Introduction to Third Party Risk Management
Understand why third-party risk matters and how to build a workable programme from the ground up.
Format: Online | Duration: One and a half days | CPD: Subject to confirmation
Introduction to Third Party Risk Management
Online · One and a half days
Course overview
Organisations rely on suppliers, service providers and other external parties to deliver important activities. This course explains how third-party risk management developed alongside outsourcing and more complex supply chains, and why a structured programme matters for service delivery, information protection and organisational resilience. Participants explore the full programme and relationship lifecycle, from governance and identifying third parties to due diligence, monitoring and exit. The course also examines seven implementation challenges, practical ways to address them and five quick wins for getting started.
Who should attend
- Risk, compliance and governance professionals, and internal auditors
- Procurement, vendor-management, technology and information security professionals
- Legal, finance and operations teams involved in third-party relationships
- Students and graduates exploring careers in audit and GRC
What you will learn
- Explain what third-party risk management is, why it matters and how it complements procurement and contract management
- Identify third-party risks and assess the criticality of services and relationships
- Describe each stage of a programme and the responsibilities and outputs involved
- Apply proportionate due diligence, contracting and monitoring approaches
- Address implementation challenges with practical workarounds
- Identify quick wins and prioritise the next steps for a programme
Learning approach
Practitioner-led discussion and scenarios help participants work through risk classification, due diligence and monitoring decisions. Exercises explore implementation barriers and help participants select quick wins and draft a proportionate programme action plan.
Facilitator
Thomas Paavo Hamata | CISA | COBIT 2019 Foundation
Thomas has experience across IT audit, technology risk, regulatory compliance and third-party control environments. He translates recognised frameworks and practical experience into workable approaches for organisations and practitioners.
Build a practical approach to third-party risk, from the first assessment to ongoing oversight and exit.