On Demand Events

Missed a recent webinar or Member Forum Call? Catch our previous virtual sessions here. We now offer CPEs from most of our on-demand offerings. To earn CPEs, please submit your information and codes in the form linked below. Note: our on-demand recordings work best when viewed in the Chrome browser.

All On-demand Events

Fireside Chat – Innovations In Third Party Risk Processes: Application Security Controls

Join Tom Garrubba and Paul Poh for a lively discussion about innovations that could change the way application developers approach common security pitfalls.

This session will explore application security best practices, and how adherence to these practices can prevent putting company networks, systems, and data at risk.

Cost: Free / Credits: 1 CPE
Speakers:
  • Tom Garrubba
    Director, TPRM Professional Services, Echelon Risk + Cyber
    Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
    View full bio
  • Paul Poh
    Managing Partner, Radical Security
    Paul Poh is a Managing Partner at Radical Security with over 25 years of technology and information security experience. He provides advisory CISO services for several public and private companies. His past roles include Chief Technology Officer and Head of Information Security and Software Architecture.
    View full bio
Register to Watch

Vendor Risk Management Maturity Benchmark Study

Study results and analysis will be discussed pertaining to the 6th Shared Assessments Vendor Risk Management Maturity Benchmark Study. The study was conducted on behalf of Shared Assessments in the United States and United Kingdom by the Ponemon Institute, a widely recognized leader in risk management research. Survey responses will help practitioners gauge the maturity of their own third-party risk management (TPRM) program against others at a sector level.

Cost: Free / Credits: 1 CPE
Speakers:
  • Gary Roboff
    Senior Advisor, Shared Assessments
    Gary Roboff is a Senior Advisor to Shared Assessments where he focuses on payments, risk management, mobile financial services, and information management. Gary has almost four decades of experience in financial services planning and management, including 25 years at JP Morgan Chase where he retired as Senior Vice President of Electronic Commerce. Gary has worked extensively in electronic payments, payments fraud, third party risk management, privacy, and information utilization, as well as business frameworks and standards for electronic commerce applications.
    View full bio
  • Dr. Larry Ponemon
    Founder, Ponemon Institute
    Dr. Larry Ponemon is the Chairman and Founder of the Ponemon Institute, a research “think tank” dedicated to advancing privacy, data protection and information security practices. Dr. Ponemon is considered a pioneer in privacy auditing and the Responsible Information Management (RIM) framework. Security Magazine named him one of the “Most Influential People for Security.”
    View full bio
Become a Member to Watch

Geopolitical Events and Third Parties: How to Effectively React Across the Supply Chain

Third parties operate globally, in unpredictable landscapes and geographies. As localized geopolitical events emerge, businesses need to react and adjust to ensure resilience of the supply chain and supporting parties.

This session will explore how to:
  • Identify third parties impacted by geopolitical events
  • Respond to events in a timely and proportionate manner
  • Reduce the impact to key business functions

  • Cost: Free / Credits: 1.5 CPEs
    Speakers:
    • Alastair Parr
      Senior Vice President, Global Products & Risk, Prevalent
      Alastair Parr is responsible for ensuring that the demands of the market space are considered and applied innovatively within the Prevalent portfolio. He comes from a governance, risk and compliance background; developing and driving solutions to the ever-complex risk management space. He brings over 12 years of experience in product management, consultancy, and operations deliverables.
      View full bio
    • Tom Garrubba
      Director of TPRM Services, Echelon Risk + Cyber
      Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
      View full bio
    Register to Watch

    Managing Your Supply Chain Risk

    Modern businesses rely on numerous third parties and their supply chains to keep their businesses running. But many lack robust processes to assess and understand how these supply chains can pose additional risks. Understanding these risks to the supply chain enables businesses to take advantage of tried-and-true strategies that mitigate risk.

    This session will feature third-party risk leaders to discuss trends in the supply chain.

