<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>D&amp;B - DoubleCheck Software</title>
	<atom:link href="https://www.doublechecksoftware.com/tag/db/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.doublechecksoftware.com</link>
	<description>Engage Your Enterprise</description>
	<lastBuildDate>Mon, 03 May 2021 13:54:33 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.5</generator>

<image>
	<url>https://www.doublechecksoftware.com/wp-content/uploads/2018/09/cropped-doublecheck-icon--32x32.png</url>
	<title>D&amp;B - DoubleCheck Software</title>
	<link>https://www.doublechecksoftware.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Integrating Third Party Data Into Your Risk Management Processes (TPRM)</title>
		<link>https://www.doublechecksoftware.com/integrating-third-party-data-into-your-risk-management-processes-tprm/</link>
					<comments>https://www.doublechecksoftware.com/integrating-third-party-data-into-your-risk-management-processes-tprm/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Mon, 03 May 2021 13:54:31 +0000</pubDate>
				<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[D&B]]></category>
		<category><![CDATA[Dun and Bradstreet]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=2638</guid>

					<description><![CDATA[<p>Some Risk Managers rely upon reported findings from internal risk assessments as the primary source of risk data in their Third Party Risk Management (TPRM) programs. Too often this approach generalizes over time from a primary to an exclusive source. That’s a missed opportunity to leverage value from other contributors to your operations, by incorporating<a href="https://www.doublechecksoftware.com/integrating-third-party-data-into-your-risk-management-processes-tprm/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/integrating-third-party-data-into-your-risk-management-processes-tprm/">Integrating Third Party Data Into Your Risk Management Processes (TPRM)</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>Some Risk Managers rely upon reported findings from internal risk assessments as the primary source of risk data in their Third Party Risk Management (TPRM) programs. Too often this approach generalizes over time from a primary to an exclusive source. That’s a missed opportunity to leverage value from other contributors to your operations, by incorporating available data sources already in hand, often leading to undetected vulnerabilities and avoidable exposures to your enterprise. These sources could provide alternative perspectives, through the lens of different disciplines, unique detail data on third party performance, and discreet validations or challenges to self-assessment findings arising from internal risk assessments.</p>
<p><span style="color: #3366ff;">Third Party Data Choices</span><br>Some of the third-party sources of input to your risk management program are standard byproducts of audit, compliance, and procurement processes, particularly with respect to third parties. These processes may incorporate reviews of external audits by banks, regulators, government agencies, as well as services that monitor and evaluate the financial health of firms, such as Dunn &amp; Bradstreet. Some of these services can represent a check or confirmation against internal assessment findings, while others may be a source of research leading to a curation and analysis of aggregate data. Services such as D&amp;B® Direct, integrated into DoubleCheck’s TPRM solutions, are a representative example of such a detailed, maintained source of reliable financial performance information. Reports from regulators, particularly ones based upon standards, such as SOC and SOCII, or compliance data regarding performance against a known standard such as HIPAA, HITECH, General Data Protection Regulation (GDPR), or FINRA, to name a few, can yield a great deal of objective input to your risk evaluation performance. Independent reviews of your financial and accounting management by external auditors may offer further insights into controls effectively in force. They may also expose vulnerabilities in data management and retention to be addressed.</p>
<p>Discovery of a vulnerability in one area or function may or may not be indicative of a widespread matter. Often disciplines will take on more or less stringent control practices, depending upon their own perception of how valuable their resources might be, and how tempting they might be to malicious actors. However, discovery of a vulnerability in one area is reason to explore its extent across the enterprise. If your risk assessment process employs a framework, you may have also mapped specific controls to the components and categories of risk across that framework. One useful report to create would be one where you explore the prevalence of a specific control being used, or, better still, how often it is not. If you identify controls largely not in force, there are several possible reasons for this. The control may not be relevant to your business. It may be unclear or especially difficult to implement or maintain, or too costly in staff resources. In some cases, it may create more disruption and expense than the vulnerability justifies. You’ll need to explore which controls are necessary, avoided, and establish some alternative approach to address any significant vulnerability. Keep in mind that a weakness in one area may instigate others in related ones. These may not be obvious at first glance but the result of chained events, where, for example, a delay in patching servers in a distribution operation leads to service outages and missed performance metrics for product delivery. You likely can identify many others in your enterprise.