Hosted by Michael Rasmussen, GRC2020
25th September 2023 10am to 5pm (including lunch and drinks reception)
Home House Private Members Club
20 Portman Square,
London,
W1H 6LW
Register InterestThird Party Management by Design Workshop
25th September 2023 10am to 5pm Including lunch and drinks receptionWorkshop Abstract:
The structures and realities of business today have changed. Traditional brick-and-mortar business is outdated: physical buildings and conventional employees no longer define the organization. The modern organization is an interconnected web of relationships, interactions, and transactions that span traditional business boundaries. Layers of relationships go beyond traditional employees to include suppliers, vendors, outsourcers, service providers, contractors, subcontractors, consultants, temporary workers, agents, brokers, dealers, intermediaries, partners, and more. Complexity grows as these interconnected relationships, processes, transactions, and systems nest themselves in intricacies, such as deep supply chains and subcontracting relationships. Roaming the hallways of an organization means crossing paths with contractors, consultants, temporary workers, and more. Business today relies and thrives on third-party relationships; this is the extended enterprise.
In this context, organizations struggle to govern their third-party relationships and too often manage risk and compliance within those relationships in silos that fail to see the big picture of risk exposure and the impact on the relationship’s objectives. Risk and compliance challenges do not stop at organizational boundaries. This is particularly true in this new era of ESG in the extended enterprise. An organization can face reputational and economic disaster by establishing or maintaining the wrong business relationships or allowing good business relationships to sour because of weak risk governance. Third-party problems are the organization’s problems and directly impact the brand and reputation, increasing exposure to risk and compliance matters. When questions of delivery, business practice, ethics, privacy, safety, quality, human rights, resiliency, corruption, security, and the environment arise, the organization is held accountable, and it must ensure that third-party partners behave appropriately.
Dissociated data, systems, processes, and a myopic risk vision leaves the organization with fragments of the truth that fail to see the big picture of third-party performance, risk, and compliance across the enterprise and how it supports its strategy and objectives. The organization needs to have holistic visibility and situational awareness of third-party risk across the enterprise. The complexity of business, intricacy, and interconnectedness of third-party risk data requires that the organization implement a third-party risk management strategy.
This workshop aims to provide a blueprint for attendees on effective third-party risk management in a dynamic business, regulatory, ESG, and risk environment. Attendees will learn third-party risk management strategies and processes that can be applied across the organization at either an enterprise or a department level. Learning is done through lectures, collaboration with peers, and workshop tasks.
Objectives of workshop:
Attendees will take back to their organization approaches to address:
- Effectively managing due diligence and third-party risk.
- Understand the challenges and pitfalls of managing third-party risk
- Achieve success capitalizing on third-party relationships while maintaining compliance
- Facilitate ongoing monitoring of third-party partners.
- Define a third party management lifecycle for managing and monitoring third party relationships
- Establish third party management ownership and accountability
- Provide third party management process consistency
- Communicate effectively with third parties on matters of risk and compliance
- Track critical workflow and tasks internally and with third party relationships
- Deliver effective third party governance and assurance to the board of directors, regulators, and stakeholders
- Monitor metrics to establish effectiveness or third party management
- Identify and resolve issues with third parties
- Map third party relationships to objectives, risks, controls, issues, and other GRC areas
Benefits to attendees:
- Understand a top-down as well as a bottom-up approach to third party management
- Implement third party management in the context of business strategy, process, and operations
- Explore third party management architecture models and how they apply to your organization
- Discover various third party assessment and monitoring techniques and how they apply to your business
- Develop an third party information architecture that aligns with business operations and processes
- Effectively communicate and gather attestation on third parties across your organizations
Who should attend?