    Topics to be discussed include:
  • Techniques for addressing supply chain risks
  • Challenges – global footprint, supply chain complexity, cyber-attacks, regulations…
  • Environmental, Social and Governance (ESG) – collaboration opportunities ,etc.
  • Integrating and leveraging IT/OT processes, technologies and solutions
  • Standardizing due diligence, risk assessments, standards (ISO, ISA 62443, …)
  • Improving efficiencies and reducing costs
  • Addressing organizational silos, process / technology solution integration, risk mitigation, and communication challenges

  • Cost: Free / Credits: 1 CPE
    Speakers:
    • Jeffrey Wheatman
      Cyber Risk Evangelist, Black Kite
      A strategic thought leader with extensive expertise in cybersecurity, Jeffrey Wheatman is regarded foremost as an expert in guiding public sector clients and Fortune 500 companies in connection with their cyber risk management programs. In his current role as Cyber Risk Evangelist at Black Kite, Jeffrey works to get the message out about the business impact of third-party risk and solutions to treat those risks. Prior to joining Black Kite, Jeffrey was a Vice President in Gartner’s Research and Advisory Group for 15 years, where he worked with clients to build and improve their security programs, assessing risk, focusing on reporting on program status, stakeholder engagement, and bridging the connection between technology and cybersecurity risk. Jeffrey has authored approximately 150 research notes read by more than 6,000 clients. For four years, Jeffrey also served as the Chair of the North America Security and Risk Management Summit, Gartner’s 2nd largest conference with 4000 attendees annually. Earlier in his career, Jeffrey contributed as Practice Manager, Information Security for Gotham Technology Group, and as a Principal Consultant, Information Security, with ThruPoint, Inc.
      View full bio
    • Tom Garrubba
      Vice President, Shared Assessments
      Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
      View full bio
    Register to Watch

    Standardized Information Gathering Questionnaire (SIG) and Secure Controls Framework (SCF): Mapping Strong Connections ​

    With the 2023 Third Party Risk Management Product launch, Shared Assessments anticipates expanding the existing content library in the SIG, by traditional and vetted means, using the SCF as a springboard for alignment with even more authoritative sources. The member forum call will allow attendees to view the partnership between Shared Assessments and SCF and what that means for developing content and expanding our content resources.

    Cost: Free / Credits: 1 CPE
    Speakers:
    • Colleen Milazzo
      Senior Vice President, TPR Software Products, Shared Assessments
      Colleen leads the TPRM software team in the development of software products/tools for third party risk assurance. Colleen has over 20 years of experience within the financial services industry and consulting. She has led programs associated with risk management, procurement/contract negotiation, mergers and acquisitions, and business process reengineering. She has regulatory and global experience executing portfolios to meet the corporate strategy.
      View full bio
    • Ronald Parham
      Vice President of Risk Regulations & Compliance, Shared Assessments
      Ronald Parham is the Vice President of Risk Regulations & Compliance at Shared Assessments where he manages regulatory mapping where he provides members with materials to assist them and their third-party partners in navigating the risk and regulatory landscape.
      View full bio
    • Tom Cornelius
      Founder & Contributor, SCF
      Tom Cornelius currently serves as both the Senior Partner at ComplianceForge and Senior Director at the Secure Controls Framework (SCF) Council. He brings over two decades of leading teams of professionals and innovating solutions to complex problems in both the public and private sectors.
      View full bio
    Become a Member to Watch

    Peeking Over the TPRM Resilience Regulatory Horizon

    After nearly two years of responding to constant disruption, many organizations are now reevaluating how their TPRM programs comply with surging regulations and adapt and respond to emerging risks. So, what's over the horizon for TPRM and resilience?

    In this session, experts will examine regulatory TPRM/Resilience expectations, with a focus on the US, Europe, and the Monetary Authority of Singapore. We'll review DORA (Digital Operational Resilience Act) status, US regulatory response to last summer's request for comments, PRA and MAS activities, and ESG regulatory direction.

    Cost: Free / Credits: 1 CPE
    Speakers:
    • Gary Roboff
      Senior Advisor, Shared Assessments
      Gary Roboff is a Senior Advisor to Shared Assessments where he focuses on payments, risk management, mobile financial services, and information management. Gary has almost four decades of experience in financial services planning and management, including 25 years at JP Morgan Chase where he retired as Senior Vice President of Electronic Commerce. Gary has worked extensively in electronic payments, payments fraud, third party risk management, privacy, and information utilization, as well as business frameworks and standards for electronic commerce applications.
      View full bio
    • Tom Garrubba
      Vice President, Shared Assessments
      Tom Garrubba, Vice President, is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
      View full bio
    Register to Watch

    How Risk Leaders Mitigate ESG Risk In Their Supply Chains and Expedite Due Diligence

    As more companies incorporate ESG across corporate programs, third party risk managers need to explore how new ESG regulations and standards will impact their third party risk management programs. This session will examine how risk leaders can shift to adopt ESG principles. Panelists will share best practices and emerging research on how to mitigate ESG Risk to ensure due diligence in their third party risk programs.

