Search Results
Search this site
506 results found with an empty search
Blog Posts (115)
- Budgeting for TPRM Success
If you've worked in third party risk management (TPRM) for any length of time, you know budget season rarely gets easier. Third party populations continue to grow. Business units expect reviews to move faster. Regulations continue to evolve, and AI has introduced new considerations into third party due diligence. Regulators have also made something else clear. Effective TPRM requires appropriate staffing, expertise, governance, and ongoing oversight. Leadership is responsible for ensuring those resources are available. The challenge, of course, is that leadership can't fund what it doesn't understand. It's up to TPRM leaders to demonstrate where the program stands today, where the gaps exist, and what resources are needed to support the business. That's where a well-built budget becomes one of the most important tools in your program. Start with Actual Spending Before building next year's budget, understand where this year's money actually went. Last year's approved budget is only part of the picture. Actual spending often tells a different story. Software renewals increase. A hiring freeze leaves a key position vacant longer than expected. An unplanned third party event requires outside expertise. Break spending into broad categories such as: Technology and software Outsourced assessments Staffing Training and certifications Consulting and audit support Some of these costs may be buried inside shared enterprise budgets, so partnering with finance early can save hours of reconstruction. Once you've organized the numbers, identify the largest variances. Those differences often reveal where the program is changing and provide the strongest justification for next year's request. Pro Tip: Compare at least two years of actual spending. Trends usually tell a stronger story than a single year's variance. Measure the Gaps The next question is whether your program is keeping pace with demand. Has your third party population grown? Are reassessments staying on schedule? Has your backlog increased? Are business units waiting longer for reviews? Are the risk domains you are assessing covering the right risks? If you aren't tracking these metrics yet, start now, even if it's only in a spreadsheet. Whenever possible, convert the problem into numbers. If third party growth resulted in forty additional assessments this year, estimate the effort required to support that increase. Finance can evaluate measurable impacts much more easily than general statements about workload. Quick Check How many third parties were added this year? What's your average assessment turnaround time? Where is your largest backlog? Which bottleneck would disappear first if your budget were approved tomorrow? How Does Your Program Compare? Every organization has different priorities, but it helps to understand where other TPRM programs are investing. According to KPMG's 2026 Global Third Party Risk Management Survey of 851 organizations, the top investment areas are risk assessments and due diligence (52%), TPRM technology (51%), cybersecurity and data protection (49%), and regulatory audits (45%). More than 80% of organizations outsource at least part of their TPRM activities, while only 17% reported having fully reliable TPRM data. These findings aren't a blueprint for your budget, but they provide a useful benchmark. Pro Tip: If your investment priorities look very different from your peers, be prepared to explain why. Sometimes there's a good reason and being able to articulate it to leadership is essential. Think about it this way... What level of third party risk does the organization need to manage, and what people, technology, intelligence, and assurance capabilities are required to manage it effectively? AI Is Expanding the Scope of TPRM AI is becoming part of more third party products every month, including products many organizations already use. As a result, existing third party relationships now require additional scrutiny. Questions about training data, model governance, customer information, and contractual protections have become routine parts of due diligence. Many organizations also expect AI to reduce costs and staffing needs. That expectation has largely outpaced reality. According to KPMG's survey, only 22% of organizations rated their AI initiatives as very effective. Finance may expect efficiency gains that haven't materialized, while TPRM teams face additional review work. Budget for the resources needed to support that growth. Budget Checklist Update AI due diligence questionnaires. Review AI-specific contract language. Invest in team training. Consider managed services or specialized expertise. Evaluate tools that improve assessment efficiency. Headcount May Not Be the Only Answer When workloads increase, it's easy to assume another team member is the answer. Sometimes that's true. Sometimes the real issue is an inefficient process, a technology gap, or the need for specialized skills. Before requesting another position, step back and identify what's actually slowing the program down. You can also ask which TPRM activities are consuming human capacity without requiring human judgement. Then consider all of the available options. Improve or redesign an existing workflow. Use capabilities already available in your technology stack. Automate repetitive administrative tasks. Outsource TPRM processes such as due diligence document collection or reviews Bring in part-time contractors during peak periods. Share platforms or subscriptions with Procurement, Information Security, or Compliance to reduce total cost of ownership. If another employee is still the right solution, you'll have a much stronger business case because you've already