- Procurement Professionals
- Supply Chain Professionals
- Ethics & Compliance Professionals
- Risk Management Professionals
- IT Security Professionals
- Legal Professionals
- Environmental, Health & Safety Professionals
- Corporate Social Responsibility & Accountability Professionals
- Individuals with third party management, ownership, or oversight responsibilities
Proposed Agenda:
Part 1: Third Party Management by Design
Why Third Party Management Matters
- Third Parties in Disarray: how organizations mismanage third parties
- Third Party Exposure: how mismanaged third parties expose the organization to risk
- Current drivers & trends pressuring organizations in third party management
- Different ways organizations approach third party management
- What Effective Third Party Management Achieves: third party management’s role in governance, risk management, and compliance
Part 2: Third Party Governance
Blueprint for Effective Third Party Management
- Third Party Governance Committee: bringing together the range of third party management roles and responsibilities in the organization
- Third Party Management Charter: defining a structure to govern third party relationships
- How to Develop a Third Party Management Strategic Plan
Part 3: Third Party Management Lifecycle
Managing Third Parties from Onboard to Offboarding
- Third party identification & onboarding
- Ongoing context monitoring
- Third party communications & attestations
- Third party monitoring & assessment
- Third party forms & approvals
- Third party metrics & reporting
- Third party re-evaluation and offboarding
Part 4: Third Party Management Architecture
Enabling Information & Technology Management of Third Party Relationships
- Third Party Management Information Architecture: Blueprint for Managing Third Party Content and Related Data
- Types of third party management information and how it integrates into third party processes
- Components and requirements for a third party information architecture
- Third Party Management Technology Architecture: Blueprint for Enabling Third Party Management Processes with Technology
- Kinds of third party management technologies and what best serves the organization
- Capabilities and requirements of third party management platforms
- Third Party Management Business Case: Articulating the Value of Effective Third Party Management
- Defining a business case and value of third party management platforms
Hosted by Michael Rasmussen, GRC2020
25th September 2023 10am to 5pm (including lunch and drinks reception)
Home House Private Members Club
20 Portman Square,
London,
W1H 6LW
Register InterestCOMPANY
CoreStream Ltd
20 Grosvenor Pl,London,
SW1X 7HN
4th Floor,
New York,
NY 10017
Privacy Overview
Cookie | Duration | Description |
---|---|---|
_GRECAPTCHA | 5 months 27 days | Google Recaptcha service sets this cookie to identify bots to protect the website against malicious spam attacks. |
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
CookieLawInfoConsent | 1 year | CookieYes sets this cookie to record the default button state of the corresponding category and the status of CCPA. It works only in coordination with the primary cookie. |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
Cookie | Duration | Description |
---|---|---|
_clck | 1 year | Microsoft Clarity sets this cookie to retain the browser's Clarity User ID and settings exclusive to that website. This guarantees that actions taken during subsequent visits to the same website will be linked to the same user ID. |
_clsk | 1 day | Microsoft Clarity sets this cookie to store and consolidate a user's pageviews into a single session recording. |
_ga | 1 year 1 month 4 days | Google Analytics sets this cookie to calculate visitor, session and campaign data and track site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognise unique visitors. |
_ga_* | 1 year 1 month 4 days | Google Analytics sets this cookie to store and count page views. |
_gid | 1 day | Google Analytics sets this cookie to store information on how visitors use a website while also creating an analytics report of the website's performance. Some of the collected data includes the number of visitors, their source, and the pages they visit anonymously. |
CLID | 1 year | Microsoft Clarity set this cookie to store information about how visitors interact with the website. The cookie helps to provide an analysis report. The data collection includes the number of visitors, where they visit the website, and the pages visited. |
MR | 7 days | This cookie, set by Bing, is used to collect user information for analytics purposes. |
SM | session | Microsoft Clarity cookie set this cookie for synchronizing the MUID across Microsoft domains. |
vuid | 1 year 1 month 4 days | Vimeo installs this cookie to collect tracking information by setting a unique ID to embed videos on the website. |
Cookie | Duration | Description |
---|---|---|
ANONCHK | 10 minutes | The ANONCHK cookie, set by Bing, is used to store a user's session ID and verify ads' clicks on the Bing search engine. The cookie helps in reporting and personalization as well. |
MUID | 1 year 24 days | Bing sets this cookie to recognise unique web browsers visiting Microsoft sites. This cookie is used for advertising, site analytics, and other operations. |
Cookie | Duration | Description |
---|---|---|
__cf_bm | 30 minutes | Cloudflare set the cookie to support Cloudflare Bot Management. |
Cookie | Duration | Description |
---|---|---|
_gat | 1 minute | Google Universal Analytics sets this cookie to restrain request rate and thus limit data collection on high-traffic sites. |
_uetsid | 1 day | Bing Ads sets this cookie to engage with a user that has previously visited the website. |
_uetvid | 1 year 24 days | Bing Ads sets this cookie to engage with a user that has previously visited the website. |
SRM_B | 1 year 24 days | Used by Microsoft Advertising as a unique ID for visitors. |