• AI Governance That Stands Up to Audit: Evidence, Controls & Third-Party Risk with Dasha Gorovenco
    2026/08/05

    In this episode of The Third Party Risk Institute Podcast, host Linda Tuck Chapman speaks with Dasha Gorovenco, Executive Director in EY Ireland’s audit practice, about what effective artificial intelligence governance looks like through an external auditor’s lens.

    Dasha explains why documentation is not the same as evidence, why AI ownership must exist in practice rather than only on paper, and why organizations need to know which AI systems are actually operating across their networks not simply which tools were approved or listed in a vendor contract.

    Together, Linda and Dasha discuss AI audit evidence, third-party and fourth-party AI risk, SOC and ISO compliance, AI inventories, model testing, regulatory readiness, data sovereignty, cybersecurity risk, and operational resilience.

    What we cover in this episode:

    • What external auditors assess when reviewing an AI governance program
    • Why policies, contracts, meeting invitations, and process documents do not necessarily prove that controls are operating effectively
    • How to define practical AI ownership across business teams, technology, risk, compliance, users, and senior leadership
    • Why one Chief AI Officer or AI Risk Officer cannot own every aspect of AI risk
    • How organizations can identify approved and unapproved AI within third-party products, software, cloud environments, and business processes
    • How functionality-based questions can help identify AI embedded within vendor products and services
    • Why SOC reports may not provide sufficient assurance over AI-specific controls
    • The growing need for AI inventories, AI Bills of Materials, monitoring, and fourth-party visibility
    • Why dynamic AI systems, large language models, algorithms, and automated decisions require ongoing testing
    • How organizations can assess AI-generated errors, model bias, inconsistent outputs, and control failures
    • What the EU AI Act, DORA, GDPR, and data-sovereignty requirements mean for global organizations
    • How AI governance, cybersecurity risk, regulatory compliance, and operational resilience are connected

    This episode is perfect for:

    • Board members, Chief Risk Officers, Chief Audit Executives, CISOs, CIOs, and AI governance leaders
    • Internal Audit, IT Audit, Risk, Compliance, GRC, and Assurance Professionals
    • Third-Party Risk Management and Vendor Risk Management Professionals
    • Procurement, Cybersecurity, Privacy, Data Governance, and Model Risk Teams
    • Professionals responsible for AI controls, regulatory compliance, operational resilience, and third-party oversight
    • Organizations implementing or purchasing AI-enabled products and services

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    続きを読む 一部表示
    1 時間
  • Stop Treating Every Vendor the Same: Daniel Liu on the Real Work of Third Party Risk
    2026/06/29

    In this episode of The Third Party Risk Institute Podcast, Linda Tuck Chapman speaks with Daniel Liu, Managing Director of Enterprise Risk Management at TMX Group, about what effective third-party risk management really looks like inside complex, regulated organizations.

    Daniel shares practical insights from his experience across enterprise risk management, operational risk, financial services, data analytics, and regulatory environments. The conversation explores how operational risk and TPRM functions should work together, why risk culture matters, and why risk teams must move beyond checklists, policies, and one-time due diligence.

    This episode covers key topics including third-party risk management, operational risk management, enterprise risk management, vendor segmentation, concentration risk, fourth-party risk, exit planning, regulatory expectations, operational resilience, OSFI expectations, first line and second line responsibilities, ongoing monitoring, and risk-based due diligence.

    Listeners will also hear why vendor segmentation should be based on criticality and inherent risk, not spend or relationship history, and why overlooked risks such as exit risk, subcontractor exposure, change in control, and scope creep can create serious operational and regulatory challenges.

    This is a valuable conversation for risk leaders, TPRM professionals, procurement teams, compliance officers, auditors, financial services executives, and anyone responsible for building stronger third-party risk and operational resilience programs.

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    続きを読む 一部表示
    1 時間 1 分
  • Third-Party Risk Monitoring in 2026: Why Annual Vendor Reviews Are No Longer Enough
    2026/06/22

    Third-party risk is no longer something organizations can review once a year and file away for audit season. Vendor incidents now move in hours, regulators expect stronger oversight, and a single provider can disrupt hundreds of businesses at once.

    In this episode of the Third Party Risk Institute Podcast, we discuss why traditional annual questionnaires are falling short and why continuous third-party risk monitoring is becoming a core expectation for risk, procurement, compliance, cybersecurity, and vendor management teams.

