MetricStream, the market leader in governance, risk and compliance (GRC) apps, has today released the results of a global survey revealing the current state of third party risk management. Respondents were from more than 40 organisations, across 15 industries – including financial services, retail, healthcare, pharmaceuticals and insurance.
As companies outsource processes and services, they expose themselves to a plethora of third party risks. Whether its data security, business disruptions or compliance risks, organisations must have the relevant measures in place to mitigate their potential impact on continuity and reputation.
The full report can be viewed here, but key findings include:
French Caldwell, chief evangelist at MetricStream, provides the following comments on the findings.
“As companies continue to outsource their processes and services in order to decrease costs, streamline or scale up quickly, they are opening themselves up to risks. However, despite some supplier incidents costing upwards of £8 million, 44 percent of the respondents said that their business had no dedicated third party risk management function. Furthermore, as enterprises rapidly adopt cloud services, entities that would have been third parties when the services were managed in-house become fourth parties which are more difficult to monitor; nearly three quarters of businesses don’t track fourth parties in any capacity. It’s clear that many enterprises are yet to grasp fully how vital vendor risk management is.
“Businesses can no longer plead ignorance. They are responsible for the actions of their third parties and they will bear the brunt of any fallout. For example, if a business shares sensitive data with a third party without checking if it has relevant cybersecurity, and that supplier suffers a data breach, under some rules the company could be liable. Not only will it suffer reputational damage, but new regulations such as the EU GDPR could see large fines imposed too.
“To build truly beneficial relationships with vendors, companies must become more vigilant. That means monitoring the entire supplier and IT services ecosystem more frequently, and, based on associated levels of risk, establishing dedicated third party risk functions and accountability with GRC technology that enables informed decisions.”