evaluated the alternatives. Pro Tip: Before requesting another FTE, ask whether the problem is capacity, process, technology, skills, or temporary workload. The answer will help you determine which investment will drive the improvement you need. Don't Overlook the Small Line Items Some of the easiest budget items to miss are also the ones most likely to create problems later. Recurring costs often increase over time, and one-time projects have a way of becoming recurring if they aren't clearly identified. Spending a little extra time reviewing your assumptions now can prevent mid-year surprises. Commonly Forgotten Budget Items Platform renewals and licensing increases Team training and certifications AI-specific assessment tools or questionnaire updates Fourth-party risk initiatives One-time consulting or implementation projects Pro Tip: Separate one-time investments from recurring operating expenses. It makes future budgeting easier and helps finance understand your long-term costs. Separate Needs from Nice-to-Haves Few organizations receive everything they request. Before budget discussions begin, decide which investments are essential and which would simply improve the program. Those decisions are much easier to make before you're sitting across the table from finance. A simple prioritization exercise can save time later. Must Have Regulatory or contractual obligations Minimum staffing requirements Critical platform renewals Required operational activities Reasonable Due Diligence capacity to support the business Nice to Have Additional reporting capabilities New dashboards Premium platform features Nice efficiency improvements that can wait another budget cycle Pro Tip: Ask yourself one question: If finance approved only half of this request tomorrow, what would stay? If you know that answer before the meeting, you're already ahead of the conversation. Build a Business Case, Not Just a Budget Budgets are approved because they support business objectives, not because a department needs more money. Rather than focusing on workload, explain what the investment enables the business to accomplish. Support your request with measurable outcomes whenever possible. For example: Improve supplier onboarding. If assessments currently take 90 days and your goal is 60, estimate how many projects or contracts could move forward 30 days sooner. Reduce operational risk. Estimate the potential impact of a supplier disruption, delayed implementation, or security incident, then compare it to the cost of earlier detection through stronger due diligence and monitoring. Strengthen regulatory readiness. If audit findings or manual processes require recurring remediation, estimate the effort required to address those issues today versus preventing them in the future. Support business growth. If the organization expects significant third party growth, estimate the additional assessment workload and show how your request will help maintain service levels and avoid backlogs. The stronger your data, the stronger your business case. Third party growth, assessment volumes, turnaround times, backlog trends, and remediation effort all provide objective evidence that leadership can evaluate. Pro Tip: Don't ask for more money. Ask for the ability to deliver a measurable business outcome. Keep Tracking Throughout the Year Budget season shouldn't be the only time you look at your numbers. Review spending throughout the year and compare actual expenses against your budget. Track trends such as assessment volume, cost per assessment, outsourced versus internal work, and unexpected costs resulting from third party incidents. Those metrics become the starting point for next year's budget instead of forcing you to rebuild the story from memory. Track These Metrics Quarterly Budget versus actual spending Third party growth Assessment turnaround time Assessment backlog Cost per assessment Outsourced versus internal work Final Thoughts No organization gets every budget request approved. The goal isn't to win every budget discussion. The goal is to build a request that's grounded in data, tied to business priorities, and realistic about where the program needs to grow. Organizations that consistently track workload, spending, and performance throughout the year rarely start from scratch when budget season arrives. They already have the data to explain where resources are needed and how those investments support the business. Budgeting is never just about the numbers. It's about demonstrating that your program understands its risks, knows where it needs to improve, and has a practical plan for getting there. Author Bio Hilary Jewhurst Sr. Membership & Education Coordinator at TPRA Hilary Jewhurst is a seasoned expert in third party risk and risk operations, with nearly two decades of experience across financial services, fintech, and the nonprofit sector. She has built and scaled third party risk programs from the ground up, designed enterprise-wide training initiatives, and developed widely respected content that helps organizations navigate regulatory complexity with clarity and confidence. Known for turning insight into action, Hilary’s thought leadership and educational work have become go-to resources for professionals looking to mature their TPRM programs. She regularly publishes articles, frameworks, and practical guides that break down complicated risk topics into meaningful, accessible strategies. Hilary recently joined the Third Party Risk Association (TPRA) as a staff member, supporting industry-wide education, peer learning, and advancing best practices. She is also the founder of TPRM Success, a boutique consultancy that helps organizations strengthen their third party risk management capabilities through targeted training, tools, and strategic guidance.
