Establishing a Third-Party Risk Management Program

Image of Third-Party Risk Management

SIG University  Certified  Third-Party Risk Management Professional  (C3PRMP) program graduate Lois Peric shares the essential components for building a third-party risk management program.


There are essential components when establishing a third-party risk management program in an organization where none exists. A framework or process must be implemented for each stage of the vendor lifecycle, from sourcing and onboarding to termination. You must also insert the third parties you are currently doing business with into the new framework. The program’s success will be heavily dependent on the “tone at the top” and the support of senior executives within the organization. It will also require cooperation from all lines of business, and the value of the program must be communicated clearly. Your stakeholders need to understand what is changing but, most importantly, why.
You must first identify the third-party population. Traditional vendors are easy to locate as outgoing payments will be on record. Non-vendor third parties are more challenging to identify, and the best way to approach this is to engage the business and determine which third parties they are interacting with that are not on a fixed payment schedule. Once the population is identified, it can be split into Tiers. A standard numerical system such as 1, 2 & or 3 equates to high, medium, and low risk. The vendor Tier can be established by creating an Inherent Risk Assessment (IRA). The IRA will also be used when sourcing or onboarding new vendors.
The IRA must include questions that will allow you to determine the criticality of the relationship, i.e., how long can the business continue to operate in the absence of the third-party product/service? The IRA must also determine what type of information is being shared with the third-party and which jurisdiction(s) they are operating in, as there may be legal or regulatory implications. The IRA must be carefully designed to help you determine your “mission-critical” third parties, which will be the focus of your efforts.
Contract management is an integral part of third-party risk management and is addressed in the onboarding phase and periodically throughout the relationship. Legal counsel should identify critical points or clauses in all contracts and have those documented in a playbook or cheat sheet so that Relationship Managers or even third parties can be aware of the “deal-breakers.”
During establishing the risk, program contracts must be collected and housed in a centralized location with a taxonomy that makes them easy to locate. This task can be difficult as arrangements may be stored physically, electronically, or not at all, in which case they may need to be obtained from the third party directly. Existing contracts can be reviewed against the cheat sheet and renegotiated if necessary and feasible. A renewal calendar can be beneficial in determining the timelines for renegotiation. Any contract issues should be logged, communicated to stakeholders, and tracked to remediation.
Due diligence must be conducted when a new relationship is established (onboarding phase) and refreshed periodically as determined by the risk tier. The third-party risk manager will require support from other risk partners such as Finance, Business Continuity Management (BCM), Compliance, Anti-Money Laundering, Information Security, or Technology risk. Typically, the third party will provide documentation and answer a series of questionnaires designed to address risks in each category.
These questionnaires can be created in-house or purchased from a third party. The questionnaires will help you assess residual risk or the risk that remains in the presence of controls. As with Contract Risk, any risks identified during the due diligence process should be logged, communicated, and tracked. Compensating controls or tactical solutions may be implemented to reduce risk until a strategic solution is implemented.
A process must also be established to track and report third-party risks and incidents. When a chance is identified in the contracting, due diligence, or ongoing monitoring phase and it cannot be remediated (to an acceptable level), it should be logged. A communication framework should be put in place so that stakeholders are aware of the risks. The risks must either be remediated or a formal risk acceptance obtained from the risk owner. Despite the risks, a risk acceptance represents an informed decision to continue the relationship with the third party. Logging third-party risk allows you to develop metrics that can demonstrate effort and value in your program.
Finally, a termination procedure must exist to ensure that risk is managed in the offboarding process. This must include steps to manage transition plans and delete proprietary or personal information and contract. All the above program segments represent the fundamentals of a third-party risk management program and are by no means exhaustive. Creating a comprehensive and robust framework can take years, but you must start somewhere. Good luck.

SIG University’s  Certified  Third-Party Risk Management Professional  (C3PRMP) program is a globally recognized certification that is the €œgold standard € in terms of relevance, scope and content. The C3PRMP  program was created by Linda Tuck Chapman, an advisor, educator, author and expert.