</p>
<p><span style="color: #3366ff;">Integration, Instigation and Collaboration</span><br>Identifying third party data sources is a start, gaining access to them is the obvious next step, and with that, understanding how frequently these sources update or refresh content is important. There are calendars and schedules to understand and align where possible. If your risk assessments are annual, using the most current data from all sources makes the most sense. Where cycles are more frequent, it is even more important to identify the most recent and up-to-date iterations of any inputs, in particular from third parties, where you are a subscriber at best, and cannot control the timing and frequency of reviews, reports, or examinations. How you access this data is equally important. Ideally, you are using a GRC tool that offers data import features, or has already enabled integration features that only require authentication and configuration to enable. These would support automated integration into your risk databases and provide data in a form that’s ready to use without manual intervention or handling by any staff. The value here is that such features are flexible and readily extensible as your enterprise and risk program expand. In cases where such tightly integrated automation may not be possible with a third party source, structured forms coupled with dedicated data extraction tools may offer some amount of resource-light capture and collaboration. Often, these forms are built around MS Word or Excel based files or editable PDFs. They may require some testing and modification to reflect field name conventions or combinations and concatenations to tailor them to target database specifications.</p>
<p>Data expressed as numerical rankings, ratings, or scores may be less challenging to align and import that narrative text. Often, the content of narrative comments may not easily be extracted from its source context and assigned to a useful categorization readily meaningful in your database of risk information. However, standard outputs from third parties often reuse their own methods and structures, so this “translation” exercise may not need to be repeated often. The work may at first glance seem tedious, but can pay significant dividends to the value and accuracy of your risk processes. Keep in mind the intent; to provide your assessment’s subject matter experts and dedicated risk analysts with the richest and most complete picture of the current field of threats, weaknesses, remediating controls and alternative risk strategies deployed to make an informed evaluation of your current risk posture.</p>
<p>Some GRC tools provide input forms and methods already mapped to the assessment and reporting processes in their modules. Such tools serve as alternatives to more costly data extraction and transformation utilities. Also, dedicated services, where integration is an out-of-the-box feature, offer not only the value of this third party content, but ease of implementation and vendor provided updates when needed to keep the embedded service working seamlessly. Again, this is a product maintenance and reliability matter. Features that are part of a product offering are maintained through upgrades and patches. They require some testing but installation and continued maintenance will not involve detailed and complex service-by-service testing and segmented upgrades. That’s important to keeping administrative and support costs in line.</p>
<p>It’s also important to consider calendars and frequencies of data refresh when preparing to integrate external findings with those you gather internally. Your assessment schedule and frequency likely won’t directly align with external inputs. Alignment of time periods to the schedule and frequency of your internal risk assessments is important to preserve and enhance the relative relevance of this external data. Mismatching these could result in identifying issues that may have been remediated following a review or assessment finding. Often external sources from audits, regulators, and the like run on annual schedules. When including this data you need to align the most recent available but also take note of the relative gap between your assessment and the latest inputs from external sources. Those findings, when presented to your subject matter experts, may lead to questions and follow-up offering useful detail.</p>