- Sanctions and Third Party Risk: What Every TPRM Practitioner Should Know || TPRM Exchange Podcast – Episode 4
Sanctions compliance may traditionally sit with legal, trade compliance, or another specialized function, but it has direct implications for third party risk management. A prohibited relationship can expose an organization to blocked transactions, frozen payments, regulatory enforcement, financial penalties, operational disruption, and reputational damage. In this episode of the TPRM Exchange, host Hilary Jewhurst speaks with Michael Volkov of The Volkov Law Group about how sanctions apply to third parties, where sanctions risk appears throughout the lifecycle, and what practitioners can do to build a practical and defensible process. Sanctions Risk Does Not Stop at the Border One of the most common—and potentially costly—misunderstandings is that U.S. sanctions no longer apply when a transaction is routed through an entity outside the United States. As Volkov explains, a U.S. company cannot avoid its sanctions obligations simply by working through a third party in another country. “The risk continues from wherever you’re located. If you’re a U.S. person or a U.S. company, it continues through your third parties, no matter where they are located.” — Michael Volkov Sanctions may target particular activities, individuals, entities, industries, or entire countries. Regardless of the specific program, the practical question for an organization is whether it is permitted to conduct business or complete a financial transaction with the party involved. Screening Should Begin During Onboarding Sanctions issues can emerge at several points in the third party lifecycle, but onboarding is the most important place to establish a control. Before a vendor, supplier, customer, distributor, or other third party is entered into an organization’s master database or approved for payment, the party should be screened. Building screening into the existing approval workflow allows the organization to identify potential issues before a contract is signed, goods are shipped, or money changes hands. Waiting until a bank blocks a payment puts the organization in a much more difficult position. By that point, goods may already have been delivered, contractual commitments may have been made, and funds may be frozen while the parties investigate. The Entity Name Is Only the Beginning Screening the contracting entity is an essential first step, but it may not reveal the full risk. Organizations may also need to examine the company’s beneficial owners, officers, directors, or other principals. Under certain sanctions rules, an entity can be treated as blocked when one or more sanctioned persons own 50% or more of it—even if the entity itself does not appear by name on a sanctions list. Ownership structures can also obscure the individuals who ultimately control or benefit from a company. When an initial screen produces a red flag, practitioners may need to gather additional ownership information and work with legal or compliance specialists to determine whether the relationship is permissible. Sanctions Exposure Extends to Nth Parties The conversation also highlights the importance of looking beyond direct contractual relationships. Sanctioned goods, materials, entities, or individuals may appear several levels down a supply chain or later in a distribution channel. Volkov uses supply chain and transshipment examples to illustrate how an organization can face liability even when it does not directly contract with the sanctioned party. Risk may arise when prohibited materials enter the supply chain through a subcontractor or when a distributor redirects a product to a sanctioned destination. Managing that exposure may require: Risk-based supply chain due diligence Appropriate sanctions and trade-compliance clauses End-use and end-user controls Supplier representations and certifications Supply chain audits Escalation procedures for geographic or ownership concerns The appropriate level of diligence will depend on the organization’s products, markets, geographic reach, distribution model, and overall exposure. Build Forward Instead of Trying to Fix Everything at Once Organizations implementing formal sanctions screening may discover that hundreds or thousands of existing third parties have never been screened. That does not mean the program must resolve the entire backlog before introducing an effective control. “You’re not going to boil the ocean over this. We don’t have time for that, nor the resources.” — Michael Volkov A more manageable approach is to establish a clear implementation date and screen every new third party from that point forward. The organization can then address its existing population using a risk-based plan. Higher-priority reviews may include third parties with: Operations in higher-risk countries or regions Significant organizational spend or revenue Exposure to known transshipment