2026 Virtual Conference Agenda & Presentations
Review session descriptions and speaker bios, and download the presentations from our 2026 Fall Virtual Conference! Members are able to watch the session recordings here.
Agenda
8:55 AM - 9:00 AM
5 minutes
Welcome & Kick-Off
Julie Gaiaschi, CEO & Co-founder, TPRA
Zoom Lobby
Kick off this virtual conference with a few words from Julie Gaiaschi, CEO & Co-founder of the Third Party Risk Association (TPRA).
9:00 AM - 9:50 AM
50 minutes
From Headlines to Action - Managing Geopolitical Risk Across Third-Party Ecosystems
Sandeep Suresh, Supply Wisdom
Room 1
Geopolitical events no longer impact only global enterprises—they can disrupt organizations of every size through third-party, fourth-party, and extended supplier ecosystems. From regional conflicts and trade restrictions to sanctions, cyber…
9:00 AM - 9:50 AM
50 minutes
A New Can of Worms: Why Compliance Alone Can't Contain a Zero-Cost Adversary
Richard Hummel, SecurityScorecard
Room 2
Compliance frameworks are built on an assumption that no longer holds: that adversaries need time, budget, and skill to iterate. That assumption is what's actually in the can of worms.
9:00 AM - 9:50 AM
50 minutes
Beyond the Checklist: Building a Unified Third-Party Control Framework
Jan Stappers, LL.M., PgD EVP, GRC Solutions Strategy, Mitratech
Room 3
The TPRM landscape has become a maze of overlapping mandates, standards, and stakeholder expectations, and a checklist alone can't get you through it. Navigating this landscape requires more than a…
10:00 AM - 10:50 AM
50 minutes
Moving at Attacker's Speed: How to Rethink TPRM for the Post-Mythos Era
Jake Olcott, Bitsight
Room 2
Third-party risk management was built for a slower world. Today, organizations face a growing volume of vulnerabilities, faster paths to exploitation, and an expanding attack surface that extends across vendor…
10:00 AM - 10:50 AM
50 minutes
Gaining c-suite acceptance of emerging risks: regulation is your friend
Rachel Elliott, DRI
Room 3
Navigating emerging supply chain risks is becoming evermore complex, particularly with events become concurrent. The tropics are expanding by 0.5 degrees each year, and new countries are being affected by…
11:00 AM - 11:50 AM
50 minutes
The Two-Front Threat: Using AI to Govern Vendors in a Post-Quantum World
Room 1
The third-party risk function is caught between two converging threats and most programs are equipped for neither.
On one front: AI-enabled vendors deploy adaptive systems that drift, bias, and change…
11:00 AM - 11:50 AM
50 minutes
Staying One Step Ahead: Why Intelligence Is Replacing Traditional Third-Party Risk Management
Austin Starowicz, RiskRecon
Room 2
Cybersecurity isn't becoming more difficult because organizations have more vendors—it's becoming more difficult because adversaries are moving faster than traditional risk management processes.
Forward-looking organizations are shifting away from static…
1:00 PM - 1:50 PM
50 minutes
Your Vendor Didn’t Change, But Its AI Did: Rethinking Material Change in TPRM
Brian Shaw, Independent
Room 1
A third party may remain under the same contract while quietly changing its models, data sources, subprocessors, embedded copilots, or level of automation. Those changes can materially alter your risk…
1:00 PM - 1:50 PM
50 minutes
When Risk Evolves, Agility Wins: AI Transforms Third-Party Risk Management
Bryn Sedlacek, Aravo
Room 2
Today's TPRM programs must support resilient operations, secure IT, ethical business practices, regulatory compliance, and sustainability while navigating an increasingly interconnected risk landscape. Learn how an agile, human-centered platform provides…
2:00 PM - 2:50 PM
50 minutes
Fourth-Party Risk: The Exposure You Can’t Always See
Tracey Forney, previously Sr Information Security Manager with Federal Reserve
Room 1
Dependencies on sub-contractors and upstream providers can introduce risk that is not obvious from primary contracts. This session considers how organizations are identifying and managing fourth-party and Nth-party risk in…
3:00 PM - 3:50 PM
50 minutes
The AI-Enabled Vendor: Building a Third-Party AI Risk Assessment Aligned to NIST AI RMF
Nitin Agarwal, Luminace
Room 1
Third-party vendors are rapidly embedding generative and agentic AI into the services organizations already consume, often without notice and rarely within the scope of existing vendor assessments. Point-in-time questionnaires capture…
3:00 PM - 3:50 PM
50 minutes
Beyond the AI Hype: What’s Actually Working in Third-Party Risk Management
Sophia Corsetti, ProcessUnity
Room 2
AI has produced no shortage of demos, claims, and new terminology. But after the initial wave of experimentation, TPRM teams need a more useful conversation: What is actually working? Where…
2:00 PM - 2:50 PM
50 minutes
From Finding to Fixing: Managing Third-Party Issues, Exceptions & Performance
Kholofelo Mothibi, Corebride Financial
Room 3
Identifying a vendor risk is only the beginning. The real test of a TPRM program is what happens next—how issues are prioritized, remediation is managed, exceptions are governed, and vendor…