Third-Party Risk, End to End
The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
- trending_upIntermediate
- schedule7h 21m
- menu_book12 节课程
- publicEnglish
- workspace_premiumBasic
课程概述
Somebody in your organisation has bought something this month that holds customer data, and procurement has never heard of it. It was thirty pounds on a card, it was signed up for with a work email address, and there is no contract. That supplier is now inside your risk position and outside your register. Most third-party risk work fails there, before any questionnaire is sent. This segment is the lifecycle. You build a register from the card statement and the sign-in logs rather than from procurement, because those two sources know things procurement does not. You write a tiering rule that decides for you, so the level of diligence a supplier gets is not negotiated afresh every time somebody is in a hurry. You cut a question set down until it is short enough to actually come back, and you learn what a returned questionnaire is: a statement of intent, written by somebody who wants the deal, about a state of affairs nobody independent has checked. You get the handful of contract clauses that change what happens on a bad day, and you leave the rest to counsel, because contracts are legal territory and this segment says so in every lesson that touches one. You then handle nine months of evidence arriving at a mailbox nobody reads. Finally you map what is behind your suppliers, discover that four of them stop at the same moment for the same reason, and write an exit plan for the one you are leaving, whose administrator account is still active five months after the contract ended. A programme that produces a two-hundred-question spreadsheet has failed. It has externalised weeks of work onto suppliers who cannot afford it, selected for the ones with a compliance team rather than the ones with good practice, and produced no decision anybody changed. The test applied throughout this segment is narrower and harder: what would this question, if answered honestly, change about what we do? If the answer is nothing, the question comes out. You finish with five artefacts: a supplier register with owners and review dates, a written tiering rule, a question set of fifteen with a closing artefact against each one, a clause list with what each clause buys you, and an exit plan. None of them is long. All of them are the sort of thing that has to survive somebody else picking it up while you are on holiday. Every money figure, count and date in this segment is illustrative. The numbers are shaped so the arithmetic behaves realistically; none of them is a claim about what anything costs or how long anything takes in the real world. Nothing in this segment is legal advice: contract and data-protection content is legal territory, and the learner's own counsel decides.
课程大纲 · 4 个模块
lock解锁权限内容- 01 寄存器,从你能看到的东西构建3 节课程·1h 36m
向采购部门要供应商列表,你会得到一份通过采购部门购买的东西的列表。这不是同一个集合。银行卡账单知道那些三十英镑的经常性费用。登录日志知道哪些应用程序持有工作身份。它们都不是想对你隐瞒什么,而在它们之间,它们会找到没有合同存在的供应商。
- 02 这些尽职调查值得投入多少3 节课程·1h 59m
四人供应商无法回答两百个问题。他们会尝试,花七周时间,回答六十个,你还是会批准他们,因为项目在三月份需要他们。参与其中的每个人从一开始就知道这一点。分层的意义在于通过不处理那九十个不重要的供应商,来赢回时间,妥善处理那十个重要的供应商。
- 03 合同及不断送达的证据3 节课程·1h 40m
条款不能阻止事件发生。它为你争取的是通知权、证据权和一条出路。这是值得拥有的,也值得知道它是什么,因为没人会行使的审计权不是控制措施,而是一句话。本模块不是法律建议。它讲的是在你自己的律师开始起草之前,应该要求的三件事。
- 04 第四方、集中化与退出3 节课程·2h 6m
你有四个供应商负责四个不同的功能,你很放心,因为这是多元化。然后你读了四份子处理方列表,其中三份位于同一个地方。集中化不是尽职调查能解决的问题。它是你组织的设计事实,有用的产出不是改变供应商的计划。它是一份具名清单,列出在同一时刻停止的东西。
常见问题
- 我将在 Third-Party Risk, End to End 中学到什么?
- The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
- 我需要有先前的经验吗?
- 建议在开始 Third-Party Risk, End to End 前具有一定的先前知识。
- Third-Party Risk, End to End 需要多长时间?
- Third-Party Risk, End to End 包含 4 个模块和 12 节课程。您可以按自己的速度学习。
- 我如何获得访问权限?
- Third-Party Risk, End to End 包含在任何付费订阅中。