SlideShare ist ein Scribd-Unternehmen logo
1 von 37
Downloaden Sie, um offline zu lesen
A Compliance
Officer’s Guide to
Third-Party
Risk Management
Table of contents
1.	 Foreword
2.	Context:
increasingly demanding regulations
and aggressive enforcement
3.	 Risks:
concrete third-party risks that businesses face
4.	 Symptoms:
things that keep us awake at night
5.	 Guidance:
risk rating your third parties
6.	 Challenges:
disconnected approach to
third-party management
7.	 Solution:
Control Risks and GAN Integrity
vantage
Control Risks and GAN Integrity are
pleased to present A Compliance
Officer’s Guide to Third-Party
Risk Management. It has been
created for compliance professionals
who want to implement a risk based
approach to third-party due diligence.
The guide starts with an overview of the
regulatory environment, then touches on the
compliance issues keeping us awake at night. It
then focuses on risk rating third parties who are
critical to the success of your business.
Most organizations rely on laborious manual
processes, juggle multiple vendors and lack
sufficient local insight to mitigate risk. There’s
a better way. Read on to learn more.
1. Foreword
1 2
vantage
2. Context:
increasingly
demanding
regulations
and aggressive
enforcement
3 4
vantage
Significant risks and increasingly demanding regulations
Reputational Risk
Modern Slavery
Trade Sanctions Tax Evasion PEP Risk
Environmental Risk Corruption
5 6
vantage
The global anti-corruption framework
Apply to you
01 Global reach
Global anti-corruption laws can apply to companies and individuals both
within and outside your jurisdiction.
Direct and indirect bribery applies
Companies need to take care in managing third-party
relationships. Most enforcement cases involve third parties.
Bribery and facilitation payments
Those who offer or pay bribes, financial or other, are in breach.
Facilitation payments also breach some regulations.
Aggressive enforcement
Large fines, imprisonment of directors.
Prevention is more cost effective and may be used as a defence.
Your
third parties
02
Know
your stuff
03
Prevention
is essential
04
7 8
vantage
Compliance
is critical,
not optional
3. Risks:
concrete
third-party risks
that businesses 
face
11 12
vantage
Production
Sourcing
Logistics and
cross borders
Joint venture
Distributors
Shops
Joint venture
Logistics
Environmental
risk
Sanctions
risk
Modern slavery
in supply chain
Reputational
risk
Corruption
An example: setting up operations for ACME corp
13 14
vantage
No business can
afford to be
caught napping
4. Symptoms:
things that keep
us awake at night
17 18
vantage
Am I allowed to do
business with that
third party?
Am I confident that
this third party is in
good standing and will
not create a legal or
reputational liability?
Can I explain and
document my decision
if something bad
happens?
?
19 20
vantage
How can we
identify hidden
or unknown
compliance risks?
A risk based approach
to third-party due
diligence:
The method by
which compliance
professionals can
determine what level
of due diligence to
complete and how
much resource to
commit, based upon
the level of risk posed
by a third party.
Number
of
vendors
Risk rating
Low High
Risk tolerance
D
i
s
t
r
i
b
u
t
i
o
n
o
f
b
u
d
g
e
t
Screening only
How do we allocate appropriate compliance
resource for the number and variety of third
parties we work with?
23 24
vantage
5. Guidance:
risk rating your
third parties
25 26
vantage
Risk rating:
develop a process to identify the risk rating
of every third party you do business with
Risk Rating
Third-Party
Profile
Exposure
Risk
27 28
vantage
With the
right strategy,
compliance
is a piece
of cake
Step 1
Screen all third parties:
can we do business with them?
31 32
vantage
Perform initial due diligence by screening all existing and
potential clients, agents and business partners. Check all
third parties against key risk categories such as:
Government, Regulatory,
Disciplinary Lists
400+ lists: global sanctions,
securities exchange actions,
fugitives, exclusions, fraud warnings,
debarment, disciplinary actions, law
enforcement etc.
Adverse Media and
Press Coverage
100K+ sources & 2.5B+ articles: daily
media scanning includes newspapers,
magazines, TV, radio, transcripts etc.