    Cost: Free / Credits: 1 CPE
    Speakers:
    • Colleen Milazzo
      Senior Vice President, TPR Software Products, Shared Assessments
      Colleen leads the TPRM software team in the development of software products/tools for third party risk assurance. Colleen has over 20 years of experience within the financial services industry and consulting. She has led programs associated with risk management, procurement/contract negotiation, mergers and acquisitions, and business process reengineering. She has regulatory and global experience executing portfolios to meet the corporate strategy.
      View full bio
    • John Bree
      Chief Evangelist & Chief Risk Officer, Supply Wisdom
      John is Chief Evangelist & Chief Risk Officer with Supply Wisdom, the leading patented continuous risk intelligence and monitoring solution for third parties and locations. He is recognized as a global financial industry executive and risk subject matter expert, in vendor/third-party risk management, AML/CTF, KYC, and anti-fraud programs. Prior to joining Supply Wisdom, John held senior positions globally for Citi and Deutsche Bank covering corporate, investment, commercial and consumer banking. John is a member and co-moderator for RiskBoard.org, a member of the Shared Assessments US and UK Steering Committees and Co-Chair of the Financial Industry Vertical Strategy Group.
      View full bio
    • Fiona O'Brien
      Head of Outsourcing Oversight & Governance, Bank of Ireland Group
      Fiona O'Brien Is the Head of Outsourcing Oversight and Governance for the New Ireland Assurance Company part of the Bank of Ireland Group. She is responsible for the development and embedding of third-party risk management activities and raising the risks at Operational, Executive and Board Risk Committee levels to ensure clear visibility on the identification, assessment, monitoring, and reporting of third party risks. Her role also involves providing support and guidance to the leadership team and business on sourcing decisions and risk management and engaging with the regulator as required. Fiona has a history of working in the financial services industry and has wide and varied experience in managing risk in senior roles within Change, IT, Risk, Compliance, and Mortgage and Investment operations. In recent years she set up the Group Supplier Due Diligence function responsible for the oversight and assessment of all the Groups material suppliers. Prior to that, she set up and led the Group's 3rd Party BCM assurance function.
      View full bio
    Register to Watch

    Third Party Business Continuity and Disaster Recovery Programs

    Business Continuity is constantly under attack from rising natural disasters, software and hardware failures, escalating and increasing instances of cyberattacks, and all the risks that accompany them. The effects of any one of these events could be devastating. While there is no sure way to avoid certain risks, there are things you can do to protect your business from any potential fallout that may follow.

    In this session, we will uncover the business resilience risks that you are inheriting from your third parties and discuss how to create a disaster recovery plan that can address these ever-growing threats.

    Cost: Free / Credits: 1 CPE
    Speakers:
    • Teresa C. Lindsey
      Senior Consultant, Shared Assessments
      Teresa is a Senior Consultant with Shared Assessments specializing in Resilience and Continuity and Third Party Risk Management. T (as she is called) has more than 30 years of experience developing business resilience, continuity and incident management best practices within the financial services industry. T is also a serial retiree having most recently retired in 2019 from Citizens Financial Group (CFG) where she served as Executive Vice President and Head of Resilience, Recovery and Crisis and Chief of Staff in Corporate Security & Resilience (CS&R). T served as the thought leader shaping the Resilience agenda for Citizens Financial Group, including Business Resilience and Continuity, IT Resilience, Disaster Recovery and Incident Management. T’s chief responsibility was to ensure the continuity of operations should any event or situation disrupt – or threaten to disrupt – the delivery of financial services, and/or profoundly and negatively impact public confidence in the Group. T also served as Chief of Staff to the Bank’s Chief Security Officer, serving as her delegate in protecting the bank’s physical and digital security. Upon her retirement, T received certificates of appreciation from the Governor of the State of Rhode Island, the Rhode Island Alliance for Business Resilience and the Head of the Federal Emergency Management Agency (FEMA). Prior to joining CFG, T had retired from RBS Group in 2009, where she was the Global Head of Business Continuity.
      View full bio
    • Robert Stebbins
      Senior Manager of Business Resilience & Disaster Recovery, Citizens Bank
      Robert is a Senior Manager at Citizens Bank specializing in Business Resilience and Disaster Recovery for the organization. Bob has more than 35 years of experience in the financial services industry developing technology solutions to support the recoverability, availability, and needs of the business. In his current role at Citizens bank, Bob is responsible for ensuring internal compliance with the bank’s disaster recovery program and for compliance by critical third parties with the bank’s disaster recovery policies. Bob is also a key contributor to the data center strategy and architecture teams as well as the Cloud governance and oversight board. Prior roles at Putnam Investments, included disaster recovery compliance, data architect, and imaging design lead. Bob is an active member of the Rhode Island Alliance for Business Resilience and his local Community Emergency Response Team (CERT). 
      View full bio
    Register to Watch

