Home / Blog / Risk Management
May 20, 2020 by FoxPointe Solutions
COVID-19 has introduced many challenges to personal and professional lives. While we continue to adapt, we must remember to continue to perform sound security and privacy practices, including when it comes to vendor management. We look to vendors as trusted partners for many aspects of our supply chain, and when it comes to health care, this can be anything from personal protective equipment (PPE) such as masks or hosting of an electronic medical record (EMR) system that helps to track patient care. In any scenario, it is important to have full insight into your business partners at all times.
The 2020 Prevalent-Shared Assessments Third-Party Risk Management Study states that there are real consequences when third party risk management is not done correctly and that ‘[w]hen asked if any incidents were experienced within the past two years that originated with a third party, 76% of the respondents said that they experienced one or more issue that impacted vendor performance, followed by operational issues (74%), with 55% indicating compliance violations”. The report continues by showing that the top incidents that involved third parties were cyber data breaches, compliance, legal and ethical violations, vendor performance issues, and operational issues. These incidents can result in loss of productivity, monetary damages, and even reputational damage.
Whether your organization has to take on new vendors to help provide the needed supplies or services required, such as how hospitals are attempting to increase their capacity as required to handle the increase in patients, or you are continuing to work with the vendors with which you have already established a relationship, here are a few (of the many) key items to keep in mind:
Vendor risk management and governance require great attention throughout the entire third-party relationship; do it thoroughly but efficiently. Need assistance? We are ready to help.
Sources includes:
¹The 2020 Prevalent-Shared Assessments Third-Party Risk Management Study Link
FoxPointe Solutions is solely responsible only for the content of FoxPointe Solutions authored information and is subject to change at any time. Any forward-looking statements are not predictions. FoxPointe Solutions is not responsible for any errors or omissions, or for the results obtained from the use of this information. Questions regarding your legal or compliance position should be addressed through your legal counsel, security advisor and/or your relevant standard authority. Nothing contained herein should be used nor relied upon as advice nor constitute a consultant-client relationship.