Due Diligence and Ongoing Monitoring

 View Only
Expand all | Collapse all

Vendor Categories

  • 1.  Vendor Categories

    This message was posted by a user wishing to remain anonymous
    Posted 03-07-2022 01:34 PM
    This message was posted by a user wishing to remain anonymous

    Hello!

    I'm looking to connect with someone who oversees procurement or vendor management of a financial institution. I have quite a few questions as I'm in a new growth position within the program I have built and I would love to chat about it with an equivalent in this position.


  • 2.  RE: Vendor Categories

    Posted 05-17-2022 01:50 PM
    perhaps I can help? Were a small bank in New York.


  • 3.  RE: Vendor Categories

    Posted 05-18-2022 09:00 AM
    Hi Monique,
    My name is Wes Carrington and I oversee the TPRM-VM Program at my large/regional, multi-state community and savings bank.
    I would greatly appreciate the opportunity to collaborate with you and others, if you/they are indeed in the same position. 
    Looking forward to hearing from you and receiving your feedback.
    Thank You,

    W.B. Carrington, MBA, CCIPS, CERP, GRCA, GRCP
    Director of Risk Management







  • 4.  RE: Vendor Categories

    Posted 05-19-2022 02:29 PM
    Hi,

    Not sure if you have found your answers yet, but I oversee the VM program for a 2.5B bank here in Alaska.  I have developed what I believe is a decent program that passes muster with Auditors and Examiners alike.  Feel free to call me to discuss.  

    Doug


  • 5.  RE: Vendor Categories

    Posted 08-18-2022 11:22 AM
    Were you able to get good answers from this source? I'm in a similar position.


  • 6.  RE: Vendor Categories

    Posted 08-18-2022 12:43 PM

    I might can help. Let me know your contact info.  I started a few procurement and vm programs from scratch.

     

     

    ROB PIOLI

    SVP Procurement

    Pacific Western Bank

     








  • 7.  RE: Vendor Categories

    Posted 08-19-2022 09:36 AM
    Good morning,

    I am interest in collaborating with others as well. 

    Isabella Dorsey, CRVPM
    QA and Risk Specialist
    SAFE FCU


  • 8.  RE: Vendor Categories

    Posted 08-19-2022 10:23 AM
    Good morning - I would also like to collaborate. While we have a vendor management program and are using Venminder, we're working on restructuring it a bit. Would really like to understand what/how others are setting up their programs, as I'm in a newer position as well.


  • 9.  RE: Vendor Categories

    Posted 08-19-2022 10:27 AM
    Greetings

    I would also like to collaborate, as I am just beginning to research vendor management programs.


    ------------------------------
    Tammy Tessier Kealy
    ------------------------------



  • 10.  RE: Vendor Categories

    Posted 08-19-2022 11:09 AM

    I would love to collaborate on a vendor management program also. It became part of my role when I transitioned to ISO a few years ago, but I haven't had the time to devote to it yet. I also don't really know where to start.

     

     

    Morgan Cannizzo

    Information Security Officer

    The content of this email is confidential and intended for the recipient specified in message only. It is strictly forbidden to share any part of this message with any third party, without a written consent of the sender. If you received this message by mistake, please reply to this message and follow with its deletion, so that we can ensure such a mistake does not occur in the future.





  • 11.  RE: Vendor Categories

    Posted 08-19-2022 11:25 AM
    Yes, I would definitely love to collaborate as well as I'm also building out our VM program.


  • 12.  RE: Vendor Categories

    Posted 08-19-2022 01:08 PM
    I would be willing to host a 1-1.5hr meeting illustrating how I took a languishing spreadsheet VM program, and turned it into a program that has received accolades from regulators and external IT Auditors.  Prior to that, I had no VM or DD experience - and didn't even have FI experience.  I believe having no "bad habits" served me well by bringing in over 30 years of Risk Management experience into a different field.  Of course we are always looking to improve too, and we are constantly evolving. My program is far from perfect, but has passed muster many, many times.

    I will not harp on the past, but simply give an overview of how we do things now, starting with classification of vendors, Due Diligence for TSPs, followed by Vendor Management and how we use Venminder, assign rating, and conclude with how we conduct recurring Due Diligence (aka Management Review).  

    If interested, I am thinking 1 or 2 September.  We are based in Alaska so it would be convenient for all time zones if we start around 0800 AKST.  

