Third-Party Risk, End to End
The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
- trending_upIntermediate
- schedule7h 21m
- menu_book12個のレッスン
- publicEnglish
- workspace_premiumBasic
ブリーフィング
Somebody in your organisation has bought something this month that holds customer data, and procurement has never heard of it. It was thirty pounds on a card, it was signed up for with a work email address, and there is no contract. That supplier is now inside your risk position and outside your register. Most third-party risk work fails there, before any questionnaire is sent. This segment is the lifecycle. You build a register from the card statement and the sign-in logs rather than from procurement, because those two sources know things procurement does not. You write a tiering rule that decides for you, so the level of diligence a supplier gets is not negotiated afresh every time somebody is in a hurry. You cut a question set down until it is short enough to actually come back, and you learn what a returned questionnaire is: a statement of intent, written by somebody who wants the deal, about a state of affairs nobody independent has checked. You get the handful of contract clauses that change what happens on a bad day, and you leave the rest to counsel, because contracts are legal territory and this segment says so in every lesson that touches one. You then handle nine months of evidence arriving at a mailbox nobody reads. Finally you map what is behind your suppliers, discover that four of them stop at the same moment for the same reason, and write an exit plan for the one you are leaving, whose administrator account is still active five months after the contract ended. A programme that produces a two-hundred-question spreadsheet has failed. It has externalised weeks of work onto suppliers who cannot afford it, selected for the ones with a compliance team rather than the ones with good practice, and produced no decision anybody changed. The test applied throughout this segment is narrower and harder: what would this question, if answered honestly, change about what we do? If the answer is nothing, the question comes out. You finish with five artefacts: a supplier register with owners and review dates, a written tiering rule, a question set of fifteen with a closing artefact against each one, a clause list with what each clause buys you, and an exit plan. None of them is long. All of them are the sort of thing that has to survive somebody else picking it up while you are on holiday. Every money figure, count and date in this segment is illustrative. The numbers are shaped so the arithmetic behaves realistically; none of them is a claim about what anything costs or how long anything takes in the real world. Nothing in this segment is legal advice: contract and data-protection content is legal territory, and the learner's own counsel decides.
コースアウトライン · 4個のモジュール
lockアクセスで解放- 01 レジスタ、見えるものから構築される3個のレッスン·1h 36m
調達に対してサプライヤーリストを要求すれば、調達を通じて購入されたものの一覧が得られます。これは同じセットではありません。カード明細書は30ポンドの定期料金を認識しています。サインインログは、どのアプリケーションが仕事用の身元を保有しているかを認識しています。どちらも意図的に情報を隠そうとしていませんし、両者の間で、契約が存在しないサプライヤーを見つけることができます。
- 02 このデューディリジェンスはどの程度の価値があるか3個のレッスン·1h 59m
4人のサプライヤーは200の質問に答えることはできません。彼らは試し、それに7週間かけ、60問に答え、プロジェクトが3月に必要だったため、いずれにせよ承認することになります。最初から関係者は皆それを知っていました。ティアリングのポイントは、重要でない90のサプライヤーに対応しないことによって、本当に重要な10のサプライヤーに適切に対応する時間を買い戻すことです。
- 03 契約とそれから届き続ける証拠3個のレッスン·1h 40m
条項はインシデントを止めない。それがもたらすのは通知、証拠への権利、そして抜け道である。それは価値がありますし、それが何であるかを知る価値があります。誰も行使することがない監査権は統制ではなく、ただの文言に過ぎないからです。このモジュールは法的助言ではありません。自分たちの弁護士が起草を始める前に、何を求めるべき3つのことかを知ることについてです。
- 04 第四者、集中、そして撤退3個のレッスン·2h 6m
四つの機能に四つのサプライヤーがあり、それが分散化だから安心しているあなた。その後、四つのサブプロセッサリストを読むと、そのうち三つが同じ場所にいる。集中はデューデリジェンスで解決するものではない。それはあなたの組織に関する設計上の事実であり、有用な成果物は供給者を変更する計画ではない。同時に停止するものが何であるかの名前付きリストなのだ。
よくある質問
- Third-Party Risk, End to Endでは何を学べますか?
- The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
- 事前の経験が必要ですか?
- Third-Party Risk, End to Endを開始する前に、ある程度の事前知識が推奨されます。
- Third-Party Risk, End to Endはどのくらいの時間がかかりますか?
- Third-Party Risk, End to Endには4個のモジュールと12個のレッスンが含まれています。自分のペースで学習できます。
- アクセスするにはどうすればよいですか?
- Third-Party Risk, End to Endは任意の有料サブスクリプションに含まれています。