2019 Third Party Risk
2019 Third Party Risk
2019 Third Party Risk
Stay
Ahead of
Growing
Third-
Party Risk
Edited by Chris Audet
Director, Gartner
Click here or press enter for the accessibility optimised version
Introduction
“There's no question that third parties are redefining how our business competes
in the new digital world,” said one chief compliance officer at a financial services
organization.
Today's third parties require more access to the organization's data assets and are
increasingly working with their own third parties, multiplying the size and
complexity of the third-party network. In fact, in the last four years, legal and
compliance leaders have classified 2.5X more third parties as high-risk.
Managing the risks associated with these networks while not hindering business
speed is a critical challenge for leaders.
Managing Third-Party Risk
A Cross-Functional Concern
The Current
Approach Is
Point-in-Time-
Focused
Traditionally, 73% of effort
devoted to risk identification is
allocated to due diligence and
recertification efforts, with only
27% of effort allocated to
identifying risks over the course
of the relationship.
Why Point-in-Time?
Mandates from regulators
and enforcement bodies
Expectations from
consumers and an activist
media
Cost implications
The point-in-time
approach often fails
because it misses
changes in third-
party relationships
The current monitoring
approach cannot account for
changes that are inevitable in
conducting business today —
those associated with strategy,
personnel, risk appetite or
scope of relationship.
Click here or press enter for the accessibility optimised version
An organization providing
telecommunications services faced two
distinct challenges. First, suppliers had an
uneven level of understanding of how to
tackle reputation risks posed by their
suppliers. Second, it was difficult to assess
the capability of data collected during
traditional ethical and environmental risk
audits.
Three Key Shifts for Legal and Compliance Leaders
An Iterative
Approach
Improves
Outcomes
An interative approach has a
positive impact on desired risk
management and business
outcomes.
Improved
Outcomes
Through this approach, leaders will see
improved outcomes, including the:
Learn more.
Dig deep.
Stay ahead.
Gartner for Legal & Compliance Leaders provides research
insights, advice, tools and data to address mission-critical
priorities and keep up with the accelerating pace of business
today.
On the web, visit:
gartner.com/en/legal-compliance