into third-party risk monitoring    Update governance documentation    Evaluate stakeholder education and collaboration   Note: Don’t overlook this important consideration! It’s crucial to update your TPRM processes and tools with a sense of urgency. However, it should be noted that AI isn’t yet as well understood as other established risk domains. Even experienced TPRM professionals may face unique challenges when dealing with AI, which could lead to delays, rework or, in the worst case, ineffective risk identification, assessment, and management.     To help prevent these AI challenges and issues, your organization should find and work with a qualified AI subject matter expert who can guide you through the process of updating the TPRM framework. This expert can help determine the right questions to ask on a vendor risk questionnaire, identify the appropriate due diligence documents, and provide ongoing support for vendor risk reviews. If you don't have access to this expertise within your organization, you may need to engage external resources or consultants.   By taking this simple approach, your organization can begin to identify vendor AI usage within your organization and start taking steps to mitigate the risks. This will leave your organization in a safer, more prepared position.

  • Significant Third-Party Risk Events and Lessons for 2024

    By Hilary Jewhurst, Head of Third-Party Risk Education & Advocacy at Venminder This past year was an eventful one for the third-party risk management (TPRM) industry. New headlines seemed to appear each month that brought attention to third-party risk, whether it was a significant cybersecurity event, like the MOVEit data breach, or the ongoing discussion of the potential risks and rewards of artificial intelligence (AI). The mid-year release of the Interagency Guidance on Third-Party Relationships: Risk Management was perhaps the most obvious reminder of the increased regulatory focus on TPRM. We’re going to review some of the lessons learned from the past year’s events and look forward to some best practices for 2024. Significant TPRM Events of 2023 and Lessons for 2024 The following list of events highlights a few TPRM trends that are worth exploring in greater detail. Although we can’t predict what 2024 will bring, TPRM leaders can stay informed of these trends and determine how to implement these best practices into their programs. Release of Interagency Guidance on Third-Party Relationships : Risk Management – The OCC, FDIC, and Federal Reserve released the final guidance in June, which brought a unified approach to TPRM best practices. The guidance offers a clear framework for how an organization should manage its third-party relationships, such as identifying critical and high-risk vendors and having awareness of subcontractors that can elevate risk. MOVEit Data Breach  – Thousands of organizations in the U.S. and abroad were impacted by the MOVEit data breach, either from using the software directly or being indirectly exposed to it through a third- or fourth-party vendor. The situation unfolded in June, but victims are still coming forward months later, indicating that this incident may not be resolved anytime soon. Emerging Risks of AI –  As AI continues to evolve with new possibilities, many experts are reminding business leaders to acknowledge the potential risks such as data manipulation and hard-to-detect automated cyberattacks. Because AI is changing so quickly, the Biden administration even released an executive order to promote new standards for the safe and secure use of this technology. TPRM continues to be a growing topic and 2024 will no doubt bring new regulatory expectations that will influence best practices across all industries. Third-party cyberattacks and data breaches will likely continue to grow in complexity and occurrence, so it’s important to have a strategy in place to respond and limit their impact to your organization. Staying aware of new risks and industry trends will help protect your organization as we head into a new year.

  • TPRM 101: Pre-Contract Due Diligence (PCDD) - Part 1

    This video introduces the second phase of the TPRM lifecycle— Pre-Contract Due Diligence —and outlines how to structure this critical stage before onboarding a third party. Welcome back to TPRA’s Third Party Risk Management 101 series, a guide for creating and enhancing your Third Party Risk Management Program. For our fourth episode of the TPRM 101 series, we will be discussing Pre-Contract Due Diligence, the second phase of the TPRM lifecycle. This phase will be explored in a two-part video series.

  • Third Party Risk Management (TPRM) 101 Guidebook

    The Third Party Risk Association (TPRA) is excited to bring you the first comprehensive Third Party Risk Management (TPRM) program guidebook. This guidebook will walk you through all phases of the TPRM lifecycle in detail and provide you with practical tools, tips, and examples for its implementation. It was developed over the course of three years from the input of numerous TPRM Practitioners, subject matter experts, and TPRM Service Provider organizations (i.e., the Third Party Risk Management Community).  We hope you find this guidebook to be helpful and easy to understand, providing you with relevant tips and examples to ensure successful implementation and/or enhancement of your current TPRM program. Downloading the Guidebook To download the Guidebook, visit the link below and complete a short form. Note: Contact information collected through this form will be used in the event TPRA publishes an updated copy of the resource. Downloaded by over 3,000 TPRM professionals! Feel free to leave a review in the comments below!

