Third-party threats have become relatively commonplace in our increasingly complex environment, heavily targeting both public and private entities. As a result, universities (regardless of size) are taking an enhanced security stance as cyber-attacks continue to increase both in size, scale, and frequency. Additionally, boards/trustees have a desire to get a better handle on the evolving risk landscape beyond cyber, including financial, geopolitical, anti-bribery & corruption, health & safety, etc. and how operations can be impacted.
To adequately respond and protect the multitude of stakeholders within universities, numerous functions (IT, Risk, Compliance, Internal Audit, Procurement, Legal, etc.) are becoming more proactive by using preventative measures via the establishment of Third Party Risk Management Programs, which can help reduce the cost of impact resulting third-party related events.
Specifically, we support our clients through:
- Cost Recovery & Compliance, review contract terms to identify high risks, understand root causes and conditions that focus on cost recovery/containment
- TPRM Program Assessments, evaluate current TPRM practices and risks against Deloitte TPRM framework and mature TPRM capabilities
- TPRM Program Design, design TPRM governance, policies & procedures, operating model, communication strategies, etc. as well as procedures to help identify and manage third party risks
- TPRM Managed Services, assist institutions with screening, assessing, reporting, and monitoring their third parties while offering support and training for stakeholders
- Technology Implementations, define TPRM technology needs and implement solutions to manage TPRM programs (standalone TPRM or GRC)