<p><span style="color: #3366ff;">KPI’s, KRI’s and Metrics</span><br>Key performance indicators (KPIs), key risk indicators (KRIs), and metrics, in general, offer great opportunities to understand where your risk program fits within others from your industry. They also can offer insights to third party performance against contractual standards. Further, they can point out areas where your own operations meet, exceed, or fall short of expectations. Operating KPIs may tell you more than just how a service or process performs. Their value, compared to some expectation of performance, may allow them to serve the dual role as KPI, where a weak showing indicates a potential risk or vulnerability resulting from the process failing to meet a required standard. Other metrics, including ones monitoring control performance, can offer assurance of process control effectiveness and external management attention to important detail. In itself, these identify signs of an attentive and risk aware management culture.</p>
<p><span style="color: #3366ff;">Where Integration Offers Risk</span><br>How data integration occurs can offer an opportunity for risk on its own. If the integration is through periodic data transfers, how is this done? What controls secure access to or exchange with the external service? Is a secure pipe, encrypted with strong authentication controls in place? How are credentials managed? How frequently changed? What is the process for assuring the data offered has arrived without alteration? In the shadow of recent events at SolarWinds it’s vital to assure only unaltered data is allowed to be integrated and repurposed. The eagerness to acquire the benefits noted above from integrating external data sources for your risk program cannot of itself risk exposure of your enterprise to equal or greater risks through the interactive practices used to access and utilize that data. The specifics must be coordinated with your IT team to determine the best means of data access. The controls for file sharing are different than for real time access to an external data source or enterprise. Regardless, it’s important to design controls and implement practices to assure end-to-end security. An external source is an extension of your risk perimeter and requires the same attention as any other extended endpoints to your overall risk footprint.</p>
<p><span style="color: #3366ff;">Conclusion</span><br>Integrating external, third party data into your TPRM risk assessment and management practices offers clear value and opportunity to refine, sharpen, and position your risk management program within your enterprise and your industry. This input can serve as a control on internal practices, also aligning performance with market and industry expectations. There needs to be attention to security to assure external data is secure as is its access. These risks should not be minimized, but they should not outweigh potential gains offered by data integration. Clearly, incorporating such data offers a clear advantage, operationally and strategically. It is worth exploring. Where your resources support its inclusion it is a worthwhile enhancement to your risk management practice.</p>
<p>About the Author:<br>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/tag/db/feed/" data-token="4526f5187a4fd274e5828ab6f518dbcd" data-token-time="1784948433"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Email Company Title</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div><div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div><div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Message</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="D&amp;B"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/tag/db/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/integrating-third-party-data-into-your-risk-management-processes-tprm/">Integrating Third Party Data Into Your Risk Management Processes (TPRM)</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/integrating-third-party-data-into-your-risk-management-processes-tprm/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2638</post-id>	</item>
		<item>
		<title>A Look At DoubleCheck’s Approach to TPRM  (Third Party Risk Management)</title>
		<link>https://www.doublechecksoftware.com/a-look-at-doublechecks-approach-to-tprm-third-party-risk-management/</link>
					<comments>https://www.doublechecksoftware.com/a-look-at-doublechecks-approach-to-tprm-third-party-risk-management/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Thu, 01 Apr 2021 15:56:53 +0000</pubDate>
				<category><![CDATA[Cyber Security Risk Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>
		<category><![CDATA[TPRM]]></category>
		<category><![CDATA[D&B]]></category>
		<category><![CDATA[Dun and Bradstreet]]></category>