Politically Exposed Persons
Government officials, senior legislative
branch, military and judicial figures,
state-controlled businesses and
key executives, ambassadors
and top diplomatic officials, family,
associates and advisors, multi-national
organizations and associated leadership.
33 34
vantage
Enquire here
Step 2
Exposure Risk:
assess the initial risk of a relationship
35 36
vantage
Collect information from your business to determine the degree
of exposure
Country risk
(of services)
Role of
third party
Criticality of
contract/relationship
Transactional
red flags
Liaising with
government bodies
1
via an internal questionnaire
2 3 4 5
37 38
vantage
Step 3
Third-Party Profile:
if level of risk is sufficient, collect
information from the third party
39 40
vantage
Collect information to build a profile of the third party
via an external questionnaire
Country risk
(of company footprint)
Ownership
& governance
Political
exposure
Entity
type
Reputation
& standing
41 42
vantage
Step 4
Decide on risk rating and conduct
appropriate level of due diligence
43 44
vantage
Assessing third parties with high risk ratings
Level 3 Bespoke
Bespoke Bespoke
Bespoke
Bespoke
Investigative Investigative
Investigative
Level 3
Level 2
Level 2
Level 1
Level 3 Level 3
Level 3
Level 2
Level 3
Level 2 Level 3
Exposure Risk (contract value, criticality etc.)
Third-Party Profile
Risk (ownership,
entity type etc.)
Use a scoring system
to plot the exposure risk
against the third-party
profile risk, and work out
the appropriate level of
due diligence.
45 46
vantage
Enquire here
consulting
vantage
Step 5
Third-party
training
?
Additional
mitigation
= Yes
Apply the right next steps based on risk level
Step 3
External
questionnaire
Step 2
Internal
questionnaire
Step 4
Enhanced due
diligence
Step 1
Screening
Risk
Low High
?
Match
= Yes
?
Acceptable
exposure
= No
?
Risk
= Yes
Scrutiny
Low High
47 48
vantage
Enquire here
6. Challenges:
disconnected
approach to 
third-party
management		
49 50
vantage
A disconnected approach
Email from the
business to
Compliance when
the third party
needs to be paid
Compliance asks
for more info,
performs database
screenings,
compiles a file
The file is saved
by Compliance in
a shared drive
Compliance issues
a recommendation
to business,
business decides
51 52
vantage
““
Personal judgment
Key challenges faced by CCOs
Unstructured 	
record keeping
Opaque jurisdictions or
lack of public information
Scattered information that’s
difficult to compile/retrieve
Proportionality
Reactive behavior
Maintaining oversight
Lack of consistent
methodology
53 54
vantage
Digitize your
processes into
workflows
Evaluate the
level of risks
consistently
Ensure decisions
are made at the
right level
Monitoring
your third parties
over time
Allocate
resources to
the risks
Automating your risk based approach can
solve these challenges and bring improvements:
55 56
vantage
With the
right solution,
compliance is
a competitive
advantage
The platform
59 60
vantage
Enquire here
““
Enabling CCOs
Efficient and scalable
solutions
Immediate oversight
Objective decision making
Centralized database
Immediate retrieval
of information
Resources
strategically allocated
Methodology documented
& consistent
Record keeping structured
61 62
vantage
7. Solution:
Control Risks
and GAN Integrity
63 64
vantage
A strategic partnership
to help compliance teams across the
globe manage third-party risk
65 66
vantage
vantage
The VANTAGE Suite
Third parties are critical to your business. They can also be the single greatest source of risk
exposure. Most organizations rely on laborious manual processes, juggle multiple vendors,
and lack sufficient local insight to mitigate risk. There’s a better way. Discover VANTAGE:
67 68
vantage
The product range
Effective third-party screening
using the industry’s largest
risk intelligence databases
platform
vantage diligence
vantage
screening
vantage consulting
vantage
Automated workflow solution to
manage third-party relationships
Standardised third-party due
diligence reports, compiled by
in-country experts
Professional third-party risk
management consulting,
delivered by experienced experts
To find out more about our joint offering, please visit:
www.discover-vantage.com

