Due Diligence and Ongoing Monitoring

 View Only
  • 1.  Low risk vendor oversight review frequency

    This message was posted by a user wishing to remain anonymous
    Posted 02-20-2023 08:18 AM
    This message was posted by a user wishing to remain anonymous

    If a vendor is considered low risk, is it industry standard / best practice to have the oversight task frequency at least every three years, or can the review period be longer (meaning 4 or 5 years)?  And does the frequency of oversight reviews need to be documented in your policy?  Or just in your procedures or program document?



  • 2.  RE: Low risk vendor oversight review frequency

    Posted 02-21-2023 10:10 AM

    We have no impact vendors being reviewed once every 5 years. The frequency of oversight reviews is documented in our policy.



    ------------------------------
    Mark Ewert, CPCU, CIC
    Director Vendor Management
    Penn National Insurance
    ------------------------------