On-Demand Events - Shared Assessments - The Trusted Source in Third Party Risk Management

On Demand Events

Missed a recent webinar or Member Forum Call? Catch our previous virtual sessions here. We now offer CPEs from most of our on-demand offerings. To earn CPEs, please submit your information and codes in the form linked below. Note: our on-demand recordings work best when viewed in the Chrome browser.

All On-demand Events

Collaborative Assurance: The New Model for TPRM–Audit Success

Audit Ready, Not Audit Reactive As third-party risk management (TPRM) programs face growing scrutiny, audit readiness should be an ongoing discipline—not a last-minute exercise. Join Shared Assessments and an Internal Audit expert for a practical conversation about what auditors look for and how TPRM teams can prepare for internal audits, external audits, and regulatory examinations. Drawing on the Shared Assessments Preparing for Audits & Examinations Best Practices paper, we’ll explore strategies for strengthening documentation and evidence, navigating auditor interactions and findings, and turning remediation into program improvement. We’ll also discuss how TPRM professionals can build productive relationships with Internal Audit and leverage auditors as champions for effective third-party risk management while preserving their independence.
Speakers:
  • Jennifer Hancock
    SVP, Professional Development & Education, Shared Assessments
    Jennifer Hancock is a third-party risk management professional with more than 20 years of experience in third-party risk management. As owner of Hancock Consulting LLC, a consultancy she founded to provide specialized advisory services, Ms. Hancock has been able to help organizations develop effective third-party risk management strategies and improve their overall resilience. Her expertise has been sought after by a wide range of clients across industries, and she is dedicated to helping organizations of all sizes manage their third-party risks effectively. As a thought leader in the field of third-party risk management, Ms. Hancock has been a featured speaker at numerous industry events and conferences. She is both a Certified Third-Party Risk Professional and a Certified Third-Party Risk Assessor (CTPRA).
    View full bio
  • Valerie Nielsen
    Managing Director, Inside Edge Risk Advisors LLC
    Valerie is a Risk Executive with expertise across Operations, Finance, Incident Response, Fraud Investigations, Financial Crimes, Board Level Communications, Third Party Assurance, Vendor Management, Compliance, and Internal Audit. She has created and led Risk Management for $2B and $5B business units at Aon. Valerie was the Chief Audit Executive at Household Finance. As a Director at PwC LLP, she was responsible for business development and service delivery for internal audit co-sourcing, risk and compliance, SOX 404, and market assessment for new products. Valerie created and led an Internal Audit Function for GE Capital’s Auto Financing Business. She has managed global teams of 30+ individuals. Her focus is on operations scaling with growth and product development/feasibility. Valerie works with start-up/incubator companies at the University of Chicago’s Polsky Center. She mentors entrepreneurs at Chicago Innovation. She is a LinkedIn Top Voice and Influencer. Valerie earned a BS in Business Administration with a minor in International Business from the University of Delaware. She also holds an MBA in Finance from the University of Delaware. Valerie has earned the following professional designations: CPA (Certified Public Accountant), CIA (Certified Internal Auditor), CTA (Certified Trust Auditor), and GE Six Sigma Greenbelt.
    View full bio
Register to Watch

Clashing with Titans: Debunking the Modern Myths of TPRM

Separate legendary fiction from reality. Join our TPRM Odyssey as we challenge long-held industry assumptions, openly debating and dismantling the myths that compromise modern third-party security.
Speakers:
  • Chris Johnson
    Senior Advisor, Shared Assessments
    Chris is a Senior Advisor to Shared Assessments where he focuses on healthcare, insurance, and artificial intelligence and emerging technology. He has more than 25 years of experience helping clients effectively manage risk while exhibiting a passionate and dynamic leadership style. Prior to joining Shared Assessments, Chris led third party risk management and information technology initiatives at Bristol Myers Squibb, Bank of America, Merrill Lynch, KPMG, and Marriott International.
    View full bio
  • Sheria Williams
    TPRM Principal, Shared Assessments
    Sheria joins us from First Electronic Bank, where she was the Third-Party Risk Management AVP, with prior experience at Transamerica and Black Knight Financial Services. At Shared Assessments, Sheria gathers member feedback to help modernize our products and acts as a liaison between members and the Products team. An Albuquerque, NM native, Sheria enjoys cooking green chili chicken enchiladas and loves spending time with her family.
    View full bio
Register to Watch

August 2026 Product Forum – Built for Teams: Collaborative Assessments with SIG EV

