VRM Governance That Scales — The Hub and Spoke Model
The Governance Challenge
The complexity of organizational structures and the multiple stakeholders involved in the management of third party risk remains a key challenge to management teams . Inefficiencies in TPRM programs can expose organizations to reputational risk .
The Hub and Spoke Model
To respond to an increasingly complex risk environment, firms should utilize a multidisciplinary approach to TPRM by adopting a hub and spoke model .
The Hub
The TPRM function would function as a hub with a central leadership team responsible for :
- Setting policies and standards
- Defining reporting requirements
- Establishing risk appetite of its operation
- Overseeing the TPRM program
The Spokes
The central hub would be supported by subject matter experts ("spokes") from relevant risk domains :
- Privacy
- Cyber security
- Business Continuity
- Disaster Recovery
- Legal
- Compliance
- IT Security
- Procurement
Lines of Defense
The hub and spoke model enables setting up a Lines of Defense model :
First Line (Business Owners) : Manage day-to-day vendor relationships and operational risks.
Second Line (Risk and Compliance) : Establish policies, standards, and risk appetite. Provide oversight and challenge.
Third Line (Internal Audit) : Provide independent assurance on the effectiveness of VRM.
Benefits of the Hub and Spoke Model
|
Benefit |
Description |
|
Comprehensive risk identification |
Multiple risk domains are considered |
|
Holistic risk mitigation |
Risks are addressed from multiple angles |
|
Consistent practices |
Consistency in risk management and compliance practices |
|
Flexibility |
Flexibility to address specific business needs |
|
Clear accountability |
Roles and responsibilities are clearly defined |
Cross-Functional Collaboration
Collaborating with the other business functions adds value as they understand the full scope of the potential geopolitical risks and their impact considering their expertise on international law, sanctions and local regulations that may impact vendor relationships .
Governance Reporting
As part of the governance process, organizations should adopt and establish stringent process controls, which need to be validated per timelines mutually agreed upon with vendor organizations .
Areas of focus for the governance report :
- Documented evidence of vendors' security policies/procedures
- Contracts documenting the vendor's commitment
- Periodic management review reports
- Intervention based on internal and external audits findings
- Data privacy input based on scope of services
- Application security (secure development life cycle, vulnerability and penetration test reports)
- Governance reporting mechanism for key risk areas and action plans
Conclusion
The hub and spoke model provides a scalable governance framework for VRM. By establishing a central leadership hub supported by subject matter experts, organizations can achieve comprehensive risk identification and mitigation while maintaining consistency and flexibility .
Action Items for Your Organization
- Establish a central TPRM leadership hub
- Identify subject matter experts for each spoke
- Define Lines of Defense
- Create governance reporting mechanisms
- Establish cross-functional collaboration