Enterprise Third Party Risk Management

Enterprise Third Party Risk Management focuses on assessing, managing and monitoring third party risks beyond cyber and data privacy risk domains

Enterprise TPRM Program Design and Implementation


KPMG in India assists global and national majors in designing, establishing, and operationalising Enterprise TPRM programme. The programme vision and services are designed based on the client’s organisational priorities and may include achieving a faster onboarding, improved focus on risk and quality, regulatory compliance and enhanced user experience for stakeholders (including internal and external).

 

Our Sevice Offerings

Design

Support in establishing and/or uplifting of Enterprise Third Party Risk Management programme in line with the industry-leading practices and regulatory requirements.

Design

Operate

Support in executing newly designed and/or uplifted Enterprise TPRM framework elements covering pre-screening, service risk profiling, risk assessments, contracting, ongoing monitoring, issue management and termination.
Operate

Transform

Support in implementing technology platform to automate Enterprise TPRM processes to gain operational efficiency and better utilisation of resources.

Transform

Enabling Enterprise TPRM Programme

Enterprise TPRM services are designed to provide coverage to various entity types, address risks across the spectrum, and enable risk management throughout the third party relationship lifecycle.

The Enterprise TPRM framework is enabled by policies, procedures, technology, and organisation construct to monitor programme metrics through strategic and operational dashboards.

Entity Scope

  • Vendor
  • Affiliates
  • Joint Ventures
  • Distributor
  • Business Partner

Third party risk domains

  • Environmental, social, governance risk
  • Reputational risk
  • Legal risk
  • Operational/supply risk
  • Financial Viability risk
  • Subcontractor/ Fourth Party risk
  • Technology/Cyber risk
  • Country risk
  • Regulatory risk
  • Concentration risk
  • Compliance risk
  • Strategic risk

Third party lifecycle phases

Inherent risk assessment > Due diligence > Contracting > Ongoing monitoring > Termination

Foundations of TRPM program:

Policies and procedures

Organisations, people, skills and training

Governance and program effectiveness

Data and reporting processes

Enabling Technology

Why KPMG in India?

We have in-house digital assets that are primarily leveraged to assess and manage non-cyber risk domains on top of the assets covered as part of TPRM (cyber focused) service offering:

Third Party Security Managed Continuous Assessment and Monitoring

  • Enables automated assessment of control implementations across multiple components
  • Enables monitoring of fourth party risk via the 'inheritance' concept
  • Facilitates scalable sharing of control information from third parties to clients

KPMG Diligence & Analytics System

  • User-friendly web-based interface to submit and receive due diligence requests
  • Access to a historical record of all due diligence reports
  • View key workflow and risk data on completed requests through interactive dashboards

KPMG Vendor Assessment & Compliance Hub

  • Simplified process for risk assessments and efficiency to reduce duplicate efforts
  • Evidence tracking notification and automated remainders
  • One-Stop controls and evidence repository

Select Credentials

Key Contacts

Connect with us

Contact our specialists for more information

connect with us