Many third-party risk-management efforts start with the goal of providing full visibility over a company’s universe of third-party relationships.

The trouble is that many companies still don’t have a firm grasp on how to achieve that transparency, or even where to begin, exposing themselves to significant legal and compliance risks. “Companies often underestimate their universe of third parties,” Randy Stephens, vice president of advisory services for NAVEX Global, says. Most tend to focus on traditional third-party relationships—such as suppliers, distributors, agents, and joint ventures, for example.  

Jaclyn Jaeger is a freelance contributor to Compliance Week after working for the company for 15 years. She writes on a wide variety of topics, including ethics and compliance, risk management, legal,...