Summary:
Reveal Risk partnered with a publicly traded life sciences company that recognized they had high third-party risk, but nascent legacy practices to manage it. We built a strategic process to prioritize & evaluate third parties and execute risk-appropriate assessments, maximizing use self-service and automation where possible.
Outcomes:
- Conducted external industry analysis and benchmarking as well as internal company process strengths and weaknesses to map the current state program and opportunities to progress risk reduction.
- Created a future state comprehensive but streamlined TPRM processes that rapidly prioritizes vendors based upon inherent risk using 3 process inputs
- Business Risk (evaluate business risk using the Reveal Risk “Business Driven Risk” methodology)
- Project Risk (using a lightweight 6-7 question process)
- Technical Risk (using a 3rd party scoring tool)
- Assisted in implementing the process, training, staff, and accelerating implementation of a tool