On Demand Events

Missed a recent webinar or Member Forum Call? Catch our previous virtual sessions here. We now offer CPEs from most of our on-demand offerings. To earn CPEs, please submit your information and codes in the form linked below. Note: our on-demand recordings work best when viewed in the Chrome browser.

All On-demand Events

Insurance Committee – Open to Members Only

This committee exchanges ideas, shares best practices, and identifies collaboration opportunities related to insurance-specific TPRM needs. Areas of interest include, but are not limited to, the complexity of Nth party relationships, the impact of climate change on complex supply chains, regulatory requirements for insurance firms, the complexity of assessing risks surrounding their client product offering(s), and additional assessments of existing service providers including agents, brokers, and managing general underwriters (MGU). Schedulers for this committee have been issued to committee members. If you are not part of this committee, please register your interest using the link below.

October 2025 Member Forum Call | From Burden to Advantage: Reframing Security Reviews Through a Trust Center

Security reviews are multiplying, but they don’t have to be a burden. Forward-looking organizations are turning client due diligence into an opportunity to deepen trust, reduce repetitive questionnaires, and free InfoSec teams to focus on higher-value risks.

In this session, leaders from Archer will share how they built a scalable model for transparency by operationalizing a Trust Center. We’ll explore how this approach has helped them simplify workflows, align security and business priorities, and transform third-party risk engagement from a reactive task into a strategic advantage.

Join this conversation to hear lessons learned and practical takeaways that can help your organization reimagine security reviews – not as overhead, but as a differentiator.
Speakers:
  • Kirsty Hart
    Head of Risk and Compliance , Archer
    Kirsty Hart is an Enterprise Risk Management (ERM) specialist with over a decade of experience in Operational Risk in Financial Services, with deep expertise in IT and Cyber Risk Management and currently is Head of Risk and Compliance at Archer.

    Prior to joining Archer, she spent five years as Head of Risk Reporting and Technology at a globally renowned Fintech, where she led the design and implementation of technology-enabled risk solutions and reporting frameworks at scale. Her experience also includes a strong focus on GRC technology, and how it can be leveraged to embed risk practices seamlessly into existing business processes.

    Kirsty brings a practical lens to risk, with a strong belief that risk management should enable decision-making—not obstruct it. She is especially interested in evolving risk practices to keep pace with emerging threats and opportunities, including the role of AI and automation in enhancing ERM capabilities. Kirsty focuses on building risk frameworks that are pragmatic, forward-looking, and aligned with business strategy.

    A firm advocate for demystifying risk, Kirsty focuses on accessibility, integration, and strategic alignment, ensuring risk supports the broader goals of the business while remaining responsive to a rapidly changing environment.
    View full bio
  • Chris McKillop
    GTM Sales Director, Responsive
    Chris McKillop serves as a GTM Sales Director at Responsive, where he focuses on advancing its Trust Center solution to help security professionals improve efficiency and collaboration through technology. He has extensive experience across cybersecurity, solutions engineering, and revenue enablement, with a primary focus on stakeholder assurance. Chris is an active member of the TPRM professional community and takes a people-first approach to solving challenges and driving success by sharing knowledge and fostering industry growth.
    View full bio
Become a Member to Watch

TPRM – Best Practices for Calculating Inherent Risk

Description Fact: Inherent risk is the most critical calculation in Third-Party Risk. When building an effective and efficient TPRM program, it's critical to understand which vendors, suppliers and business partners are most critical to your business operations, and which ones present the most risk. In times where TPRM resources are stretched thin, inherent risk helps your team prioritize which third parties get assessed, when they get assessed, and what's in scope. Join this webinar for expert advice and best practice on how to calculate inherent risk and put it to work for your program. Attendees will learn how to:

  • • Develop inherent risk calculations and a scoring methodology
  • • Tier your third parties by criticality and high risk
  • • Scope and schedule assessments based on inherent risk scores
  • • Leverage inherent risk ratings from assessment exchanges, data science and crowdsourcing
  • • Prepare for next-generation inherent risk powered by artificial intelligence

Don't miss your opportunity to benchmark your program against industry best practices. Register for your seat today.