		<category><![CDATA[Third Party Risk Management]]></category>
		<category><![CDATA[Vendor Risk Management]]></category>
		<guid isPermaLink="false">https://www.doublechecksoftware.com/?p=2600</guid>

					<description><![CDATA[<p>This month, I’m going to depart a bit from the independent discussions of IT risk and cybersecurity to explore some of the specific ways this blog’s host, DoubleCheck Software, provides tools, resources, and value to companies working to manage their supply chain and partner risk—TPRM (Third Party Risk Management). The DoubleCheck GRC offers a platform<a href="https://www.doublechecksoftware.com/a-look-at-doublechecks-approach-to-tprm-third-party-risk-management/">[...]</a></p>
<p>The post <a href="https://www.doublechecksoftware.com/a-look-at-doublechecks-approach-to-tprm-third-party-risk-management/">A Look At DoubleCheck’s Approach to TPRM  (Third Party Risk Management)</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>This month, I’m going to depart a bit from the independent discussions of IT risk and cybersecurity to explore some of the specific ways this blog’s host, DoubleCheck Software, provides tools, resources, and value to companies working to manage their supply chain and partner risk—TPRM (Third Party Risk Management).</p>
<p>The DoubleCheck GRC offers a platform for managing risk, and its product offerings include a module specific to managing third party risk. They also offer a turnkey third-party risk management solution offering an easy to use, cost effective means to understand and manage third-party risk, called DoubleCheck TPRM. This risk management tool incorporates integration points into D&amp;B<sup>®</sup> Direct<a href="#_ftn1" name="_ftnref1">[1]</a> Live Business, offering seamless access to identify information linked to financial performance on over 370 million business entities globally. DoubleCheck’s TPRM supports a high-level risk assessment process that walks users through identifying and gathering relevant evidence based on criticality and risk factors, including key D&amp;B<sup>®</sup> data. Users may license D&amp;B content through D&amp;B<sup>®</sup> Direct.  The program’s process management features direct information to subject matter experts (SME’s) for review. Reporting tools produce clear and demonstrative real-time dashboards and scorecards, making assessment findings and current states straightforward to understand and communicate,  leading to informed necessary actions.</p>
<p>I’ve often discussed and recommended a business question approach to reporting and information graphics in particular. Reports should answer business questions that are important to management and the successful operation of its business.  In like manner, the titles to graphical displays could be answers to those questions in the form of declarative statements. This sounds straightforward but presumes a few fundamentals.  First, that management understands what questions to ask to inform business decisions it must make.  Second, the business must be able to gather reliable, accurate data needed to answer those questions in a timely manner.  Sometimes, management delivers the all-consuming generality that it needs to “know everything”.  I disagree.  If you need to know everything, then you don’t know the answer to my first presumption, so you ask for it all in the belief you’ll capture what’s needed, eventually. It’s not a cost effective nor efficient approach. A better test is this: “As a result of knowing “x”, I’m able to take this action “y””!  If the x and y cannot be clearly stated, what value would be added by knowing “x”?  But if you know, the next question needs to be, “what data is needed to know “x”?” Now you’re getting to something practical and actionable.  This is useful.  For TPRM, it’s important to know that more data is not necessarily merrier, but the <em>right</em> data is invaluable to your risk management program and its contribution to your business. This is value-based information reporting!</p>
<p>Specifically regarding TPRM, think about the key business questions to answer about a prospective supplier or partner.  Are they financially sound? Have they had performance issues in the past? How do they compare to their peers? Can they support our current security and operating requirements? What specific risks will our use of their services create? Can they mitigate them effectively? Will they need to store your data locally in their environment? Will they access your network?  Use their equipment or yours? Do they offer any special opportunities or advantages aside from price, delivery, and quality? Are they consistent and reliable? You likely have many more. Each business is unique. Further, to manage third party risk at the program level, these questions would and could be modified to rank your third party portfolio of suppliers, so you can readily identify potentially troubled relationships and address them before they become critical issues. There are also questions about the state of your risk management process, and how well it’s serving to monitor governance of third party risk. Let’s take a look at some DoubleCheck TPRM displays and see what answers are readily available.</p>
