SlideShare a Scribd company logo
1 of 20
Download to read offline
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
1
JOIN. ENGAGE. LEAD.
KEY CHALLENGES FACING VENDOR
RISK MANAGEMENT PROGRAMS
Third-Party/Vendor Risk Management Survey
Results
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
2
JOIN. ENGAGE. LEAD.
THE THIRD-PARTY/VENDOR RISK
MANAGEMENT SURVEY
The survey was conducted between June and
August 2014 by RMA, in association with
MetricStream. It sought to:
1. Capture the range of
practices in third-
party/vendor risk
management (VRM)
over a cross section of
RMA member
institutions.
2. Gather detailed
information on some of
the key challenges that
banks and other
financial institutions
are facing
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
3
JOIN. ENGAGE. LEAD.
SURVEY FOCUS
Vendor
management
framework
Vendor selection
and monitoring
process
Critical vendors
and critical
activities
Fourth-party
suppliers.
Tools and
techniques
Contracts
Reporting
Regulatory and
compliance
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
4
JOIN. ENGAGE. LEAD.
WHAT WE FOUND
• For most of the responding organizations,
the vendor management programs are still
in their nascent stage.
1.
• Third party relationships have evolved
beyond the traditional models of goods and
service providers.
2.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
5
JOIN. ENGAGE. LEAD.
VENDOR MANAGEMENT FRAMEWORK
Some of the bigger
organizations surveyed have
thousands of supplier
relationships to manage—
extremely difficult without
mature vendor governance
framework.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
6
JOIN. ENGAGE. LEAD.
VENDOR SELECTION AND
MONITORING PROCESS
Financial institutions should
conduct continuous in-depth
assessments on the third-
party’s capability to perform
the activities commensurate
with the risk and complexity of
the relationship.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
7
JOIN. ENGAGE. LEAD.
VENDOR SELECTION AND MONITORING
PROCESS (CONT.)
Each institution surveyed has multiple areas or SMEs for
vendor selection and due diligence of third parties.
Information security
Information
technology
BCM Legal
Key groups
conducting
secondary supplier
risk assessments
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
8
JOIN. ENGAGE. LEAD.
CRITICAL VENDORS
• “Critical activities” include:
• Significant bank functions.
• Shared services, such as:
• internal audit
• Information technology
OCC
Guidance
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
9
JOIN. ENGAGE. LEAD.
CRITICAL VENDORS (CONT.)
• For most of the
surveyed
organizations, the
number of enterprise
critical suppliers
ranges from 3 to 15.
• Risk and risk and
spend are the
primary factors when
segmenting suppliers
on the basis of
criticality.0% 20% 40% 60% 80% 100%
Conduct site visits,
especially for critical
vendors.
Have defined, or are
in the process of
defining, the critical
activities in their
institution.
73%
97%
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
10
JOIN. ENGAGE. LEAD.
FOURTH PARTY SUPPLIERS
0 10 20 30 40 50 60 70
Done when the primary supplier notifies
them of a new material fourth party
Perform due diligence at time of
sourcing/contracting the 3rd party
4th party suppliers identified at RFP
stage
No due diligence on 4th parties
13%
20%
50%
67%
% of Respondents
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
11
JOIN. ENGAGE. LEAD.
TOOLS AND TECHNIQUES
Organizations need to
gain a clearer
understanding of their
third party’s business
processes and
technologies that will be
used to support the
outsourced activity.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
12
JOIN. ENGAGE. LEAD.
CONTRACTS
After your bank selects a third party, your bank should negotiate a
contract that clearly defines the rights and responsibilities of the
parties involved. The majority of our survey participants use contracts.
20% use
standard
contracts
37% use
standard
contracts
“with
exceptions”
57% of
surveyed
institutions
use
contracts
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
13
JOIN. ENGAGE. LEAD.
REPORTING
Survey
Responses
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
14
JOIN. ENGAGE. LEAD.
REPORTING (CONT.)
Monitor third parties continuously
to ensure that they comply with all
applicable laws and regulations,
and operate in line with the bank’s
policies and expectations.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
15
JOIN. ENGAGE. LEAD.
REGULATORY AND COMPLIANCE
72% of the institutions
surveyed conduct annual
validation of regulatory
compliance and
effectiveness of the
vendor risk management
framework.
0%
10%
20%
30%
40%
50%
60%
70%
80%
72%
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
16
JOIN. ENGAGE. LEAD.
REGULATORY AND COMPLIANCE (CONT.)
Based on the most recent regulatory examination.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
17
JOIN. ENGAGE. LEAD.
CONCLUSIONS
The survey offered a good indication of the preparedness of
financial institutions to manage the current challenges, risks,
and complexities related to vendor risk management.
Companies must keep pace with the new sanctions, frequent
regulatory changes, increasing complexity, and a diverse
and multi-tiered vendor network.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
18
JOIN. ENGAGE. LEAD.
CONCLUSIONS (CONT.)
Organizations need to manage newer risks arising from
emerging technologies and trends, such as increasing
mobility and the use of social media.
Some of the leading organizations understand the value of
integrating their vendor information with their overall
business processes, products, and services.
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
19
JOIN. ENGAGE. LEAD.
Read about RMA’s Third-Party/Vendor Risk
Management Survey here:
http://www.rmahq.org/tools-publications/surveys-
studies/third-party-vendor-risk-management-
survey
LEARN MORE
Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending
20
JOIN. ENGAGE. LEAD.
SHARE THIS PRESENTATION
Visit http://www.rmahq.org for information on risk management.
Visit our blog at http://rmablog.rmahq.org/
RMA is a member-driven professional association whose sole
purpose is to advance sound risk principles in the financial services
industry.
RMA helps its members use sound risk principles to improve
institutional performance and financial stability, and enhance the
risk competency of individuals through information, education, peer
sharing, and networking.
Become a member today.

