US Banks Face New Vendor Risk Guidance

Four US financial regulators have proposed new third-party risk management guidance aimed at helping banks and credit unions tailor vendor oversight to the actual risks posed by individual third-party relationships. The proposal was issued by the Office of the Comptroller Read More …

Security Risk Management Extends Beyond Illegal Mining

Security risk management in the mining sector is evolving beyond the traditional focus on illegal mining, encompassing a broader spectrum of operational, environmental, and strategic risks. The article highlights the need for a more comprehensive and integrated approach to managing Read More …

Banks Face New Third-Party Risk Rules

US federal banking regulators have proposed revised guidance for third-party risk management, seeking to replace existing guidance with a more risk-based framework for banks and credit unions. The proposal was issued jointly by the Office of the Comptroller of the Read More …

DORA Tightens Vendor Risk Rules

The European Union’s Digital Operational Resilience Act (DORA) is making third-party and ICT vendor risk management a formal regulatory responsibility for financial institutions, increasing the importance of documented controls, contractual safeguards and continuous oversight. DORA strengthens requirements around how financial Read More …

Online Certificate Course in Third Party Vendor Risk Management

Third Party Vendor Risk Management

Struggling to keep third party vendor risk in check? Smart Online Course, in association with Risk Management Association of India (RMAI) offers the Online Certificate Course in Third Party and Vendor Risk Management. This 6-hour online course empowers you with Read More …

Case Study: The 2025 Salesforce CRM Breach Wave

Google, Air France/KLM, Workday and TransUnion – When Third-Party SaaS Becomes the Weakest Link leading to Salesforce CRM Breach Why Salesforce CRM Breach case matters In mid–2025, a coordinated cyber campaign hit dozens of major enterprises by targeting their Salesforce Read More …

Fourth-party risk: Why your supply-chain security and risk assessments need a wider lens

The concept of fourth-party risk is increasingly relevant for organisations that rely on extended supply chains and multi-layer subcontracting. In the article by Russell McVeagh, a prominent New Zealand law firm, the authors argue that firms must look beyond their Read More …

RegTech Interventions in Vendor Risk Management

Vendor Risk Management (VRM) or Third-Party Risk Management (TPRM) is emerging as a key focus area for the Enterprise Risk Management team in the recent years. Mitigation of Third-party Risk is becoming increasingly challenging given the interconnected Business environment. Also, Read More …

Your vendors are likely your biggest cyber security risk

As speed of business increases, more and more organizations are looking to either buy companies or outsource more services to gain market advantage. With organizations expanding their vendor base, there is a critical need for holistic third-party risk management (TPRM) and comprehensive Read More …

Practical tips to minimize third-party vendor risks to your business

Businesses across most industries are becoming increasingly reliant on third-party vendors to support critical business functions, but with the granting of access to a business’s internal networks comes cyber risks and data breach threats. In fact, more than 50% of Read More …