    If interested, send me a new email (Subject Line: VM with NRIM) with preferred date and then I can send a meeting link.  [email removed by Community Manager for privacy reasons. Message the member directly for contact information.] If you have any quick questions - feel free to call [phone number removed by Community Manager for privacy reasons. Message the member directly for contact information].
    ------------------------------
    Douglas Frey
    SVP, Security & Risk Management
    Information Security Officer

    ------------------------------



  • 13.  RE: Vendor Categories

    Posted 08-19-2022 01:16 PM
    I would love to partake in this as well. Douglas I will send you an email and my contact info if you are arranging this! 

    [Email removed by Community Manager for privacy reasons. Message the member directly to request contact information.]

    ------------------------------
    Kayla Davis, CRVPM II
    Vendor Relations Analyst II

    ------------------------------



  • 14.  RE: Vendor Categories

    Posted 08-22-2022 08:24 AM
    Please count me in: [Email removed by Community Manager for privacy reasons. Message the member directly for their contact information.] -------------------------------------------
    Original Message:
    Sent: 08-19-2022 11:39 AM
    From: Douglas Frey
    Subject: Vendor Categories

    I would be willing to host a 1-1.5hr meeting illustrating how I took a languishing spreadsheet VM program, and turned it into a program that has received accolades from regulators and external IT Auditors.  Prior to that, I had no VM or DD experience - and didn't even have FI experience.  I believe having no "bad habits" served me well by bringing in over 30 years of Risk Management experience into a different field.  Of course we are always looking to improve too, and we are constantly evolving. My program is far from perfect, but has passed muster many, many times.

    I will not harp on the past, but simply give an overview of how we do things now, starting with classification of vendors, Due Diligence for TSPs, followed by Vendor Management and how we use Venminder, assign rating, and conclude with how we conduct recurring Due Diligence (aka Management Review).  

    If interested, I am thinking 1 or 2 September.  We are based in Alaska so it would be convenient for all time zones if we start around 0800 AKST.  

    If interested, send me a new email (Subject Line: VM with NRIM) with preferred date and then I can send a meeting link.  [email removed by Community Manager for privacy reasons. Message the member directly for contact information.] If you have any quick questions - feel free to call [phone number removed by Community Manager for privacy reasons. Message the member directly for contact information].
    ------------------------------
    Douglas Frey
    SVP, Security & Risk Management
    Information Security Officer




  • 15.  RE: Vendor Categories

    Posted 08-22-2022 08:47 AM

    Hello Douglas – I would like to join your session on setting up a successful VM Program.  Excited to learn from an ISO's perspective.

     

    Please count me in, and I am open to either 9/1 or 9/2 and 0800 AKST is perfect as I am on the East Coast.

     

    Thank you for offering to hold this!

     

    Best,

    Charlotte

     

    Charlotte Campbell-Pennella

     

    Contract Administrator - IT VMO

     






  • 16.  RE: Vendor Categories

    Posted 08-22-2022 08:51 AM
    Hi Douglas, 

    I would certainly like to know more about your journey. I am only available on 9/1. 

    Thanks, 
    Matt


  • 17.  RE: Vendor Categories

    Posted 08-22-2022 08:52 AM
    9/1 works for me as well.  Thank you.


  • 18.  RE: Vendor Categories

    Posted 08-22-2022 09:21 AM

    You can count me in.

     

    Trellis Company

    Marvin Rubio

    Quality Analyst

     


     

     

     

     






  • 19.  RE: Vendor Categories

    Posted 08-22-2022 08:54 AM
    Hello Douglas,

    I would like to join your session.  Either day works for me and 8:00 AKSt worksas well.
    Thank you for organizing!

    Barbara Martindell
    AVP / Network Administrator


  • 20.  RE: Vendor Categories

    Posted 08-22-2022 08:58 AM

    Hello Douglas

    I would also like to join the session and collaborate with others, thank you for organising. 



    ------------------------------
    Pav Chahall
    Supplier Risk Management
    Director
    ------------------------------



  • 21.  RE: Vendor Categories

    Posted 08-22-2022 09:18 AM
    I would be interested in this too.  

    Thanks,

    David Pittman | Information Technology Security Architect






  • 22.  RE: Vendor Categories

    Posted 08-22-2022 09:09 AM
    I am very interested in joining this discussion. Sept. 1st works best for me, but I can also make Sept. 2nd work as well.

    Thank you!