locations Complex or unclear ownership structures Access to regulated products, technology, or services Roles deeper within critical supply or distribution chains This approach allows the organization to establish a consistent control immediately while addressing historical exposure in a deliberate, defensible order. Screening Is Not a One-Time Activity A third party that passes screening today may be added to a sanctions list tomorrow. Sanctions designations can change quickly in response to geopolitical events, national security concerns, criminal activity, or changes in government policy. Automated screening platforms can help by retaining screened parties and issuing alerts when a party’s status changes. Organizations without an automated tool may begin with available government screening resources or seek assistance from qualified legal or compliance professionals, but manual screening becomes harder to sustain as international activity grows. Regardless of the technology used, the process should define: Who is screened When screening occurs Which lists and data sources are used How potential matches are reviewed Who can clear or reject a match How decisions are documented How active relationships are monitored When issues must be escalated The tool supports the control, but it does not replace a clear workflow and accountable decision-making. TPRM Does Not Have to Own the Process—but It Must Understand It Sanctions screening may be performed by compliance, legal, procurement, trade compliance, sustainability, or another team. Organizational structures vary, and there is no single operating model that works for every company. However, TPRM practitioners should understand how the process works even when another function owns it. They should know who makes sanctions decisions, what tools or information that team uses, what evidence confirms that screening occurred, and how an issue is escalated. That knowledge is necessary to explain the organization’s controls to business stakeholders, auditors, examiners, and leadership. It also prevents gaps between functions—particularly when onboarding involves several teams with different approval responsibilities. Compliance Must Be Positioned as a Business Partner Business stakeholders may view sanctions screening as another obstacle standing between them and a time-sensitive transaction. Volkov recommends approaching those conversations as a partner focused on helping the business proceed safely. The message should be straightforward: involve the appropriate risk and compliance teams early, and they can identify concerns, explore permissible options, and help prevent transactions from being blocked later. TPRM and compliance teams should also establish reasonable turnaround expectations. A well-designed screening process should support timely decision-making while ensuring that unresolved red flags do not pass unnoticed into the vendor master or payment process. When an Existing Supplier Triggers an Alert If a long-term supplier appears on a sanctions notice, the organization must act promptly. The immediate response should generally include pausing business and financial activity, notifying the appropriate internal stakeholders, and investigating the alert. The organization should contact the third party for an explanation while legal or trade-compliance personnel determine whether the notice is accurate and whether the relationship can lawfully continue. Contracts and purchase orders should contain sanctions-compliance language that supports the organization’s ability to suspend or terminate prohibited activity. These protections are particularly important when a designation occurs in the middle of a transaction or during a multiyear agreement. Practitioners should not assume that every alert establishes a confirmed violation. False positives and explainable matches occur. Nevertheless, activity should not resume until qualified personnel have reviewed the issue and documented a defensible decision. Two Practical Priorities Volkov closes with two primary actions for practitioners: Implement a sanctions-screening capability that supports onboarding and continued monitoring. Provide annual sanctions training to employees whose responsibilities may bring them into contact with sanctions-related issues. Training does more than communicate rules. It creates an opportunity for employees to raise questions, describe emerging business activities, and identify transactions or relationships that might otherwise remain outside the risk team’s view. Ultimately, effective sanctions compliance depends on visibility, defined ownership, appropriate technology, and cooperation across the organization. By embedding screening into onboarding, monitoring active relationships, accounting for beneficial ownership and nth parties, and responding quickly to alerts, TPRM practitioners can help protect the organization while still enabling the business to move forward.
