On Demand Events

Missed a recent webinar or Member Forum Call? Catch our previous virtual sessions here. We now offer CPEs from most of our on-demand offerings. To earn CPEs, please submit your information and codes in the form linked below. Note: our on-demand recordings work best when viewed in the Chrome browser.

All On-demand Events

Forum Call

2023 TPRM Toolkit Review

The Shared Assessments Tool Development team and committees have spent the last year updating and upgrading the SIG, SCA, VRMMM, and Data Governance Tools just for you. Members will be the first to receive the special overview.

Cost: Free / Credits: 1.5 CPEs
Speakers:
  • Colleen Milazzo
    Senior Vice President, TPR Software Products, Shared Assessments
    Colleen leads the TPRM software team in the development of software products/tools for third party risk assurance. Colleen has over 20 years of experience within the financial services industry and consulting. She has led programs associated with risk management, procurement/contract negotiation, mergers and acquisitions, and business process reengineering. She has regulatory and global experience executing portfolios to meet the corporate strategy.
    View full bio
  • Andy Hout
    Vice President, Tool Development & Implementation, Shared Assessments
    Andy has more than 30 years in data communications/information security and is familiar with all types of systems and transport technologies. Using this knowledge, Andy has conducted hundreds of vendor assessments and implemented vendor risk management programs for several large clients.
    View full bio

Webinar

Third-Party Risk Assessments: Going Beyond Compliance Checks and IT Risk Management

In third-party risk management, to lower vendor and supplier risks to an acceptable level, practitioners must recognize which controls need to be in place. Understanding the types of vendors being onboarded and their potential inherent risks is key. This webinar will explore strategies for mitigating risk through consideration of crucial factors including location, type of data, and connection to the corporate network.

Cost: Free / Credits: 1 CPE
Speakers:
  • Nasser Fattah
    Senior Advisor, Shared Assessments
    Nasser has 20+ years as a Cybersecurity, Supply Chain, and IT leader. With a focus on customer-first and team-building approaches, Fattah is able to align programs to support company strategies, regulatory requirements, and growth initiatives. He drives cybersecurity, supply chain, and IT as enablers for enterprise-wide transformation initiatives. He partners with executives to identify and select strategic external partners to deliver essential IT and cybersecurity services to the business. Nasser worked with global parent companies and subsidiaries to establish technology standards to maximize investments and operations efficacy to best support business needs and growth. Nasser has a strong, consistent record working successfully with Business and IT executives, regulators, auditors, and risk partners. Nasser also teaches cybersecurity at several colleges and is the chair for North America Shared Assessments – an industry best practices for the supply chain.
    View full bio
  • Ken Wolckenhauer
    Vice President, Vendor Management, Nordea Bank, International Corporate Branches
    Ken Wolckenhauer is the head of Vendor Management at Nordea Bank’s International Corporate Branch network. Prior to that, he worked for the major FinTech, FIS, in its Financial Crimes solutions division, and in the retail money services business. At Nordea Bank, he built out the vendor management program for the International Division, helping to build a responsible supply chain in areas outside the Nordics. He worked with both building management and suppliers to develop environmentally sustainable programs at the branch. Wolckenhauer is a graduate of Bucknell University with an Associates from the University at Buckingham (UK), a Certified Third Party Risk Professional and a Certified Anti-Money Laundering Specialist.
    View full bio
  • Persio Reyes
    Cybersecurity & Technology Risk Management Executive , Société Générale
    Persio Reyes is currently a Cybersecurity & Technology Risk Management Executive for Société Générale in the Americas Group Chief Risk Office. Prior to joining Société Générale, Persio was the Americas BISO for all CTO aligned applications for three (3) years. Persio has extensive cybersecurity experience in both the First and Second Lines of Defense. Previously, he was the Head of Endpoint Security & Risk Management at a major investment bank. In these roles, Persio participated in various Working Groups as a key stakeholder in driving the Bank’s new Security Architecture. Persio is an accomplished Information Technology Executive with more than 15 years of technology experience in the financial services industry, and holds various industry certifications in InfoSec, cybersecurity and risk management Persio received his Bachelor of Arts in Economics from the City College of New York (CCNY) and his M.B.A. degree in Technology Management from the University of Phoenix.
    View full bio