    ------------------------------
    Wendy Dickson
    Third Party Risk Manager
    ------------------------------



  • 23.  RE: Vendor Categories

    Posted 08-22-2022 09:21 AM
    Good Morning, 

    I am interested in joining in the discussion, either the 1st or 2ne will work for me. 

    Thanks you!

    Rosanne Hernandez


  • 24.  RE: Vendor Categories

    Posted 08-22-2022 10:38 AM

    Hi,  please send your request to douglas.frey @ nrim.com from your email client.  ThirdPartyThinkTank is anonymizing emails and stripping addresses.

    Doug

     

    Douglas Frey | SVP, Security & Risk Management

    Information Security Officer
    Northrim Bank | Achieve More
    t: 907-341-6340 | m: 907-205-8188
    www.northrim.com

     

    This email and any attachments are intended solely for the individual or entity to whom they are addressed.  If you have received this message in error, please notify us by sending a reply email to the sender and delete this message and any attachments.  Unauthorized use of the information in this email may be a violation of the law.





  • 25.  RE: Vendor Categories

    Posted 08-22-2022 09:28 AM
    Good Morning,

    I would like to know more about your journey.  I am new to all this.  I am available September 1st.


  • 26.  RE: Vendor Categories

    Posted 08-22-2022 09:41 AM
    I am new to VM, so I would be interested in this discussion. 
    Thanks!


  • 27.  RE: Vendor Categories

    Posted 08-22-2022 09:41 AM
    Interested as well. Sent email with info, as requested.  - Pam

    ------------------------------
    Pam Rackley
    Risk Analyst
    ------------------------------



  • 28.  RE: Vendor Categories

    Posted 08-22-2022 12:19 PM

    Hi,  please send your request to douglas.frey @ nrim.com from your email client.  ThirdPartyThinkTank is anonymizing emails and stripping addresses.

    Doug

     

    Douglas Frey | SVP, Security & Risk Management

    Information Security Officer
    Northrim Bank | Achieve More
    t: 907-341-6340 | m: 907-205-8188
    www.northrim.com

     

    This email and any attachments are intended solely for the individual or entity to whom they are addressed.  If you have received this message in error, please notify us by sending a reply email to the sender and delete this message and any attachments.  Unauthorized use of the information in this email may be a violation of the law.





  • 29.  RE: Vendor Categories

    Posted 08-22-2022 09:46 AM
    I sent a message with my information to join as well. Thank you.


  • 30.  RE: Vendor Categories

    Posted 08-22-2022 09:20 AM

    Hello Douglas,

     

    I would like to participate as well and am available either day.

     

    Thank you for organizing!

    LaDonna

     






  • 31.  RE: Vendor Categories

    Posted 08-22-2022 10:21 AM
    Hello
    I am also interested in participating

    --
    Toni Peinado| VP Compliance
    Key Mortgage Services Inc.




  • 32.  RE: Vendor Categories

    Posted 08-22-2022 09:26 AM
    I am interested in participating in this discussion, also.


  • 33.  RE: Vendor Categories

    Posted 08-22-2022 09:56 AM

    Hello Douglas,

                    I would be interested in attending this meeting/presentation.

     

    Thank you

    Weston Roberts

     

     

     






    The information transmitted is intended only for the person or entity to which it is addressed and may contain confidential or privileged material. Any review, distribution, or other unauthorized use of the information by persons or entities other than the intended recipient is prohibited. If you received this communication in error, please contact the sender and delete the material from any computer.


    *** Arvest Confidential ***





  • 34.  RE: Vendor Categories

    Posted 08-22-2022 09:51 AM

    I would like to join.  Either day works for me.

     

    Thanks

    Alice

     

     

    Alice Dubbs
    Risk Management Specialist
    Banking Done Your Way

     

    I would be willing to host a 1-1.5hr meeting illustrating how I took a languishing spreadsheet VM program, and turned it into a program that has... -posted to the "Due Diligence and Ongoing Monitoring" community

    Community dedicated to third party risk professionals.


    Image removed by sender. Third Party ThinkTank

    Due Diligence and Ongoing Monitoring

     

    Re: Vendor Categories

    Image removed by sender. Douglas Frey

    Aug 19, 2022 1:08 PM

    Douglas Frey

    I would be willing to host a 1-1.5hr meeting illustrating how I took a languishing spreadsheet VM program, and turned it into a program that has received accolades from regulators and external IT Auditors.  Prior to that, I had no VM or DD experience - and didn't even have FI experience.  I believe having no "bad habits" served me well by bringing in over 30 years of Risk Management experience into a different field.  Of course we are always looking to improve too, and we are constantly evolving. My program is far from perfect, but has passed muster many, many times.