Speakers:
  • Ed Thomas
    SVP, ProcessUnity
    Ed Thomas is a Senior Vice President at ProcessUnity, with an extensive background in Third-Party Risk Management. A seasoned expert in the field, Ed has years of experience guiding organizations on their journey to establish efficient and effective risk management programs. Combining his deep industry knowledge with practical insights, Ed aims to assist organizations in realizing the full potential of their TPRM programs.
    View full bio
  • Elizabeth Dunsmoor
    TPRM Principal, Shared Assessments
    Elizabeth Dunsmoor recently joined Shared Assessments as a TPRM Principal after 15 years as a TPRM practitioner. She has experience designing holistic programs and delivering assessment work within the cybersecurity, financial services, manufacturing, and healthcare sectors. With a proven ability to oversee and execute long-term operational strategies and methodologies for risk programs, Elizabeth is proficient in a variety of management actions including translating strategies into measurable plans, partnering with Procurement, corporate teams, and firm leaders to develop a pipeline of cross-functional leaders within the risk management function. She now provides training and guidance to business leaders to ensure understanding of program requirements, third-party capabilities, and performance expectations.
    View full bio
Register to Watch

Agility, Resilience, and the Unseen Flow: Mastering Third-Party Risk in the Spirit of The Water Book

Inspired by Miyamoto Musashi’s Water Book, this session reframes Third-Party Risk Management (TPRM) through the lens of adaptability and flow. Rather than relying on rigid frameworks and static controls, we’ll explore how resilience is built through agility—by anticipating disruption, not reacting to it. Like water, effective TPRM should be responsive, balanced, and constantly in motion. We’ll examine practical strategies for creating a flexible, intelligence-driven approach to managing third-party ecosystems—one that aligns with modern risk realities and moves beyond checkbox compliance. This is about shifting mindset. Because in a world where risk moves fast, rigidity fails—and resilience flows.
Speakers:
  • Bob Maley
    CSO, BlackKite
  • Jennifer Hancock
    SVP Professional Development & Education, Shared Assessments
    Jennifer Hancock is a third-party risk management professional with more than 20 years of experience in third-party risk management. As owner of Hancock Consulting LLC, a consultancy she founded to provide specialized advisory services, Ms. Hancock has been able to help organizations develop effective third-party risk management strategies and improve their overall resilience. Her expertise has been sought after by a wide range of clients across industries, and she is dedicated to helping organizations of all sizes manage their third-party risks effectively. As a thought leader in the field of third-party risk management, Ms. Hancock has been a featured speaker at numerous industry events and conferences. She is both a Certified Third-Party Risk Professional and a Certified Third-Party Risk Assessor (CTPRA).
    View full bio
Register to Watch

Top Risks Challenging TPRM Programs in 2025

While many of the top risks in today’s business environment are long-term in nature, there are also new and emerging dynamics within several traditional risk domains. This webinar will highlight those more fluid and changing nuances, providing insights into the top risks challenging today’s TPRM programs and suggesting potential actions for practitioners.
Speakers:
  • Rhonda K.R. Cook
    Senior Advisor, Shared Assessments
    Rhonda K.R. Cook is retired Chief Risk Officer for SEI Investments in Oaks, PA. She also served 4 years as Chair of the Investment Company Institute’s (ICI’s) Chief Risk Officer Committee. Over the course of her 25 years at SEI, Rhonda worked in a variety of client service, solution development, and risk management roles. She led projects in SEI’s Hong Kong and London offices, and she spent three years in New Delhi as SEI’s first Unit Leader, India. Rhonda has an M.B.A. from Northeastern University with a dual concentration in International Management and Innovation Entrepreneurship. Prior to joining SEI Investments, Rhonda graduated from the United States Military Academy at West Point; she served nine years as a Military Intelligence Officer in the U.S. Army, including multiple duty assignments in Europe, the Middle East, and Asia.
    View full bio
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is the CEO of Shared Assessments, a global membership organization that supports hundreds of companies, risk programs, and thousands of associated third-party and other risk professionals. As a risk practitioner and executive, he has driven a culture of accountability and diligence in safeguarding information and other assets for organizations and their third parties. He has more than 25 years of experience in risk management and information security.
    View full bio
Register to Watch

July 2025 Member Forum Call – Beyond the ROI Headache: How DORA is Reframing TPRM for the Digital Supply Chain Era

