Vendor Risk Management

INTRODUCTION

In today's business environment, outsourcing plays an essential role, allowing organizations to have access to all types of services, from simple information storage services to complex data processing services.

There is no doubt that outsourcing allows organizations to focus their efforts on their core business by obtaining the supplier's expertise and technology without having to invest in its development and maintenance.

However, there are many cases in which an organization is affected by incidents at its suppliers, be they information security, privacy or continuity incidents. This is why outsourcing entails the responsibility of managing the risks associated with outsourcing services, which is complex as there is less direct control over the supplier's risk, assets and operations (connectivity, platforms, technology, accessed data, personnel, location, subcontracting, etc.).

As a solution for the control of these risks, BDO proposes a Vendor Risk Management for information security, privacy and business continuity (hereinafter VRM) model that identifies, categorizes, assesses, monitors and manages the security, privacy and continuity risks of outsourcing throughout the supplier's life cycle (evaluation of the service to be outsourced, risk assessment of proposed suppliers, establishment of the contract, provision of the service and return of the service).

Each entity has its own particularities and type of suppliers, so the VRM model must be adapted to the specific casuistry of the entity. BDO provides support in all phases of the model, from its definition and implementation (methodology, model, analysis and valuation of services and suppliers), its maintenance (risk management of existing and new suppliers) and its application to VRM tools (selection and feeding of the same).

At BDO we believe that outsourcing services provides a great number of advantages to entities that can be taken advantage of as long as their risks are adequately controlled to protect the entity and its clients.


OUR SERVICES

Model definition and implementation

  • Definition of methodology and model.
  • Identification of existing services and suppliers.
  • Categorization of existing supplier services.
  • Valuation of existing suppliers.
  • Audit of existing suppliers.

Model maintenance

  • Model management support.
  • Categorization of new suppliers.
  • Valuation of new suppliers and re-evaluation of existing suppliers.
  • Audit of new suppliers and re-evaluation of existing suppliers.

Evaluation and GAP analysis of existing VRM model.

  • Evaluation and GAP analysis of the existing VRM model.
  • Updating and improvement of the existing model.

Model support in VRM tools

  • Tool selection support.
  • Adaptation of methodology to tool capabilities.
  • Support in tool feeding.

PARTNERS

POST

ARTICLES

EVENTS

Internal Audit Seminars


REFERENCE ORGANIZATIONS

ISACA, ISMS FORUM, Instituto de Auditores Internos, ENISA