I'm looking for perspectives from others in the third-party risk management space regarding a potential enhancement to our Engagement Risk Assessment (ERA).
Today, our assessment considers factors such as the sensitivity and type of data involved in a third-party engagement. However, we do not currently capture the overall volume of organizational data that may be shared with or accessible to a vendor, consultant, contractor, auditor, or service provider.
One challenge is that not all third-party engagements involve an application. While our Application Risk Assessment (ARA) captures application-related transaction volumes, many third parties can still have access to significant amounts of data without triggering an ARA. As a result, we may not have a consistent way to evaluate the scale of data exposure associated with certain engagements.
Additionally, the volume of data shared with a third party has occasionally been considered when evaluating or adjusting vendor risk ratings. We're exploring whether this factor should be incorporated more formally into our assessment methodology.
One option under consideration is a question such as:
On a scale of 1-10, how would you rate the overall volume of organizational data that will be shared with or accessible to the third party?
1-2 (Low): Minimal volume of data; limited records or non-sensitive information.
3-4 (Medium-Low): Access to a small subset of customer, employee, or business data.
5-6 (Medium): Access to a moderate volume of data supporting a specific business process or department.
7-8 (Medium-High): Access to a substantial volume of customer, employee, financial, or confidential business information.
9-10 (High): Access to large-scale datasets, enterprise-wide information, or significant amounts of sensitive or regulated data.
Before moving forward, I'd appreciate feedback from the community:
- Do you currently evaluate data volume as part of your vendor or third-party risk assessments?
- If so, how do you define or measure "data volume" in a way that minimizes subjective interpretation?
- Have you found data volume to be a meaningful risk indicator when determining inherent risk or risk tiering?
- Are there industry practices, frameworks, or examples you've seen that effectively assess third-party data volume or exposure?
- Would you use a subjective scale like the example above, or have you found a more objective approach to be effective?
Any insights, lessons learned, or examples would be greatly appreciated as we evaluate whether and how to incorporate this concept into our ERA process.