Software

Gain a 360-degree view of third-party risk by using our SaaS software to centralize, track, automate, assess and report on your vendors. 

Managed Services

Let us handle the manual labor of third-party risk management by collaborating with our experts to reduce the workload and mature your program. 

Overview
Document Collection
Policy/Program Template/Consulting
Virtual Vendor Management Office
Vendor Site Audit

Ongoing Monitoring

Let us handle the manual labor of third-party risk management by collaborating with our experts.

VX LP Sequence USE FOR CORPORATE SITE-thumb
Venminder Exchange

As Venminder completes assessments for clients on new vendors, they are then made available inside the Venminder Exchange for you to preview scores and purchase as you need.

CREATE FREE ACCOUNT

Use Cases

Learn more on how customers are using Venminder to transform their third-party risk management programs. 

Industries

Venminder is used by organizations of all sizes in all industries to mitigate vendor risk and streamline processes

Why Venminder

We focus on the needs of our customers by working closely and creating a collaborative partnership

1.7.2020-what-is-a-third-party-risk-assessment-FEATURED
Sample Vendor Risk Assessments

Venminder experts complete 30,000 vendor risk assessments annually. Download samples to see how outsourcing to Venminder can reduce your workload.

DOWNLOAD SAMPLES

Resources

Trends, best practices and insights to keep you current in your knowledge of third-party risk.

Webinars

Earn CPE credit and stay current on the latest best practices and trends in third-party risk management.  

See Upcoming Webinars

On-Demand Webinars

 

Community

Join a free community dedicated to third-party risk professionals where you can network with your peers. 

Weekly Newsletter

Receive the popular Third Party Thursday newsletter into your inbox every Thursday with the latest and greatest updates.

Subscribe

 

Venminder Samples

Download samples of Venminder's vendor risk assessments and see how we can help reduce the workload. 

resources-whitepaper-state-of-third-party-risk-management-2023
State of Third-Party Risk Management 2023!

Venminder's seventh annual whitepaper provides insight from a variety of surveyed individuals into how organizations manage third-party risk today.

DOWNLOAD NOW

Protecting Commercial Real Estate With Third-Party Business Continuity Planning

6 min read
Featured Image

Unforeseen natural disasters and unexpected events can wreak havoc on any business, but particularly for commercial real estate developers. Not only do developers need to worry about the physical building, but also the safety of occupants and operational continuity. To remain prepared, commercial real estate developers must establish a robust and comprehensive business continuity plan (BCP) and ensure their vendors have done the same.

Business continuity planning plays a vital role in safeguarding developers' interests, ensuring client satisfaction, and facilitating seamless business operations. But what happens if the business-disrupting event is with a critical service provider or third-party vendor? Developers must be able navigate disruptions and crises effectively, even when the supply chain is disrupted. 

Let’s cover the basics of business continuity planning and third-party risk management, how to integrate the two together, and key third parties to include. 

What Is Third-Party Risk Management?

Third-party risk management is a comprehensive approach to identifying, assessing, managing, and monitoring risks associated with outsourcing to third-party vendors or service providers. It considers various operational, financial, legal, compliance, and reputational risks.

Effective third-party risk management is a crucial component for relationships with contractors, suppliers, and other third parties. It helps ensure the quality of work, timeliness, compliance with regulations, and overall stakeholder satisfaction. By integrating third-party risk management into their business strategy, real estate developers can strengthen resilience, protect business interests, and navigate disruptions and crises more effectively.

What Is Vendor Business Continuity Planning? 

Business continuity planning is the process of creating a plan that ensures business operations continue if a disruption occurs. It involves identifying potential risks, developing strategies to mitigate those risks, and creating a plan to implement during a crisis. By implementing solid business continuity plan, developers can minimize disruptions and continue to operate smoothly during and after a disruptive event. 

Vendor business continuity planning is verifying your vendors have plans in place to ensure products and services continue to be delivered, even during a business-disrupting event. It should be reviewed before contracting with the vendor and then on an annual basis through ongoing monitoring. The plan should include personnel loss and planning, facility loss contingencies, breach/disruption notification procedures, and annual testing results.   

