REQUEST A DEMO
venminder_eBook_resources_Mini_Vendor_Management_Handbook
New Call-to-action
New Call-to-action
Blog-Bg.jpg

Podcasts

CONTACT SALES: (270) 506-5140
CONTACT SALES: (270) 506-5140
banner-bg.jpg

Subscribe to the Third Party Thursday Series

vendor oversight
Responsibilities

Non-Elective Vendor Oversight Responsibility

A non-elective vendor is one you don't have a direct relationship with, but your third party does - making them a risk to you and therefore requiring some oversight. Listen to learn the associated responsibilities.

Check It Out
integrate third party risk management in erm
Best Practices

Fit Third Party Risk Management in ERM

Various components of vendor risk feed in to your ERM strategy and considerations. Learn steps and tips on how to properly integrate Third Party Risk Management in your Enterprise Risk Management Program.

Check It Out
General Data Protection Regulation gdpr
Regulations

How GDPR Impacts Third Party Risk Management

While the General Data Protection Regulation (GDPR) has a global impact on any company which is collecting, storing, or accessing European resident data. Listen to Third Party Thursday to learn what you need to know.

Check It Out
difference between erm and tprm
Best Practices

Erm vs. TPRM

Enterprise Risk Management (ERM) and Third Party Risk Management (TPRM) are are often used interchangeably, but they are two different functions. ERM is more high level, while TPRM is a smaller subset. Listen to learn more.

Check It Out
vendor management staffing
Best Practices

Third Party RIsk Management Staffing

Recommendations from a seasoned third party risk expert for how to determine how many staff members to have on your vendor management team. Follow our three tips in this podcast.

Check It Out
best practices vendor contracts
Contracts

5 Common Pitfalls in Vendor Contracts

Save time, money and other valuable resources by learning mistakes companies make with their vendor contracts. Listen to see how you can avoid some common pitfalls during all phases of the vendor lifecycle.

Check It Out
third party risk management best practices
Best Practices

Creating Awareness of Third Party Risk Mgmt

Tips for fostering a third party risk mindset within your organization - how to create awareness, important members of your company to involve & who the third party risk responsibility lies within every organization.

Check It Out
third party risk management plan best practices
Best Practices

9 Key Components to a Successful TPR Mgmt Plan

What makes a third party risk management plan successful? Listen to learn 9 best practices and key components of a well-managed third party risk management plan for you to implement now.

Check It Out
complaint  management system
Responsibilities

Consumer Complaints and Vendor Management

Learn how a well-run complaint management system (cms) can turn an upset customer into your best customer along with five elements to include your vendor management policy on complaint management.

Check It Out
third party risk regulatory compliance
Regulations

TPR Management Regulatory Compliance during Regulatory Change

Here are daily vendor management regulatory compliance efforts you can implement in order to keep up with third party risk regulatory reform.

Check It Out
udaap third party risk program
Regulations

UDAAP And What It Means to Your TPRM Program

What you need to know about UDAAP (Unfair, Deceptive or Abusive Acts or Practices), how they affect your third party risk management program and items the CFPB is highly critical of.

Check It Out
Due Diligence on Your Fintech Vendors
Due Diligence

Due Diligence on Your Fintech Vendors

Tips and recommendations for determining due diligence questions to ask your fintech vendors. We'll also provide insight into setting the standards that should firmly be expected.

Check It Out
critical vendor classification
Risk Assessment

How To Properly Identify Your Critical Vendors

Go through critical vendor classification and identification with us. Learn standards for identifying your vendors, how to properly identify your scope and 3 questions to ask to determine if a vendor is critical.

Check It Out
vendor management
Best Practices

Third Party Risk Management Year End 2017

Join us as we close out 2017 with this thank you vendor management podcast. And, see what our top 10 most popular videos and podcasts were from our Third Party Thursday series for this year.

Check It Out
regulatory compliance
Regulations

Why to Stay Abreast of New Vendor Management Regulatory Guidance

The best way to prepare for new regulatory guidance, how to stay in compliance and some commentary on new regulations taking effect in 2018.

Check It Out
vendor classification
Risk Assessment

vendor classification

Learn about 'bucketing your vendors' - a high level vendor classification system that can help you with third party oversight, ongoing monitoring and preventing problems down the road. We'll also tell you how to develop buckets of your own.