The SIG you know and trust is better than ever — and now it’s built for teamwork. SIG Evolution (SIG EV) brings the familiar SIG framework into a collaborative environment where teams can assess, review, and manage vendors beyond Excel seamlessly. In this Product Forum, we’ll show you just how close SIG EV is to what you’re doing today — and how the upgrade to real-time collaboration and consistent outputs streamlines the experience from end to end.
Speakers:
  • Mike Baker
    Software Developer, Shared Assessments
  • Sheetal Chaudhari
    Senior Software Engineer, Shared Assessments
  • Sheria Williams
    TPRM Principal, Shared Assessments
Subscribe to Watch

The Assurance Problem Nobody Owns

The Assurance Problem Nobody Owns Why Security Questionnaires, Customer Trust, Regulatory Inquiries, and Third-Party Risk Have Become One Business Challenge Organizations spend thousands of hours each year responding to security questionnaires, customer due diligence requests, regulatory inquiries, audits, privacy assessments, AI governance reviews, and third-party risk activities—yet these efforts are often managed by different teams, using different processes, and drawing from the same underlying evidence. In this thought-provoking 50-minute session, we will explore how assurance activities have become fragmented across the enterprise, creating inefficiencies, inconsistent responses, increased operational burden, and unnecessary trust friction. Attendees will learn why traditional organizational structures struggle to keep pace with growing assurance demands, the hidden costs of assurance silos, and how leading organizations are beginning to view assurance as a strategic business capability rather than a collection of disconnected tasks. Participants will leave with a practical framework for identifying assurance gaps, improving cross-functional collaboration, and building a more unified approach to establishing and maintaining trust with customers, regulators, partners, and other stakeholders.
Speakers:
  • Tom Garrubba
    Chief Commercial & Partnership Officer / Co-founder, FusionAIrre
    Tom Garrubba is the Co-Founder and Chief Commercial & Partnership Officer of FusionAIrre, an agentic-AI company delivering external-party assurance solutions that help organizations efficiently and defensibly respond to regulatory, due-diligence, and RFP questionnaires. He is an internationally recognized third-party risk management (TPRM) and cybersecurity expert with more than two decades of experience building, leading, and advising enterprise risk programs across highly regulated industries, including financial services, healthcare, and technology, working closely with regulators, auditors, and executive leadership. Throughout his career, Tom has helped mature enterprise third-party risk, cybersecurity, privacy, and governance programs and has been actively involved in Shared Assessments, contributing to industry standards and practitioner education. A published author and creator of the TPRM Tidbits thought-leadership series, Tom is also an adjunct professor at Robert Morris University.
    View full bio
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is the CEO of Shared Assessments, a global risk membership organization that supports hundreds of companies, risk programs, and thousands of their associated third-party, compliance, cyber, and other risk professionals. As a risk practitioner and executive with more than 25 years in risk management, Andrew promotes the creation of cultures of accountability for organizations and their third parties. Prior to joining Shared Assessments in 2022, Andrew served as Senior Vice President, Vendor Risk Management and Corporate Insurance at Blackstone for four years, where he led a team of risk professionals responsible for supporting all business teams through all phases of the vendor lifecycle. Prior to Blackstone, he worked at BlackRock from 2010-18, where he first joined and then eventually led the firm’s Vendor Risk Management team. He also worked at Citigroup nine years, finishing as a Senior Vice President and Business Information Security Officer in Global Fixed Income, leading onsite third-party risk assessments across the United States, Europe, and Asia.
    View full bio
Register to Watch

July 2026 Member Forum | SOC 2 Under the Microscope: Rethinking Trust, Quality, and Risk

As reliance on SOC 2 reports grows within TPRM programs, organizations face a significant challenge: determining how much trust to place in the reports they receive. Recent AICPA guidance has heightened scrutiny on SOC 2 engagements, particularly flagging risk tied to templated, high-volume assessments that may not reflect each organization’s unique risk profile. Join Shared Assessments and Bill Deller (Schneider Downs) to examine what these developments mean for both issuers and users of SOC 2 reports. This session will highlight emerging concerns around overreliance on platforms, inconsistent quality, and the diminishing role of professional judgement. Participants will share techniques on how to better evaluate SOC 2 reports by identifying red flags, asking more effective questions of providers, and aligning report analysis with broader TPRM practices. Register to look beyond the report to understand what matters!
Speakers:
  • Elizabeth Dunsmoor
    TPRM Principal, Shared Assessments
    Elizabeth Dunsmoor recently joined Shared Assessments as a TPRM Principal after 15 years as a TPRM practitioner. She has experience designing holistic programs and delivering assessment work within the cybersecurity, financial services, manufacturing, and healthcare sectors. With a proven ability to oversee and execute long-term operational strategies and methodologies for risk programs, Elizabeth is proficient in a variety of management actions including translating strategies into measurable plans, partnering with Procurement, corporate teams, and firm leaders to develop a pipeline of cross-functional leaders within the risk management function. She now provides training and guidance to business leaders to ensure understanding of program requirements, third-party capabilities, and performance expectations.
    View full bio
  • William Deller
    Shareholder, IT Risk Advisory, Schneider Downs & Co., Inc.
    Bill is a Shareholder on Schneider Downs' IT Risk Advisory Services team, specializing in Cybersecurity Governance, Risk Management, and Compliance (GRC). Bill advises organizations across all verticals—including financial services, healthcare, technology, higher education, insurance, and energy—on strengthening security posture, managing cyber risk, and achieving regulatory and industry standards.
    View full bio
Become a Member to Watch

