180 likes | 298 Views
Third-party Assurance — Case Studies. Global Financial Institution. Challenge. 2,000 vendors and internal assets Assurance activities in silos Manual a ssessment tools. Automated, efficient, multi-tier process Aligned, focused evaluation tools
E N D
Global Financial Institution Challenge • 2,000 vendors and internal assets • Assurance activities in silos • Manual assessment tools • Automated, efficient, multi-tier process • Aligned, focused evaluation tools • Assessment coordination and schedule management • Issue and remediation tracking Solution • High program rating from external regulator • Management control of assurance process • Easy visibility of vendor risk rankings • Reduction in vendor assessment time and effort • Reusable assessment tools and patterns • Third-party satisfaction with streamlined process Results
Global Technology Services Company Challenge • Financial risk exposure due to contract non-performance • Objective evaluation of third-party contract risk • Develop standardized risk taxonomy and rating levels • Catalog of rated risks • Contract risk evaluation built into review process • Management of contract review documentation • Management reporting of gaps and regulatory non-compliance Solution • Reduced incidence of errors in previously manual process • Process-based exception triggers and alerts • Enhanced control of contract review documentation • Real-time access to contract performance and compliance status • Common risk repository for use throughout the organization Results
Common Risk Framework • Consistent taxonomy • Risk categories • Risk responsibility
Vendor Impact Visibility • Systems • Business process • Facilities • Regulations • Standards …
A Common Business Language • Consistency of reference • De-facto authoritative sources • Easy global access • Alignment with other enterprise systems Screenshot: Application Hierarchy
Multiple Assessment Types • Questionnaire • Analyst findings • Controls testing Screenshot: Findings Report
Vendor Rankings • Assessment results • Risk ratings • Risk categories Screenshot: Vendor Risk Report by Rating with Categories
Issues and Remediation • In-context creation • Responsibility assignment • Collaboration dialog • Resolution tracking • Local and global reporting
Focus on High-Risk • Multi-step process — effective and efficient • Funnel to the risky few • Screen out low-risk entities • Benefits • Confident control of high-risk relationships • Elimination of redundant, unnecessary work • Additional subjective evaluation • Detailed scoring • Controls testing • Remediation
Full Relationship Lifecycle • New third-party relationships • Ongoing third-party relationships Resolve Issues Assess Monitor
Triggers for Action • Process-based • Exception-based • Alerts • Metric changes • Business change • Acquisitions
Program Alignment • Coherent third party interaction • Coordinated scheduling • Non-redundant evaluation tools • Shared evaluation results • Integrated risk picture • Coordination with internal asset reviews
Collaboration • Third-party access • Self-assessments • Issues • Remediation • Documentation • Regulatory access Screenshot: Vendor Specific Issues Report
Staged Deployment • Incremental • Incorporate departments one at a time • Go global gradually • Benefits • Immediate return • On-the-ground learning • Evolving optimization