Webinar

The Top 4 Ways to Ease Third-Party Vendor Onboarding In Risk Management

Vendor onboarding is an essential early step in the third-party risk management lifecycle. What types of risk insights are helpful as you establish approved providers of technology, goods, or services? What should a successful supplier onboarding process look like in your organization? This session, presented by Director, TPRM Professional Services, Echelon Risk + Cyber, and Alastair Parr, Senior Vice President of Global Products & Services at Prevalent, will:

  • • Identify challenges organizations face when onboarding new suppliers
  • • Explore the right metrics and risks to consider prior to onboarding a vendor including Cyber, Business, Hack/Breach, Financial, ESG, and Sanctions Intelligence
  • • Review the opportunities consolidated risk insights provide
Speakers:
  • Tom Garrubba
    Director, TPRM Professional Services, Echelon Risk + Cyber
    Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
    View full bio
  • Joe Toley
    Project Director, Prevalent
    Joe Toley is responsible for assisting organizations in operationalizing and maturing their Third Party Risk Management Programs. He joined Prevalent from 3GRC where he was instrumental in defining the services and deliverables to support the use of the risk management technology and prides himself in taking client requirements and translating them into achievable plans. He comes from an IT security background, with an original focus on data security and data loss prevention, before shifting his efforts to the Third Party Risk Management space 5 years ago.
    View full bio

Forum Call

Evolving Work Environments

The Covid-19 pandemic introduced considerable changes to third-party risk management processes. Vendors experienced evolutions in worker location, geographic dispersion, and resilience. Company cultures transformed as work-from-anywhere became a reality. This MFC will highlight the significant workplace shifts that have affected third-party risk management and recommend actionable next steps for practitioners.
Speakers:
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is an accomplished leader and trailblazer in third party risk management. As a practitioner and a senior risk management executive, he has driven a culture of accountability and diligence in safeguarding information. Andrew has more than 25 years in risk management and information security. He has contributed greatly to the transformation and advancement of risk management as a strategic function that intersects with and helps guide all aspects of organizations.
    View full bio
  • Avani Desai
    CEO, Schellman
    Avani Desai is a Chief Executive Officer at Schellman, the largest niche cybersecurity assessment firm in the world that focuses on technology assessments. Avani is an accomplished executive with domestic and international experience in information security, operations, P&L, oversight, and marketing involving both start-up and growth organizations. She has been featured in Forbes, CIO.com, and the Wall Street Journal, and is a sought-after speaker as a voice on a variety of emerging topics, including security, privacy, information security, future technology trends, and the expansion of young women involved in technology.
    View full bio

Webinar

Fourth Parties and Beyond: Managing Risk in the Extended Supply Chain

Just as managing the risk of your direct suppliers is critical, understanding the risk of your suppliers' suppliers is imperative. While you may work most directly with secure third-party vendors and platforms, unknown Fourth Parties (vendors of vendors) can cause significant disruptions to your business. How do you manage the threats posed by these Fourth or Nth Parties? Participants will learn practical ways to identify and manage fourth parties through an overview of the tools and techniques experienced risk professionals use to effectively measure and address risk across all levels of the supply chain.
Speakers:
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is an accomplished leader and trailblazer in third party risk management. As a practitioner and a senior risk management executive, he has driven a culture of accountability and diligence in safeguarding information. Andrew has more than 25 years in risk management and information security. He has contributed greatly to the transformation and advancement of risk management as a strategic function that intersects with and helps guide all aspects of organizations.
    View full bio
  • John Bree
    Chief Evangelist & Chief Risk Officer, Supply Wisdom
    John is Chief Evangelist & Chief Risk Officer with Supply Wisdom, the leading patented continuous risk intelligence and monitoring solution for third parties and locations. He is recognized as a global financial industry executive and risk subject matter expert, in vendor/third-party risk management, AML/CTF, KYC, and anti-fraud programs. Prior to joining Supply Wisdom, John held senior positions globally for Citi and Deutsche Bank covering corporate, investment, commercial and consumer banking. John is a member and co-moderator for RiskBoard.org, a member of the Shared Assessments US and UK Steering Committees and Co-Chair of the Financial Industry Vertical Strategy Group.
    View full bio
  • Michelle Clement
    Experienced Third Party Risk Professional,
    Michelle Clement is an experienced risk professional that has led global teams across the first and second lines of defense for many years. Her focus is on transforming third party risk frameworks to continue to meet the demands of large enterprises. At BlackRock, she led the Global Third Party Risk division and the Governance Infrastructure for Global Provider Strategy. Her career started in the Securities Lending within trading. She holds an MBA from San Francisco State in Strategic Management and a BA in Management Information Systems.
    View full bio
  • Charles Forde
    Head of Operational Risk, Nomura
    Charles has more than 25 years of experience in senior risk, technology and transformation roles at global banks, a Big 4 consultancy and at international organisations. He has extensive experience in designing, transitioning and leading risk and transformation programmes to drive efficiency and regulatory compliance. Currently, Charles is Head of Operational Risk at Nomura EMEA for Global Markets and Investment Banking.
    View full bio