DORA’s Register of Information (ROI) requirement has introduced a new layer of operational complexity – but it may also be the industry’s best opportunity to link contract oversight with business context and risk prioritization. This session explores how the ROI format can help third-party risk programs move beyond compliance checklists and into meaningful engagement with stakeholders across the organization. By treating DORA not just as a mandate but as a model, organizations can strengthen digital supply chain resilience while improving transparency, alignment, and efficiency across ICT risk management efforts.
Speakers:
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is CEO of Shared Assessments, a global membership organization supporting risk, compliance, cyber, and third-party professionals. With over 25 years in risk management, he champions cultures of accountability across organizations and their third parties. Prior to joining in 2022, Andrew led vendor risk programs at Blackstone, BlackRock, and Citigroup, with global experience spanning all phases of the vendor lifecycle.
    View full bio
  • Dov Goldman
    Vice President of Risk Strategy , Panorays
    Dov is a serial entrepreneur who’s been involved with third-party risk programs of every scale, up to the largest enterprises. He is known as a thought leader who explains complex problems and their solutions in plain English. Many in the industry think of him as the “third party therapist” due to Dov’s intuitive grasp of third party risk leaders’ challenges, and his entertaining and informative approach as a speaker and writer.
    View full bio
  • Alok Haldar
    Head of TPSMO (Third-Party Supplier Management Office), Liberty Global Group
    Alok is the Head of Third-Party Supplier Management at Liberty, enabling a collaborative framework to manage risks. With over 17 years of pure risk experience, he's well versed in Information and Cyber Security, Technology and Data, Operational Resilience, Third Party Risk, Operational and Enterprise Risk Management across lines of defence. He previously worked with the London Stock Exchange Group and HSBC.
    View full bio
  • Martin Freeman
    Cyber Security and Compliance Managing Director, Calastone
    Martin is a dedicated Information Security Professional with 20 years’ experience and is passionate about his subject matter. He specializes in implementing Cyber Security / Information Security frameworks and has previously worked in both the Fast-Moving Consumer Goods and Fintech industries.
    View full bio
Become a Member to Watch

Elevating the Strategic Impact of Third-Party Risk Management, Part 2

Part 2 of "From Compliance to Confidence: Elevating the Strategic Impact of Third-Party Risk Management." Leaders from Archer and Shared Assessments will share insights on how third-party risk management (TPRM) can drive a resilient business model. TPRM is often perceived as a checkbox exercise driven by regulatory requirements and internal protocols. Organizations may view it as an important risk and compliance function but often allocate just enough attention and resources to keep it running. Yet TPRM holds far more potential when we move beyond the standard approach. When fully leveraged, it becomes a powerful tool for shaping strategic decisions and enhancing long-term performance. It can reveal critical insights into the value chain, highlight emerging risks, and uncover opportunities for growth and innovation. Watch this webinar to learn about: • The need to expand TPRM programs beyond basic compliance requirements. • The strategic advantages of integrating TPRM into enterprise risk management and long-term planning. • Improved decision-making and stronger operational risk management enabled by unlocking the potential of a comprehensive TPRM approach.
Speakers:
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is the CEO of Shared Assessments, a global membership organization that supports hundreds of companies, risk programs, and thousands of associated third-party and other risk professionals. As a risk practitioner and executive, he has driven a culture of accountability and diligence in safeguarding information and other assets for organizations and their third parties. He has more than 25 years of experience in risk management and information security.
    View full bio
  • Tahmina Day
    Global Head ESG and TPRM solutions, Archer Technologies
    Tahmina Day is the Global Head ESG and TPRM solutions at Archer Technologies – a leading provider of GRC technology. In this role, she leads the development of Archer’s environmental, social and governance (ESG) solution and its integration with enterprise risk management. Tahmina also oversees one of Archer’s flagship products – third-party risk management (TPRM). With over 20 years of experience in risk management and sustainability, Tahmina spent more than 11 years as a Corporate Governance Officer in the ESG department of the International Finance Corporation (IFC). Prior to joining Archer, she held leadership roles in risk and compliance at CIT Group, Inc., Fannie Mae, and Seacoast Bank. Tahmina holds an MBA from the Darden School of Business at the University of Virginia and is a Certified Enterprise Risk Professional (CERP).
    View full bio
Register to Watch

