Obtenez 3 mois à 0,99 $/mois

OFFRE D'UNE DURÉE LIMITÉE
Page de couverture de The Third Party Risk Institute Podcast

The Third Party Risk Institute Podcast

The Third Party Risk Institute Podcast

Auteur(s): Linda Tuck Chapman
Écouter gratuitement

À propos de cet audio

Go beyond the headlines with The Third Party Risk Institute Podcast, the official podcast of Third Party Risk Institute.


Each episode brings you into the room with top experts in third-party risk, cybersecurity, procurement, governance, and compliance. Hear how risk leaders tackle real-world challenges, share lessons learned, and stay ahead of evolving threats.


We explore the strategies that work, the mistakes that teach, and the insights you won’t hear anywhere else.


Perfect for risk professionals, procurement leaders, auditors, and decision-makers who want to lead with confidence.


🎧 Subscribe now, new episodes drop monthly on Spotify, Apple Podcasts, YouTube Music, and Amazon Music.

© 2025 Third Party Risk Institute Ltd.
Développement commercial et entrepreneuriat Entrepreneurship Gestion et leadership Économie
Épisodes
  • Black Box AI: Due Diligence Questions Every Risk Leader Must Ask
    Oct 16 2025

    In this episode of The Third Party Risk Institute Podcast, we tackle one of the most urgent challenges in risk management today: artificial intelligence entering your organization through third-party vendors. AI promises efficiency and insights, but behind the buzzwords lie hidden risks that can compromise compliance, trust, and resilience.

    We break down the building blocks of AI data, algorithms, and infrastructure to show you where vulnerabilities really start, and how to ask the right due diligence questions before onboarding an “AI-powered” vendor. From model drift and explainability gaps to cloud concentration and fourth- and fifth-party dependencies, this episode arms you with the literacy needed to separate hype from reality.

    What we cover in this episode:
    • The “black box” problem in AI and why explainability is a regulatory must-have
    • Key risks in data provenance, model drift, adversarial attacks, and bias amplification
    • How hyperscale cloud reliance creates hidden concentration risk for enterprises
    • The overlooked fourth- and fifth-party risks in AI supply chains
    • Practical due diligence questions to embed in RFPs and vendor questionnaires
    • How regulators from the EU AI Act to U.S. financial agencies are already shaping expectations

    You’ll walk away with practical guidance on:
    • Identifying red flags in vendor claims about AI
    • Shifting from one-time reviews to continuous monitoring of AI vendors
    • Embedding AI-specific obligations into contracts, including audit rights and incident reporting
    • Building functional literacy so you can challenge vendors and protect your organization

    This episode is perfect for:
    • Third-Party Risk Management, Procurement, and Compliance Leaders
    • CROs, CISOs, and Risk Executives navigating AI-driven vendor ecosystems
    • Internal Audit, Legal, and Governance Professionals under regulatory pressure
    • Anyone seeking to translate AI complexity into concrete risk oversight

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    Voir plus Voir moins
    17 min
  • Global Insights on Internal Audit, Risk Culture, and Third Party Accountability
    Oct 1 2025

    In this episode of The Third Party Risk Institute Podcast, we sit down with Shagen Ganason, Group Chief Auditor at Liva Group, to explore the evolving role of internal audit, the impact of regulatory diversity, and why third-party accountability can never be outsourced. With over 30 years of leadership experience across insurance, banking, aviation, manufacturing, and the public sector, and having worked in seven countries, Shagen brings a rare global perspective to audit, risk, and governance.

    Drawing on his books The Storyteller’s Ledger and The Auditor’s Secret Weapon, Shagen shares how communication, storytelling, and cultural adaptability are becoming essential skills for auditors and risk leaders. He also highlights why regulators in regions like the GCC are moving fast on cybersecurity, outsourcing oversight, and financial crime risks, and what that means for boards and executives.

    What we cover in this episode:
    • The three dimensions of modern internal audit: assurance, advisory, and strategic oversight
    • How principles-based vs. prescriptive regulations shape audit and compliance practices across countries
    • Building resilience through risk culture, and why it looks different in New Zealand, Korea, and the Middle East
    • The link between risk appetite and corporate strategy, and how boards translate it into actionable decisions
    • Concentration risk, fourth-party dependencies, and why cloud reliance creates hidden exposures
    • Why accountability for third-party risk can never be outsourced, and how boards and auditors should address it

    You’ll walk away with practical guidance on:
    • Communicating audit findings through storytelling that sticks and drives action
    • Aligning audit plans with organizational strategy and risk appetite
    • Building credibility and independence while maintaining strong business relationships
    • Understanding how regulatory diversity and cultural context influence governance effectiveness

    This episode is perfect for:
    • Chief Audit Executives, CROs, and Board Members
    • Internal Audit, Compliance, and Risk Professionals
    • Procurement and Vendor Risk Leaders facing regulatory scrutiny
    • Anyone looking to strengthen their understanding of risk culture, assurance, and third-party accountability

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    Voir plus Voir moins
    57 min
  • Cyber Crossroads 2025: How DORA, NIS2, and SEC Rules Are Reshaping Third Party Cyber Risk Management
    Sep 19 2025

    In this episode of The Third Party Risk Institute Podcast, we take a deep dive into the three landmark regulations set to redefine cybersecurity and third-party risk management (TPRM) in 2025:

    • DORA (EU Digital Operational Resilience Act) – binding requirements for financial institutions and ICT providers, including detailed vendor contract clauses, unrestricted audit rights, and concentration risk analysis.
    • NIS2 Directive – expanding cybersecurity obligations across 18 critical sectors with strict incident reporting timelines, supplier security expectations, and senior management accountability.
    • U.S. SEC Cybersecurity Disclosure Rule – mandating public companies to disclose material cyber incidents within four days and report annually on vendor cyber risk management practices.

    Together, these regulations signal a global shift: cyber resilience and third-party risk oversight are now board-level imperatives.

    What we cover in this episode:
    • Key contract clauses and due diligence steps required by DORA
    • How NIS2 expands supply chain risk accountability beyond finance
    • Why SEC rules make vendor cyber incidents investor disclosures
    • Practical ways to embed vendor oversight into enterprise risk programs
    • Actionable steps for CROs, CISOs, and TPRM teams to stay compliant

    You’ll walk away with practical guidance on:
    • Performing a regulatory gap analysis across DORA, NIS2, and SEC rules
    • Updating vendor contracts with notification, audit, and cooperation clauses
    • Building a structured supply chain security program aligned with ISO 27001 and NIST CSF
    • Preparing disclosure processes and templates to meet SEC 8-K reporting deadlines
    • Using certifications like C3PRMP to build in-house expertise and demonstrate readiness

    This episode is essential listening for:
    • Chief Risk Officers, CISOs, Vendor Risk Managers, and Procurement Leaders
    • Cybersecurity, Compliance, and Audit Professionals
    • Board Members and Executives overseeing enterprise resilience

    By embracing these regulatory changes, you won’t just avoid penalties, you’ll strengthen trust, enhance resilience, and gain a competitive edge in today’s interconnected economy

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    Voir plus Voir moins
    21 min
Pas encore de commentaire