Weitere ähnliche Inhalte

Was ist angesagt?

Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance frameworkCeyeap
 
Third Party Vendor Risk Managment
Third Party Vendor Risk ManagmentThird Party Vendor Risk Managment
Third Party Vendor Risk ManagmentPivotPointSecurity
 
Governance risk and compliance
Governance risk and complianceGovernance risk and compliance
Governance risk and complianceMagdalena Matell
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014Paul Simidi
 
Walk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 rule
Walk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 ruleWalk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 rule
Walk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 ruleEnterpriseGRC Solutions, Inc.
 
ISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptxISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptxDr Madhu Aman Sharma
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveMax Neira Schliemann
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk Managementbanerjeerohit
 
Legal Governance, Risk Management and Compliance
Legal Governance, Risk Management and ComplianceLegal Governance, Risk Management and Compliance
Legal Governance, Risk Management and ComplianceEffacts
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & complianceHR Globe Consulting
 
Iso27001 Risk Assessment Approach
Iso27001   Risk Assessment ApproachIso27001   Risk Assessment Approach
Iso27001 Risk Assessment Approachtschraider
 
Guide to Risk Management Framework (RMF)
Guide to Risk Management Framework (RMF)Guide to Risk Management Framework (RMF)
Guide to Risk Management Framework (RMF)MetroStar
 
Iso27001 Audit Services
Iso27001 Audit ServicesIso27001 Audit Services
Iso27001 Audit Servicesmcloete
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance BOC Group
 
Information Security Metrics - Practical Security Metrics
Information Security Metrics - Practical Security MetricsInformation Security Metrics - Practical Security Metrics
Information Security Metrics - Practical Security MetricsJack Nichelson
 
Cybersecurity Metrics: Reporting to BoD
Cybersecurity Metrics: Reporting to BoDCybersecurity Metrics: Reporting to BoD
Cybersecurity Metrics: Reporting to BoDPranav Shah
 
Introduction to Risk Management via the NIST Cyber Security Framework
Introduction to Risk Management via the NIST Cyber Security FrameworkIntroduction to Risk Management via the NIST Cyber Security Framework
Introduction to Risk Management via the NIST Cyber Security FrameworkPECB
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksAronson LLC
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated frameworkIrfan Ahmed - ACA, CICA
 

Was ist angesagt? (20)

Governance, risk and compliance framework
Governance, risk and compliance frameworkGovernance, risk and compliance framework
Governance, risk and compliance framework
 
Third Party Vendor Risk Managment
Third Party Vendor Risk ManagmentThird Party Vendor Risk Managment
Third Party Vendor Risk Managment
 
Governance risk and compliance
Governance risk and complianceGovernance risk and compliance
Governance risk and compliance
 
GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014GRC - Isaca Training 16.9.2014
GRC - Isaca Training 16.9.2014
 
Walk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 rule
Walk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 ruleWalk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 rule
Walk This Way: CIS CSC and NIST CSF is the 80 in the 80/20 rule
 
ISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptxISO 27001 Awareness/TRansition.pptx
ISO 27001 Awareness/TRansition.pptx
 
GRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance ExecutiveGRC Governance, Risk mgmt. & Compliance Executive
GRC Governance, Risk mgmt. & Compliance Executive
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk Management
 
Legal Governance, Risk Management and Compliance
Legal Governance, Risk Management and ComplianceLegal Governance, Risk Management and Compliance
Legal Governance, Risk Management and Compliance
 
Grc governance, risk management & compliance
Grc  governance, risk management & complianceGrc  governance, risk management & compliance
Grc governance, risk management & compliance
 
Iso27001 Risk Assessment Approach
Iso27001   Risk Assessment ApproachIso27001   Risk Assessment Approach
Iso27001 Risk Assessment Approach
 
Guide to Risk Management Framework (RMF)
Guide to Risk Management Framework (RMF)Guide to Risk Management Framework (RMF)
Guide to Risk Management Framework (RMF)
 
Iso27001 Audit Services
Iso27001 Audit ServicesIso27001 Audit Services
Iso27001 Audit Services
 
What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance What is GRC – Governance, Risk and Compliance
What is GRC – Governance, Risk and Compliance
 
Information Security Metrics - Practical Security Metrics
Information Security Metrics - Practical Security MetricsInformation Security Metrics - Practical Security Metrics
Information Security Metrics - Practical Security Metrics
 
Cybersecurity Metrics: Reporting to BoD
Cybersecurity Metrics: Reporting to BoDCybersecurity Metrics: Reporting to BoD
Cybersecurity Metrics: Reporting to BoD
 
Iso 27001 2013
Iso 27001 2013Iso 27001 2013
Iso 27001 2013
 
Introduction to Risk Management via the NIST Cyber Security Framework
Introduction to Risk Management via the NIST Cyber Security FrameworkIntroduction to Risk Management via the NIST Cyber Security Framework
Introduction to Risk Management via the NIST Cyber Security Framework
 