More Related Content

What's hot

A compliance officer's guide to third party risk management
A compliance officer's guide to third party risk managementA compliance officer's guide to third party risk management
A compliance officer's guide to third party risk managementSALIH AHMED ISLAM
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk ManagementEC-Council
 
Third Party Risk Management Introduction
Third Party Risk Management IntroductionThird Party Risk Management Introduction
Third Party Risk Management IntroductionNaveen Grover
 
Vendor Management - Compliance Checklist Manifesto Series
Vendor Management - Compliance Checklist Manifesto SeriesVendor Management - Compliance Checklist Manifesto Series
Vendor Management - Compliance Checklist Manifesto SeriesContinuity Control
 
Third-party Governance and Risk Management - 2018
Third-party Governance and Risk Management - 2018Third-party Governance and Risk Management - 2018
Third-party Governance and Risk Management - 2018Deloitte UK
 
third party risk management best practices
third party risk management best practicesthird party risk management best practices
third party risk management best practicesSALIH AHMED ISLAM
 
Vendor Management Best Practices: Is Your Program Up to Par?
Vendor Management Best Practices: Is Your Program Up to Par?Vendor Management Best Practices: Is Your Program Up to Par?
Vendor Management Best Practices: Is Your Program Up to Par?EDR
 
Third Party Risk Assessment Due Diligence - Managed Service as Best Practice
Third Party Risk Assessment Due Diligence - Managed Service as Best PracticeThird Party Risk Assessment Due Diligence - Managed Service as Best Practice
Third Party Risk Assessment Due Diligence - Managed Service as Best PracticeDVV Solutions Third Party Risk Management
 
Vendor Selection Best Practices - Crowe Mead
Vendor Selection Best Practices - Crowe MeadVendor Selection Best Practices - Crowe Mead
Vendor Selection Best Practices - Crowe MeadBetterLeadershipBlog
 
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk ManagementProtect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk ManagementDevOps.com
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Resolver Inc.
 