Check It Out
complaint management system for vendor management
Responsibilities

complaint management system

What to include in your complaint policy and complaint management system to improve vendor management. A well-run system can turn upset customers.

Check It Out
vendor management examination prep
Exam Prep

What Should Be In your Third Party Risk Examination Preparation Handbook

The best strategy for preparing for an examination is to constantly be ready. Listen to learn 7 items you should have in your examination preparation playbook.

Check It Out
vendor management best practices
Best Practices

Learning the Fundamentals of Third Party Risk Management

Learn the key takeaways from important third party risk regulatory guidance released by the OCC, FDIC and FFIEC from our compliance expert. 

Check It Out
vendor management best practices
Bank Vendor Managment

Third Party Risk Management Education

Learn how to get ahead of the game education wise in third party risk management with these 10 best practices. Staying up to date is a great idea for everyone involved in vendor management. 

Check It Out
vendor management best practices
Best Practices

Prevention of Problems in Third Party Risk

An ounce of prevention is worth a pound of cure! Perhaps there is no better example than in the world of third party risk management. Here are three ways you can be proactive to prevent problems. 

Check It Out
third party risk enforcement actions
Best Practices

Learning From Third Party Enforcement Actions

Let's say you find out one of your third parties is named in an enforcement action, even if it is unrelated to your institution, what do you do? Listen to learn the six necessary steps to take.

Check It Out
compliance management system
Best Practices

Creating a Culture of Compliance for Vendor Management

Learn what regulators & senior gov officials in financial services had to say on creating a culture of compliance, why they strongly recommend it and what this entails.

Check It Out
Venminder Risk Rating Every Vendor
Risk Assessment

Do I Have to Risk Rate Every Vendor?

One of the most frequent questions we get asked is, "am I supposed rate EVERY single vendor?" Learn why it's necessary to risk rate every vendor when conducting your vendor risk assessments and gather some tips.

Check It Out
board report
Reporting

Vendor Management Board Reporting

The regulator guidance is clear - you must keep your senior management and your board informed on developments within your third party risk management program. Learn what this looks like.

Check It Out
udaap
Regulations

UDAAP - Unfair, Deceptive or Abusive Acts or Practices

Learn about UDAAP - Unfair, Deceptive or Abusive Acts or Practices and the role of the CFPB and enforcement actions in the world of third party risk by listening to this informative podcast.

Check It Out
Brand Names and Vendor Due Diligence
Due Diligence

Brand Names and Vendor Due Diligence

Sometimes people feel too comfortable with a well-known vendor. We cover why even vendors with recognizable brand names require thorough due diligence. No one is immune from third party risk.

Check It Out
guidance on OCC Bulletins 2017-7 and 2017-21
Regulations

Guidance on OCC Bulletins 2017-7 and 2017-21

Learn key takeaways from two OCC Bulletins issued this year on third party risk management - OCC Bulletins 2017-7 and 2017-21. Is your institution's vendor management program in compliance?

Check It Out
third party risk management framework
Third Party Risk Management

The Basic Concepts of Third Party Risk Management Framework

Listen to learn the basics of the third party risk management framework, including how it relates to enterprise risk management (ERM).

Check It Out
contract management
Vendor Contract Management

Best Practices in Vendor Contract Management

Learn how to do proper vendor contract management. We'll provide best practices, the importance of contracts to your institution and what steps to take to protect your institution from contract risk.

Check It Out
vendor risk assessment
Best Practices

7 VENDOR RISK ATTRIBUTES TO CONSIDER

Learn 7 key things you should do with every new vendor. These steps are essential to the vendor vetting process and determining how much you know about the company with whom are you planning to do business.

Check It Out
information security questionnaire
Information Security

How, When and Why to Use an InfoSec Questionnaire

Learn the how, when and why of using vendor information security questionnaires for your third party risk management and how your due diligence process can benefit from it.

Check It Out
information security
Information Security

CIA Triad Within Vendor Management

In this podcast, you'll learn how your vendor's approach to the CIA triad of information security impacts you and your customers. Being aware will help you against third party risk.

Check It Out
Third Party Due Diligence
vendor due diligence

Third Party Due Diligence

In this short vendor management video, you will learn four key points you need to know regarding third party due diligence and what items your due diligence checklist should contain to keep your institution safe from third party risk. 

