Managing third-party risks
Whenever an organization determines a service that needs to be outsourced, a risk practitioner should be involved in assisting the business in determining the right partners, as well as performing due diligence on the selected vendor. The typical process to determine the right partners and manage the third-party risk should go like this:
- The business process owner comes up with a use case for outsourcing a service to a third party and has all the necessary approvals from relevant stakeholders.
- A request for proposal (RFP) or similar is published or key players in the space are reached out to so that they can assess the availability and alignment of the requirements of the organization.
- Of all the vendors, a selected few are moved to the next stage so that they can demonstrate how their capabilities are aligned with the requirements of the organization, any niche features that are not available with other vendors, and budget considerations...