What Every Procurement Professional Should Know About Supplier Risk Managemen...
What Every Procurement Professional Should Know About Supplier Risk Managemen...What Every Procurement Professional Should Know About Supplier Risk Managemen...
What Every Procurement Professional Should Know About Supplier Risk Managemen...IBM Watson Commerce
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesCapgemini
 
Supplier Risk Assessment
Supplier Risk AssessmentSupplier Risk Assessment
Supplier Risk AssessmentGary Bahadur
 

What's hot (18)

A compliance officer's guide to third party risk management
A compliance officer's guide to third party risk managementA compliance officer's guide to third party risk management
A compliance officer's guide to third party risk management
 
Third Party Risk Management
Third Party Risk ManagementThird Party Risk Management
Third Party Risk Management
 
Third Party Risk Management Introduction
Third Party Risk Management IntroductionThird Party Risk Management Introduction
Third Party Risk Management Introduction
 
Vendor risk management 2013
Vendor risk management 2013Vendor risk management 2013
Vendor risk management 2013
 
Vendor Management - Compliance Checklist Manifesto Series
Vendor Management - Compliance Checklist Manifesto SeriesVendor Management - Compliance Checklist Manifesto Series
Vendor Management - Compliance Checklist Manifesto Series
 
Third-party Governance and Risk Management - 2018
Third-party Governance and Risk Management - 2018Third-party Governance and Risk Management - 2018
Third-party Governance and Risk Management - 2018
 
third party risk management best practices
third party risk management best practicesthird party risk management best practices
third party risk management best practices
 
Vendor Management Best Practices: Is Your Program Up to Par?
Vendor Management Best Practices: Is Your Program Up to Par?Vendor Management Best Practices: Is Your Program Up to Par?
Vendor Management Best Practices: Is Your Program Up to Par?
 
Third Party Risk Assessment Due Diligence - Managed Service as Best Practice
Third Party Risk Assessment Due Diligence - Managed Service as Best PracticeThird Party Risk Assessment Due Diligence - Managed Service as Best Practice
Third Party Risk Assessment Due Diligence - Managed Service as Best Practice
 
Vendor Selection Best Practices - Crowe Mead
Vendor Selection Best Practices - Crowe MeadVendor Selection Best Practices - Crowe Mead
Vendor Selection Best Practices - Crowe Mead
 
Integrated GRC
Integrated GRCIntegrated GRC
Integrated GRC
 
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk ManagementProtect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
 
TI Managing Third Party Risk
TI Managing Third Party RiskTI Managing Third Party Risk
TI Managing Third Party Risk
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
 
Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management Creating Value Through Enterprise Risk Management
Creating Value Through Enterprise Risk Management
 
What Every Procurement Professional Should Know About Supplier Risk Managemen...
What Every Procurement Professional Should Know About Supplier Risk Managemen...What Every Procurement Professional Should Know About Supplier Risk Managemen...
What Every Procurement Professional Should Know About Supplier Risk Managemen...
 
Governance, Risk, and Compliance Services
Governance, Risk, and Compliance ServicesGovernance, Risk, and Compliance Services
Governance, Risk, and Compliance Services
 
Supplier Risk Assessment
Supplier Risk AssessmentSupplier Risk Assessment
Supplier Risk Assessment
 

Viewers also liked

Jeffrey Sweet - Third Party Risk Governance - Why? and How?
Jeffrey Sweet - Third Party Risk Governance - Why? and How?Jeffrey Sweet - Third Party Risk Governance - Why? and How?
Jeffrey Sweet - Third Party Risk Governance - Why? and How?centralohioissa
 
Ariba Coverage of Risk Management within the Supplier Lifecycle
Ariba Coverage of Risk Management within the Supplier LifecycleAriba Coverage of Risk Management within the Supplier Lifecycle
Ariba Coverage of Risk Management within the Supplier LifecycleSean Thomson
 
Certificate Tracking Brochure
Certificate Tracking BrochureCertificate Tracking Brochure
Certificate Tracking Brochurepaulkallol
 
Effective Assessment of Vendors Risk Management
Effective Assessment of Vendors Risk Management Effective Assessment of Vendors Risk Management
Effective Assessment of Vendors Risk Management Amit Bhargava
 
CRM Vendor Evaluation Matrix
CRM Vendor Evaluation MatrixCRM Vendor Evaluation Matrix
CRM Vendor Evaluation MatrixDemand Metric
 
Vendor management using COBIT 5
Vendor management using COBIT 5Vendor management using COBIT 5
Vendor management using COBIT 5Robert Stroud
 
The Business Case for Robotic Process Automation (RPA)
The Business Case for Robotic Process Automation (RPA)The Business Case for Robotic Process Automation (RPA)
The Business Case for Robotic Process Automation (RPA)Joe Tawfik
 