Other Pages (385)
- TPCRA | TPRA
The Third Party Cyber Risk Assessor (TPCRA) Certification validates your expertise in assessing third party cybersecurity controls, advancing your career in third party risk management. Third Party Risk Association's Third Party Cyber Risk Assessor (TPCRA) Certification The TPCRA Certification is a specialized qualification that validates expertise in assessing third-party cybersecurity controls, managing cyber risk assessments, and evidencing proficiency in cybersecurity assessment techniques, as well as establishing credibility for third-party risk management professionals. Register Now By clicking this button, you will be redirected to our Training & Certification Platform (Inspire360). Your TPRA website login credentials will not work on Inspire360, and a separate account is required to register for & access courses. What is the TPCRA? The TPCRA Certification is a specialized qualification designation which will: Confirm your understanding & skill in the assessment of third party cyber security controls and processes. Validate your competency in the creation, execution, & management of third party cyber risk assessments. Authenticate & add credibility to your expertise as a third party cyber risk assessor. Evidence your proficiency with various cyber security & information technology assessment terms & techniques. About TPCRA Register Domains Pricing Examination Overview Training Schedule FAQs Who is the TPCRA for? The TPCRA is the standard of achievement for those who assess, monitor, and review third party cyber security and information technology controls, as well as identify and mitigate risk related to said controls. Such roles may include, but not be limited to: Third Party Risk Management Practitioners Procurement Specialist Vendor Managers Auditors Information Security Professionals Privacy or Compliance Specialists Legal Professionals "The TPCRA Certification is foundational to achieving success as a third party risk management professional." Domains Building Core Competencies for Lasting Professional Excellence Cybersecurity & Third Party Risk Management Basics Pre-Contract Due Diligence Continuous Monitoring Physical Validation Disengagement Due Diligence Cloud Due Diligence Reporting & Analytics Practitioner Ethics Pricing Register Now Where will this button take me? Item TPRA Standard, Vendor, & Non-Members TPRA Premium Practitioner Members Examination $500 $425 Training $400 $340 Examination & Training Bundle $800 $700 Examination Retake Fee $200 $200 Certification Renewal $100 $85 Examination Overview Examination Outline The examination is a 150-question, multiple-choice assessment. Questions will include a variety of formats, such as scenario-based, true or false, and choose the best response. The time limit is 3 hours for the examination process, broken out into the following: 5 minutes to read and sign the NDA 10 minutes to complete the optional tutorial 160 minutes to complete the examination 5 minutes to complete the post-exam survey The examination is a closed-book assessment that will be monitored via an assigned proctor. Passing Score You must receive a score of 80% or higher to pass the TPCRA examination. Exam Scheduling The examination will be taken in person at a Pearson VUE testing facility. Examinations may be scheduled at a day/time that suits you via a Pearson VUE location. Pearson VUE offers over 5,000 test facilities worldwide and is ADA-compliant. Training Schedule SESSION DATE TIME LOCATION REGISTER TPCRA On-Demand Training Only REGISTER TPCRA On-Demand Training & Exam Bundle REGISTER TPCRA 4-Day November Training Only 11/16/2026 5 PM - 8 PM CT REGISTER TPCRA 4-Day November Training & Exam Bundle 11/16/2026 5 PM - 8 PM CT REGISTER PLEASE NOTE: When you click "Register" above, you will be redirected to our Training & Certification Platform ( Inspire360 ). Your TPRA website login credentials will not work on Inspire360, and a separate account is required to register for and access courses. Learn more on our FAQ page . " I thought the training was fantastic. I've been a TPRM practitioner for nearly 7 years now and still walked away with new knowledge and insight. I am so proud of the TPRA and honored to be a part of the board! " Nicole Makinney Product Owner, Third Party Risk | McKesson TPCRA Training Attendee TPCRA Frequently Asked Questions General TPCRA Information About TPCRA Certification TPCRA Requirements TPCRA Examination TPCRA Training Maintaining Your TPCRA Certification Examination Outline Certification Eligibility Criteria Certification Pricing TPCRA Training Instructor Certification Renewal Registration Certification Process Training Need Help? Visit our Support page for Frequently Asked Questions and, if that doesn't work, key contacts to reach out to for further assistance. Support & FAQs →
- WNTPRM Recorded Meetings | TPRA
Watch Women in TPRM recordings of past monthly meetings. Hear insights from women leaders and practitioners driving change in third party risk management. Meetings WNTPRM On-Demand Meetings Tuesday, August 18, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, June 16, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, May 19, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, April 28, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, March 17, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video Tuesday, February 17, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting PowerPoint Watch Video LOAD MORE
