code grc

Third-Party Risk, End to End

The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.

  • trending_upIntermediate
  • schedule7h 21m
  • menu_book12 堂課程
  • publicEnglish
  • workspace_premiumBasic
Third-Party Risk, End to End

課程簡介

Somebody in your organisation has bought something this month that holds customer data, and procurement has never heard of it. It was thirty pounds on a card, it was signed up for with a work email address, and there is no contract. That supplier is now inside your risk position and outside your register. Most third-party risk work fails there, before any questionnaire is sent. This segment is the lifecycle. You build a register from the card statement and the sign-in logs rather than from procurement, because those two sources know things procurement does not. You write a tiering rule that decides for you, so the level of diligence a supplier gets is not negotiated afresh every time somebody is in a hurry. You cut a question set down until it is short enough to actually come back, and you learn what a returned questionnaire is: a statement of intent, written by somebody who wants the deal, about a state of affairs nobody independent has checked. You get the handful of contract clauses that change what happens on a bad day, and you leave the rest to counsel, because contracts are legal territory and this segment says so in every lesson that touches one. You then handle nine months of evidence arriving at a mailbox nobody reads. Finally you map what is behind your suppliers, discover that four of them stop at the same moment for the same reason, and write an exit plan for the one you are leaving, whose administrator account is still active five months after the contract ended. A programme that produces a two-hundred-question spreadsheet has failed. It has externalised weeks of work onto suppliers who cannot afford it, selected for the ones with a compliance team rather than the ones with good practice, and produced no decision anybody changed. The test applied throughout this segment is narrower and harder: what would this question, if answered honestly, change about what we do? If the answer is nothing, the question comes out. You finish with five artefacts: a supplier register with owners and review dates, a written tiering rule, a question set of fifteen with a closing artefact against each one, a clause list with what each clause buys you, and an exit plan. None of them is long. All of them are the sort of thing that has to survive somebody else picking it up while you are on holiday. Every money figure, count and date in this segment is illustrative. The numbers are shaped so the arithmetic behaves realistically; none of them is a claim about what anything costs or how long anything takes in the real world. Nothing in this segment is legal advice: contract and data-protection content is legal territory, and the learner's own counsel decides.

課程大綱 · 4 個單元

lock隨存取權限解鎖
  1. 01 暫存器,由你能看到的內容構建
    3 堂課程·1h 36m

    向採購部門要供應商清單,你會得到一份透過採購部門購買的清單。這不是同一個集合。信用卡帳單知道那些三十英鎊的定期費用。登入日誌知道哪些應用程式持有工作身分。它們都不是想對你隱瞞任何東西,在它們之間它們會找到沒有任何合約的供應商。

  2. 02 這個盡職調查值得花多少工夫
    3 堂課程·1h 59m

    四人規模的供應商無法回答兩百個問題。他們會試著回答,花七週時間,回答六十個,然後你還是會核可他們,因為專案在三月就需要他們了。所有相關人員一開始就知道這點。分層的重點是買回時間來妥善處理十家重要供應商,方法就是不去處理九十家無關緊要的供應商。

  3. 03 契約與持續送達的證據
    3 堂課程·1h 40m

    一條條款不會阻止事件發生。它為你買到的是通知權、證據權,還有一條出路。這值得擁有,也值得知道那是什麼,因為一個永遠不會被行使的稽核權只是紙上談兵,不是真正的控制措施。這個模組不是法律建議。它是在你自己的律師開始起草之前,讓你知道該要求哪三件事。

  4. 04 第四方、集中度與下架
    3 堂課程·2h 6m

    你有四個供應商負責四項功能,你很安心,因為那就是多元化。然後你讀了四份次級處理者清單,發現其中三份都在同一個地方。集中度不是盡職調查能修補的東西。它是你的組織的設計事實,有用的結果不是改變供應商的計畫。它是一份具名清單,列出什麼東西會同時停止。

常見問題

我將在 Third-Party Risk, End to End 中學到什麼?
The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
我需要事先具備經驗嗎?
建議在開始 Third-Party Risk, End to End 前具備一些先備知識。
Third-Party Risk, End to End 需要多長時間?
Third-Party Risk, End to End 包含 4 個單元和 12 堂課程。你可以按自己的進度學習。
我如何取得存取權限?
Third-Party Risk, End to End 包含在任何付費訂閱方案中。

程式設計 中的更多內容

Binary, Hex and Data Units
Beginner Binary, Hex and Data Units The topic that costs more marks than any other on the paper, taught by hand. Bits and bytes, binary and hex in all six directions, the 1000-versus-1024 trap, file sizes, transmission times, overflow, two's complement and character sets. Every module ends in a timed drill marked the way an examiner marks it.
Python From a White Sheet
Beginner Python From a White Sheet 九位學生已經走過的確切序列,從空白檔案到詢問問題、檢查答案並拒絕不良輸入的程式。無需事前程式設計知識。無需數學。你會故意反覆破壞它。
First Program — Scratch for ages 5–9
Beginner First Program — Scratch for ages 5–9 Nine Scratch blocks, three sessions of about twenty-five minutes, and one small program a child of five to nine builds themselves. Written for the parent sitting beside them: what to click, what they will get stuck on, what to say when it goes wrong, and when to keep your hands off the mouse.
AI Without the Hype
Beginner AI Without the Hype What the model is actually doing when it answers you, why that produces something that looks like thinking, why it invents citations, and the cost mechanic almost nobody explains: a chat resends the entire conversation on every single turn. You will do the arithmetic yourself.
IGCSE and GCSE Computer Science — Theory That Actually Gets Marked
Intermediate IGCSE and GCSE Computer Science — Theory That Actually Gets Marked The theory half of the paper, taught so it survives the exam room. The memory hierarchy and what actually happens at boot. Compilers, interpreters and assemblers, including the answer that sounds right and scores nothing. Databases from a spreadsheet up to keys and normalisation. DNS and the full path between pressing Enter and seeing the page. Systems software, and the ethical and legal section that is the easiest ten marks on the paper.
Programming for the Exam — Python Answers That Score
Intermediate Programming for the Exam — Python Answers That Score The programming half of the paper, taught at exam pitch. Pseudocode translated both ways, because the mark scheme is written in a notation nobody practises. Trace tables done column by column, including the ones with a loop and a condition inside it. Linear and binary search, bubble and insertion sort, what each costs and the comparison questions boards love. Validation against verification, and the boundary test data everybody forgets. Procedures against functions, and a systematic method for finding your own error with four minutes left.