Vendor Management Systems Best Practices
Vendor Management Systems Best PracticesVendor Management Systems Best Practices
Vendor Management Systems Best Practicesjeffmonaghan
 
Outsourcing and Vendor management
Outsourcing and Vendor managementOutsourcing and Vendor management
Outsourcing and Vendor managementRaminder Pal Singh
 

Viewers also liked (10)

Jeffrey Sweet - Third Party Risk Governance - Why? and How?
Jeffrey Sweet - Third Party Risk Governance - Why? and How?Jeffrey Sweet - Third Party Risk Governance - Why? and How?
Jeffrey Sweet - Third Party Risk Governance - Why? and How?
 
Ariba Coverage of Risk Management within the Supplier Lifecycle
Ariba Coverage of Risk Management within the Supplier LifecycleAriba Coverage of Risk Management within the Supplier Lifecycle
Ariba Coverage of Risk Management within the Supplier Lifecycle
 
Vendor Management
Vendor ManagementVendor Management
Vendor Management
 
Certificate Tracking Brochure
Certificate Tracking BrochureCertificate Tracking Brochure
Certificate Tracking Brochure
 
Effective Assessment of Vendors Risk Management
Effective Assessment of Vendors Risk Management Effective Assessment of Vendors Risk Management
Effective Assessment of Vendors Risk Management
 
CRM Vendor Evaluation Matrix
CRM Vendor Evaluation MatrixCRM Vendor Evaluation Matrix
CRM Vendor Evaluation Matrix
 
Vendor management using COBIT 5
Vendor management using COBIT 5Vendor management using COBIT 5
Vendor management using COBIT 5
 
The Business Case for Robotic Process Automation (RPA)
The Business Case for Robotic Process Automation (RPA)The Business Case for Robotic Process Automation (RPA)
The Business Case for Robotic Process Automation (RPA)
 
Vendor Management Systems Best Practices
Vendor Management Systems Best PracticesVendor Management Systems Best Practices
Vendor Management Systems Best Practices
 
Outsourcing and Vendor management
Outsourcing and Vendor managementOutsourcing and Vendor management
Outsourcing and Vendor management
 

Similar to Key Challenges Facing Vendor Risk Management Programs

How to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct RiskHow to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct RiskColleen Beck-Domanico
 
Cyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial InstitutionsCyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial InstitutionsColleen Beck-Domanico
 
The Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial InstitutionsThe Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial InstitutionsColleen Beck-Domanico
 
How to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksHow to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksColleen Beck-Domanico
 
How to Stack Your Bank’s Portfolio with More Winners and Fewer Losers
How to Stack Your Bank’s Portfolio with More Winners and Fewer LosersHow to Stack Your Bank’s Portfolio with More Winners and Fewer Losers
How to Stack Your Bank’s Portfolio with More Winners and Fewer LosersColleen Beck-Domanico
 
Being a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the UnderwriterBeing a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the UnderwriterColleen Beck-Domanico
 
What to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursWhat to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursColleen Beck-Domanico
 
What You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate UnderwritingWhat You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate UnderwritingColleen Beck-Domanico
 
The Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services IndustryThe Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services IndustryColleen Beck-Domanico
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkColleen Beck-Domanico
 
Operational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory ExpectationsOperational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory ExpectationsColleen Beck-Domanico
 
2015 WACHA Hot Regulatory Exam Issues 03202015
2015 WACHA Hot Regulatory Exam Issues 032020152015 WACHA Hot Regulatory Exam Issues 03202015
2015 WACHA Hot Regulatory Exam Issues 03202015Brent Siegel
 
Meeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA ComplianceMeeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA ComplianceColleen Beck-Domanico
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk ManagementColleen Beck-Domanico
 
Implementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence RuleImplementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence RuleColleen Beck-Domanico
 
How to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan PortfolioHow to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan PortfolioColleen Beck-Domanico
 
The 8 steps of Credit Risk Management
The 8 steps of Credit Risk ManagementThe 8 steps of Credit Risk Management
The 8 steps of Credit Risk ManagementHak Kim
 
The 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk ManagementThe 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk ManagementColleen Beck-Domanico
 

Similar to Key Challenges Facing Vendor Risk Management Programs (20)

