Growing Vendor Management

Size: px
Start display at page:

Download "Growing Vendor Management"

Transcription

1 V E N D O R M A N A G E M E N T P R O F I L E S E R I E S A Wh it e Pap e r by Ve n d or I NS I G HT an d C MPG, L L C Growing Vendor Management as a Sustainable Business Process with Automated Vendor Management Systems November 1, 2013 C O P Y R I G H T B Y V E N D O R I N S I G H T A N D C M P G, L L C. A L L R I G H T S R E S E RV E D.

2 Vendor Management Evolved Boundaries and Origins Vendor management, by its nature, is a broad-ranging business process that crosses many organizational boundaries, including Sourcing, Procurement, Risk and Compliance, IT, Information Security, Disaster Recovery Planning, Finance, and Accounting, Retail and Operations groups. In addition to requiring the collaborative participation of these groups, a company s successful vendor management program must facilitate many business needs. These include: Vendor research and selection Vendor evaluation and due diligence activities Contract development, monitoring and alerting Multi-dimensional risk assessment (financial, legal, information security, fraud, technology, etc.) Performance measurement and SLA (service level agreement) monitoring Market news monitoring Financial health monitoring SSAE16 review and monitoring Business risk and business trend monitoring The development of vendor management into the multifaceted business process it is today was enabled by the maturity of sourcing as a strategic business discipline. Sourcing taught organizations to control costs and set expectations for vendor performance on the front end of the relationship - during the vendor selection process. Vendor management evolved by necessity because of the need to monitor contracts, track service level agreements, and ensure that the services and performance that were negotiated were being realized. Vendor management embodies the closed-loop side of the traditional plan-execute-measure-control model, where sourcing constitutes the planning and execution phases, and vendor management embodies the measurement and control phases. Because so much of the risk borne by a company can be evaluated from information that is typically revealed concurrently with vendor evaluation, selection and contracting activities, vendor management naturally extends upstream into the stages of sourcing where this information first becomes available. So, in essence, vendor management - especially its risk components - has engulfed the traditional sourcing model which was previously cost-focused, in the interest of ensuring improved risk management, reliability and performance. The Three Primary Objectives of Vendor Management A reliable vendor management program is built around features that help manage three domains related to the vast array of vendors and third parties who are contracted to provide services, management data, products, software, hardware, or the outsourcing of critical business functions. These domains are Relationship, Risk and Performance. Interdependent, they provide essential information, data, and analysis that is essential to management s understanding of the importance, reliability and strength of the vendors and third parties the company relies on. In highly regulated industries like financial services or healthcare, these three domains also represent the primary 1

3 concerns of regulators, auditors and examiners, at the federal and state level, as they enact guidance and laws and evaluate an organization s operational risk and enterprise risk management program. Financial institutions increasingly rely on third parties for the creation, delivery and maintenance of products and customer relationships. All of these critical vendor relationships bear the burden of standing up under the daily pressure of a dynamic and changing business and technology environment, and they must successfully avoid harming the financial stability, profitability, or customers of the financial institution that relies on them. As the industry has matured and as new risks emerge from evolving B2B behavior that increasingly relies on social media, unique outsourcing arrangements, and leveraged supply chain relationships, the regulators have responded with new guidance and laws aimed at mitigating these risks. In fact, it can be argued that the new guidance imposes managerial oversight and mandates specific process design for companies as they carry out the business of vendor and third party risk management. In 2013 alone, three new updated regulatory guidance documents were published that relate to the financial services industry. These include: FFIEC Guidance on Social Media (January 2013); FDIC Compliance Manual, Abusive Practices - Third Party Procedures (July 2013); OCC New Guidance for Third Party Risks (October 2013) In late 2013, company internal audits and regulatory examination findings increasingly reflect the new standards. Companies and industries struggle to keep up as they continually work at developing their vendor management programs into more formal, consistent and efficacious business processes that provide a competitive advantage while satisfying regulators and enterprise risk management objectives. Relationship. Risk. Performance. Effective Risk Management and Sustainably Consistent Business Practices are Enabled by Automated Vendor Management Systems. Relationship - Knowing all of your vendors, how many there are, what services they provide and which ones are most important is similar to understanding and classifying the many species and the working ecology of a forest. Risk - Examining vendors in detail to evaluate their information security strength, financial strength or health is much like a forensics analysis. It requires specialized knowledge and the tools to do the job efficiently. Performance - Measuring your vendors and their performance, adherence to SLAs and other key metrics is important to ensure your organization will perform at its highest level and grow without disruption. 2