Real-Time Resilience: Scaling Continuous Vendor Monitoring

Point-in-time assessments are obsolete the moment they are submitted. To protect your organization from modern supply chain breaches, your Third-Party Risk Management (TPRM) program must shift to real-time, continuous monitoring. In this streamlined 60-minute session, we cover the essentials to build a proactive defense: • The Visibility Gap: How continuous monitoring catches threats that annual questionnaires miss. • Smart Implementation: Strategies for selecting the right threat data without causing alert fatigue. • Proven Results: Real-world examples of automated alerts stopping vendor threats before they hit your network. Join us to transform your TPRM from a static compliance checklist into a dynamic defense mechanism.
Speakers:
  • Tom Garrubba
    Chief Commercial & Partnership Officer / Co-founder, FusionAIrre
    Tom Garrubba is the Co-Founder and Chief Commercial & Partnership Officer of FusionAIrre, an agentic-AI company delivering external-party assurance solutions that help organizations efficiently and defensibly respond to regulatory, due-diligence, and RFP questionnaires. He is an internationally recognized third-party risk management (TPRM) and cybersecurity expert with more than two decades of experience building, leading, and advising enterprise risk programs across highly regulated industries, including financial services, healthcare, and technology, working closely with regulators, auditors, and executive leadership. Throughout his career, Tom has helped mature enterprise third-party risk, cybersecurity, privacy, and governance programs and has been actively involved in Shared Assessments, contributing to industry standards and practitioner education. A published author and creator of the TPRM Tidbits thought-leadership series, Tom is also an adjunct professor at Robert Morris University.
    View full bio
  • Douglas White
    Manager – Information Security Office, Delta Dental of New Jersey & Connecticut
    CISSP, CISM, CTPRP, and CompTIA Security+ certified information security and third-party risk leader with more than 30 years of IT experience, including over 28 years in information security, risk management, and the development of enterprise security programs. Brings extensive experience leading third-party risk initiatives, including vendor risk assessments, control evaluations, risk mitigation planning, and cross-functional engagement with business, technical, and executive stakeholders. Recognized for translating complex risk and compliance requirements into actionable decisions and scalable oversight processes.
    View full bio
Register to Watch

June 2026 Product Forum – Built for Teams: Collaborative Assessments with SIG EV

The SIG you know and trust is better than ever — and now it’s built for teamwork. SIG Evolution (SIG EV) brings the familiar SIG framework into a collaborative environment where teams can assess, review, and manage vendors beyond Excel seamlessly. In this Product Forum, we’ll show you just how close SIG EV is to what you’re doing today — and how the upgrade to real-time collaboration and consistent outputs streamlines the experience from end to end.
Speakers:
  • Mike Baker
    Software Developer, Shared Assessments
  • Sheetal Chaudhari
    Senior Software Engineer, Shared Assessments
  • Sheria Williams
    TPRM Principal, Shared Assessments
Subscribe to Watch

May 2026 Member Forum – From Guidance to Action: Building Resilience Across Critical Third-Party Ecosystems

As global regulators intensify their focus on third-party ecosystems, organizations must rethink how they identify, assess, and manage critical vendors through the lens of operational resilience. This session explores the shifting regulatory landscape and what it signals for the future of third-party risk. We’ll connect the dots between regulatory intent, sector-wide dependencies, and emerging pressures like AI-driven complexity. Attendees will walk away with clear considerations for strengthening resilience across their most critical third-party relationships.
Speakers:
  • Toby Chan
    Associate Director, Protiviti, Inc.
    As an Associate Director at Protiviti UK, Toby brings over 15 years of experience in technology consulting, specializing in privacy, data protection, and third-party risk management. His work focuses on implementing robust enterprise risk and compliance frameworks that enable organizations to navigate complex regulatory landscapes while fostering resilience and operational efficiency. ​
    View full bio
  • Gary Roboff
    Senior Advisor, Shared Assessments
    Gary Roboff is a Senior Advisor to Shared Assessments where he focuses on payments, risk management, mobile financial services, and information management. Gary has almost four decades of experience in financial services planning and management, including 25 years at JP Morgan Chase where he retired as Senior Vice President of Electronic Commerce. Gary has worked extensively in electronic payments, payments fraud, third party risk management, privacy and information utilization, as well as business frameworks and standards for electronic commerce applications. Gary was a founder of the International Security Trust and Privacy Alliance (ISTPA); led the effort to return the Bank to the merchant services business with the founding of Chase Merchant Services LLC (now Chase Paymentech); and led the development of pinned debit services at Chemical and Manufacturers Hanover. During 1993 and 1994, while on assignment from Chemical Bank, Gary served as President and CEO of the New York Switch Corporation, (the NYCE ATM and Debit Network), and was a founder of its successor corporation (NYCE Corporation, now an affiliate of FIS). Gary has served on the Board of Directors at multiple companies and organizations including ISTPA, the NYCE network, and the Electronic Funds Transfer Association, and served on the Board of Trustees at Clark University for 12 years, nine of them as Vice Chair. Gary received his B.A. and M.A. degrees from Clark University, and has completed additional graduate work at M.I.T.
    View full bio
Become a Member to Watch