How to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct RiskHow to Measure and Mitigate Conduct Risk
How to Measure and Mitigate Conduct Risk
 
Small Business Lending Outlook
Small Business Lending OutlookSmall Business Lending Outlook
Small Business Lending Outlook
 
Cyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial InstitutionsCyber Security Tips and Resources for Financial Institutions
Cyber Security Tips and Resources for Financial Institutions
 
The Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial InstitutionsThe Rise and Risks of Lending to Non-Depository Financial Institutions
The Rise and Risks of Lending to Non-Depository Financial Institutions
 
How to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community BanksHow to Manage Increasing Data Compliance Issues in Community Banks
How to Manage Increasing Data Compliance Issues in Community Banks
 
How to Stack Your Bank’s Portfolio with More Winners and Fewer Losers
How to Stack Your Bank’s Portfolio with More Winners and Fewer LosersHow to Stack Your Bank’s Portfolio with More Winners and Fewer Losers
How to Stack Your Bank’s Portfolio with More Winners and Fewer Losers
 
Being a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the UnderwriterBeing a Banker Today: The Changing Role of the Underwriter
Being a Banker Today: The Changing Role of the Underwriter
 
What to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident OccursWhat to Do Before a Cyber Incident Occurs
What to Do Before a Cyber Incident Occurs
 
What You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate UnderwritingWhat You Really Need to Know about Commercial Real Estate Underwriting
What You Really Need to Know about Commercial Real Estate Underwriting
 
The Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services IndustryThe Top Risks Challenging the Financial Services Industry
The Top Risks Challenging the Financial Services Industry
 
Winning Tactics for Data Governance
Winning Tactics for Data GovernanceWinning Tactics for Data Governance
Winning Tactics for Data Governance
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Operational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory ExpectationsOperational Risk Governance: 5 Core Regulatory Expectations
Operational Risk Governance: 5 Core Regulatory Expectations
 
2015 WACHA Hot Regulatory Exam Issues 03202015
2015 WACHA Hot Regulatory Exam Issues 032020152015 WACHA Hot Regulatory Exam Issues 03202015
2015 WACHA Hot Regulatory Exam Issues 03202015
 
Meeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA ComplianceMeeting the Challenge of HMDA Compliance
Meeting the Challenge of HMDA Compliance
 
10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management10 Key Principles of Operational Risk Management
10 Key Principles of Operational Risk Management
 
Implementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence RuleImplementing the New BSA Customer Due Diligence Rule
Implementing the New BSA Customer Due Diligence Rule
 
How to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan PortfolioHow to Lower the Risk Profile of Your Auto Loan Portfolio
How to Lower the Risk Profile of Your Auto Loan Portfolio
 
The 8 steps of Credit Risk Management
The 8 steps of Credit Risk ManagementThe 8 steps of Credit Risk Management
The 8 steps of Credit Risk Management
 
The 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk ManagementThe 8 Steps of Credit Risk Management
The 8 Steps of Credit Risk Management
 

More from Colleen Beck-Domanico

The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...Colleen Beck-Domanico
 
How Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking IndustryHow Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking IndustryColleen Beck-Domanico
 
Recruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk TalentRecruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk TalentColleen Beck-Domanico
 
How will climate change affect financial services?
How will climate change affect financial services?How will climate change affect financial services?
How will climate change affect financial services?Colleen Beck-Domanico
 
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your GameCredit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your GameColleen Beck-Domanico
 
What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028Colleen Beck-Domanico
 
Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now Colleen Beck-Domanico
 
What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?Colleen Beck-Domanico
 
3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals3 Things You Should Know about Appraisals
3 Things You Should Know about AppraisalsColleen Beck-Domanico
 
How to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk ManagerHow to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk ManagerColleen Beck-Domanico
 
5 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 20175 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 2017Colleen Beck-Domanico
 
8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know NowColleen Beck-Domanico
 
A Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality LendingA Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality LendingColleen Beck-Domanico
 
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...Colleen Beck-Domanico
 
A Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate LendingA Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate LendingColleen Beck-Domanico
 
8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCsColleen Beck-Domanico
 

More from Colleen Beck-Domanico (19)

The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
The Top 7 Risks Challenging the Financial Services Industry in the COVID-19 E...
 