Check It Out
vendor soc reports
SOC Reports

Understanding Vendor SOC Scope, Time and Narrative

Learn what the scope of a vendor's SOC report means and where to find it along with what typical audit periods are and a few questions to ask yourself while reviewing the narrative.

Check It Out
7 Steps of Vendor Vetting Vendor Management Video
Due Diligence

7 Steps of Vendor Vetting

Learn the 7 key things you should do with every new vendor. These steps are essential to the vendor vetting process and determining how much you know about the company with whom are you planning to do business.

Check It Out
vendor soc report
SOC Reports

Analyzing SOC Controls

In this vendor management video, you will learn where to find the controls section within a vendor SOC report along with what the control objectives and activities are and what to look out for in the findings and exceptions.

Check It Out
vendor risk assessment
Best Practices

Critical Vendors: What to Review

We cover the key questions you need to ask yourself to determine if your vendors are critical. Then, we dive deeper and talk about what you should review on your critical risk vendors.

Check It Out
what is ssae 18
SOC Reports

What is SSAE 18?

As of Monday, May 1, SSAE 18 is now in effect. Are you familiar with SSAE 18 yet? Join us now as we talk about SSAE 18 - what it is and how it affects how you do vendor management at your institution. Let's get started.

Check It Out
vendor management risk assessments
Risk Assessment

Vendor Management Risk Assessments

We’re going to talk through a few key things you need to know about vendor management risk assessments for your institution's third party risk management program. 

Check It Out
10 steps to create your vendor list
Best Practices

10 Steps to Creating Your Vendor List

We’re going to talk through the 10 main steps you need to take to create your proper vendor list for your third party risk management program at your institution. Let's get started.

Check It Out
third party risk vendor management errors video
Best Practices

10 Common Vendor Management Errors

It’s easy to get so deep in the weeds of your vendor management program that you make some pretty basic errors. Sometimes you need to take a step back and evaluate. Here are some of the ones that we see most often.

Check It Out
Third-Party-Thursday-Video-Library-3-lines-of-defense
Responsibilities

3 Lines of Vendor Management Defense

You may have heard the term “three lines of defense”. But, what is a three lines of defense strategy? We'll go through those three lines of defense you have for vendor management at your financial institution.

Check It Out
ERM vs Vendor Management
Best Practices

Enterprise Risk Management vs Vendor Management

We often get asked, "Is there a difference between an ERM and VM?" The answer is “YES” – they are different, but there are some areas of overlap as well. Learn about what some of the differences are.

Check It Out
Lifecycle Approach to Third Party Risk Management
Best Practices

Lifecycle Approach to Third Party Risk Management

Third party risk management must flow in a lifecycle. We'll discuss how it's a constant evolutionary process rather than an annual static event - a core aspect that you should incorporate into your program.

Check It Out
vendor management best practices
Best Practices

Fundamental Third Party Risk Management Best Practices

We'll discuss fundamental best practices of third party risk management that you need to implement such as education, tailored ongoing monitoring, outsourcing and not cutting corners.

Check It Out
video-img1.png
Best Practices

Why Is There So Much Focus On Third Party Risk?

You have to do a lot for your third party risk management now... but why? We'll go through a few reasons for the increased third party risk management regulation and concern. 

Check It Out
video-img1.png
Best Practices

How to Write a Third Party Program

It should cite relevant regulations and guidance; it should describe its relationship to other parts of your compliance program and establish its importance as a foundational document for your institution.

Check It Out
Third-Party-Thursday-Video-how-to-write-vendor-management-policy.png
Best Practices

How to Write a Third Party Policy

A policy is the first main foundational third party risk management document you should have on file. Learn about key aspects in writing a proper third party policy for your financial institution.

Check It Out
Third-Party-Thursday-Video-FFIEC-cybersecurity-assessment
Cybersecurity

FFIEC Cybersecurity Assessment Tool

The FFIEC released a Cybersecurity Assessment Tool. We'll go over in depth the benefits of it and why your financial institution should use it for your vendor management. 

Check It Out
Third-Party-Thursday-Video-contract-confidentiality.png
Contracts

Security & Confidentiality Provisions Which Should Be Addressed

Even though each vendor agreement includes different contractual terms, 5 security and confidentiality provisions should always be addressed. Let's go through them.