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging RisksC-Suite’s Guide to Enterprise Risk Management and Emerging Risks
C-Suite’s Guide to Enterprise Risk Management and Emerging Risks
 
Coso internal control integrated framework
Coso internal control   integrated frameworkCoso internal control   integrated framework
Coso internal control integrated framework
 

Ähnlich wie A compliance officer's guide to third party risk management

Definitive guide to third-party risk management - how to successfully mitigat...
Definitive guide to third-party risk management - how to successfully mitigat...Definitive guide to third-party risk management - how to successfully mitigat...
Definitive guide to third-party risk management - how to successfully mitigat...Kyiv National Economic University
 
Anti-Bribery and Corruption Compliance for Third Parties
Anti-Bribery and Corruption Compliance for Third PartiesAnti-Bribery and Corruption Compliance for Third Parties
Anti-Bribery and Corruption Compliance for Third PartiesDun & Bradstreet
 
The 5 Steps to Managing Third-party Risk
The 5 Steps to Managing Third-party RiskThe 5 Steps to Managing Third-party Risk
The 5 Steps to Managing Third-party RiskElizabeth Dimit
 
Ilta 2009 law firm risk management can it grow profitability - panel member...
Ilta 2009 law firm risk management   can it grow profitability - panel member...Ilta 2009 law firm risk management   can it grow profitability - panel member...
Ilta 2009 law firm risk management can it grow profitability - panel member...David Cunningham
 
The Science and Art of Cyber Incident Response (with Case Studies)
The Science and Art of Cyber Incident Response (with Case Studies)The Science and Art of Cyber Incident Response (with Case Studies)
The Science and Art of Cyber Incident Response (with Case Studies)Kroll
 
Ingenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM complianceIngenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM complianceSami Benafia
 
2015 Corporate general counsel survey results
2015 Corporate general counsel survey results2015 Corporate general counsel survey results
2015 Corporate general counsel survey resultsGrant Thornton LLP
 
ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...
ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...
ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...Leas Bachatene
 
Middle East Summit on Anti-Corruption
Middle East Summit on Anti-CorruptionMiddle East Summit on Anti-Corruption
Middle East Summit on Anti-CorruptionRachel Hamilton
 
GP_for_Third_Party_Anti-Corruption_product_sheet
GP_for_Third_Party_Anti-Corruption_product_sheetGP_for_Third_Party_Anti-Corruption_product_sheet
GP_for_Third_Party_Anti-Corruption_product_sheetMarco Villacorta Olano
 
Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...
Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...
Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...Ethisphere
 
Did you know that along with modernization, the risks of fraud exposure incre...
Did you know that along with modernization, the risks of fraud exposure incre...Did you know that along with modernization, the risks of fraud exposure incre...
Did you know that along with modernization, the risks of fraud exposure incre...May Martinsen
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Fraud, bribery and corruption: Protecting reputation and value
Fraud, bribery and corruption: Protecting reputation and valueFraud, bribery and corruption: Protecting reputation and value
Fraud, bribery and corruption: Protecting reputation and valueDavid Graham
 
Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...
Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...
Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...EY
 
Cybersecurity and the regulator, what you need to know
Cybersecurity and the regulator, what you need to knowCybersecurity and the regulator, what you need to know
Cybersecurity and the regulator, what you need to knowCordium
 
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfQuestions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfinfosecTrain
 
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬priyanshamadhwal2
 

Ähnlich wie A compliance officer's guide to third party risk management (20)

Definitive guide to third-party risk management - how to successfully mitigat...
Definitive guide to third-party risk management - how to successfully mitigat...Definitive guide to third-party risk management - how to successfully mitigat...
Definitive guide to third-party risk management - how to successfully mitigat...
 
Anti-Bribery and Corruption Compliance for Third Parties
Anti-Bribery and Corruption Compliance for Third PartiesAnti-Bribery and Corruption Compliance for Third Parties
Anti-Bribery and Corruption Compliance for Third Parties
 
The 5 Steps to Managing Third-party Risk
The 5 Steps to Managing Third-party RiskThe 5 Steps to Managing Third-party Risk
The 5 Steps to Managing Third-party Risk
 
Ilta 2009 law firm risk management can it grow profitability - panel member...
Ilta 2009 law firm risk management   can it grow profitability - panel member...Ilta 2009 law firm risk management   can it grow profitability - panel member...
Ilta 2009 law firm risk management can it grow profitability - panel member...
 
