I'm looking for perspectives from others in the third-party risk management space regarding a potential enhancement to our Engagement Risk Assessment (ERA). Today, our assessment considers factors such as the sensitivity and type of data involved ...
We absolutely consider VISA/Mastercard a high-risk vendor. They are a high risk vendor because they are providing services considered "mission critical" to the our credit union's daily operations; involved with the storage and/or transmission ...
This message was posted by a user wishing to remain anonymous Yes, we consider Visa a vendor/third-party relationship. We do have them classified as an exempt vendor, which is approved by Steering Committee annually. Exempt vendors are typically ...
This message was posted by a user wishing to remain anonymous We also consider Visa and Mastercard to be vendors that must go through recertification annually. It's like pulling teeth to get the documents our SMEs need to do their risk assessments, ...
We consider Visa a vendor. We collect approx. 20 - 25 documents from them to include: SOCs, BCP, Recovery Exercise Report or latest Recovery Exercise Report , Most Recent Visa PCI Attestation of Compliance, Latest Visa Global Key Controls ...
This Week's Power Users
Join a community dedicated to an area of third-party risk including contracts, infosec, risk assessments, policies, and more.
Gain TPRM knowledge fast. Read through these latest blog articles.
Meet, connect, and network with other users using the same third-party risk tool as you - get support and share new ideas and best practices.
Download the latest guides, infographics, samples, whitepapers, checklists, and more that can help guide you through best practices on third party risk. Visit Resources
Register and join live webinars to learn current trends and best practices from knowledgeable experts.Register Now