I'm often asked what sort of things a third party risk or compliance manager might be asked to have ready for an examination that's going to touch on third party risk management. Well, there's good news and there's bad news.
The good news is unless it's a targeted exam, it's probably not going to be specifically all about third party risk management which takes some weight off of you. The bad news is, on the flip side, since there's no template for specific documents, there's no easy way to know exactly what to expect or what to have available.
I recommend you start with the examiner's request list and look for any items, specifically or otherwise, that could involve third party risk management. Next, make sure you have those items ready to go. After you’ve thoroughly reviewed the request list, there are a few things I'd suggest you do routinely and have available in addition:
Finally, while I know we're all eager to impress examiners or hope to get things over with quickly, don't share items until asked. Once requested, supply the document quickly but take the time to review each item thoroughly, even getting a second set of eyes to look at it can help.
Also be sure to meet with the examiner to clarify any questions or even educate them, if needed, on ways in which your practices may have changed or may be different from what they are accustomed to reviewing. It’s always better to clarify items ahead of time rather than scrambling when the draft report is issued. In other words, don't just dump all of the documentation to the examiner.
Exams can be stressful, but if you're professional, well-organized and deliberate in your preparation, you've actually accomplished quite a lot before the exam even happens. For more tips on preparing for a third party risk management examination, download our eBook.