Tag: Third Party Risk Management
-

Norway’s BankID outage shows what DORA-grade third-party risk management actually requires
Read more: Norway’s BankID outage shows what DORA-grade third-party risk management actually requiresFor 2 days, millions of Norwegians couldn’t sign a contract, complete a house sale or access a health record because a single supplier’s infrastructure failed for the second time in 5 years. What happens when an entire country’s digital ID depends on a single supplier? On the morning of 3 September 2026, a real estate agent in…
-

Third party risk management
Read more: Third party risk managementThird party risk management is the process of identifying, assessing, monitoring, and managing the risks that come from working with external organizations. These third parties can include suppliers, vendors, contractors, service providers, consultants, technology providers, outsourced partners, and other external relationships. In governance, risk, and compliance (GRC), third party risk management matters because organizations are…
-

World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?
Read more: World Cup stadium strike was narrowly averted: how resilient are your critical suppliers?Key takeaways Introduction: What happened at the 2026 World Cup? Days before the World Cup began, a supplier issue at one of the tournament’s highest-profile venues was narrowly avoided. Reuters reported that a union representing around 2,000 food and beverage workers at SoFi Stadium reached a tentative agreement with Legends Hospitality only days before the tournament. AP described the agreement as averting a…
-

Is the vendor risk assessment dead?
Read more: Is the vendor risk assessment dead?Is the traditional vendor questionnaire still fit for purpose? Imagine beginning a vendor assessment without sending another 200-question form. Before contacting the third party, you already understand who the organization is, who sits behind it, and whether there are public risk signals that warrant closer attention. You can ask the vendor for the evidence it already holds, identify the gaps that…
-

AI is redefining third party risk: why your “approved” vendors may no longer be safe storage for data
Read more: AI is redefining third party risk: why your “approved” vendors may no longer be safe storage for dataFor years, vendor risk was treated almost exclusively as a procurement event. You assessed a new provider, negotiated terms, signed the contract and moved on to monitoring. However, that model is starting to break. The real issue now is not just new vendors entering your business ecosystem. Existing vendors are changing underneath you, in unprecedented…
-

Managing third party risk: what modern, risk based due diligence really requires
Read more: Managing third party risk: what modern, risk based due diligence really requiresHow VinciWorks and CoreStream GRC help you build a risk-based, defensible third-party risk management program. If you want a practical, easy to follow walkthrough of how to get third-party risk management right, this webinar is a great place to start. What this webinar is about: connecting Governance, Risk and Compliance (GRC) with smarter third-party due…
-

A practical step‑by‑step guide to the Third‑Party Risk Management lifecycle
Read more: A practical step‑by‑step guide to the Third‑Party Risk Management lifecycleThird parties keep modern businesses running. Vendors host systems, process data, deliver critical services, and sit inside day-to-day operations. That reality creates two truths at once: The problem is not that teams do not understand the risk. The problem is that a lot of third-party risk management (TPRM) programs were built for a simpler world.…
-

DORA just got a UK handshake: the EU – UK ICT oversight pact is a warning shot for third-party risk
Read more: DORA just got a UK handshake: the EU – UK ICT oversight pact is a warning shot for third-party riskIf your business depends on a small set of shared providers like cloud, identity, payments, or data platforms, your operational resilience risk is no longer just a “your firm” issue. It’s a system wide dependency. Regulators are now shifting supervision to where that risk sits: at the provider level, not just inside each regulated company.…
-

A first look: Michael Rasmussen’s expert review of CoreStream GRC’s Third Party Risk Management Solution
Read more: A first look: Michael Rasmussen’s expert review of CoreStream GRC’s Third Party Risk Management SolutionCoreStream GRC for Third Party Risk Management GRC pioneer Michael Rasmussen, widely recognized as the original Forrester analyst who coined the term “GRC”, recently reviewed our third-party risk management (TPRM) solution. As part of his evaluation, he spoke directly with several of our TPRM clients to gather firsthand feedback on their experiences. Based on these…
-

Black Kite’s AI capabilities supercharge CoreStream GRC’s Third-Party Risk Management solution
Read more: Black Kite’s AI capabilities supercharge CoreStream GRC’s Third-Party Risk Management solutionCoreStream GRC, the governance, risk, and compliance platform built to work for enterprise teams, has announced a powerful new integration with Black Kite’s AI engine. This partnership redefines how organizations assess, monitor, and act on third-party cyber risk: faster, smarter, and with context that matters. For CoreStream GRC users who opt in, this integration delivers…