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
The State of TPRM in the UK - DVV Solutions Breakfast Briefing March 2019
 
The Science and Art of Cyber Incident Response (with Case Studies)
The Science and Art of Cyber Incident Response (with Case Studies)The Science and Art of Cyber Incident Response (with Case Studies)
The Science and Art of Cyber Incident Response (with Case Studies)
 
Ingenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM complianceIngenia consultants-9 basic steps towards TRM compliance
Ingenia consultants-9 basic steps towards TRM compliance
 
2015 Corporate general counsel survey results
2015 Corporate general counsel survey results2015 Corporate general counsel survey results
2015 Corporate general counsel survey results
 
ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...
ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...
ethiXbase-Anti-Corruption-Compliance-Achieving-100-percent-third-party-due-di...
 
Middle East Summit on Anti-Corruption
Middle East Summit on Anti-CorruptionMiddle East Summit on Anti-Corruption
Middle East Summit on Anti-Corruption
 
GP_for_Third_Party_Anti-Corruption_product_sheet
GP_for_Third_Party_Anti-Corruption_product_sheetGP_for_Third_Party_Anti-Corruption_product_sheet
GP_for_Third_Party_Anti-Corruption_product_sheet
 
Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...
Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...
Best Practices in Anti-Corruption Diligence on M&A Targets, Joint Venture Par...
 
Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19 Standards in Third Party Risk - DVV Solutions ISACA North May 19
Standards in Third Party Risk - DVV Solutions ISACA North May 19
 
Did you know that along with modernization, the risks of fraud exposure incre...
Did you know that along with modernization, the risks of fraud exposure incre...Did you know that along with modernization, the risks of fraud exposure incre...
Did you know that along with modernization, the risks of fraud exposure incre...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Fraud, bribery and corruption: Protecting reputation and value
Fraud, bribery and corruption: Protecting reputation and valueFraud, bribery and corruption: Protecting reputation and value
Fraud, bribery and corruption: Protecting reputation and value
 
Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...
Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...
Overcoming compliance fatigue - Reinforcing the commitment to ethical growth ...
 
Cybersecurity and the regulator, what you need to know
Cybersecurity and the regulator, what you need to knowCybersecurity and the regulator, what you need to know
Cybersecurity and the regulator, what you need to know
 
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdfQuestions for a Risk Analyst Interview - Get Ready for Success.pdf
Questions for a Risk Analyst Interview - Get Ready for Success.pdf
 
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
𝐑𝐢𝐬𝐤 𝐀𝐧𝐚𝐥𝐲𝐬𝐭 𝐈𝐧𝐭𝐞𝐫𝐯𝐢𝐞𝐰 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬
 

Mehr von SALIH AHMED ISLAM

8 moves to becoming an agile internal audit
8 moves to becoming an agile internal audit8 moves to becoming an agile internal audit
8 moves to becoming an agile internal auditSALIH AHMED ISLAM
 
7 musts to establish a strategic plan
7 musts to establish a strategic plan7 musts to establish a strategic plan
7 musts to establish a strategic planSALIH AHMED ISLAM
 
6 implications of internal audit
6 implications of internal audit6 implications of internal audit
6 implications of internal auditSALIH AHMED ISLAM
 
6 benefits of internal auditing
6 benefits of internal auditing6 benefits of internal auditing
6 benefits of internal auditingSALIH AHMED ISLAM
 
5 benefits of a whistleblower hotline
5 benefits of a whistleblower hotline5 benefits of a whistleblower hotline
5 benefits of a whistleblower hotlineSALIH AHMED ISLAM
 
5 critical tasks of Internal Audit
5 critical tasks of Internal Audit5 critical tasks of Internal Audit
5 critical tasks of Internal AuditSALIH AHMED ISLAM
 
What do internal auditors do?
What do internal auditors do?What do internal auditors do?
What do internal auditors do?SALIH AHMED ISLAM
 
CORRUPTION PERCEPTIONS INDEX 2020
CORRUPTION PERCEPTIONS INDEX 2020CORRUPTION PERCEPTIONS INDEX 2020
CORRUPTION PERCEPTIONS INDEX 2020SALIH AHMED ISLAM
 
Cpi 2020 - main -infographic
Cpi 2020 - main  -infographicCpi 2020 - main  -infographic
Cpi 2020 - main -infographicSALIH AHMED ISLAM
 
