Hello Darren,
Regarding intercompany ongoing monitoring, you may have an opportunity to engage the third line of defense (Audit department) and monitor any audit findings owned by the affiliated companies that have an impact on your operation. I had monitored for finding level (high, medium, did very little with low's), time to resolve, impact on my intercompany area of responsibility, associated category such as IT or Compliance, and whether findings exceeded their estimated completion dates.
Considering getting SOC reports from affiliates for example was a challenge, continuous monitoring of findings by the independent third line was helpful. Also, depending how extensive you would want to go, certain critical services provided by the affiliate may benefit from documented service level agreements, with someone assigned to monitoring SLAs/KP and KRIs).
Good luck
Original Message:
Sent: 05-31-2024 12:04 PM
From: Mike Esqueda
Subject: Intercompany/2nd Party/Affiliated Service Provider Monitoring Programs & Exit Planning
Hello Darren,
We will be going down a similar route starting in 2025 and would love to connect to connect to share lessons learned!