Elevating the Strategic Impact of Third-Party Risk Management, Part 1

Leaders from Archer and Shared Assessments will share insights on how third-party risk management (TPRM) can drive a resilient business model. TPRM is often perceived as a checkbox exercise driven by regulatory requirements and internal protocols. Organizations may view it as an important risk and compliance function but often allocate just enough attention and resources to keep it running. Yet TPRM holds far more potential when we move beyond the standard approach. When fully leveraged, it becomes a powerful tool for shaping strategic decisions and enhancing long-term performance. It can reveal critical insights into the value chain, highlight emerging risks, and uncover opportunities for growth and innovation. Watch this webinar to learn about: • The need to expand TPRM programs beyond basic compliance requirements. • The strategic advantages of integrating TPRM into enterprise risk management and long-term planning. • Improved decision-making and stronger operational risk management enabled by unlocking the potential of a comprehensive TPRM approach.
Speakers:
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is the CEO of Shared Assessments, a global membership organization that supports hundreds of companies, risk programs, and thousands of associated third-party and other risk professionals. As a risk practitioner and executive, he has driven a culture of accountability and diligence in safeguarding information and other assets for organizations and their third parties. He has more than 25 years of experience in risk management and information security.
    View full bio
  • Tahmina Day
    Global Head ESG and TPRM solutions, Archer Technologies
    Tahmina Day is the Global Head ESG and TPRM solutions at Archer Technologies – a leading provider of GRC technology. In this role, she leads the development of Archer’s environmental, social and governance (ESG) solution and its integration with enterprise risk management. Tahmina also oversees one of Archer’s flagship products – third-party risk management (TPRM). With over 20 years of experience in risk management and sustainability, Tahmina spent more than 11 years as a Corporate Governance Officer in the ESG department of the International Finance Corporation (IFC). Prior to joining Archer, she held leadership roles in risk and compliance at CIT Group, Inc., Fannie Mae, and Seacoast Bank. Tahmina holds an MBA from the Darden School of Business at the University of Virginia and is a Certified Enterprise Risk Professional (CERP).
    View full bio
Register to Watch

June 2025 Product Forum Call – A Fresh Look At The Vendor Risk Management Maturity Model (VRMMM)

Back by popular demand, this Product Forum takes a fresh look at the Vendor Risk Management Maturity Model (VRMMM)–a cornerstone tool for evaluating and advancing third-party risk programs. Whether you're new to the model or ready to take your assessment to the next level, this session will walk you through the latest applications and real-world insights. Developed with the support of industry leaders, the VRMMM enables organizations to benchmark their third-party risk management (TPRM) practices, assess program maturity, and create a clear, actionable roadmap for improvement. We'll also highlight how the VRMMM supports investment justification, program tracking over time, and even external use cases like M&A due diligence. Join us to explore how this powerful tool continues to evolve alongside your program needs.
Speakers:
  • Sheria Williams
    TPRM Principal, Shared Assessments
  • Mike Baker
    Software Developer, Shared Assessments
Subscribe to Watch

April 2025 Member Forum Call – Leveraging AI and Automation in TPRM: Practical Strategies for Efficiency

Join us for an engaging Member Forum Call where we'll explore how AI and automation are transforming Third Party Risk Management (TPRM). Our discussion will highlight practical use cases, including leveraging AI to parse security documentation and populate SIG assessments, as well as implementing AI-powered chatbots to streamline the intake process for business owners. This conversation will provide valuable insights into how AI can improve efficiency, reduce vendor burden, and enhance overall risk assessment processes. Whether you’re just starting to explore AI or actively implementing solutions, this session will offer actionable strategies to help you optimize your TPRM program.
Speakers:
  • Chris Johnson
    Senior Advisor, Shared Assessments
    Chris is a Senior Advisor to Shared Assessments where he focuses on healthcare, insurance, and artificial intelligence and emerging technology. He has more than 25 years of experience helping clients effectively manage risk while exhibiting a passionate and dynamic leadership style. Prior to joining Shared Assessments, Chris led third party risk management and information technology initiatives at Bristol Myers Squibb, Bank of America, Merrill Lynch, KPMG, and Marriott International.
    View full bio
  • Brian Shaw
    VP, Head of North America , Certa
    Brian has automated risk and compliance for over 25 years, supporting hundreds of Fortune 500 and mid-market firms across all industries. Since 2011, Brian has focused on Third-Party Risk, Compliance and Performance Management, Master Data Management and Know your Customer (KYC) At Certa, Brian serves as Vice President, Head of North America.
    View full bio
Become a Member to Watch
1 2 3 9