    ESG Challenges in TPRM Programs

    The Member Forum Call will be a high-level summary from our 2022 pre-summit workshop focusing on maturing third party risk management sustainability practices in today’s fast paced ESG arena.

    Panelists will speak about fast changing ESG frameworks, policies, metrics, procedures, and regulations.

    Cost: Free / Credits: 1 CPE
    Speakers:
    • Gary Roboff
      Senior Advisor, Shared Assessments
      Gary Roboff is a Senior Advisor to Shared Assessments where he focuses on payments, risk management, mobile financial services, and information management. Gary has almost four decades of experience in financial services planning and management, including 25 years at JP Morgan Chase where he retired as Senior Vice President of Electronic Commerce. Gary has worked extensively in electronic payments, payments fraud, third party risk management, privacy, and information utilization, as well as business frameworks and standards for electronic commerce applications.
      View full bio
    • Charlie Miller
      Senior Advisor, Shared Assessments
      Charlie Miller is a frequent speaker and a recognized expert in third party risk. His key responsibilities include expanding the Shared Assessments Third-Party Risk Management membership-driven program, facilitating thought leadership, industry vertical strategy groups, continuous monitoring / operational technology working groups, and loT research studies.
      View full bio
    • Colleen Milazzo
      Senior Vice President, TPR Software Products, Shared Assessments
      Colleen leads the TPRM software team in the development of software products/tools for third party risk assurance. Colleen has over 20 years of experience within the financial services industry and consulting. She has led programs associated with risk management, procurement/contract negotiation, mergers and acquisitions, and business process reengineering. She has regulatory and global experience executing portfolios to meet the corporate strategy.
      View full bio
    Become a Member to Watch

    Third Party Service Inherent Risk

    The TPRM process of utilizing a third party requires the identification and classification of the services to determine the inherent risk associated with those services provided.

    Panelists will cover the techniques that are required for TPRM organizations to identify the potential risks and classify that risk with its ratings which drives the frequency and depth of due diligence activities.

    Cost: Free / Credits: 1 CPE
    Speakers:
    • Colleen Milazzo
      Senior Vice President, TPR Software Products, Shared Assessments
      Colleen leads the TPRM software team in the development of software products/tools for third party risk assurance. Colleen has over 20 years of experience within the financial services industry and consulting. She has led programs associated with risk management, procurement/contract negotiation, mergers and acquisitions, and business process reengineering. She has regulatory and global experience executing portfolios to meet the corporate strategy.
      View full bio
    • Andrew D'Angelo
      Associate Director, Protiviti
      Andrew D'Angelo is an Associate Director in Protiviti’s New York Data Security and Privacy practice, with a focus on third-party risk management and data security. In addition to helping lead Protiviti’s third party risk managed service offering, he has supported clients along the journey of designing, implementing, and monitoring a variety of information security and compliance management programs across different industries. Andrew is also a regular participant in third-party risk thought leadership at the Shared Assessments.
      View full bio
    • Jill Ray
      Director of Third Party Risk Management, SEI Investments
      Jill leads SEI’s Third Party Risk Management Program. Jill has 10 years of experience with third party risk management in the financial services industry. Her background includes oversight of activities across the entire vendor lifecycle, as well as responsibilities related to program design, regulatory examinations, and third party systems implementation. Jill is also a Certified Third Party Risk Professional (CTPRP.)
      View full bio
    Become a Member to Watch
    1 8 9 10 11 12 15