Cpi 2020-western-europe-and-european-union-infographic
Cpi 2020-western-europe-and-european-union-infographicCpi 2020-western-europe-and-european-union-infographic
Cpi 2020-western-europe-and-european-union-infographicSALIH AHMED ISLAM
 
Cpi 2020-sub-saharan-africa-infographic v2
Cpi 2020-sub-saharan-africa-infographic v2Cpi 2020-sub-saharan-africa-infographic v2
Cpi 2020-sub-saharan-africa-infographic v2SALIH AHMED ISLAM
 
Cpi 2020-middle-east-and-north-africa-infographic
Cpi 2020-middle-east-and-north-africa-infographicCpi 2020-middle-east-and-north-africa-infographic
Cpi 2020-middle-east-and-north-africa-infographicSALIH AHMED ISLAM
 
Cpi 2020-eastern-europe-and-central-asia-infographic
Cpi 2020-eastern-europe-and-central-asia-infographicCpi 2020-eastern-europe-and-central-asia-infographic
Cpi 2020-eastern-europe-and-central-asia-infographicSALIH AHMED ISLAM
 
Cpi 2020-asia-pacific-infographic
Cpi 2020-asia-pacific-infographicCpi 2020-asia-pacific-infographic
Cpi 2020-asia-pacific-infographicSALIH AHMED ISLAM
 
CPI 2020 - Americas - Info-graphic
CPI 2020 - Americas - Info-graphicCPI 2020 - Americas - Info-graphic
CPI 2020 - Americas - Info-graphicSALIH AHMED ISLAM
 

Mehr von SALIH AHMED ISLAM (20)

10 advice for ia executives
10 advice for ia executives10 advice for ia executives
10 advice for ia executives
 
8 moves to becoming an agile internal audit
8 moves to becoming an agile internal audit8 moves to becoming an agile internal audit
8 moves to becoming an agile internal audit
 
7 musts to establish a strategic plan
7 musts to establish a strategic plan7 musts to establish a strategic plan
7 musts to establish a strategic plan
 
6 implications of internal audit
6 implications of internal audit6 implications of internal audit
6 implications of internal audit
 
6 benefits of internal auditing
6 benefits of internal auditing6 benefits of internal auditing
6 benefits of internal auditing
 
5 benefits of a whistleblower hotline
5 benefits of a whistleblower hotline5 benefits of a whistleblower hotline
5 benefits of a whistleblower hotline
 
What is risk management
What is risk managementWhat is risk management
What is risk management
 
5 critical tasks of Internal Audit
5 critical tasks of Internal Audit5 critical tasks of Internal Audit
5 critical tasks of Internal Audit
 
5 fraud tips
5 fraud tips5 fraud tips
5 fraud tips
 
What do internal auditors do?
What do internal auditors do?What do internal auditors do?
What do internal auditors do?
 
Code of Conduct
Code of ConductCode of Conduct
Code of Conduct
 
CORRUPTION PERCEPTIONS INDEX 2020
CORRUPTION PERCEPTIONS INDEX 2020CORRUPTION PERCEPTIONS INDEX 2020
CORRUPTION PERCEPTIONS INDEX 2020
 
Fraud awareness training
Fraud awareness trainingFraud awareness training
Fraud awareness training
 
Cpi 2020 - main -infographic
Cpi 2020 - main  -infographicCpi 2020 - main  -infographic
Cpi 2020 - main -infographic
 
Cpi 2020-western-europe-and-european-union-infographic
Cpi 2020-western-europe-and-european-union-infographicCpi 2020-western-europe-and-european-union-infographic
Cpi 2020-western-europe-and-european-union-infographic
 
Cpi 2020-sub-saharan-africa-infographic v2
Cpi 2020-sub-saharan-africa-infographic v2Cpi 2020-sub-saharan-africa-infographic v2
Cpi 2020-sub-saharan-africa-infographic v2
 
Cpi 2020-middle-east-and-north-africa-infographic
Cpi 2020-middle-east-and-north-africa-infographicCpi 2020-middle-east-and-north-africa-infographic
Cpi 2020-middle-east-and-north-africa-infographic
 
Cpi 2020-eastern-europe-and-central-asia-infographic
Cpi 2020-eastern-europe-and-central-asia-infographicCpi 2020-eastern-europe-and-central-asia-infographic
Cpi 2020-eastern-europe-and-central-asia-infographic
 