The RMA COVID-19 Resource Center
The RMA COVID-19 Resource CenterThe RMA COVID-19 Resource Center
The RMA COVID-19 Resource Center
 
How Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking IndustryHow Modernized Training Is Influencing the Banking Industry
How Modernized Training Is Influencing the Banking Industry
 
Recruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk TalentRecruiting, Developing, and Retaining Risk Talent
Recruiting, Developing, and Retaining Risk Talent
 
How will climate change affect financial services?
How will climate change affect financial services?How will climate change affect financial services?
How will climate change affect financial services?
 
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your GameCredit Risk Certification (CRC): 5 Reasons to Up Your Game
Credit Risk Certification (CRC): 5 Reasons to Up Your Game
 
5 Risks in Commercial Lending
5 Risks in Commercial Lending5 Risks in Commercial Lending
5 Risks in Commercial Lending
 
What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028What Skills Will Risk Managers Need in 2028
What Skills Will Risk Managers Need in 2028
 
Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now Implementing the CECL Standard: 5 Actions to Take Now
Implementing the CECL Standard: 5 Actions to Take Now
 
What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?What is Blockchain and How Can It Change the Game for Financial Institutions?
What is Blockchain and How Can It Change the Game for Financial Institutions?
 
3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals3 Things You Should Know about Appraisals
3 Things You Should Know about Appraisals
 
How to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk ManagerHow to Keep Your Balance as a Risk Manager
How to Keep Your Balance as a Risk Manager
 
5 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 20175 Commercial Real Estate (CRE) Challenges in 2017
5 Commercial Real Estate (CRE) Challenges in 2017
 
8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now8 Risk Management Tips You Need to Know Now
8 Risk Management Tips You Need to Know Now
 
A Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality LendingA Quick Guide to Credit Considerations in Hospitality Lending
A Quick Guide to Credit Considerations in Hospitality Lending
 
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
How to Make Your Specialty Services Lending Rock: Credit Considerations for 4...
 
A Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate LendingA Quick Guide to Credit Considerations in Real Estate Lending
A Quick Guide to Credit Considerations in Real Estate Lending
 
8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs8 Things You Need to Know about HELOCs
8 Things You Need to Know about HELOCs
 
7 Tips to Help You Prepare for CECL
7 Tips to Help You Prepare for CECL7 Tips to Help You Prepare for CECL
7 Tips to Help You Prepare for CECL
 

Recently uploaded

原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证jdkhjh
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escortsranjana rawat
 
Stock Market Brief Deck for "this does not happen often".pdf
Stock Market Brief Deck for "this does not happen often".pdfStock Market Brief Deck for "this does not happen often".pdf
Stock Market Brief Deck for "this does not happen often".pdfMichael Silva
 
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With RoomVIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Roomdivyansh0kumar0
 
Andheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot ModelsAndheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot Modelshematsharma006
 
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service AizawlVip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawlmakika9823
 
House of Commons ; CDC schemes overview document
House of Commons ; CDC schemes overview documentHouse of Commons ; CDC schemes overview document
House of Commons ; CDC schemes overview documentHenry Tapper
 
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130Suhani Kapoor
 
Interimreport1 January–31 March2024 Elo Mutual Pension Insurance Company
Interimreport1 January–31 March2024 Elo Mutual Pension Insurance CompanyInterimreport1 January–31 March2024 Elo Mutual Pension Insurance Company
Interimreport1 January–31 March2024 Elo Mutual Pension Insurance CompanyTyöeläkeyhtiö Elo
 
How Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingHow Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingAggregage
 
Lundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfLundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfAdnet Communications
 
Bladex 1Q24 Earning Results Presentation
Bladex 1Q24 Earning Results PresentationBladex 1Q24 Earning Results Presentation
Bladex 1Q24 Earning Results PresentationBladex
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex
 
Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111Sapana Sha
 
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130  Available With RoomVIP Kolkata Call Girl Serampore 👉 8250192130  Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Roomdivyansh0kumar0
 
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证rjrjkk
 
SBP-Market-Operations and market managment
SBP-Market-Operations and market managmentSBP-Market-Operations and market managment
SBP-Market-Operations and market managmentfactical
 
fca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdffca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdfHenry Tapper
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignHenry Tapper
 