    I will not harp on the past, but simply give an overview of how we do things now, starting with classification of vendors, Due Diligence for TSPs, followed by Vendor Management and how we use Venminder, assign rating, and conclude with how we conduct recurring Due Diligence (aka Management Review).  

    If interested, I am thinking 1 or 2 September.  We are based in Alaska so it would be convenient for all time zones if we start around 0800 AKST.  

    If interested, send me a new email (Subject Line: VM with NRIM) with preferred date and then I can send a meeting link.  douglas.frey@nrim.com  If you have any quick questions - feel free to call @ 907-341-6340.  

    ------------------------------
    Douglas Frey
    SVP, Security & Risk Management
    Information Security Officer
    907-341-6340
    ------------------------------

    I might can help. Let me know your contact info.  I started a few procurement and vm programs from scratch.

     

     

    ROB PIOLI

    SVP Procurement

    Pacific Western Bank

     

     


    Sending an unencrypted email is not a secure method of transmitting confidential information. If you intend to transmit confidential information to us, please visit our website: https://www.pacwest.com and click on the "Contact Us" link on the top right side of our Home Page. Then using the "Send Secure Email" feature, Secure Mail will encrypt any emails addressed to Pacific Western Bank personnel. Note: This message contains information which may be confidential and/or privileged. If you received this email by mistake, please notify the sender of the error by return email and delete this message.




    Original Message:
    Sent: 8/18/2022 11:22:00 AM
    From: Jay Shue
    Subject: RE: Vendor Categories

    Were you able to get good answers from this source? I'm in a similar position.
    Original Message:
    Sent: 03-07-2022 01:01 PM
    From: Anonymous Member
    Subject: Vendor Categories

    This message was posted by a user wishing to remain anonymous

    Hello!

    I'm looking to connect with someone who oversees procurement or vendor management of a financial institution. I have quite a few questions as I'm in a new growth position within the program I have built and I would love to chat about it with an equivalent in this position.

      View Thread   Like   Forward   Flag as Inappropriate  



     

     

    You are subscribed to "Due Diligence and Ongoing Monitoring" as alice.dubbs@f-mtrust.com. To change your subscriptions, go to My Subscriptions. To unsubscribe from this community discussion, go to Unsubscribe.

    Image removed by sender.




    Original Message:
    Sent: 8/19/2022 11:40:00 AM
    From: Douglas Frey
    Subject: RE: Vendor Categories

    I would be willing to host a 1-1.5hr meeting illustrating how I took a languishing spreadsheet VM program, and turned it into a program that has received accolades from regulators and external IT Auditors.  Prior to that, I had no VM or DD experience - and didn't even have FI experience.  I believe having no "bad habits" served me well by bringing in over 30 years of Risk Management experience into a different field.  Of course we are always looking to improve too, and we are constantly evolving. My program is far from perfect, but has passed muster many, many times.

    I will not harp on the past, but simply give an overview of how we do things now, starting with classification of vendors, Due Diligence for TSPs, followed by Vendor Management and how we use Venminder, assign rating, and conclude with how we conduct recurring Due Diligence (aka Management Review).  

    If interested, I am thinking 1 or 2 September.  We are based in Alaska so it would be convenient for all time zones if we start around 0800 AKST.  

    If interested, send me a new email (Subject Line: VM with NRIM) with preferred date and then I can send a meeting link.  [email removed by Community Manager for privacy reasons. Message the member directly for contact information.] If you have any quick questions - feel free to call [phone number removed by Community Manager for privacy reasons. Message the member directly for contact information].
    ------------------------------
    Douglas Frey
    SVP, Security & Risk Management
    Information Security Officer

    ------------------------------

    Original Message:
    Sent: 08-19-2022 09:51 AM
    From: Colleen Byrne
    Subject: Vendor Categories

    Good morning - I would also like to collaborate. While we have a vendor management program and are using Venminder, we're working on restructuring it a bit. Would really like to understand what/how others are setting up their programs, as I'm in a newer position as well.
    Original Message:
    Sent: 08-19-2022 09:35 AM
    From: Isabella Dorsey
    Subject: Vendor Categories

    Good morning,

    I am interest in collaborating with others as well. 