4 The Six Common Plagues of Vendor Management Business Problems Drive the Need for Vendor Management Automation Today, vendor management activities at most companies are directed, or at least heavily influenced, by a department of Risk Management and Compliance. The responsibilities for maintaining and organizing vendor information falls on an often small group of dedicated personnel who, through the management mechanisms of policy design, oversight, subject matter expertise, and reporting and accountability, attempt to ensure that vendor management procedures are carried out diligently, timely, and in a consistent and formal manner across the enterprise. Seven business problems are common to nearly every organization. These business problems expose financial institutions and other companies alike to significant cost risk, regulatory risk, and strategic business risk: 1. There is not enough time or manpower resources available to be able to properly carry out vendor management activities that range from extensive due diligence to contracting to monitoring and performance management. 2. Performance and SLA monitoring of vendors - a critical component of the business value received from a vendor - is inconsistent at best and must be performed manually. 3. There is currently no standard or consistently-applied risk rating methodology that can easily be applied to ALL vendor relationships. This results in inconsistency among the vendor records and documentation. 4. There is insufficient visibility into the contractual obligations of the company, including key notice dates, automatic renewal dates and options within the contracts with mission critical and high value service providers and third parties. Additionally, it is difficult and time-consuming to locate key contracts with service providers when they are needed for planning or strategic projects. 5. An extensive manual effort is required to maintain and manage the vast array of information that is essential and pertinent to the proper governance of vendor and third party relationships. 6. Managers and employees who interface with suppliers and who own the business processes the suppliers support, do not prioritize vendor management and are not held accountable by management for the timely and proper completion of their assigned tasks and activities within the vendor management process. Each of these business problems can be alleviated by an automated vendor management system that enables better access to information, a centralized repository of vendor information, a consistent methodology for vendor assessments, and improved workflow with enhanced visibility, reporting, oversight and control. 3

5 ROI and Cost-Benefit Analysis for an Automated Vendor Management System Assumptions The following analysis is based on vendor management metrics that are specific to and that have been developed by UBSI, including compensation and expense numbers. Metrics, where utilized, have been validated with industry research. The data utilized in the ROI analysis has been selected to present a conservative ROI calculation in order to mitigate any inherent risk in the assumptions. Number of Expected Vendor Contracts Managed: 400! Average Annual Contract Value: $85,000 Average Contract Length (Frequency of Renewal): 3 Years! Percentage of Contracts Renewing that Require RFP/Negotiation: 20% Frequency of Audit or Examination: 12 Months!! Cost of Outside Legal Counsel: $250/hr.!! Total Compensation (Salary and Benefits):! Program Administrator: $62,000! Clerical/Administration: $ 45,000 Classification and Quantification of Benefits Fortunately, vendor management is not just an added cost and resources burden to an organization, rather, it brings with it significant and tangible business benefits and savings. The companies that maintain a formal vendor management program learn quickly that getting real business benefits and achieving regulatory compliance and risk management go hand-in-hand. A strong vendor management program delivers benefits across three dimensions: Activity and Productivity Benefits - Enables easier, faster completion of required tasks and activities like vendor risk assessments, performance reviews, or RFPs and results in improved resource utilization, improved productivity and lower personnel costs. Business Benefits - Improves the visibility and reliability of management information that is needed to make strategic and daily business decisions like whether to renew a contract, when to terminate a vendor relationship, or when a critical vendor decision may be needed. Compliance and Risk Benefits - Ensures that your policies and procedures, and the federal and state laws they are designed to comply with, are consistently and formally met. Meeting the regulatory and compliance requirements requires better organization of data and vendor information which is equally useful for business strategy, planning and execution, including cost control, budgeting and legal risk mitigation. Clearly, the business benefits of a vendor management system alone easily justify the expense of an automated vendor management system, even in the absence of essential risk and compliance benefits. Results The ROI analysis shows that a vendor management system will easily provide annual benefits that exceed the cost of the system, including setup and training. The Internal Rate of Return (IRR) exceeds 700% with quantifiable financial benefits plus reduced enterprise risk levels accompanied by a significantly improved risk management position. 4

