Your strongest analyst shouldn’t spend Tuesday morning cross-referencing SOC 2 exceptions by hand. But that’s where the work goes when a Third-Party Risk Management (TPRM) program runs on manual labor: Vendor requests sit in the intake queue, certificates of insurance expire unnoticed, and findings go quiet while board decks eat up days that should have […]
Third-Party Risk Management (TPRM) teams have never had more trouble collecting information about their vendors. On the surface, everything seems fine: Vendors return questionnaires and share evidence. The problem isn’t a shortage of raw material, it’s the time spent interpreting the data and applying it within your program. Scale this problem against hundreds of new […]
When the UK’s financial regulators finalised their new third-party reporting rules, they did something regulators rarely do: they told firms, explicitly, that the requirements were designed to line up. The PRA and FCA published aligned rules on the same day, with shared templates and a single submission system for dual-regulated firms. The incident report matches […]
When the Prudential Regulation Authority published PS7/26, most third-party risk teams filed it under “reporting requirements” and moved on. That was a mistake twice over. First, because the updated SS2/21 buried in its appendices changes what regulators expect firms to know about every material third party they rely on. And second, because the PRA didn’t […]
This panel webinar brings three perspectives together to talk through how to close that gap. Giles Witherspoon of Dayforce shares how his team moved from periodic questionnaires to continuous monitoring. Sophia Corsetti of ProcessUnity and Austin Starowicz of RiskRecon by Mastercard, add their perspectives on what a data-first program looks like in practice, from pairing […]
An intake queue that quietly hides a duplicate vendor for four days. A SOC 2 report nobody has time to read past page 20. A Certificate of Insurance that lapsed without anyone noticing until renewal season was already underway. If any of these challenges sound familiar, the problem isn’t just that your risk team is […]