<p>Let’s examine Figure 1, the Risk Profile. The numbers on these heat maps are drillable (i.e. click to get more detailed data) which will then display a table of the third parties that fall into that bucket.</p>
<p><img fetchpriority="high" decoding="async" class="alignnone  wp-image-2609" src="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Risk-Profile-table-APRIL-300x152.jpg" alt="" width="578" height="293" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Risk-Profile-table-APRIL-300x152.jpg 300w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Risk-Profile-table-APRIL-150x76.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Risk-Profile-table-APRIL-768x389.jpg 768w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Risk-Profile-table-APRIL.jpg 994w" sizes="(max-width: 578px) 100vw, 578px" /></p>
<p><em>Figure 1: Risk Profile; DoubleCheck TPRM</em></p>
<p>At a glance there’s some very useful information about which suppliers and how many of them represent a critical risk, how many are related to exchanged, stored, or shared client data, and the relative state of your reviews regarding these critical matters. It’s useful to note the Third Party Criticality vs Supplier Risk heatmap in the upper left, and the Highest Risk Third Parties below it are using D&amp;B&#8217;s Supplier Risk value, or SER. The Supplier Evaluation Risk (SER) Rating is Dun &amp; Bradstreet&#8217;s proprietary scoring system used to assess the probability that a business will seek relief from creditors or cease operations within the next 12 months. SER ratings range from 1 to 9, with 9 indicating the highest risk of failure.  The SER Rating predicts the likelihood that a supplier may cease business operations or become inactive over the next 12 month period based on the depth of predictive data attributes available on the business. While it’s calculated as a number ranging from 1-9 it’s represented as a Minor-Low-Medium-High-Extreme here for easier reference on these charts. The close integration of DoubleCheck’s TPRM with D&amp;B services enables and automates this important graphic. These integrated displays support drill down clicking on a section, revealing detailed information to help answer specifics about individual vendors so rated. It helps pinpoint where your critical risk resides, and which vendors participate.  The other implicit information offered is context.  Are the critical vendors 3 of 20, 3 of 4, or 3 of 200?  The implications may be categorically useful to policy, procurement processes and contract management.</p>
<p>The Criticality rating represented in Figures 2 and 3 are generated through TPRM.  It represents both potential loss and time-to-replace data for that vendor to our customer.  The combined values, represented together here, offer a unique multi-vector representation of potential risk arising through the service of a particular third party.</p>
<p><img decoding="async" class="alignnone  wp-image-2608" src="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Dist-By-Co-APRIL-300x163.jpg" alt="" width="565" height="307" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Dist-By-Co-APRIL-300x163.jpg 300w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Dist-By-Co-APRIL-150x81.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Dist-By-Co-APRIL-768x417.jpg 768w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Dist-By-Co-APRIL.jpg 770w" sizes="(max-width: 565px) 100vw, 565px" /></p>
<p><em>Figure 2 Criticality Distribution By Company</em></p>
<p><img decoding="async" class="alignnone  wp-image-2607" src="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Counts-by-Supplier-APRIL-300x140.png" alt="" width="559" height="261" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Counts-by-Supplier-APRIL-300x140.png 300w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Counts-by-Supplier-APRIL-150x70.png 150w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Counts-by-Supplier-APRIL-768x358.png 768w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Critical-Counts-by-Supplier-APRIL.png 826w" sizes="(max-width: 559px) 100vw, 559px" /></p>
<p><em>Figure 3 Criticality Counts By Supplier Risk Rating</em></p>
<p>D&amp;B notes further that their company data records include Diversity Indicator data, which may be valuable to some companies, particularly if they do business with state or Federal government.  This allows report creation that could array your company’s supplier and partner portfolio along such lines as:</p>
<ul>
<li>Minority Owned</li>
<li>Female Owned</li>
<li>Historically Underutilized</li>
<li>Veteran Business</li>
</ul>
