It is second line and while there is close interaction with procurement for planning purposes, if the procurement function is truly first line, they should be independent.

Gene Fox
VP, Third-Party Risk Management Officer
-------------------------------------------
Important Message to our valued customers: Fraud, phishing and e-mail compromise are on the rise.
Never share sensitive personal information via unsecure email. Talk to your banker about our Secure Messaging Portal.
NOTICE TO RECIPIENTS: The information contained in and accompanying this communication may be confidential, subject to legal privilege, or otherwise protected from disclosure, and is intended solely for the use of the intended recipient(s). If you are not the intended recipient, you are hereby notified that the use, distribution, disclosure or reproduction of the message or attachments, as well as any reliance thereon, is prohibited. In such a case, please notify the sender by return e-mail immediately and erase all copies of the message and any attachments. This communication does not reflect an intention by the sender, Stellar Bank ("Stellar"), to conduct a transaction or make any agreement by electronic means. Unless a specific statement to the contrary is included herein, nothing contained within either this message or any attachment shall satisfy the requirements for a writing, and nothing contained herein shall constitute a contract or electronic signature under the Electronic Signatures in Global and National Commerce Act (ESIGN), any version of the Uniform Electronic Transactions Act (UETA), or any other statute governing electronic transactions. The recipient should check this e-mail and any attachments for the presence of viruses. We accept no liability for any loss or damage from the receipt or use of any e-mail transmission. We reserve the right to monitor all e-mail communications through our network.
We will never request that you provide personal or financial information via unsecured e-mail. Please report to us any suspicious e-mails you receive that request personal or financial information and claim to be from us.
Original Message:
Sent: 4/30/2024 5:32:00 AM
From: Lunathi Ntshalintshati
Subject: Reporting lines
Where should TPRM function report to within the three lines of defence? Struggling to effectively get traction for a newly formed Vendor risk management function as it reports to Procurement. Please advice on what is the best practice on the reporting lines.