6 Type Benefit COST- BENEFIT ANALYSIS FOR AUTOMATED VENDOR MANAGEMENT SYSTEM A - Activity and Productivity Savings Annual Savings A PRODUCTIVITY / Personnel Savings - Vendor Management Due Dilgence and Compliance Task Automation $ 124,000 A PRODUCTIVITY / Personnel Savings - Contract Ownership, Management and Vendor Monitoring $ 42,408 A PRODUCTIVITY / Personnel Savings - Document Review and Data Entry $ 18,000 A PRODUCTIVITY / Personnel Savings - Sourcing and RFP Administration and Management $ 12,000 A PRODUCTIVITY / Personnel Savings - Finance, Information Security/IT, and RIsk Management Administration $ 4,133 A PRODUCTIVITY / Personnel Savings - Risk and Compliance / Examinations and Audit Preparation and Response $ 1,240 B - Business (Non- Interest Expense) Savings NONINTEREST EXPENSE REDUCTION - REDUCED STAFFING REQUIREMENT / B Personnel Savings from Program Administration Included with Software $ 62,000 B NONINTEREST EXPENSE REDUCTION / Contract Pricing and Price Increase Avoidance $ 51,000 B NONINTEREST EXPENSE REDUCTION / Legal Review by Outside Counsel $ 33,333 B NONINTEREST EXPENSE REDUCTION / Contract Renewals, Strategic Visibility and Cost Avoidance $ 25,500 B NONINTEREST EXPENSE REDUCTION / Paper and Printing Cost Savings $ 9,000 B NONINTEREST EXPENSE REDUCTION - Regulatory Awareness & Program Upkeep $ 8,125 C - Compliance Requirements (Non- Quantified / Partial List) C Compliance with Differentiated Monitoring and Management Control Requirements for High/Medium/Low Risk Vendors Requirement Compliance with Newest RegulatoryRequirements: FFIEC Social Media Monitoring (January 2013), FDIC Abusive Practices C and CFPB Consumer Compaints (July 2013), and OCC Revised Third Party Management Guidance (October 2013) Requirement Assessment of the "Criticality" or Vendor Relationship to Determine Appropriate Level of Due Diligence and Risk C Assessment Requirement C Identification of Vendors with Poor or Downward Trendng Performance or Risk Profiles Requirement C Proactive Monitoring and Alerting of Key Contract Notice Dates, Cost Increases, Planning Horizons and SLAs Requirement C Automatic OFACand CFPB Customer Complaint Database Checking of All New Vendors Requirement C Maintenance and Archive of Vendor Selection Decision Documentation Requirement Monitoring/Enforcement of Roles and Responsibilities for Vendor Management Policy and Procedures (Including C Requirement Training) C Consistency in Maintaining Policy Compliance Visibility Across All Vendor Management Records Requirement TOTAL ANNUAL SAVINGS $ 390,740 Vendor Management Automated System One- Time Setup Cost: $ Vendor Management Automated System Annual Recurring Cost: $ 20,000 40,000 IRR (INTERNAL RATE OF RETURN) 718%

7 Conclusions and Recommendations The Case for Automated Vendor Management Systems Automated vendor management systems, especially the class-leading solutions offered by reliable, established companies like VendorINSIGHT, can be easily and quickly deployed in less than 30 to 45 days. They utilize cloudbased strategies to minimize costs and employ the latest technologies. The solutions are easy to use, reliable, and cost-effective. With one-time initial setup costs that average less than $20,000 and recurring annual costs frequently less than $40,000, these solutions cost less than a single employee, deliver benefits and productivity improvements equivalent to several employees and provide an internal rate of return of more than 700%. Moreover, they provide a scalable platform to more fully develop a vendor management program over time as companies grow or expand, as new vendor management best practices evolve, or as new requirements are imposed by regulatory bodies. Without a leading automated vendor management program in place to provide the controls needed to ensure consistency and proper execution of vendor management policies and good practices, a company is unnecessarily exposed to excessive legal risk, financial risk, performance risk, information security risk, business continuity risk, customer risk and repetitional risk. When the analysis shows a strong hard-dollar financial return, an inherentlyunderstood promise of reduced risk and improved compliance, with improved productivity and better management information and reporting, utilizing an automated vendor management system just makes good business sense. Grant Karnes is the Executive Director of VendorINSIGHT and the lead vendor management implementation consultant for CMPG, LLC. For more details or to discuss VendorINSIGHT as a solution for your business, contact a VendorINSIGHT representative at or by VendorINSIGHT and CMPG, LLC. 5

Vendor Management. Outsourcing Technology Services

Vendor Management. Outsourcing Technology Services Vendor Management Outsourcing Technology Services Objectives Board and Senior Management Responsibilities Risk Management Program Risk Assessment Service Provider Selection Contracts Ongoing Monitoring

More information

Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks.

Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks. Blind spot Banks are increasingly outsourcing more activities to third parties. But they can t outsource the risks. For anyone familiar with the banking industry, it comes as no surprise that banks are

More information

Software Asset Management on System z

Software Asset Management on System z Software Asset Management on System z Mike Zelle Tivoli WW IT Asset Management Marketing SAM in SHARE Project Manager mzelle@us.ibm.com Agenda Why Software Asset Management (SAM) The Discipline of Software

More information

RISK MANAGEMENT PROGRAM THAT WORKS FOUR KEYS TO CREATING A VENDOR. HEADQUARTERS 33 Bradford Street Concord, MA 01742 PHONE: 978-451-7655

RISK MANAGEMENT PROGRAM THAT WORKS FOUR KEYS TO CREATING A VENDOR. HEADQUARTERS 33 Bradford Street Concord, MA 01742 PHONE: 978-451-7655 FOUR KEYS TO CREATING A VENDOR RISK MANAGEMENT PROGRAM THAT WORKS HEADQUARTERS 33 Bradford Street Concord, MA 01742 PHONE: 978-451-7655 FOUR KEYS TO CREATING A VENDOR RISK MANAGEMENT PROGRAM THAT WORKS

More information

White Paper THE FIVE STEPS TO MANAGING THIRD-PARTY RISK. By James Christiansen, VP, Information Risk Management

White Paper THE FIVE STEPS TO MANAGING THIRD-PARTY RISK. By James Christiansen, VP, Information Risk Management White Paper THE FIVE STEPS TO MANAGING THIRD-PARTY RISK By James Christiansen, VP, Information Management Executive Summary The Common Story of a Third-Party Data Breach It begins with a story in the newspaper.

More information

Best Practices: Cloud Computing for Associations

Best Practices: Cloud Computing for Associations Best Practices: Cloud Computing for Associations What You Should Expect from this Session A solid understanding of cloud computing and Software as a Service Best practices for how cloud computing is being

More information

Best-in-Class Vendor Management Office

Best-in-Class Vendor Management Office Drive Your Business Strategy Brief IT Best-in-Class Vendor Management Office Vendor Management Should be a Core Competency of the IT Function With the role of key vendors evolving and with more vendors

More information

Contact Centers in the Cloud: A Better Way to Source

Contact Centers in the Cloud: A Better Way to Source Contact Centers in the Cloud: A Better Way to Source By Irwin Lazar Vice President and Service Director, Nemertes Research Executive Summary Contact Center Software as a Service (CCSaaS) solutions provide

More information

How To Use Cautela Labs Cloud Agile.Com

How To Use Cautela Labs Cloud Agile.Com 1 Correlation and analysis of security and network events in one integrated solution Cautela Labs Cloud Agile. Secured. Log Management 1 Log Management A great deal of events cross your network, servers,

More information

3 rd Party Vendor Risk Management

3 rd Party Vendor Risk Management 3 rd Party Vendor Risk Management Session 402 Tuesday, June 9, 2015 (11 to 12pm) Session Objectives The need for enhanced reporting on vendor risk management Current outsourcing environment Key risks faced

More information

building a business case for governance, risk and compliance

building a business case for governance, risk and compliance building a business case for governance, risk and compliance contents introduction...3 assurance: THe last major business function To be integrated...3 current state of grc: THe challenges... 4 building

More information

END TO END DATA CENTRE SOLUTIONS COMPANY PROFILE

END TO END DATA CENTRE SOLUTIONS COMPANY PROFILE END TO END DATA CENTRE SOLUTIONS COMPANY PROFILE About M 2 TD M2 TD is a wholly black Owned IT Consulting Business. M 2 TD is a provider of data center consulting and managed services. In a rapidly changing

More information

VENDOR MANAGEMENT. General Overview

VENDOR MANAGEMENT. General Overview VENDOR MANAGEMENT General Overview With many organizations outsourcing services to other third-party entities, the issue of vendor management has become a noted topic in today s business world. Vendor

More information

2014 Vendor Risk Management Benchmark Study

2014 Vendor Risk Management Benchmark Study 2014 Vendor Risk Management Benchmark Study Introduction/Executive Summary You can have all the security in the world inside your company s four walls, but all it takes is a compromise at one third-party

