Compliance Week has pared down its list of more than 300 nominees for its first annual Excellence in Compliance Awards and is pleased to announce the finalists for nine of the 15 categories.
In this time of fear and uncertainty, it’s more critical than ever to practice good cyber-security hygiene (just think of it as the technical version of proper handwashing).
As the coronavirus worldwide pandemic spreads, the ramifications for any business has gone from temporary disruption to a serious impediment. Here are 10 steps your company can take to mitigate its risks.
A new executive order issued in January places additional sanctions on a much broader portion of Iran’s economy and, from a compliance and risk management standpoint, puts a broader range of companies in the crosshairs of U.S. enforcement.
Telemedicine platform GoodRx has committed to enhancements of its consumer data protection after Consumer Reports called out its sharing practices regarding personal health information.
Compliance Week spoke with Tiffany Archer, regional ethics and compliance officer and corporate counsel at Panasonic Avionics Corporation, on demystifying OFAC’s 50 Percent rule.
Cardinal Health reached an $8.8 million settlement with the SEC for violations of the FCPA concerning the operations of its former Chinese subsidiary. For prudent compliance officers, it’s a tale of how not to do business in China.
Measuring compliance against third-party risk management requirements is complex and time consuming; and with growing numbers of data breaches originating with third parties and all the regulatory activity that comes as a result, it never lets up.
The burgeoning coronavirus outbreak not only sent markets crashing on Monday, it also put a spotlight on companies whose supply chains have been severely disrupted by the ongoing crisis.
Airbus is free to go about its business after paying a record fine to three anti-corruption agencies for widespread bribery, but the trouble is only beginning for some of its implicated contractors.
Even as companies continue to agree to multi-billion-dollar settlements related to the corrupt acts of third parties, managing the risks associated with them nevertheless eludes many compliance departments.
Compliance Week is proud to announce its first four finalists for the “Excellence in Compliance Awards,” a newly formed program that recognizes individual achievement in one of 13 categories relating to risk and compliance.
Join Aravo and Compliance Week for a webinar on TPM 101: Mapping To Maturity on April 9th. This webinar is intended for anyone that is looking to build a TPM program from scratch or for advancing your current program to a more mature state.
Traditionally, third-party risk management (TPRM) has focused on procurement executing contracts, managing relationships (not risk), and conducting quarterly business reviews. But with today’s organizations relying on vendors to fulfill core business objectives and support competitive advantages, these measures are no longer enough.
Ensuring compliance with third-party risk management (TPRM) regulatory and cyber security requirements means having the right combination of processes and controls in place, and that you can efficiently demonstrate these processes and controls to auditors.
With the clock ticking toward the Jan. 1 implementation date, Compliance Week and ACA Aponix asked 100 compliance practitioners whether their company would be CCPA compliant by the deadline. Their collective answer? Nope.
Do risks from your third-party ecosystem keep you up at night, especially during these trying times? How have third-party risks changed over the years, but especially lately, considering the current crisis?
The latest edition of the Ask Amii mailbag analyzes a case of a third party’s recommendation being ignored and offers tips on when it’s the right time to change career paths.
This webinar presents the results of a recent industry survey on Board oversight of third-party risk. In an environment of increased business risks, close to half (43 percent) of surveyed practitioners claimed that their board doesn’t have a good handle on third-party risk! Together with a dive into the results, ...
At CW’s Third-Party Risk Management and Oversight Summit, the head of Wells Fargo’s global TPRM group took a few pages out of biotech startup Theranos’ book to shed light on what not to do when building a risk culture.
Speaking at CW’s Third-Party Risk Management and Oversight Summit, former FCPA Unit chief Kara Brockmeyer called attention to recent enforcement actions against Walmart and Ericsson as a way to highlight seven steps to third-party compliance.
Today, it’s imperative for companies to manage third-party risk as part of a comprehensive compliance program to protect their brand and avoid exposure to bribery and corruption.
You need help managing your third parties, and over the course of two days in San Francisco, we hope to help you find the answers to the questions that keep TPRM stakeholders up at night.
In a guest column for CW, Uber’s senior counsel for global compliance helps to outline a best-in-class compliance monitoring program.