Cpi 2020-asia-pacific-infographic
Cpi 2020-asia-pacific-infographicCpi 2020-asia-pacific-infographic
Cpi 2020-asia-pacific-infographic
 
CPI 2020 - Americas - Info-graphic
CPI 2020 - Americas - Info-graphicCPI 2020 - Americas - Info-graphic
CPI 2020 - Americas - Info-graphic
 

Kürzlich hochgeladen

Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Sheetaleventcompany
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture conceptP&CO
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceDamini Dixit
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...daisycvs
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...amitlee9823
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...amitlee9823
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxpriyanshujha201
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...allensay1
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfAmzadHosen3
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 

Kürzlich hochgeladen (20)

Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort ServiceEluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
Eluru Call Girls Service ☎ ️93326-06886 ❤️‍🔥 Enjoy 24/7 Escort Service
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
Call Girls Jp Nagar Just Call 👗 7737669865 👗 Top Class Call Girl Service Bang...
 
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
VVVIP Call Girls In Greater Kailash ➡️ Delhi ➡️ 9999965857 🚀 No Advance 24HRS...
 
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptxB.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
B.COM Unit – 4 ( CORPORATE SOCIAL RESPONSIBILITY ( CSR ).pptx
 
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
Call Girls Service In Old Town Dubai ((0551707352)) Old Town Dubai Call Girl ...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 