Recently uploaded (20)

原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
 
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur EscortsCall Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
Call Girls Service Nagpur Maya Call 7001035870 Meet With Nagpur Escorts
 
Stock Market Brief Deck for "this does not happen often".pdf
Stock Market Brief Deck for "this does not happen often".pdfStock Market Brief Deck for "this does not happen often".pdf
Stock Market Brief Deck for "this does not happen often".pdf
 
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With RoomVIP Kolkata Call Girl Jodhpur Park 👉 8250192130  Available With Room
VIP Kolkata Call Girl Jodhpur Park 👉 8250192130 Available With Room
 
Andheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot ModelsAndheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot Models
 
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service AizawlVip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
Vip B Aizawl Call Girls #9907093804 Contact Number Escorts Service Aizawl
 
House of Commons ; CDC schemes overview document
House of Commons ; CDC schemes overview documentHouse of Commons ; CDC schemes overview document
House of Commons ; CDC schemes overview document
 
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
 
Interimreport1 January–31 March2024 Elo Mutual Pension Insurance Company
Interimreport1 January–31 March2024 Elo Mutual Pension Insurance CompanyInterimreport1 January–31 March2024 Elo Mutual Pension Insurance Company
Interimreport1 January–31 March2024 Elo Mutual Pension Insurance Company
 
Monthly Economic Monitoring of Ukraine No 231, April 2024
Monthly Economic Monitoring of Ukraine No 231, April 2024Monthly Economic Monitoring of Ukraine No 231, April 2024
Monthly Economic Monitoring of Ukraine No 231, April 2024
 
How Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingHow Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of Reporting
 
Lundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfLundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdf
 
Bladex 1Q24 Earning Results Presentation
Bladex 1Q24 Earning Results PresentationBladex 1Q24 Earning Results Presentation
Bladex 1Q24 Earning Results Presentation
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024
 
Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111Call Girls In Yusuf Sarai Women Seeking Men 9654467111
Call Girls In Yusuf Sarai Women Seeking Men 9654467111
 
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130  Available With RoomVIP Kolkata Call Girl Serampore 👉 8250192130  Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Room
 
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
原版1:1复刻温哥华岛大学毕业证Vancouver毕业证留信学历认证
 
SBP-Market-Operations and market managment
SBP-Market-Operations and market managmentSBP-Market-Operations and market managment
SBP-Market-Operations and market managment
 
fca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdffca-bsps-decision-letter-redacted (1).pdf
fca-bsps-decision-letter-redacted (1).pdf
 
Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaign
 

Key Challenges Facing Vendor Risk Management Programs

  • 1. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 1 JOIN. ENGAGE. LEAD. KEY CHALLENGES FACING VENDOR RISK MANAGEMENT PROGRAMS Third-Party/Vendor Risk Management Survey Results
  • 2. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 2 JOIN. ENGAGE. LEAD. THE THIRD-PARTY/VENDOR RISK MANAGEMENT SURVEY The survey was conducted between June and August 2014 by RMA, in association with MetricStream. It sought to: 1. Capture the range of practices in third- party/vendor risk management (VRM) over a cross section of RMA member institutions. 2. Gather detailed information on some of the key challenges that banks and other financial institutions are facing
  • 3. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 3 JOIN. ENGAGE. LEAD. SURVEY FOCUS Vendor management framework Vendor selection and monitoring process Critical vendors and critical activities Fourth-party suppliers. Tools and techniques Contracts Reporting Regulatory and compliance
  • 4. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 4 JOIN. ENGAGE. LEAD. WHAT WE FOUND • For most of the responding organizations, the vendor management programs are still in their nascent stage. 1. • Third party relationships have evolved beyond the traditional models of goods and service providers. 2.
  • 5. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 5 JOIN. ENGAGE. LEAD. VENDOR MANAGEMENT FRAMEWORK Some of the bigger organizations surveyed have thousands of supplier relationships to manage— extremely difficult without mature vendor governance framework.
  • 6. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 6 JOIN. ENGAGE. LEAD. VENDOR SELECTION AND MONITORING PROCESS Financial institutions should conduct continuous in-depth assessments on the third- party’s capability to perform the activities commensurate with the risk and complexity of the relationship.
  • 7. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 7 JOIN. ENGAGE. LEAD. VENDOR SELECTION AND MONITORING PROCESS (CONT.) Each institution surveyed has multiple areas or SMEs for vendor selection and due diligence of third parties. Information security Information technology BCM Legal Key groups conducting secondary supplier risk assessments
  • 8. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 8 JOIN. ENGAGE. LEAD. CRITICAL VENDORS • “Critical activities” include: • Significant bank functions. • Shared services, such as: • internal audit • Information technology OCC Guidance
  • 9. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 9 JOIN. ENGAGE. LEAD. CRITICAL VENDORS (CONT.) • For most of the surveyed organizations, the number of enterprise critical suppliers ranges from 3 to 15. • Risk and risk and spend are the primary factors when segmenting suppliers on the basis of criticality.0% 20% 40% 60% 80% 100% Conduct site visits, especially for critical vendors. Have defined, or are in the process of defining, the critical activities in their institution. 73% 97%
  • 10. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 10 JOIN. ENGAGE. LEAD. FOURTH PARTY SUPPLIERS 0 10 20 30 40 50 60 70 Done when the primary supplier notifies them of a new material fourth party Perform due diligence at time of sourcing/contracting the 3rd party 4th party suppliers identified at RFP stage No due diligence on 4th parties 13% 20% 50% 67% % of Respondents
  • 11. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 11 JOIN. ENGAGE. LEAD. TOOLS AND TECHNIQUES Organizations need to gain a clearer understanding of their third party’s business processes and technologies that will be used to support the outsourced activity.
  • 12. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 12 JOIN. ENGAGE. LEAD. CONTRACTS After your bank selects a third party, your bank should negotiate a contract that clearly defines the rights and responsibilities of the parties involved. The majority of our survey participants use contracts. 20% use standard contracts 37% use standard contracts “with exceptions” 57% of surveyed institutions use contracts
  • 13. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 13 JOIN. ENGAGE. LEAD. REPORTING Survey Responses
  • 14. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 14 JOIN. ENGAGE. LEAD. REPORTING (CONT.) Monitor third parties continuously to ensure that they comply with all applicable laws and regulations, and operate in line with the bank’s policies and expectations.
  • 15. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 15 JOIN. ENGAGE. LEAD. REGULATORY AND COMPLIANCE 72% of the institutions surveyed conduct annual validation of regulatory compliance and effectiveness of the vendor risk management framework. 0% 10% 20% 30% 40% 50% 60% 70% 80% 72%
  • 16. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 16 JOIN. ENGAGE. LEAD. REGULATORY AND COMPLIANCE (CONT.) Based on the most recent regulatory examination.
  • 17. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 17 JOIN. ENGAGE. LEAD. CONCLUSIONS The survey offered a good indication of the preparedness of financial institutions to manage the current challenges, risks, and complexities related to vendor risk management. Companies must keep pace with the new sanctions, frequent regulatory changes, increasing complexity, and a diverse and multi-tiered vendor network.
  • 18. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 18 JOIN. ENGAGE. LEAD. CONCLUSIONS (CONT.) Organizations need to manage newer risks arising from emerging technologies and trends, such as increasing mobility and the use of social media. Some of the leading organizations understand the value of integrating their vendor information with their overall business processes, products, and services.
  • 19. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 19 JOIN. ENGAGE. LEAD. Read about RMA’s Third-Party/Vendor Risk Management Survey here: http://www.rmahq.org/tools-publications/surveys- studies/third-party-vendor-risk-management- survey LEARN MORE
  • 20. Enterprise Risk · Credit Risk · Market Risk · Operational Risk · Regulatory Compliance · Securities Lending 20 JOIN. ENGAGE. LEAD. SHARE THIS PRESENTATION Visit http://www.rmahq.org for information on risk management. Visit our blog at http://rmablog.rmahq.org/ RMA is a member-driven professional association whose sole purpose is to advance sound risk principles in the financial services industry. RMA helps its members use sound risk principles to improve institutional performance and financial stability, and enhance the risk competency of individuals through information, education, peer sharing, and networking. Become a member today.