• Short: Tech Gians and OFAC with Michael Volkov
    2026/09/16

    Send us Fan Mail

    In this short video, Mike explains how this is an unappreciated risk

    Support the show

    続きを読む 一部表示
    1 分
  • Short: How to Identify Material Third Parties with Julie Giaischi
    2026/09/15

    Send us Fan Mail

    In this short video, we hear Julie explain how to identify the vendors risks that really matter - with your "material" third-parties.

    Support the show

    続きを読む 一部表示
    1 分
  • Sanctions Ready Third-Party Risk with Michael Volkov
    2026/09/15

    Send us Fan Mail

    Sanctions enforcement is starting to feel like the new FCPA, and that is not just a catchy line, it is a warning. When more and more OFAC and export controls violations trace back to distributors, agents, and vendors, “third-party risk” stops being an onboarding task and becomes a real legal and operational threat. We talk through how strict liability changes the stakes, why diversion risk through transshipment points can catch even well-meaning companies, and what happens when regulators decide your controls were never built to see the end user in the first place.

    We also dig into the enforcement trend line: DOJ’s National Security Division is leaning in, and sanctions cases can now resemble classic FCPA outcomes with coordinated settlements, criminal exposure, and painful fines. The practical question is simple: if the government asks why you did business with a third party, can you pull a complete, auditable due diligence file that shows your screening, your OSINT research, your beneficial ownership checks, and your documented compliance sign-off? If your evidence lives in emailed questionnaires and scattered attachments, we explain why that approach breaks the moment there is a subpoena, an investigation, or a breach.

    Then we widen the lens to today’s vendor ecosystem, where cybersecurity and AI governance are inseparable from third-party due diligence. Vendors can become the pathway into your systems, and AI tools can create liability when they act on your behalf, especially in HR hiring decisions. We share a clear next-step mindset: automate onboarding workflows, build cross-functional partnerships with procurement and IT, and put AI guardrails and a framework in place so the program can evolve without chaos. If this helps, subscribe, share the episode with a colleague, and leave a review with the biggest third-party risk you are tackling right now.

    Support the show

    続きを読む 一部表示
    28 分
  • Treat Vendors As Part Of The Enterprise with Julie Giaischi
    2026/09/10

    Send us Fan Mail

    Vendor risk feels like it’s turning into paperwork at scale: endless security questionnaires, overwhelmed vendors, and yet third-party breaches keep climbing. We sit down with Julie Giaischi, CEO and co-founder of the Third Party Risk Association, to challenge the habits that quietly keep programs stuck in compliance theater and to map a path toward measurable risk reduction.

    We dig into a core myth that still drives bad decisions: scaling third-party risk management based on the number of vendors. Julie explains why mature TPRM scales by risk and strategic impact, not raw volume, and why soft skills like communication and relationship building become even more critical as AI changes what “doing the work” looks like. We also unpack why standardized questionnaires can create assessment fatigue when they’re treated as a checkbox, and how evidence-based testing and continuous monitoring better reflect the real control environment.

    From there, we get practical about the future: AI-powered vendor risk tools, trust portals, and the move toward near real-time assurance that can become predictive, not just reactive. We also address the governance side of AI, including the risk of feeding vendor data into frontier AI when contracts and confidentiality rules say you cannot. Finally, we break down nth-party and fourth-party supply chain risk, including a simple set of questions to identify which sub-tier providers are truly material, plus how to translate benchmarks and risk metrics into board-level messaging that supports budget and action.

    If you found this useful, subscribe, share it with a risk leader who is drowning in questionnaires, and leave a review with your biggest TPRM challenge.

    Support the show

    続きを読む 一部表示
    27 分
  • Short: Communicate Risk in Business Terms for Success with Becky Newton
    2026/09/09

    Send us Fan Mail

    In this short video, Becky explains how to do this best.

    Support the show

    続きを読む 一部表示
    1 分
  • Short: How TPRA is Accelerating Threat Intelligence Sharing with Heather Kadavy
    2026/09/09

    Send us Fan Mail

    In this short video, Heather provides examples of how this is being accomplished.

    Support the show

    続きを読む 一部表示
    1 分
  • Vendor Risk Beyond The SOC Report with Becky Newton
    2026/09/08

    Send us Fan Mail

    A vendor hands you a clean SOC 2 Type II report, the boxes look checked, and everyone relaxes. Then the breach happens anyway. That’s the control assurance paradox, and it’s why we sat down with Becky Newton, founder and managing partner of Newton Risk Intelligence, to get brutally practical about what third-party risk management should look like when the goal is real operational security, not paperwork comfort.

    We unpack why TPRM is neither “just audit” nor “just security,” but a risk management discipline that translates vendor controls into business exposure and informed decisions. Becky explains a surprisingly common miss in SOC and ISO reviews: CUECs (complementary user entity controls). If we aren’t performing our side of the controls like access removal and internal mapping, vendors can’t truly assure outcomes, no matter how polished the report looks. We also talk about the biggest vendor red flag: inconsistency without transparency, and how to spot it across questionnaires, evidence, and documentation.

    From there, we move into what actually closes the gap: understanding the service, the data, the access, and the vendor’s criticality, then backing it up with continuous conversations and operational testing. We dig into business continuity, disaster recovery, and incident response table-tops with vendors, plus how to prioritize limited resources across tiered vendor populations. Finally, we tackle AI vendor risk and AI governance, including why you should audit the system the model runs in, focus on permissions, and ask your top critical vendors what changed with AI bolt-ons and expansion.

    If you want a vendor risk assessment approach that executives understand and attackers don’t laugh at, hit play, then subscribe, share, and leave a review so more teams can build stronger third-party risk programs.

    Support the show

    続きを読む 一部表示
    24 分
  • Relationships Beat Tools In Vendor Risk with Heather Kadavy
    2026/09/03

    Send us Fan Mail

    Vendor risk doesn’t fail because you picked the wrong platform. It fails because nobody trusts the program, nobody speaks the business unit’s language, and everyone thinks it’s someone else’s job. We’re joined by Heather Kadavy, Director of Membership Success at the Third Party Risk Association (TPRA), to get honest about what actually moves third-party risk management forward when teams are lean, vendors are complex, and AI is changing the rules.

    We dig into the biggest myth in TPRM and supply chain risk management: that technology “solves” the problem. Heather lays out why relationships and governance matter more than automation in the early days of fixing a broken program, and how to earn first line buy-in by shifting from compliance talk to business impact. If your stakeholders only care about sales and speed, we walk through how to translate cyber vendor risk into outcomes they already track like revenue loss, operational disruption, customer impact, and regulatory exposure.

    From there, we get practical about resilience. Heather shares her “depth of three” strategy for training successors so TPRM survives turnover, plus the cultural marker of mature programs: leaving egos at the door and treating risk management as a team sport across security, compliance, finance, and the business. We also tackle shadow AI, AI governance, and fourth-party dependencies with concrete approaches like mapping critical business services, identifying concentration risk, asking direct AI questions, and combining continuous monitoring with human judgment where it counts.

    If you want a clearer, more effective vendor risk management program that partners with the business and improves nth-party visibility, hit play. Subscribe, share this with a colleague, and leave a review so more practitioners can find the conversation.

    Support the show

    続きを読む 一部表示
    24 分