A compliance officer's guide to third party risk management

  • 1. A Compliance Officer’s Guide to Third-Party Risk Management
  • 2. Table of contents 1. Foreword 2. Context: increasingly demanding regulations and aggressive enforcement 3. Risks: concrete third-party risks that businesses face 4. Symptoms: things that keep us awake at night 5. Guidance: risk rating your third parties 6. Challenges: disconnected approach to third-party management 7. Solution: Control Risks and GAN Integrity vantage
  • 3. Control Risks and GAN Integrity are pleased to present A Compliance Officer’s Guide to Third-Party Risk Management. It has been created for compliance professionals who want to implement a risk based approach to third-party due diligence. The guide starts with an overview of the regulatory environment, then touches on the compliance issues keeping us awake at night. It then focuses on risk rating third parties who are critical to the success of your business. Most organizations rely on laborious manual processes, juggle multiple vendors and lack sufficient local insight to mitigate risk. There’s a better way. Read on to learn more. 1. Foreword 1 2 vantage
  • 5. Significant risks and increasingly demanding regulations Reputational Risk Modern Slavery Trade Sanctions Tax Evasion PEP Risk Environmental Risk Corruption 5 6 vantage
  • 6. The global anti-corruption framework Apply to you 01 Global reach Global anti-corruption laws can apply to companies and individuals both within and outside your jurisdiction. Direct and indirect bribery applies Companies need to take care in managing third-party relationships. Most enforcement cases involve third parties. Bribery and facilitation payments Those who offer or pay bribes, financial or other, are in breach. Facilitation payments also breach some regulations. Aggressive enforcement Large fines, imprisonment of directors. Prevention is more cost effective and may be used as a defence. Your third parties 02 Know your stuff 03 Prevention is essential 04 7 8 vantage
  • 8. 3. Risks: concrete third-party risks that businesses  face 11 12 vantage
  • 9. Production Sourcing Logistics and cross borders Joint venture Distributors Shops Joint venture Logistics Environmental risk Sanctions risk Modern slavery in supply chain Reputational risk Corruption An example: setting up operations for ACME corp 13 14 vantage
  • 10. No business can afford to be caught napping
  • 11. 4. Symptoms: things that keep us awake at night 17 18 vantage
  • 12. Am I allowed to do business with that third party? Am I confident that this third party is in good standing and will not create a legal or reputational liability? Can I explain and document my decision if something bad happens? ? 19 20 vantage
  • 13. How can we identify hidden or unknown compliance risks?
  • 14. A risk based approach to third-party due diligence: The method by which compliance professionals can determine what level of due diligence to complete and how much resource to commit, based upon the level of risk posed by a third party. Number of vendors Risk rating Low High Risk tolerance D i s t r i b u t i o n o f b u d g e t Screening only How do we allocate appropriate compliance resource for the number and variety of third parties we work with? 23 24 vantage
  • 15. 5. Guidance: risk rating your third parties 25 26 vantage
  • 16. Risk rating: develop a process to identify the risk rating of every third party you do business with Risk Rating Third-Party Profile Exposure Risk 27 28 vantage
  • 18. Step 1 Screen all third parties: can we do business with them? 31 32 vantage
  • 19. Perform initial due diligence by screening all existing and potential clients, agents and business partners. Check all third parties against key risk categories such as: Government, Regulatory, Disciplinary Lists 400+ lists: global sanctions, securities exchange actions, fugitives, exclusions, fraud warnings, debarment, disciplinary actions, law enforcement etc. Adverse Media and Press Coverage 100K+ sources & 2.5B+ articles: daily media scanning includes newspapers, magazines, TV, radio, transcripts etc. Politically Exposed Persons Government officials, senior legislative branch, military and judicial figures, state-controlled businesses and key executives, ambassadors and top diplomatic officials, family, associates and advisors, multi-national organizations and associated leadership. 33 34 vantage Enquire here
  • 20. Step 2 Exposure Risk: assess the initial risk of a relationship 35 36 vantage
  • 21. Collect information from your business to determine the degree of exposure Country risk (of services) Role of third party Criticality of contract/relationship Transactional red flags Liaising with government bodies 1 via an internal questionnaire 2 3 4 5 37 38 vantage
  • 22. Step 3 Third-Party Profile: if level of risk is sufficient, collect information from the third party 39 40 vantage
  • 23. Collect information to build a profile of the third party via an external questionnaire Country risk (of company footprint) Ownership & governance Political exposure Entity type Reputation & standing 41 42 vantage
  • 24. Step 4 Decide on risk rating and conduct appropriate level of due diligence 43 44 vantage
  • 25. Assessing third parties with high risk ratings Level 3 Bespoke Bespoke Bespoke Bespoke Bespoke Investigative Investigative Investigative Level 3 Level 2 Level 2 Level 1 Level 3 Level 3 Level 3 Level 2 Level 3 Level 2 Level 3 Exposure Risk (contract value, criticality etc.) Third-Party Profile Risk (ownership, entity type etc.) Use a scoring system to plot the exposure risk against the third-party profile risk, and work out the appropriate level of due diligence. 45 46 vantage Enquire here consulting vantage
  • 26. Step 5 Third-party training ? Additional mitigation = Yes Apply the right next steps based on risk level Step 3 External questionnaire Step 2 Internal questionnaire Step 4 Enhanced due diligence Step 1 Screening Risk Low High ? Match = Yes ? Acceptable exposure = No ? Risk = Yes Scrutiny Low High 47 48 vantage Enquire here
  • 28. A disconnected approach Email from the business to Compliance when the third party needs to be paid Compliance asks for more info, performs database screenings, compiles a file The file is saved by Compliance in a shared drive Compliance issues a recommendation to business, business decides 51 52 vantage
  • 29. ““ Personal judgment Key challenges faced by CCOs Unstructured record keeping Opaque jurisdictions or lack of public information Scattered information that’s difficult to compile/retrieve Proportionality Reactive behavior Maintaining oversight Lack of consistent methodology 53 54 vantage
  • 30. Digitize your processes into workflows Evaluate the level of risks consistently Ensure decisions are made at the right level Monitoring your third parties over time Allocate resources to the risks Automating your risk based approach can solve these challenges and bring improvements: 55 56 vantage
  • 31. With the right solution, compliance is a competitive advantage
  • 33. ““ Enabling CCOs Efficient and scalable solutions Immediate oversight Objective decision making Centralized database Immediate retrieval of information Resources strategically allocated Methodology documented & consistent Record keeping structured 61 62 vantage
  • 34. 7. Solution: Control Risks and GAN Integrity 63 64 vantage
  • 35. A strategic partnership to help compliance teams across the globe manage third-party risk 65 66 vantage vantage
  • 36. The VANTAGE Suite Third parties are critical to your business. They can also be the single greatest source of risk exposure. Most organizations rely on laborious manual processes, juggle multiple vendors, and lack sufficient local insight to mitigate risk. There’s a better way. Discover VANTAGE: 67 68 vantage The product range Effective third-party screening using the industry’s largest risk intelligence databases platform vantage diligence vantage screening vantage consulting vantage Automated workflow solution to manage third-party relationships Standardised third-party due diligence reports, compiled by in-country experts Professional third-party risk management consulting, delivered by experienced experts
  • 37. To find out more about our joint offering, please visit: www.discover-vantage.com