Forum Call

Trends and Strategies for Procurement & Sourcing Cohesion

A big headache for many organizations is properly defining and aligning the third-party risk roles and responsibilities with the Procurement division. The Shared Assessments Procurement & Sourcing Working Group have been working diligently on identifying, defining, and aligning those roles and responsibilities to ensure cohesion of the onboarding, assessment, and monitoring processes. Attendees of this MFC will hear the results of our identified trends and strategies in tackling this ever-fluid challenge.

Cost: Free / Credits: 1 CPE
Speakers:
  • John Bree
    Chief Evangelist & Chief Risk Officer, Supply Wisdom
    John is Chief Evangelist & Chief Risk Officer with Supply Wisdom, the leading patented continuous risk intelligence and monitoring solution for third parties and locations. He is recognized as a global financial industry executive and risk subject matter expert, in vendor/third-party risk management, AML/CTF, KYC, and anti-fraud programs. Prior to joining Supply Wisdom, John held senior positions globally for Citi and Deutsche Bank covering corporate, investment, commercial and consumer banking. John is a member and co-moderator for RiskBoard.org, a member of the Shared Assessments US and UK Steering Committees and Co-Chair of the Financial Industry Vertical Strategy Group.
    View full bio
  • Tom Garrubba
    Director, TPRM Professional Services, Echelon Risk + Cyber
    Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
    View full bio

Webinar

Fireside Chat – Innovations In Third Party Risk Processes: Application Security Controls

Join Tom Garrubba and Paul Poh for a lively discussion about innovations that could change the way application developers approach common security pitfalls.

This session will explore application security best practices, and how adherence to these practices can prevent putting company networks, systems, and data at risk.

Cost: Free / Credits: 1 CPE
Speakers:
  • Tom Garrubba
    Director, TPRM Professional Services, Echelon Risk + Cyber
    Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
    View full bio
  • Paul Poh
    Managing Partner, Radical Security
    Paul Poh is a Managing Partner at Radical Security with over 25 years of technology and information security experience. He provides advisory CISO services for several public and private companies. His past roles include Chief Technology Officer and Head of Information Security and Software Architecture.
    View full bio

Forum Call

Vendor Risk Management Maturity Benchmark Study

Study results and analysis will be discussed pertaining to the 6th Shared Assessments Vendor Risk Management Maturity Benchmark Study. The study was conducted on behalf of Shared Assessments in the United States and United Kingdom by the Ponemon Institute, a widely recognized leader in risk management research. Survey responses will help practitioners gauge the maturity of their own third-party risk management (TPRM) program against others at a sector level.

