Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Incorporating Data Volume into Third-Party Risk Assessments

    Posted 21 days ago

    I'm looking for perspectives from others in the third-party risk management space regarding a potential enhancement to our Engagement Risk Assessment (ERA).

    Today, our assessment considers factors such as the sensitivity and type of data involved in a third-party engagement. However, we do not currently capture the overall volume of organizational data that may be shared with or accessible to a vendor, consultant, contractor, auditor, or service provider.

    One challenge is that not all third-party engagements involve an application. While our Application Risk Assessment (ARA) captures application-related transaction volumes, many third parties can still have access to significant amounts of data without triggering an ARA. As a result, we may not have a consistent way to evaluate the scale of data exposure associated with certain engagements.

    Additionally, the volume of data shared with a third party has occasionally been considered when evaluating or adjusting vendor risk ratings. We're exploring whether this factor should be incorporated more formally into our assessment methodology.

    One option under consideration is a question such as:

    On a scale of 1-10, how would you rate the overall volume of organizational data that will be shared with or accessible to the third party?

    1-2 (Low): Minimal volume of data; limited records or non-sensitive information.

    3-4 (Medium-Low): Access to a small subset of customer, employee, or business data.

    5-6 (Medium): Access to a moderate volume of data supporting a specific business process or department.

    7-8 (Medium-High): Access to a substantial volume of customer, employee, financial, or confidential business information.

    9-10 (High): Access to large-scale datasets, enterprise-wide information, or significant amounts of sensitive or regulated data.

    Before moving forward, I'd appreciate feedback from the community:

    1. Do you currently evaluate data volume as part of your vendor or third-party risk assessments?
    2. If so, how do you define or measure "data volume" in a way that minimizes subjective interpretation?
    3. Have you found data volume to be a meaningful risk indicator when determining inherent risk or risk tiering?
    4. Are there industry practices, frameworks, or examples you've seen that effectively assess third-party data volume or exposure?
    5. Would you use a subjective scale like the example above, or have you found a more objective approach to be effective?

    Any insights, lessons learned, or examples would be greatly appreciated as we evaluate whether and how to incorporate this concept into our ERA process.




  • 2.  RE: Incorporating Data Volume into Third-Party Risk Assessments

    This message was posted by a user wishing to remain anonymous
    Posted 5 days ago
    This message was posted by a user wishing to remain anonymous

    Our third-party risk assessments incorporate data 'type' when assessing the overall risks.  Taking into account the industry I work in, data groups were developed, e.g. Group 1 (Low): name, address, email, etc. Group 2 (Moderate): birthdate, license plate, etc. Group 3 (High) : Signature, Driver's license #, etc. Group 4 (Critical): SSN, Biometrics, Precise Geo, etc.   You develop your groups dependent upon your company's risk tolerance. Access to the company's environment automatically defaults to critical; however, the residual risk can be reduced dependent upon the company's risk tolerance and the controls which are put into place.  For example, if the access is limited to SFTP and the data to Group 1, then the residual risk (for this portion of the assessment) would be reduced to Low.  There are other risk areas which are not limited to data and/or systems which could result in a critical risk score; it is all dependent upon the scope of the assessment, research & discovery, and the company's risk tolerance.  In past employment, I have had residual critical risk scores due to discovery resulting in the company doing business with a defunct company (the vendor having failed to report its' demise to its' client), from a vendor that had a judgment entered upon a class action law suit that could impact a client's reputation, discovery of source code with a company located in the PRC, a company under a government investigation, and more. Most had nothing to do with IT and everything to do with security and reputation, and all findings were found critical and resulted in termination of the relationship.  So, while volume may play a role in determining risk appetite, the type of data is more relevant as it only takes one major infraction incident which could result in a multi-million dollar penalty.