<p>One of the most often sought and infrequently delivered features of DoubleCheck’s TPRM is the individual Vendor Scorecard, shown in Figure 4; think of it as a single panel display summarizing all the key information about an individual third party.  This detail can be exceptionally useful for procurement, legal, and operations, in addition to risk managers.</p>
<p><img loading="lazy" decoding="async" class="alignnone  wp-image-2610" src="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Vendor-Summary-Scorecard-APRIL-300x178.jpg" alt="" width="602" height="357" srcset="https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Vendor-Summary-Scorecard-APRIL-300x178.jpg 300w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Vendor-Summary-Scorecard-APRIL-1024x607.jpg 1024w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Vendor-Summary-Scorecard-APRIL-150x89.jpg 150w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Vendor-Summary-Scorecard-APRIL-768x455.jpg 768w, https://www.doublechecksoftware.com/wp-content/uploads/2021/03/Vendor-Summary-Scorecard-APRIL.jpg 1326w" sizes="(max-width: 602px) 100vw, 602px" /></p>
<p><em>Figure 4  Vendor Summary Scorecard</em></p>
<p>This single vendor summary shows the current risk profile of the third party, review cycles, contact information recommended and remedial actions all in one place.  In the future, it may include Diversity Indicators too. The fields provide links to underlying detail and afford a business-centric reference point from which you can explore the current and forthcoming posture of a critical vendor to your business. There are two pieces of useful information based on that Supplier Risk value from D&amp;B.  The area plot (Failure Risk Population) displays your entire third party (TP) population, showing counts of TPs in each risk category.  The large triangle below the array shows where this particular vendor falls on that same scale.  This simple graphic tells you the Supplier risk for this vendor, in the context of where that value falls related to all your other vendors. Many business questions about a third party can be resolved from the information access through this “single entity portal” into the information gathered, assessed, and the state of resulting recommendations to date.</p>
<p>Beyond these included standardized displays are the access to ad hoc reporting through an embedded reporting engine.  The normal data gathering associated with third party risk assessment builds a substantial data pile, and the inclusion of financial and other data from D&amp;B<sup>®</sup> Direct further enriches this cache.  Ad hoc reporting tools let you easily create custom analyses to summarize remediations by risk category and third party, build risk assessment calendars that can be shared with prospective SME’s (subject matter experts) so resource scheduling does not disrupt the risk process, and much more.</p>
<p>The DoubleCheck TPRM solution provides a feature rich tool for identifying, assessing, and managing third party risk. It provides the means to answer the key business questions necessary to integrate its features and data with other risk practices across the enterprise. Policy dictates through your processes can easily be modeled using workflow tools. Through easily understood operating panels it offers a straightforward and east-to-learn process configurable to your own practices.  Ease of use is a critical requirement for TPRM solutions, one that can sometimes make a difference in participation by small firms or ones with minimal technological resources to spare for such administrative processes. Outward facing resources toward the third party supplier are as important as those offering efficiencies and operating ease within your organization.  Further, this module will integrate seamlessly with other platform modules of the DoubleCheck GRC suite so that data shares rather than replicates. Together with its D&amp;B<sup>®</sup> Direct embedded services, it can assure a single authoritative source for risk information unencumbered by the burdensome needs to oversee complex and expensive data currency and duplication practices. If you are looking for automation tools to assist your TPRM processes, this is a worthy contemporary offering to consider for your company.</p>
<p><a href="#_ftnref1" name="_ftn1">[1]</a> This integration includes all current versions of D&amp;B<sup>®</sup> Direct including D&amp;B<sup>®</sup> Direct 2.0, and forthcoming D&amp;B<sup>®</sup> Direct+</p>
<p>About the Author:</p>
<p>Simon Goldstein is an accomplished senior executive blending both technology and business expertise to formulate, impact, and achieve corporate strategies. A retired senior manager of Accenture’s IT Security and Risk Management practice, he has achieved results through the creation of customer value, business growth, and collaboration. An experienced change agent with primary experience in financial, technology, and retail industries, he’s led efforts to achieve ISO2700x certification and HIPAA compliance, as well as held credentials of CRISC, CISM, CISA.</p>


