Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Third-Party & Supply Chain

Federal Regulators Propose Risk-Based Overhaul of Third-Party Management Guidance

The Federal Reserve Board, Federal Deposit Insurance Corporation, National Credit Union Administration, and Office of the Comptroller of the Currency on Friday requested comment on proposed guidance for managing risks associated with third-party relationships. The proposal draws on the agencies’ supervisory experience and what they have learned examining financial institutions’ third-party risk management practices.

Canada’s Privacy Commissioner Sets New Expectations for Third-Party Privacy Due Diligence

Privacy Commissioner of Canada, Philippe Dufresne, released new guidance for organizations subject to the Personal Information Protection and Electronic Documents Act (PIPEDA), laying out how businesses should assess the privacy practices of prospective third-party service providers. The guidance applies when an outside product, service, or technology will involve the collection, use, or disclosure of personal information, whether the provider is processing information directly, supplying technology that handles it, or working somewhere further down the chain.

KPMG Surveys Find Third-Party & Supply Chain Risk Converging

Regulatory compliance and cyber risk are driving third-party risk management strategies. Supply chain leaders, meanwhile, rank cybersecurity as their top perceived risk and managing risk and geopolitical uncertainty as their leading transformation objective. Companies are preparing to expand their partner networks and automate more of the work that holds those networks together. Their risk functions are not always keeping pace.

Reality, Not Snapshots: Rethinking Third-Party Risk

Every risk discipline carries a habit that outlives its usefulness. In third-party risk management, that habit is the self-attested questionnaire. It is the artifact the whole practice is organized around. A relationship begins, a security questionnaire goes out, the vendor returns a few hundred answers, an analyst reviews them, and the file is closed until next year's cycle. The ritual is so established that it is easy to forget it was built for a smaller, slower, more stable world than the one we operate in now

UK Regulators Put Four Technology Giants Under Direct Resilience Oversight

Britain’s financial regulators will begin overseeing four of the world’s largest technology providers on Monday, extending their reach into the cloud infrastructure that banks and other financial institutions increasingly rely on to keep operating.

ACCC Uses New Emergency Powers for First Time Amid Middle East Supply Chain Disruptions

For months the world's attention has drifted toward the Strait of Hormuz with the uneasy awareness reserved for places that are both geographically small and economically immense. The waterway has always been more than a shipping route. It is a pressure point. When conflict interrupts traffic there, the consequences do not remain in the Gulf for long. They surface weeks later in warehouses, procurement meetings and production schedules half a world away, where businesses discover that the shortest distance between a geopolitical crisis and an empty shelf is often a container ship that never arrived.

When Trade Changes Suppliers, Third-Party Risk Changes Too

A supplier that looked perfectly sensible in January can become a liability by April without having changed at all. The factory is the same, the quality standards are the same, and the people answering the phone are the same people they were a few months earlier. What changed happened somewhere else, perhaps in a government office thousands of miles away, perhaps in the latest round of trade negotiations, perhaps in a policy announcement that never mentioned the supplier by name. Yet procurement is suddenly looking elsewhere, finance is recalculating costs, and operations is asking how quickly production can move if it has to.