ERM Approach to Vendor Risk Management

greatwallofchina.png?width=230What the Great Wall of China can teach us about Vendor Risk Management

vendor risk management approach is all about creating centralized standards that transcend business silos, which is very different from the approach taken in traditional vendor management software. Vendor management needs tools with a risk-based approach to overcome their difficulty of objectively putting the vendor compliance pieces together across legal, purchasing , security reviews, and accounts payable silos for contract renewals and new contracts. Too many controls and oversight are dedicated to addressing low likelihood risks, leaving vendor management with inadequate time to identify and focus resources on the risks that matter the most.

History repeats itself. The Great Wall of China itself was never breached. However, during an inside job, a traitor opened a gate for invaders at a strategic Shanghai pass, leading to the downfall of the Ming Dynasty!

In today's terms, most companies perform rigorous vendor due diligence with penetration tests, SAEE 16 and insurance certifications, financial reviews, etc. More often than not, however, the vendor breach is through employee emails, data stored at homes or other poor operational controls that are not reviewed during the vendor due diligence process. The root cause risks need to be assessed in context of the business process that relies upon them to prioritize mitigation activities.

Ask yourself what part of your enterprise does not, in some way, depend upon a vendor and its products and services to run effectively. The big loser in not having a vendor risk management approach, beyond the vendor management function, are the business stakeholders. Count the hundreds of hours lost unnecessarily by teams performing compliance activities on low risk vendors and multiple of that number lost due to the delays of getting the key high value vendors they need in place to support their business because they are caught up in a low value compliance process. When you add up these opportunity costs, the disproportionate imbalance between risk and reward is staggering for a non-risk based approach.

ERM software supporting vendor management recognizes that due diligence of a contract renewal is a risk assessment, that the contract terms are risk mitigation activities for those risks and SLA’s are just another name for risk monitoring activities. The ERM vs GRC approach uses risk assessments to tell you which clauses need to be added to your contract renewal and what monitoring activities need to go into place. A risk-based vendor management approach is more strategic by connecting the touch points between vendors and the business processes, risks, controls, monitoring, incidents and reporting that take place across the enterprise and their impact on the bottom line and corporate objectives.

By applying a common set of standards or risk assessment templates, ERM streamlines the communication, workflow, data collection and reporting on vendor management, compliance, purchasing, contracting, IT reviews and audit processes to reduce your overall time spent on these activities by 40-80% due to the unnecessary overlap and redundancies currently going on between these business silos. By collecting this information only once and using those relationships, an ERM approach turns all these activities into standardized libraries that can be used and reused over time without reinventing the wheel.

Resources should be allocated to the highest risk, not just another brick in an already overly reinforced wall.

Votes: 0
E-mail me when people leave their comments –

Steven Minsky, CEO and Founder of LogicManager, is a recognized thought leader in risk management. Steven is well known for his precinct abilities to guide organizations through future risk events. Steven is a frequent speaker in the Energy, Financial Services and Cyber industries. While the first wave of COVID-19 caught many organizations by surprise, Steven predicted the pandemic impacts in January of 2020 and swiftly published action plans to help organizations prepare.

You need to be a member of Global Risk Community to add comments!

Join Global Risk Community

    About Us

    The GlobalRisk Community is a thriving community of risk managers and associated service providers. Our purpose is to foster business, networking and educational explorations among members. Our goal is to be the worlds premier Risk forum and contribute to better understanding of the complex world of risk.

    Business Partners

    For companies wanting to create a greater visibility for their products and services among their prospects in the Risk market: Send your business partnership request by filling in the form here!

lead