From bribery and corruption to emerging ESG and reputational risks, corporate compliance functions are expected to protect their business from regulatory liability without slowing the pace of business. This is despite often having fewer resources to manage ever-increasing amounts of third parties and data.
Compliance Week is making some changes to its annual awards for 2020, evolving the “Top Minds” recognition into a full-blown, specifically targeted awards program dubbed “The Excellence in Compliance Awards.”
It is virtually impossible to move forward in business without vendor relationships, but having vendors also means having potential risk.
In a preview of their upcoming session at Compliance Week’s Third-Party Risk Management & Oversight Summit, two experts share best practices on how to ”Earthquake-Proof Your Organization.”
Those in accounting who want to understand better the inherent risks, threats and vulnerabilities, and internal control best practices associated with the use of blockchain technology now have a first-of-its-kind framework to follow.
An organization is only as strong as its weakest link. As enterprises expand their international reach, the potential for uncovering fallible business associates multiplies.
Walmart, TechnipFMC, Fresenius—just to name a few—have all fallen prey to the Foreign Corrupt Practices Act in a record year of jacked-up enforcement and sky-high penalties.
In today’s ever-escalating regulatory environment, companies are expected to understand who they are doing business with. Ultimate Beneficial Ownership (UBO) is required on a mandatory basis for organizations that fall within the scope of AML and beyond. And while the legislation is complex and a challenge for most organizations to ...
This webcast will help compliance executives explore the latest research and practical insights on how to manage human trafficking and manage third-party risks.
A new survey published by Deloitte highlights the latest trends—both opportunities and challenges—in companies’ journey toward a more mature extended enterprise risk management program, one in which third-party risk management is integrated across the firm and led from the top.
DoorDash announced an incident of unauthorized third-party access to user data—a reminder companies need to mind the cyber-security of vendors in addition to their own.
Damaging headlines like this have grown steadily in recent years. Triggered by third parties – such as suppliers, joint-venture partners, and contractors – and exacerbated by longer, more complex supply chains, compliance failures are becoming commonplace. Especially as regulators extend their reach. Building a sustainable framework for third-party risk using ...
In today’s shifting security and regulatory environment, ongoing third-party monitoring is crucial to compliance success. But how do you keep up with a constantly changing and growing list of vendors? This session will outline the keys to third-party risk management success through a modern approach to monitoring vendors.
The Shared Assessments Program announced a new addition to its TPRM framework covering the subjects of periodic assessments and continuous monitoring.
Mastercard is investigating two data breaches relating to a loyalty program it ran in Germany following a leak of personal information that saw customers’ names, addresses, and credit card numbers circulating on the internet.
Enterprises are now, more than ever, relying on a higher number of third-party, mission-critical technologies (along with their support and maintenance). As a result, enterprises are unintentionally opening themselves up to the largest source of data breaches.
Third-party relationships present one of the biggest risks a company can take on, which makes doing all you can to properly vet and monitor these partners of tantamount importance.
Honeywell International announced in a regulatory filing that it is being investigated by U.S. and Brazilian authorities as to whether the company’s use of third parties in Brazil violated the Foreign Corrupt Practices Act.
CyberGRX, a third-party cyber-risk management platform provider, announced the release of a new feature that provides users with immediate visibility into potential threats in their ecosystem.
ProcessUnity has added third-party risk management specialist DVV Solutions to its Partner Program as a managed-service provider.
Managing third-party risk is vital to every business’ reputation and long-term success. But with growing regulatory requirements, compliance skills shortages and numerous potential sources of information, managing third-party risk as an organization can feel like a very painful process.
In the last five years, FINRA, the primary self-regulatory organization for broker-dealers, has focused on prioritizing designated third-party compliance.
Results from the Compliance Week and Refinitiv survey revealed some surprising facts about companies’ third-party training; based on those results, the following article offers suggestions for how to enhance the process.
Determining which business partners to flag for enhanced due diligence all depends on the quality, and sources, of your data.
Outsourcing is nothing new, but recently we’ve seen companies increasingly rely on a network of third-party vendors to help them compete.
The ever-changing regulatory landscape and sheer volume of third parties requires organizations to rethink their processes around pre-contract due diligence and ongoing vendor assessment reviews. Today’s most successful programs rely less on tedious, manual processes while incorporating verified, up-to-date information on financial status, watchlist compliance and information security from trusted ...