Risk Assessments

 View Only
  • 1.  Risk Register

    Posted 01-10-2020 11:40 AM
    Does anyone actively log all identified risk pertaining to third parties into a Risk Register(i.e. Compliance Risk, Reputation, Privacy, InfoSec, Resiliency, Cloud Computing)?


  • 2.  RE: Risk Register

    Posted 01-10-2020 11:58 AM
    Not necessarily a "Risk Register", but we do track QOS in a Performance Log so that the Vendor Manager has it available during the next periodic review or contract renewal activity to assess whether to keep the vendor on board, or to require additional diligence on the vendor's part to correct any issues.


  • 3.  RE: Risk Register

    Posted 01-13-2020 08:43 AM
    I am new to Venminder... would you mind sharing how you go about tracking the QOS then?  Did you start with a questionnaire, or merely placing a 'document' under that Vendor that you are keeping outside of Venminder?


  • 4.  RE: Risk Register

    Posted 01-15-2020 09:25 AM
    Sheila,

    I hope I'm not too late to the party to share a thought. I have a couple recommendations for monitoring and tracking QOS.

    First, I recommend you build a QOS Questionnaire within your Venminder system. This will allow you to gather the information needed to score this directly from your vendor. As an accompaniment, build a QOS Risk Assessment to use as an input for your Questionnaire responses. Once risk scores are assigned within Venminder, you'll have an array of reporting options to capture this risk.

    My second recommendation removes a step, thereby simplifying the process and making your QOS tracking one-stop. At the end of the month we'll be introducing an upgrade feature for Advanced Questionnaires. This new feature allows you to assign scoring to your Questionnaires. You can build a QOS Questionnaire, send it directly to your vendor, and their direct responses will generate a risk score which can be tracked and managed within the system.

    Please let me know if you have any questions about and of the ideas suggested above. I'd be happy to assist!


  • 5.  RE: Risk Register

    Posted 01-13-2020 08:49 AM
    Similar situation at my bank.  We track the various vendor risks within the Vendor Risk Program, then report monthly  on the risks.  The risks are also part of the vendor's profile, available to anyone; involved in new engagements with that vendor or  periodic vendor reviews.