Third-Party Risk, End to End
The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
- trending_upIntermediate
- schedule7h 21m
- menu_book12 堂課程
- publicEnglish
- workspace_premiumBasic
課程簡介
Somebody in your organisation has bought something this month that holds customer data, and procurement has never heard of it. It was thirty pounds on a card, it was signed up for with a work email address, and there is no contract. That supplier is now inside your risk position and outside your register. Most third-party risk work fails there, before any questionnaire is sent. This segment is the lifecycle. You build a register from the card statement and the sign-in logs rather than from procurement, because those two sources know things procurement does not. You write a tiering rule that decides for you, so the level of diligence a supplier gets is not negotiated afresh every time somebody is in a hurry. You cut a question set down until it is short enough to actually come back, and you learn what a returned questionnaire is: a statement of intent, written by somebody who wants the deal, about a state of affairs nobody independent has checked. You get the handful of contract clauses that change what happens on a bad day, and you leave the rest to counsel, because contracts are legal territory and this segment says so in every lesson that touches one. You then handle nine months of evidence arriving at a mailbox nobody reads. Finally you map what is behind your suppliers, discover that four of them stop at the same moment for the same reason, and write an exit plan for the one you are leaving, whose administrator account is still active five months after the contract ended. A programme that produces a two-hundred-question spreadsheet has failed. It has externalised weeks of work onto suppliers who cannot afford it, selected for the ones with a compliance team rather than the ones with good practice, and produced no decision anybody changed. The test applied throughout this segment is narrower and harder: what would this question, if answered honestly, change about what we do? If the answer is nothing, the question comes out. You finish with five artefacts: a supplier register with owners and review dates, a written tiering rule, a question set of fifteen with a closing artefact against each one, a clause list with what each clause buys you, and an exit plan. None of them is long. All of them are the sort of thing that has to survive somebody else picking it up while you are on holiday. Every money figure, count and date in this segment is illustrative. The numbers are shaped so the arithmetic behaves realistically; none of them is a claim about what anything costs or how long anything takes in the real world. Nothing in this segment is legal advice: contract and data-protection content is legal territory, and the learner's own counsel decides.
課程大綱 · 4 個單元
lock隨存取權限解鎖- 01 暫存器,由你能看到的內容構建3 堂課程·1h 36m
向採購部門要供應商清單,你會得到一份透過採購部門購買的清單。這不是同一個集合。信用卡帳單知道那些三十英鎊的定期費用。登入日誌知道哪些應用程式持有工作身分。它們都不是想對你隱瞞任何東西,在它們之間它們會找到沒有任何合約的供應商。
- 02 這個盡職調查值得花多少工夫3 堂課程·1h 59m
四人規模的供應商無法回答兩百個問題。他們會試著回答,花七週時間,回答六十個,然後你還是會核可他們,因為專案在三月就需要他們了。所有相關人員一開始就知道這點。分層的重點是買回時間來妥善處理十家重要供應商,方法就是不去處理九十家無關緊要的供應商。
- 03 契約與持續送達的證據3 堂課程·1h 40m
一條條款不會阻止事件發生。它為你買到的是通知權、證據權,還有一條出路。這值得擁有,也值得知道那是什麼,因為一個永遠不會被行使的稽核權只是紙上談兵,不是真正的控制措施。這個模組不是法律建議。它是在你自己的律師開始起草之前,讓你知道該要求哪三件事。
- 04 第四方、集中度與下架3 堂課程·2h 6m
你有四個供應商負責四項功能,你很安心,因為那就是多元化。然後你讀了四份次級處理者清單,發現其中三份都在同一個地方。集中度不是盡職調查能修補的東西。它是你的組織的設計事實,有用的結果不是改變供應商的計畫。它是一份具名清單,列出什麼東西會同時停止。
常見問題
- 我將在 Third-Party Risk, End to End 中學到什麼?
- The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
- 我需要事先具備經驗嗎?
- 建議在開始 Third-Party Risk, End to End 前具備一些先備知識。
- Third-Party Risk, End to End 需要多長時間?
- Third-Party Risk, End to End 包含 4 個單元和 12 堂課程。你可以按自己的進度學習。
- 我如何取得存取權限?
- Third-Party Risk, End to End 包含在任何付費訂閱方案中。