Cost: Free / Credits: 1 CPE
Speakers:
  • Gary Roboff
    Senior Advisor, Shared Assessments
    Gary Roboff is a Senior Advisor to Shared Assessments where he focuses on payments, risk management, mobile financial services, and information management. Gary has almost four decades of experience in financial services planning and management, including 25 years at JP Morgan Chase where he retired as Senior Vice President of Electronic Commerce. Gary has worked extensively in electronic payments, payments fraud, third party risk management, privacy, and information utilization, as well as business frameworks and standards for electronic commerce applications.
    View full bio
  • Dr. Larry Ponemon
    Founder, Ponemon Institute
    Dr. Larry Ponemon is the Chairman and Founder of the Ponemon Institute, a research “think tank” dedicated to advancing privacy, data protection and information security practices. Dr. Ponemon is considered a pioneer in privacy auditing and the Responsible Information Management (RIM) framework. Security Magazine named him one of the “Most Influential People for Security.”
    View full bio

Webinar

Geopolitical Events and Third Parties: How to Effectively React Across the Supply Chain

Third parties operate globally, in unpredictable landscapes and geographies. As localized geopolitical events emerge, businesses need to react and adjust to ensure resilience of the supply chain and supporting parties.

This session will explore how to:
  • Identify third parties impacted by geopolitical events
  • Respond to events in a timely and proportionate manner
  • Reduce the impact to key business functions

  • Cost: Free / Credits: 1.5 CPEs
    Speakers:
    • Alastair Parr
      Senior Vice President, Global Products & Risk, Prevalent
      Alastair Parr is responsible for ensuring that the demands of the market space are considered and applied innovatively within the Prevalent portfolio. He comes from a governance, risk and compliance background; developing and driving solutions to the ever-complex risk management space. He brings over 12 years of experience in product management, consultancy, and operations deliverables.
      View full bio
    • Tom Garrubba
      Director of TPRM Services, Echelon Risk + Cyber
      Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
      View full bio

    Webinar

    Managing Your Supply Chain Risk

    Modern businesses rely on numerous third parties and their supply chains to keep their businesses running. But many lack robust processes to assess and understand how these supply chains can pose additional risks. Understanding these risks to the supply chain enables businesses to take advantage of tried-and-true strategies that mitigate risk.

    This session will feature third-party risk leaders to discuss trends in the supply chain.

    Topics to be discussed include:
  • Techniques for addressing supply chain risks
  • Challenges – global footprint, supply chain complexity, cyber-attacks, regulations…
  • Environmental, Social and Governance (ESG) – collaboration opportunities ,etc.
  • Integrating and leveraging IT/OT processes, technologies and solutions
  • Standardizing due diligence, risk assessments, standards (ISO, ISA 62443, …)
  • Improving efficiencies and reducing costs
  • Addressing organizational silos, process / technology solution integration, risk mitigation, and communication challenges

  • Cost: Free / Credits: 1 CPE
    Speakers:
    • Jeffrey Wheatman
      Cyber Risk Evangelist, Black Kite
      A strategic thought leader with extensive expertise in cybersecurity, Jeffrey Wheatman is regarded foremost as an expert in guiding public sector clients and Fortune 500 companies in connection with their cyber risk management programs. In his current role as Cyber Risk Evangelist at Black Kite, Jeffrey works to get the message out about the business impact of third-party risk and solutions to treat those risks. Prior to joining Black Kite, Jeffrey was a Vice President in Gartner’s Research and Advisory Group for 15 years, where he worked with clients to build and improve their security programs, assessing risk, focusing on reporting on program status, stakeholder engagement, and bridging the connection between technology and cybersecurity risk. Jeffrey has authored approximately 150 research notes read by more than 6,000 clients. For four years, Jeffrey also served as the Chair of the North America Security and Risk Management Summit, Gartner’s 2nd largest conference with 4000 attendees annually. Earlier in his career, Jeffrey contributed as Practice Manager, Information Security for Gotham Technology Group, and as a Principal Consultant, Information Security, with ThruPoint, Inc.
      View full bio
    • Tom Garrubba
      Vice President, Shared Assessments
      Tom Garrubba is an internationally recognized subject matter expert, lecturer, writer, and blogger on third-party risk, and is the head instructor for the Certified Third-Party Risk Professional (CTPRP) certification program. He is a contributor to Future of Sourcing, blogged for the Huffington Post’s Business section, and for Government Health IT, ISACA, Risk.net, and numerous eGRC websites.
      View full bio
    1 4 5 6 7 8 12