    Isabella Dorsey, CRVPM
    QA and Risk Specialist
    SAFE FCU
    Original Message:
    Sent: 08-18-2022 11:25 AM
    From: Robert Pioli
    Subject: Vendor Categories

    I might can help. Let me know your contact info.  I started a few procurement and vm programs from scratch.

     

     

    ROB PIOLI

    SVP Procurement

    Pacific Western Bank

     



    Sending an unencrypted email is not a secure method of transmitting confidential information. If you intend to transmit confidential information to us, please visit our website: https://www.pacwest.com and click on the "Contact Us" link on the top right side of our Home Page. Then using the "Send Secure Email" feature, Secure Mail will encrypt any emails addressed to Pacific Western Bank personnel. Note: This message contains information which may be confidential and/or privileged. If you received this email by mistake, please notify the sender of the error by return email and delete this message.




    Original Message:
    Sent: 8/18/2022 11:22:00 AM
    From: Jay Shue
    Subject: RE: Vendor Categories

    Were you able to get good answers from this source? I'm in a similar position.
    Original Message:
    Sent: 03-07-2022 01:01 PM
    From: Anonymous Member
    Subject: Vendor Categories

    This message was posted by a user wishing to remain anonymous

    Hello!

    I'm looking to connect with someone who oversees procurement or vendor management of a financial institution. I have quite a few questions as I'm in a new growth position within the program I have built and I would love to chat about it with an equivalent in this position.


  • 35.  RE: Vendor Categories

    Posted 08-22-2022 10:08 AM
    Hello, 

    I am also interested in attending this event, could you please send me invite to [Email removed by Community Manager for privacy reasons. Message the member directly for their contact information.]

    Regards
    Sonali P


  • 36.  RE: Vendor Categories

    Posted 08-22-2022 10:16 AM
    Hi Doug,
    Thank you.  I work definitely be interested.  I inherited a VM program including SOC 2 Type II reviews, etc. that I translate into a 9 page cybersecurity questionnaire which covers what we need. We update the CSQ before sending out based on inspected controls, any findings from the Service Auditor, etc.  Over time, I have realized service auditors are inconsistent (since AICPA doesn't have requirements for the report format) and sometimes the common criterial is not the same report to report. So I then compensate for that bringing it into a review template, etc.  I would like to learn from you to move towards a more meaningful way to track, etc.

    Larry Timmins



  • 37.  RE: Vendor Categories

    Posted 08-22-2022 10:23 AM

    I would like to participate as well and am available either day.

     

    Thank you for organizing!

     

     

    Cecilia Bastady, CRVPM II

    Vice President, Vendor Risk Officer

    Lakeland Bank






  • 38.  RE: Vendor Categories

    Posted 08-22-2022 10:27 AM

    Thanks Doug – obviously you have peaked the interest from a "cast of thousands". To keep all our inboxes from continuing to blow up, perhaps we can finalize a date/time to meet? 😉

    Thanks,
    Mike



    ------------------------------
    Michael Magone Director of Technology Services
    Stockman Bank
    ------------------------------



  • 39.  RE: Vendor Categories

    Posted 09-06-2022 12:46 PM
      |   view attached
    You may find the slides from the briefing in the Library titled Vendor Management with Northrim (or attached here).  Thanks for attending, and I hope the briefing helps you make your program even better.

    ------------------------------
    Douglas Frey
    SVP, Security & Risk Management
    Information Security Officer
    ------------------------------

    Attachment(s)



  • 40.  RE: Vendor Categories

    Posted 09-06-2022 03:55 PM
    Hi Doug and Tze,
    I wanted to thank you both for conducting the presentation on Sept 1st, repeated on 2nd, and found your insights and answers to questions very helpful using your model of non-technical and technical service providers. 

    Have a great day!
    Larry


  • 41.  RE: Vendor Categories

    Posted 09-07-2022 08:17 AM

    Doug and Tze – I really appreciate you taking the time out of your days to run through this with us!  It was a very good presentation, well informed and I especially liked the Q&A at the end!  So awesome to throw things back and forth with people who have similar responsibilities.

     

    Many Thanks!!

     

    Charlotte Campbell-Pennella

     

    Contract Administrator - IT VMO




  • 42.  RE: Vendor Categories

    Posted 08-19-2022 10:28 AM

    I agree, it would be good to have some collaboration on vm.  I took over an IT Director role at an FI a few years ago and have been struggling with the vm program ever since (it's an unpleasant part of my role).  It was all done with spreadsheets and Word docs previously, which unfortunately, the previous Director took all knowledge of when he left.  I purchased Venminder for the bank in 2019 but haven't got to where vm is a solid program.

