
Let’s be honest: most organisations don’t do third-party risk management. They do third-party risk administration. Questionnaires get sent, nobody reads the answers, a SOC 2 report gets filed that covers half the actual infrastructure, and everyone moves on feeling compliant. Meanwhile, your actual supply chain risk sits in a SaaS tool nobody assessed, a subprocessor you’ve never heard of, or a “SOC 2 certified” vendor whose report was scoped by a compliance factory and falls apart the moment you read page three.
I’ve spent far too many years doing hands-on TPRM assessments. I’ve been poking through auto-generated policies, catching infrastructure that doesn’t match the audit scope, and finding vendors whose entire compliance posture is a 10 minute SOC2 “audit” stamp on a PDF. In this session I’ll walk through what I’ve actually found, why the current approach is broken, and what you can do about it without buying another platform or hiring another auditor. Three things you’ll walk away with: how to spot a vendor assessment that’s worth nothing, what EU legislation actually mean for your supply chain obligations, and a practical approach to TPRM that actually works with none of the theatrics.
We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking 'Accept All', you consent to our use of cookies.