Check It Out
vendor due diligence
Financials

When a Vendor Refuses to Provide Financials

When a third party company doesn't provide financial documents we tend to think there's nothing we can do. But actually, there is and we'll show you that alternate path in this video.

Check It Out
soc reports
SOC Reports

Importance of Complimentary User Entity Controls

Learn what Complimentary User Entity Controls are, how they're related to SOC reports, what you do with them, why they're important and more.

Check It Out
contract management
Contracts

Mitigating Vendor Contract Risk

In order to have vendor management control, you must have a firm understanding or knowledge of third party vendor contracts. Learn the 3 pillars in managing them and other points about mitigating contract risk.  

Check It Out
soc 1 2 3
SOC Reports

5 Types of Vendor SOC Reports

So, what are the types of service organization control (SOC) reports and which type of SOC report did your vendors have performed? It can be confusing to keep track of them. To help, we'll briefly go through all 5 of them in this video.

Check It Out
vendor management
Due Diligence

Fourth Parties

So you're asking yourself right now, "What is a fourth party? I've just gotten my head around the whole concept of having third parties. And why are they important to my financial institution's vendor management program?" Let's discuss.

Check It Out
vendor information security
Information Security

Your Vendors and Cloud Computing

The Cloud has many benefits, but like everything, there are risks you need to consider. Protecting your institution’s data is ultimately your responsibility so you should know how your vendor safeguards it.

Check It Out
third party risk regulatory compliance
Regulations

Evolution of Third Party Risk

In this video we’re going to talk a little about the evolution of third party risk management and the increased regulatory expectations on financial institutions. This will be helpful to know as you expand your third party risk knowledge.

Check It Out
business continuity plan example
Business Continuity

Vendor Business Continuity and Disaster Recovery Plans

Ensuring your critical vendors can survive in disaster helps ensure your financial institution can also survive. Learn what Business Continuity & Disaster Recovery plans are & how our team reviews them. 

Check It Out
what is soc 1 2 3
SOC Reports

3 Key Points to Review In SOC Reports

Learn the 3 key points to review in service organization control reports, SOC reports for short, as you begin assessing your vendor's environment. Meet examiner requests and gain strategic business advantages.

Check It Out
contract management
Contracts

5 Key Provisions to look for in your Critical Vendor Contracts

When reviewing and negotiating critical vendor contracts, consider many elements. Here's 5 key provisions to give special attention.

Check It Out
financial statement analysis
Financials

Consequences of a Vendor's Poor Financial Performance

You report the vendor's financial health to senior management and board. What happens when the financial health is poor? We will go over the domino effect, the issue in the industry and what you can do about it.

Check It Out
ffiec compliance
Regulations

FFIEC Appendix J and E

You should be familiar with Appendix J and Appendix E of the FFIEC guidance. We will go over what each of them are, what they mean and how your teams can stay informed on new vendor management guidance and regulations.

Check It Out
vendor due diligence
Due Diligence

Defining Critical Vs. Non Critical Vendors

Do you know the difference between a critical and non critical vendor? Learn about defining them for your financial institution. We'll cover why it's important, the business impact, exit strategies and more.

Check It Out
third party risk management framework
Best Practices

Defining the Scope of your Third Party Risk Management Program

You must define specifically who will be a part of your third party risk management program and also, equally important, who is out

Check It Out
vendor management best practices 2017
Best Practices

What you can do now to prepare for 2017

So, what can you do right now in preparation for next year? There’s actually quite a lot, depending on the maturity of your third party program. Watch this video to learn what you can do now to prepare for 2017.

Check It Out
vendor management best practices
Best Practices

Best Practices in Vendor Management

With all the vendor management industry changes and guidance updates, it's easy to get overwhelmed. In this video, we will talk about basic vendor management best practices to implement.

Check It Out
pillars of third party risk
Best Practices

THE PILLARS OF THIRD PARTY RISK

Regulatory guidance sets out fundamental expectations. It’s important for the day to day management and exam standpoint that these pillars are in place and functioning in your institution. Learn more about these pillars.

Check It Out
vendor management best practices cyber security
Cybersecurity

What's In the News Matters

Vendor management is covered a lot more in industry news now. It's hard to keep up, and sometimes tempting not to try. This video mentions recent examples of important items covered.

Check It Out