     

    I've viewed lots of webinars, read online, but just don't have the time to really focus on it with all the other roles I have (IT support at times, network engineer, business continuity/DR coordinator, project manager, etc.).  What I really need is to just get a template program/policy/process and plug in our vendors.

     

    Thanks,
    David

     

    DAVID EKSTROM
    Vice President / IT Director

     






  • 43.  RE: Vendor Categories

    Posted 08-19-2022 11:42 AM
    Someone posted "Third Party Risk Association | TPRA | www.tprassociation.org"as an already established place to collaborate. The free version offers this benefit: "MEMBER MEETINGS: Interactive monthly calls to discuss a variety of third party risk topics decided upon by members."  Might be good, nothing against that. I wouldn't mind participating in a grass roots movement like we maybe have going on here. Someone want to be the organizer? I am procurement more than vendor so I defer.


  • 44.  RE: Vendor Categories

    Posted 08-19-2022 11:52 AM
    Hi Everyone,

    Just catching up on posts and I too like the idea of meeting.  I am a 1 person shop and want to make enhancements to our current VM program.  So would appreciate learning what others are doing.

    Have a great weekend.

    Karen

    ------------------------------
    Karen Waterman, CFSA, NCCO, NCRM, CUERME
    Enterprise Risk Director
    Nusenda Credit Union
    ------------------------------



  • 45.  RE: Vendor Categories

    Posted 08-19-2022 11:56 AM
    Hi all,

    I would be very interested to hear what everyone is doing.  I'm a junior analyst on our security team and we're looking to build out our program.  I'm also very green to TPRM so this would be great for me to learn.


  • 46.  RE: Vendor Categories

    Posted 08-19-2022 12:15 PM
    Hi Karen,
    There was a NY DFS presentation aimed at small businesses who still needed a security program and third party vendor management even though they also qualified for exemption from parts of their cybersecurity regulations (NY DFS 23 NYCRR Part 500).

    The May 2022 presentation may be worth a viewing:  https://www.dfs.ny.gov/event/dfs-cybersecurity-symposium-spotlight-small-business

    Specifically, you may find the Global Cyber Alliance segment by Renee N. McLaughlin called "Free Cybersecurity Tools for Small Businesses: Cybersecurity Toolkit".

    The list of resources provided:  https://www.dfs.ny.gov/system/files/documents/2022/06/DFS_GCA_Resources_for_Small_Businesses.pdf
    The training scenario slides:    https://www.dfs.ny.gov/system/files/documents/2022/05/DFS_Training_Scenario_Slides.pdf

    I hope this helps.  Larry


  • 47.  RE: Vendor Categories

    Posted 08-19-2022 01:11 PM
    I support this suggestion for member meetings as it would be very helpful.


  • 48.  RE: Vendor Categories

    Posted 08-19-2022 11:28 AM
    I would also be interested in collaborating on this as I've been working to rebuild our TPRM program.


  • 49.  RE: Vendor Categories

    Posted 08-19-2022 11:32 AM
    There is a group established for TPRM collaboration.  Third Party Risk Association | TPRA | www.tprassociation.org


  • 50.  RE: Vendor Categories

    Posted 08-19-2022 02:59 PM
    Thanks for sharing the TPRA link. My only concern with that Association is the focus appears to be InfoSec Centric. Not an uncommon area of interest in the industry. And as is common, Cyber and InfoSec topics get management attention and thereby are often well funded. 

    That said, in the Banking space the complexities of TPRM are further reaching. The Regulatory definition of Third Party is so broad, that TPRM programs need to consider more than just "procurement" principles. The trouble I've noticed is where in the Org your program sits... 

    If you're under IT, the CIO is more often than not only interested in getting the widgets they need in IT... and will be prone to Accept Risk... You'll get the... "just write up the Acceptable Risk Memo and I'll sign it."  SMH I've experienced that more than once... 

    If you're under the CFO, you'll have the pressure of saving money as the priority and get questions about "why are you so focused on engagements that aren't suppliers?" Even if you explain the role is to manage risk... the CFO will say, "yes. the risk is financial; you need to save me money." 