    We cover what continuous monitoring really means, why security ratings should be treated as early-warning signals rather than final answers, and how organizations can monitor vendor risk across cybersecurity, operational resilience, financial health, concentration risk, fourth-party risk, and AI-related vendor exposure.

    You’ll also hear practical insights on DORA, NIST CSF 2.0, U.S. banking guidance, security ratings, KRIs, vendor risk dashboards, concentration risk, and the operating model needed to turn alerts into action.

    If your organization still relies heavily on point-in-time assessments, spreadsheets, or annual vendor reviews, this episode will help you rethink what effective third-party risk management should look like in 2026.

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    続きを読む 一部表示
    20 分
  • The Future of Third-Party Risk Management: AI, Resilience, Cyber Risk, and What Comes Next with Matthew Moog
    2026/05/29

    Third-party risk management is changing fast. For years, many organizations have relied on questionnaires, point-in-time assessments, manual workflows, and fragmented ownership across procurement, cyber, compliance, resilience, privacy, model risk, and business teams. But with AI, cyber ratings, data ecosystems, shared assessments, trust centers, regulatory pressure, and operational resilience expectations becoming more important, the future of TPRM is moving beyond traditional vendor due diligence.

    In this episode of the Third Party Risk Institute Podcast, Linda Tuck Chapman speaks with Matthew Moog, Principal of Risk Managed Services at EY, about where third-party risk management is heading and what risk professionals need to understand now. Matt shares lessons from his career across EY, TrueSight, and OneTrust, including the challenges of standardizing assessments, building shared third-party risk utilities, using data before sending questionnaires, and rethinking how organizations assess, monitor, and respond to supplier risk.

    This conversation explores some of the biggest issues facing risk, procurement, cybersecurity, compliance, and operational resilience teams today, including:

    • Why traditional third-party risk assessments are no longer enough
    • How AI and automation may change vendor risk management workflows
    • Why the future of TPRM depends on better data, not more questionnaires
    • The role of cyber ratings, trust centers, attestations, certifications, and standardized data
    • How organizations can reduce fragmented third-party risk processes
    • Why operational resilience, fourth-party risk, and dependency mapping are becoming critical
    • How DORA, regulatory expectations, and global financial services guidance are shaping TPRM
    • Why human judgment still matters in an AI-enabled risk environment
    • What risk professionals should focus on to build a stronger career in TPRM

    Matt also shares practical career advice for professionals entering or growing in third-party risk management, operational risk, cyber risk, vendor risk, and governance roles.

    This episode is essential listening for anyone working in third-party risk management, vendor risk management, supplier risk, operational resilience, cybersecurity risk, regulatory compliance, procurement, financial services risk, AI governance, fourth-party risk, or enterprise risk management.

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    続きを読む 一部表示
    54 分
  • "Trust Path Failures" The Weakest Link in 2026: What Third-Party Risk Leaders Are Missing
    2026/04/27

    The first four months of 2026 have already reshaped how organizations think about third-party risk.

    From regulatory pressure like Digital Operational Resilience Act to the rapid adoption of AI across vendor ecosystems, the gap between what organizations assess and what they actually understand is becoming more visible and more risky.

    In this episode, we break down what’s actually changed in third-party risk so far this year, not at a theoretical level, but based on real developments, regulatory shifts, and operational challenges organizations are facing right now.

    This is not a high-level conversation. This is a practical review of where programs are falling short and what needs to change.

    What We Cover in This Episode

    • Why traditional third-party risk models are failing in 2026
    • The growing disconnect between vendor assessments and real-world dependencies
    • How AI adoption is introducing new, unmeasured risks in third-party ecosystems
    • What regulators are actually expecting (and where organizations are still behind)
    • The rise of concentration risk, fourth-party risk, and infrastructure dependencies
    • Why business continuity assumptions are no longer holding up
    • What strong third-party risk programs are starting to do differently
    • Practical steps to rethink your approach, immediately

    Who This Podcast Is For

    • Third-Party Risk Managers
    • Vendor & Supplier Risk Professionals
    • Procurement Leaders
    • Operational Risk & Resilience Teams
    • Compliance and Audit Professionals
    • Anyone responsible for understanding how third parties impact business continuity and resilience

    If you’re responsible for third-party risk, this episode will help you step back and ask a harder question:

    👉 Are you assessing vendors… or actually understanding your exposure?

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    続きを読む 一部表示
    20 分