As AI becomes more deeply embedded in third-party products and services, Planning and Due Diligence have become critical stages for identifying risks before they are locked into contracts or operations. This paper highlights leading practices for organizations seeking to strengthen early-stage oversight of AI-enabled suppliers. It emphasizes the need for cross-functional collaboration, clear alignment with […]
As third-party risk continues to grow across industries, resourcing challenges are emerging from all directions. With increasing reliance on third parties, rising regulatory pressure, and rapid advances in AI and automation, Third-Party Risk Management (TPRM) programs are being stretched in new ways. This briefing paper explores why traditional staffing models for TPRM are struggling to […]
The Shared Assessments Mid-Year Risk Report explores how recent global disruptions are reshaping the top risk domains impacting Third-Party Risk Management (TPRM) programs in 2025. Drawing on industry-leading research and insights from our member community, this paper examines the shifting landscape and provides practical guidance for risk leaders navigating an increasingly complex environment. Key topics […]
Types of Vendor Risk and How to Mitigate Them Vendor partnerships enable organizations to innovate, scale operations, and improve service delivery. Yet these same relationships introduce exposures that can impact operational stability and compliance integrity. When third-party relationships are not properly managed, vulnerabilities can emerge that increase the likelihood of data breaches, regulatory penalties, or […]
Introducing the Next Evolution of the SIG SIG-EV: A Cloud-Based Platform for Modern TPRM Teams For nearly two decades, the Standardized Information Gathering (SIG) Questionnaire has set the benchmark for third-party risk assessments. Trusted by organizations across every industry, the SIG has streamlined due diligence, strengthened vendor oversight, and unified the language of risk. Now, […]
NIST vs. ISO: Key Differences and Choosing the Right Framework Cybersecurity frameworks are the foundation of effective risk management. They help organizations protect sensitive data, maintain compliance, and build trust with stakeholders. Two of the most widely recognized are NIST (National Institute of Standards and Technology) and ISO (International Organization for Standardization). While both provide […]
In this episode of The Risk Rundown with Shared Assessments, host Elizabeth Dunsmoor delves into the dynamic world of third-party risk management with leading experts. Together, they unpack the challenges and opportunities of navigating today’s rapidly evolving risk landscape. From adapting to shifting regulatory demands to leveraging cutting-edge tools and fostering collaboration, this episode offers […]
In this special “CEO Corner” episode, Elizabeth Dunsmoor, TPRM Principal at Shared Assessments, sits down with Mark Orsi, CEO of Global Resilience Federation, to explore the evolving landscape of operational resilience and third-party risk management from the perspective of the C-suite. They discuss the shift from cybersecurity to resilience, the importance of understanding supply chain […]
In this episode of The Risk Rundown with Shared Assessments, Elizabeth Dunsmoor is joined by Shriparna Ghosh, Director at EY and expert in Third-Party Risk and Resilience Management. Together, they explore the evolving landscape of third-party risk management (TPRM), emphasizing the critical importance of resilience in today’s interconnected world. Sri shares her insights on building robust […]
Please register or log in to complete the checkout process. You will be redirected to the checkout page after logging in.
By downloading this software, you acknowledge that you may be invited to provide usability feedback to help improve its functionality. Feedback does not guarantee changes or compensation.