    If you're under the CRO, you'll be working upstream trying to explain that TPRM is more than just Operational Risk... however, there will be focus on making the vendors "perform" better. You suddenly shift from a second line role to a first line responder and then the business units shovel all things "vendor" on you... and now you're a part of every audit as the business says "I don't do that, that's TPRM/VRMOs responsibility" and then I/A is knocking on your door.

    The real challenge TPRM needs to sit in the Org similar to I/A; not as a Third Line, but in the Org reporting to a Board Risk Committee; just as I/A reports to a Board Risk Committee to maintain independence from Management. 

    That or be part of Legal... but it's not a good fit, however, it moves roadblocks. :-) I've two instances where being in the "Legal" department made the job a bit easier... because it appeared that "Legal" said, we need to do xyz... and everyone on the Org differs to Legal as a superior group of Subject Matter Experts. :-) 

    And while we have tools like Venminder; it's simply a tool that we use to organize and report what our Process is and does. We use it for workflows; but it's still very limited in providing the "full" solution to an overall TPRM/VRM program. 

    To make it even more complicated, we have Supplier Diversity and ESG programs we need to include in our programs... 
    We have the battle of being the perceived "road block" to getting the project moving... 
    We all run into the "but we don't have time to do all this stuff; we just need to sign the Contract..."  
    And if you have an established Procurement program, you're likely not seeing vendors or contracts that you should be reviewing... and even if you have some visibility the scope creep that occurs often changes the Risk without a new risk assessment being performed. This often is met with the "but they're already an approved vendor; why do I need to do another risk assessment." 

    I've been doing this for a while and have a laundry list of horror stories; and I'm sure we all could share. 

    Maybe we need to collaborate in a Group Therapy session... We're all living in the same pain. :-)

    ------------------------------
    Bradley Martin
    ------------------------------



  • 51.  RE: Vendor Categories

    Posted 08-19-2022 01:08 PM
    I would love to collaborate. Who's setting it up? I have built the vendor management program for my company and I love collaborating, sharing, and learning from others as well!


    ------------------------------
    Sheila Freyou

    Director, Vendor Management
    Celebrity Home Loans, LLC
    ------------------------------



  • 52.  RE: Vendor Categories

    Posted 08-19-2022 01:14 PM

    I would like to collaborate as well.

     

    Best,

    Kimberly

     

    Kimberly D. Sambuchi, CRVPM II

    First Vice President

    Risk Management

    mutualone-signature

     

    NOTICE: Under no circumstances should non-public customer information (NPCI) be transmitted via unsecured email. For your protection and that of our customer, please do not include account numbers, social security numbers, passwords or any other NPCI in email messages sent to the MutualOne Bank. This message is from the MutualOne Bank and may be private and confidential and is for the intended recipient only. If the reader of this message, regardless of the address or routing, is not an intended recipient, you are hereby notified that you have received this transmittal in error and any review or use is strictly prohibited. If you have received this message in error, please delete this email and all files transmitted with it from your system and immediately notify MutualOne Bank by sending a reply e-mail to the sender of this message. Thank you.

     






  • 53.  RE: Vendor Categories

    Posted 08-19-2022 02:52 PM
    I would love to collaborate as well.


  • 54.  RE: Vendor Categories

    Posted 08-19-2022 02:55 PM
    I would like to collaberate.


  • 55.  RE: Vendor Categories

    Posted 08-19-2022 04:48 PM
    I would like to collaborate as well.. I have been doing VMO type work for several years and were experiencing some "growing pains" with org change and the current economical landscape and would be very interested in what others are doing, have done, etc. Maybe we can set up a series of meeting times with topics to swap stories?  Happy to set up a meeting link or working group thread via email if others are interested.


  • 56.  RE: Vendor Categories

    Posted 08-22-2022 08:22 AM

    I would like to be included as well.  Just began working on Vendor Review in the last few months and trying to grasp the whole concept.

     

    Jutta Codori | Senior Administrative Officer, SVP

    CATALYST BANK




  • 57.  RE: Vendor Categories

    Posted 08-22-2022 11:20 AM
    Please include me as well. I'm a newbie to VRM. Thanks.


  • 58.  RE: Vendor Categories

    Posted 08-22-2022 12:01 PM
    Hi Everyone, 

    I hope you all are having a wonderful day and it's great to see so much interest in this discussion! I just want to send a quick reminder that Douglas Frey shared he'll organize the discussion and has asked that you email him directly to communicate further as he coordinates the meeting.

    Thank you, 
    Brittany Padgett
    Community Manager