Third Parties to Include in Business Continuity Planning 

It's important to consider all critical third parties and suppliers when it comes to continuity planning. These third parties’ service disruptions can directly and significantly impact business operations. An easy way to identify your critical third parties is to ask the following questions:

  1. Would an abrupt loss of the third party cause a significant disruption to operations?
  2. Would the sudden loss of the third party impact customers?
  3. If the time to restore the service is more than 24 hours, would there be a negative impact on the organization?

 If you answer yes to any of these three questions, you’re likely dealing with a critical third party.

Let's explore some examples of critical third parties in commercial real estate development:  

  • Security system providers: Robust security systems, including surveillance cameras, access control systems, and alarm systems, are a necessity to protect real estate properties. If these systems were to fail, real estate developers could face break-ins or unauthorized access. 
  • Life safety systems: Life safety systems, such as fire detection and suppression systems, emergency exit signage, and emergency lighting, are crucial in mitigating risks and providing a safe environment. A system disruption or loss would increase the risk of accidents and injuries, which would have devastating consequences for real estate developers. 
  • Banking or financial partners: In some cases, banking partners could be considered critical to real estate development, particularly if the financial risk with the partner is high. The loss of a key financial partner could create a serious financial shortfall, damaging your real estate firm’s services and reputation.  
  • Construction and renovation contractors: These third parties would be considered critical while a project is ongoing. Delays and disruptions can take project off track, reduce property value, and cause financial losses. It’s important to ensure contractors have plans in place to mitigate any disruptions. 
  • Insurance providers: An insurance provider would be considered critical to your operations if your real estate firm only used one provider. Generally, it’s recommended to maintain relationships with multiple providers to ensure uninterrupted coverage. If the one provider experiences a disruption or unexpectedly shuts down, developers can be exposed to significant financial risks. 

protect commercial real estate third-party business continuity planning

How Third-Party Risk Management Supports Business Continuity Planning in Commercial Real Estate 

Integrating third-party risk management into business continuity planning strengthens developers’ resilience, protects business interests, and ensures both third parties and developers are able to respond quickly to disruptions. 

Here are 7 steps to including third parties in business continuity planning:  

Step 1: Risk assess each third-party engagement at the product or service level. Use a rating scale of low, moderate, and high risk to categorize your third-party inventory. Understanding the types and amounts of risks present in each engagement can help your organization better identify which risks are significant and require remediation.

Step 2: Identify which of your third parties are critical to your operations or its customers. While all third parties are important, every organization has a subset that is truly critical to their operations. Ask the three questions listed above to determine which third parties or suppliers are critical to your operations

Step 3: Conduct risk-based due diligence to validate the third party’s risk practices and controls. Consider their financial stability, operational reliability, information security and privacy, and compliance with industry standards and regulations when evaluating third-party vendors.

Step 4: Ensure critical third parties have robust business continuity plans. This includes understanding their recovery strategies and procedures during a disruption. Review their business continuity plans and ensure these are regularly updated and tested. Maintaining open communication and fostering collaboration with your third parties is vital in this process to ensure expectations are aligned and responsibilities are clearly defined.

Step 5: Test third-party vendors’ business continuity plans. Conduct regular drills to ensure both parties are familiar with the response plans and procedures in case of a disruption. Regularly monitor the performance of your third parties to ensure compliance with expectations laid out in the business continuity plan.

Step 6: Monitor and review third-party vendors’ business continuity plans. Stay vigilant for any changes in the business environment that may pose risks or disruptions. Ensure adherence to compliance standards and update business continuity plans accordingly to reflect these changes. Conduct regular reviews with your third parties to discuss any modifications.

Step 7: Continually improve third-party risk management practices. Once you've completed reviews and tests with your third-party vendors, use the insights gathered to refine your third-party risk management practices. This will create a dynamic and resilient strategy that adapts and grows with your organization and its third-party relationships.

By taking these steps, your organization can ensure business continuity planning is a robust component of your third-party risk management practices.

Effective third-party risk management, which includes comprehensive business continuity planning, is an indispensable practice that empowers commercial real estate developers to boost their resilience, ensure operational continuity, and safeguard their reputation and financial well-being.

Subscribe to Venminder

Get expert insights straight to your inbox.

Ready to Get Started?

Schedule a personalized solution demonstration to see if Venminder is a fit for you.

Request a Demo