April 2026 Product Forum | Transitioning from Excel to SIG Evolution (SIG EV)

Transitioning from Excel to SIG Evolution (SIG EV)
What stays the same. What gets easier. What gets better.

For years, the SIG has been a foundational tool for third-party risk assessments, but as programs have grown more complex, so has the operational burden around managing assessments in Excel—version control, collaboration challenges, inconsistent outputs, and difficulty scaling across teams and vendors.

SIG Evolution (SIG EV) was built in direct response to those challenges. In this Product Forum, we’ll walk through what it means to transition from the traditional Excel-based SIG to SIG EV—and how to carry forward everything you already know into a more structured, consistent, and scalable experience.
Speakers:
  • Mike Baker
    Software Developer, Shared Assessments
  • Ian Gregory
    Compliance Analyst, Shared Assessments
Subscribe to Watch

From Questionnaires to Consequences: Measuring Third-Party Cyber Risk That Matters

Third-party risk programs rely on standardized tools like the SIG to evaluate cybersecurity posture, yet many organizations struggle to connect assessment responses to the real-world impact of cyber incidents. This webinar explores how incident-severity modeling and real-world ransomware intelligence can strengthen third-party risk decisions. The discussion introduces a structured approach to measuring the magnitude, duration, and operational impact of cyber incidents, alongside analysis of ransomware trends from 2023–2025 that show how attacker behavior and targeting of third parties are evolving. Together, these perspectives help risk teams better understand which control gaps lead to high-impact incidents, how to interpret SIG responses in the context of active threats, and how to communicate third-party incident severity clearly to internal stakeholders. The session is designed for organizations looking to move from static questionnaire-based assessments toward operationally meaningful third-party cyber risk insight.
Speakers:
  • Munish Walther-Puri
    Head of Critical Digital Infrastructure, TPO Group
    Munish develops and presents the Infrastructure Cyber Incident Scale, a model designed to measure the severity of operational technology cybersecurity incidents. The scale adapts concepts from natural disaster measurement tools such as the Richter Scale to quantify the magnitude, duration, and impact of OT events. His work focuses on giving OT operators, emergency response teams, public officials, and communicators a clear and intuitive way to understand and compare incident severity in real time, along with the underlying rationale and structure of the scale.
    View full bio
  • Steve Thomas
    Founder & CEO, HackNotice
    Steve analyzes ransomware activity from 2023 through 2025 through continuous monitoring of attacker communications, leaks, and victim disclosures. His work examines shifts in ransomware gang behavior, consolidation among top groups, evolving tactics, and the economic incentives driving attacker operations. The analysis highlights high impact trends across industries and regions and details the techniques emerging in 2025. The focus is on identifying how ransomware threats are changing and which patterns matter most for preparation and defense.
    View full bio
  • Andrew Moyad
    CEO, Shared Assessments
    Andrew is the CEO of Shared Assessments, a global risk membership organization that supports hundreds of companies, risk programs, and thousands of their associated third-party, compliance, cyber, and other risk professionals. As a risk practitioner and executive with more than 25 years in risk management, Andrew promotes the creation of cultures of accountability for organizations and their third parties. Prior to joining Shared Assessments in 2022, Andrew served as Senior Vice President, Vendor Risk Management and Corporate Insurance at Blackstone for four years, where he led a team of risk professionals responsible for supporting all business teams through all phases of the vendor lifecycle. Prior to Blackstone, he worked at BlackRock from 2010-18, where he first joined and then eventually led the firm’s Vendor Risk Management team. He also worked at Citigroup nine years, finishing as a Senior Vice President and Business Information Security Officer in Global Fixed Income, leading onsite third-party risk assessments across the United States, Europe, and Asia.
    View full bio
Register to Watch
1 2 3 10