  • How Continuous Vendor Monitoring Benefits Organizations

    By Hilary Jewhurst, Head of Third-Party Risk Education & Advocacy at Venminder Most third-party risk professionals understand the importance of conducting thorough due diligence. After all, it’s essential to ensure that your potential vendors have the appropriate practices and controls to address the risks of the products and services they’ll provide to your organization. However, it’s important to remember that performing initial due diligence and signing a contract doesn't eliminate vendor risks. Due diligence only captures a snapshot in time. Vendor risks, controls, quality, and service fluctuate. To lessen the impact and severity of vendor risks on your organization, it's crucial to practice continuous monitoring – also known as ongoing monitoring. This ensures that your vendors remain in compliance with applicable laws and regulations, provide quality products and services, and address any issues effectively and promptly. What Does Continuous Monitoring on Vendors Mean? Continuous monitoring is the practice of constantly and consistently keeping your eye on your vendors and their risk and performance. You’ll need to periodically reassess their risks and validate controls throughout the contract term to verify vendor performance aligns with contractual requirements and industry standards. It's important to keep continuous monitoring risk based. This means that the frequency and rigor of monitoring is proportionate to the vendor's (and their products’ and services’) risk. A rule of thumb for reviews is annually for all critical and high-risk vendors, every 18-24 months for moderate-risk vendors, and every two to three years for low-risk vendors. Four Benefits of Vendor Continuous Monitoring Not only is continuous monitoring a best practice, but for many industries, it's a regulatory requirement. This may be your organization’s only incentive for performing continuous monitoring, but it has other important benefits, including: Decisions based on real-time data – As vendor risk is subject to change, it’s essential to gather multiple forms of data to compare and analyze. Initial due diligence can help you quickly compare two vendors, but continuous monitoring tracks changes over time in a specific vendor's risk. It offers the most comprehensive understanding of your vendors' risks and enables better organizational decision-making. Maximized productivity – To use your limited resources effectively, it’s important to clearly understand which vendors need the most attention. By identifying which vendors are a priority, you can allocate your time and resources so that pressing issues are addressed on time. Confirmed vendor value – Continuous monitoring keeps your vendor relationships productive and beneficial for your organization. This enables you to evaluate whether your vendors fulfill contractual expectations. You can then make the necessary adjustments to improve the partnership. Avoided expensive surprises. With continuous monitoring, you can identify and address potential costly situations, including regulatory violations, data breaches, and vendor instability. A proactive approach ensures your operations are efficient and mitigates the risk and expense of potential issues. How Vendor Continuous Monitoring Safeguards Your Organization It's crucial to have a clear understanding of how your organization should handle any issues that arise during vendor monitoring. It's not enough to simply recognize a problem exists, but you have to take action. Here are three significant outcomes of continuous monitoring: Identifying problems and issue management: Identified problems should be added to a formal issues log. The log should include a full description of the issue, root causes, ownership, remediation steps, and timing. Issues must be tracked and monitored until closed. Issues at risk or past due should be escalated to management to ensure proper closure. Identifying emerging risks: It's important to keep an eye on emerging risks that could affect your vendor relationship. Changes in vendor management or ownership, regulatory requirements, or even declining financial health are all examples of emerging risks. You should discuss any emerging risks with your vendor and gather additional documentation or remediation plans as needed. You may also need to perform vendor control assessments or other risk reviews. Don’t hesitate to sign up for vendor risk monitoring and alerts, such as Google Alerts, or seek help from outside risk intelligence firms that specialize in this. By taking these steps, you can ensure that emerging risks are kept in check. More frequent monitoring. If vendors have any issues or emerging risks, it's important to monitor them more frequently and rigorously. This is because problems rarely occur in isolation and can signal the presence of other potential issues or emerging risks. By keeping a close eye on problem areas, you can identify and address any problems before they become more significant or difficult to manage. Vendor risk is always changing, and continuous monitoring is an essential activity to minimize vendor risks and their potential impact on your organization and customers. By implementing a risk-based approach to continuous monitoring, your organization can identify and address issues early on before they become unmanageable. Although it may seem like a daunting task, don't view monitoring as a chore. Instead, embrace it as a valuable tool for successful third-party risk management.

  • TPRM 101: Contract Review

    This video unpacks the Contract Review phase of the TPRM lifecycle, guiding practitioners on how to protect the organization by documenting enforceable third-party expectations in legal agreements. The third video in TPRA's "TPRM 101" series explains Contract Review, the third phase of the TPRM lifecycle. Contract Review is an essential step in the TPRM process, as it ensures organizations document relationship expectations in an agreement that can be upheld in a court of law.

bottom of page