TPRA News

Q4: October 2020 

Volume 1, Issue 4

Inside This Issue

  • From the CEO
  • TPRA Quick Hits
  • Upcoming Events
  • TPRA Member Spotlight
  • TPRA Vendor Spotlight
  • Post a Job With Us
  • Write the Editor & Contact Us

 

www.TPRAssociation.org 

From the CEO

 

Hello TPRA Members,

 

It is hard to believe the holiday season is upon us!  It feels like 2020 flew by and I couldn't be happier to see it go.  Although, I must admit that while this year threw many curve balls, I was able to spend more time with family and focus on what really matters.  If this year has taught me anything, it's that slowing down to stop and smell the roses is just as important as working hard.  And speaking of working hard, we've had quite the year here at the Third Party Risk Association!  I want to first thank you for your continued participation in our forums, roundtables, webinars, focus groups, and conferences.  I'm a firm believer that you get out what you put in to your careers, and our organization is here to support you. 

 

Hopefully you were able to participate in our October Practitioner meeting on "Automating Third Party Risk Management".  If you were not, I would encourage you to view the playback on our website.  The meeting included a panel discussion from four industry subject matter experts discussing what to automate within your programs, when to automate, the issues with automation, and how to better leverage data output from an automated process.  It was a great conversation and includes information you can leverage if you are building out a business case for automating your own program.  

 

Our November Practitioner meeting will take place during our Winter Virtual Conference.  We are diverging a bit from our normal one-day conference format to bring you a week-long event.  Each day during the week of November 9th, the TPRA will bring you three presentations from both Practitioners and Third Party Risk Service Providers from the hours of 10 AM and 12 PM.  All presentations will point towards our theme, "The Strategy of Third Party Risk".  This conference is free for both members and non-members and will provide you with 10 hours of Continuing Professional Education (CPE) credits.  For additional details and to register, please visit our Winter Virtual Conference page. 

 

As the TPRA begins planning for 2021, we will look for your feedback in the form of our annual member survey.  You will receive an email within the next month requesting information on the value you receive from your member benefits and Association events.  It will also request information on a variety of topics so that we can ensure our 2021 discussions include topics that you wish to hear about. 

 

Last, as our second year comes to an end, so too does the terms of two of our Board Members.  If you are interested in serving as a TPRA Board member, please reach out to me at Julie@tprassociation.org. You must be a current Practitioner Member (in good standing) and in a Third Party Risk-related leadership role within your organization to apply.

 

As always, please let me know if there is anything you need and stay safe during this holiday season. 

 

~ Julie Gaiaschi, CEO & Founder

TPRA Quick Hits

 

11 Secrets TPRM Solution Vendors Won't Tell You

By: Censinet

 

With more connected technology and devices in use at health systems, it’s no surprise that security teams struggle to keep up. There’s more to protect, less personnel to protect it, and not enough time.

 

 
Read More
 

Healthcare's Gamble with Business Associate Breach Risks

By: CORL technologies

 

Security breaches from third-party Business Associates and related regulato ry penalties are piling up for healthcare entities this year. Too many healthcare entities continue to gamble with underinvestment in their TPRM programs.

 
Read More
 

Reliability of Questionnaires and How to Validate Answers

By: ComplyScore

 

Risk assessment questionnaires play a key role in an organization’s vendor governance program. Yet, for all their value, questionnaires can have shortcomings.  How do you know that the answers given are accurate and helpful?

 
Read More
 

Managing Third Party Contractual Disruptions Caused by COVID-19

By: TPRA & Nyemaster Goode

 

What improvements can and should be made to contracts in response to a global pandemic?  Nyemaster Goode Law Firm provides us with helpful tips on improving your Force Majeure clause and what broad contract language to avoid.

 
Read More

“It is not the manager’s job to prevent risks. It is the manager’s job to make it safe to take them.” 

– Ed Catmull, co-founder of Pixar Animation Studios, president of Pixar Animation and Disney Animation

Upcoming Events

Winter Virtual Conference

"The Strategy of Third Party Risk"

 

November 9 - 13

Daily from 10:00 am - 12:00 pm CST

 
Register Here

November Focus Group Call

TPRM 101 Guidance Build-Out

November 19

10:00 - 11:00 am CST

 
Register Here

December Practitioner Meeting 

 

December 10

10:00 AM - 11:00 AM CST

 
Register Here

External Meetings

 

TPRA Posts a Variety of External Meetings that May be of Interest to You

 
Register Here

TPRA Member Spotlight

Member: Nicole Makinney

Nicole is the Product Owner, Third Party Risk Management for McKesson and currently resides in Atlanta, GA.  She has been a member of the TPRA since February 2019 and thinks that "it is incredibly valuable to be part of a professional association that directly relates to my responsibilities. Being able to discuss best practices, challenges, and supporting technologies has helped me tremendously, and I hope whatever I share in our discussions is valuable to someone else!"  

Fun Fact: My partner and I are renovating a 1976 Fleetwood Prowler travel trailer and although it’s not yet done, we’re currently in the middle of a month-long journey (with appropriate social distancing and COVID protocol, of course!). I’m writing this from a picnic table at a state park in Colorado.

TPRA Vendor Spotlight: Whistic

Partnerships@whistic.com

800-655-6905

 Whistic is a unique TRPM SaaS platform that can automate your vendor risk assessments, track vendor inventory, triage vendors and risk rank vendors based on custom scoring. You can even communicate with vendors via the platform eliminating the spreadsheet and email back and forth. 

Whistic also has a product that allows you to respond to vendor assessments! You can eliminate time wasted filling our security questionnaire by proactively publishing your 'Security Profile'. A single source of truth for security documentation to be shared securely and updated annually. 

Lastly, Whistic offers the Trust Catalog which is an exchange where vendors are opting in to share their questionnaires with the network and where Whistic is providing additional security information like which audits and certs the vendor has. By accessing these assessments on demand you may eliminate the need to reach out to a vendor entirely! 

 

Interesting Tidbit:
1. Whistic recently raised our Series A round of funding led by Emergence Capital.
2. Whistic is the only TRPM platform that allows you to publish your CAIQ to the STAR registry. 
3. Whistic co-authored the CAIQ-Lite last year which has become extremely popular to assess your cloud vendors. 

 

Interested in learning more?  Watch this video. 

If you would like to be a TPRA Practitoner or Vendor Member Spotlight, please email your bio and pic to info@tprassociation.org.

Have a third party risk-related job you would like communicate to qualified candidates?  Post it in our Practitioner Member Forums!

WRITE THE EDITOR 
Do you have a newsletter idea, want to write an article, participate in a spotlight, or provide additional newsletter content?  We would love to hear from you.  Please email the editor at info@tprassociation.org. 

CONTACT US

Third Party Risk Association P.O Box 824, Ankeny, IA 50021

www.TPRAssociation.org    info@tprassociation.org 

Visit us on the web