<div class="wpforms-container wpforms-container-full" id="wpforms-116"><form id="wpforms-form-116" class="wpforms-validate wpforms-form" data-formid="116" method="post" enctype="multipart/form-data" action="/tag/db/feed/" data-token="4526f5187a4fd274e5828ab6f518dbcd" data-token-time="1784948433"><div class="wpforms-head-container"><div class="wpforms-title">Newsletter Signup</div><div class="wpforms-description">Interested in being informed when a new blog post is released?</div></div><noscript class="wpforms-error-noscript">Please enable JavaScript in your browser to complete this form.</noscript><div class="wpforms-field-container"><div id="wpforms-116-field_0-container" class="wpforms-field wpforms-field-name" data-field-id="0"><label class="wpforms-field-label" for="wpforms-116-field_0">Name <span class="wpforms-required-label">*</span></label><div class="wpforms-field-row wpforms-field-medium"><div class="wpforms-field-row-block wpforms-first wpforms-one-half"><input type="text" id="wpforms-116-field_0" class="wpforms-field-name-first wpforms-field-required" name="wpforms[fields][0][first]" required><label for="wpforms-116-field_0" class="wpforms-field-sublabel after">First</label></div><div class="wpforms-field-row-block wpforms-one-half"><input type="text" id="wpforms-116-field_0-last" class="wpforms-field-name-last wpforms-field-required" name="wpforms[fields][0][last]" required><label for="wpforms-116-field_0-last" class="wpforms-field-sublabel after">Last</label></div></div></div><div id="wpforms-116-field_1-container" class="wpforms-field wpforms-field-email" data-field-id="1"><label class="wpforms-field-label" for="wpforms-116-field_1">Email <span class="wpforms-required-label">*</span></label><input type="email" id="wpforms-116-field_1" class="wpforms-field-medium wpforms-field-required" name="wpforms[fields][1]" spellcheck="false" required></div><div id="wpforms-116-field_2-container" class="wpforms-field wpforms-field-text" data-field-id="2"><label class="wpforms-field-label" for="wpforms-116-field_2">Company</label><input type="text" id="wpforms-116-field_2" class="wpforms-field-medium" name="wpforms[fields][2]" ></div>		<div id="wpforms-116-field_4-container"
			class="wpforms-field wpforms-field-text"
			data-field-type="text"
			data-field-id="4"
			>
			<label class="wpforms-field-label" for="wpforms-116-field_4" >Title Name Email</label>
			<input type="text" id="wpforms-116-field_4" class="wpforms-field-medium" name="wpforms[fields][4]" >
		</div>
		<div id="wpforms-116-field_3-container" class="wpforms-field wpforms-field-text" data-field-id="3"><label class="wpforms-field-label" for="wpforms-116-field_3">Title</label><input type="text" id="wpforms-116-field_3" class="wpforms-field-medium" name="wpforms[fields][3]" ></div><script>
				( function() {
					const style = document.createElement( 'style' );

					style.appendChild( document.createTextNode( '#wpforms-116-field_4-container { position: absolute !important; overflow: hidden !important; display: inline !important; height: 1px !important; width: 1px !important; z-index: -1000 !important; padding: 0 !important; } #wpforms-116-field_4-container input { visibility: hidden; } #wpforms-conversational-form-page #wpforms-116-field_4-container label { counter-increment: none; }' ) );
					document.head.appendChild( style );
					document.currentScript?.remove();
				} )();
			</script></div><!-- .wpforms-field-container --><div class="wpforms-field wpforms-field-hp"><label for="wpforms-116-field-hp" class="wpforms-field-label">Website</label><input type="text" name="wpforms[hp]" id="wpforms-116-field-hp" class="wpforms-field-medium"></div><div class="wpforms-submit-container" ><input type="hidden" name="wpforms[id]" value="116"><input type="hidden" name="page_title" value="D&amp;B"><input type="hidden" name="page_url" value="https://www.doublechecksoftware.com/tag/db/feed/"><button type="submit" name="wpforms[submit]" id="wpforms-submit-116" class="wpforms-submit" data-alt-text="Sending..." data-submit-text="Keep Me Informed" aria-live="assertive" value="wpforms-submit">Keep Me Informed</button></div></form></div>  <!-- .wpforms-container --><p>The post <a href="https://www.doublechecksoftware.com/a-look-at-doublechecks-approach-to-tprm-third-party-risk-management/">A Look At DoubleCheck’s Approach to TPRM  (Third Party Risk Management)</a> first appeared on <a href="https://www.doublechecksoftware.com">DoubleCheck Software</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://www.doublechecksoftware.com/a-look-at-doublechecks-approach-to-tprm-third-party-risk-management/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">2600</post-id>	</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Content Delivery Network via N/A
Lazy Loading (feed)
Minified using Disk
Database Caching using Disk (Request-wide modification query)

Served from: www.doublechecksoftware.com @ 2026-07-24 23:00:33 by W3 Total Cache
-->