- WOMEN IN TPRM PROGRAM | TPRA
Join TPRA’s Women in TPRM program to uplift and support women in the industry through mentorship, leadership development, and recognition. Empowering the next generation of women leaders in TPRM. Our Goals Our Goals The Women in TPRM (WNTPRM) Program is dedicated to empowering women in the Third Party Risk Management (TPRM) industry. This program is open to all , regardless of TPRA membership status or gender identity. Through collaborative efforts, we aim to: Uplift Women in TPRM : Advocate for professional growth and recognition. Provide Access to Higher-Paying Roles: Break barriers to equitable opportunities in TPRM careers. Celebrate & Support Women: Establish a platform to spotlight achievements and nurture community. Cultivate Future Leaders: Develop the next generation of trailblazers in TPRM. What We Do What We Do We meet monthly to strategize on achieving these goals and to address challenges within the field. You do not need to be a TPRA member to participate in this program, but some facets of this program are member-specific, such as our 'Women in TPRM' Slack Channel, where TPRA Practitioner Members can continue meaningful conversations, share resources, and collaborate. Standard Practitioner Membership is free , and all TPRA Practitioner Members are invited to join our Slack Forum here . Members and non-members can join our LinkedIn group to stay connected. Our Initiatives Include: Advocating for the importance of women in TPRM through educational resources and outreach. Providing access to tools, techniques, and insights that uplift and empower women in the field. Showcasing and celebrating women leaders who inspire and shape the TPRM landscape. Sharing job opportunities from organizations committed to supporting women in TPRM. Join us as we drive change, foster leadership, and build a brighter future for women in TPRM! Meetings Upcoming Meetings Watch On-Demand Meetings September 15, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting Read All October 20, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting Read All November 17, 2026 1:00 – 2:00 PM CT Women In TPRM Meeting Read All Programs & Resources Women Lead Spotlights Our Women Lead Program is dedicated to showcasing inspiring leaders by highlighting their stories. Our goal for this program is to learn from and be inspired by women leaders in the field of Third Party Risk Management (TPRM) throughout various industries. View our Leaders and learn how to nominate and/or apply to become a spotlight. View Spotlights Resource Sharing Library Our Women in TPRM Resource Sharing Library contains a variety of women in business-related materials. Included are reports on the latest women in business trends and statistics, blogs and articles on relevant and current happenings, and TED Talks featuring inspiring women in business educating others on how to navigate the business world and find success in their careers. View Library Leadership Ladders Originally developed by TPRA's Women in TPRM "Lead" work group, this training activity is designed for all current & aspiring leaders within the Third Party Risk Management (TPRM) industry. Inspired by the classic "Shoots and Ladders" game, it is an all-in-one roadmap to leadership in the form of a nostalgic, virtual board game! E ach box on the board is linked to a valuable resource–including customized guides, blogs, videos, quizzes, and more–with the goal of enhancing your leadership potential through buildable skills and expert insights. Any professional, regardless of what stage they're at in their career, can find value in this activity. Check It Out Recorded Meetings View meeting recordings and PowerPoints from our monthly Women In TPRM Meetings. Recorded Meetings Resources Statistics Women only represent 15-20% of the Governance, Risk and Compliance profession (GRC World Forums, 2021). Read Full Article Only about 25% of every 100 security and risk management (SRM) executives are women (Gartner Inc., 2019). Read Full Article Gender-diverse and inclusive teams outperform gender-homogeneous, less-inclusive teams by an average of 50 % (Gartner Inc., 2019). Read Full Article According to one survey, 24% of global cybersecurity employees are women, and 18% of CIOs/CTOs are female (Deloitte, 2021 ). Read Full Article Quotes "Diversity matters not just because increasing representation of minorities and women in a fast growing and critical field is the right thing to do, but because a variety of viewpoints are key to solving hard problems." SVP, General Counsel - Legal, Bitsight Johanna Werbach “...change must come from within the industry and not be mandated from external parties.” Chief Data and Privacy Officer, MeritB2B Karie Burt "With different backgrounds and perspectives and voices at the table and in an environment where their contributions are really valued, you benefit from a much more expansive conversation and one that’s much more likely to uncover the full range of possibilities and solutions." VP & GM, TPRM, BitSight Vanessa Jankowski Read "Women in CyberSecurity"