More information

Information Technology

Information Technology Information Technology Information Technology Session Structure Board of director actions Significant and emerging IT risks Practical questions Resources Compensating Controls at the Directorate Level

More information

Domain 1 The Process of Auditing Information Systems

Domain 1 The Process of Auditing Information Systems Certified Information Systems Auditor (CISA ) Certification Course Description Our 5-day ISACA Certified Information Systems Auditor (CISA) training course equips information professionals with the knowledge

More information

The future of application outsourcing: making the move from tactical to strategic

The future of application outsourcing: making the move from tactical to strategic IBM Global Business Services White Paper The future of application outsourcing: making the move from tactical to strategic Application Services Page 2 Contents 2 Introduction 2 Success brings new challenges

More information

Services Providers. Ivan Soto

Services Providers. Ivan Soto SOP s for Managing Application Services Providers Ivan Soto Learning Objectives At the end of this session we will have covered: Types of Managed Services Outsourcing process Quality expectations for Managed

More information

SOLUTION BRIEF: CA IT ASSET MANAGER. How can I reduce IT asset costs to address my organization s budget pressures?

SOLUTION BRIEF: CA IT ASSET MANAGER. How can I reduce IT asset costs to address my organization s budget pressures? SOLUTION BRIEF: CA IT ASSET MANAGER How can I reduce IT asset costs to address my organization s budget pressures? CA IT Asset Manager helps you optimize your IT investments and avoid overspending by enabling

More information

THE BUSINESS OF CLOUD

THE BUSINESS OF CLOUD THE BUSINESS OF CLOUD THE BUSINESS OF CLOUD Introduction Chapter 1: Chapter 2: Chapter 3: Chapter 4: Chapter 5: Chapter 6: Choose the Right Model Overcome Procurement Barriers to Cloud Adoption Meet Complex

More information

10 Best Practices in Printer Fleet Management

10 Best Practices in Printer Fleet Management 10 Best Practices in Printer Fleet Management Corporations recognize that they need to address out of control costs associated with network printing. How do they get there? Many are looking to solve it

More information

Certified Identity and Access Manager (CIAM) Overview & Curriculum

Certified Identity and Access Manager (CIAM) Overview & Curriculum Identity and access management (IAM) is the most important discipline of the information security field. It is the foundation of any information security program and one of the information security management

More information

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered Over the last decade, cloud backup, recovery and restore (BURR) options have emerged

More information

TAKE COST CONTROL AND COMPLIANCE TO A NEW LEVEL. with ACL Travel & Entertainment Expense Fraud and Cost Control Solution

TAKE COST CONTROL AND COMPLIANCE TO A NEW LEVEL. with ACL Travel & Entertainment Expense Fraud and Cost Control Solution TAKE COST CONTROL AND COMPLIANCE TO A NEW LEVEL with ACL Travel & Entertainment Expense Fraud and Cost Control Solution TAKE COST CONTROL AND COMPLIANCE TO A NEW LEVEL with ACL Travel & Entertainment Expense

More information

THE UH OH MOMENT. Financial Services Enterprises Focus on Governance, Transparency and Supply Chain Risk

THE UH OH MOMENT. Financial Services Enterprises Focus on Governance, Transparency and Supply Chain Risk THE UH OH MOMENT Financial Services Enterprises Focus on Governance, Transparency and Supply Chain Risk By Lois Coatney, Chuck Walker and Joseph Yacura, ISG Directors www.isg-one.com INTRODUCTION A top

More information

Vendor Risk Management in the New Regulatory Environment. kpmg.com

Vendor Risk Management in the New Regulatory Environment. kpmg.com Vendor Risk Management in the New Regulatory Environment kpmg.com Vendor Risk Management in the New Regulatory Environment 2 Vendor Risk Management in the New Regulatory Environment Background Regulators

More information

Emptoris Contract Management Solution for Healthcare Providers

Emptoris Contract Management Solution for Healthcare Providers Emptoris Contract Management Solution for Healthcare Providers An Emptoris White Paper Emptoris, an IBM Company www.emptoris.com CMS-HP-4/12 Emptoris Contract Management Solution for Healthcare Providers

More information

agility made possible

agility made possible SOLUTION BRIEF CA IT Asset Manager how can I manage my asset lifecycle, maximize the value of my IT investments, and get a portfolio view of all my assets? agility made possible helps reduce costs, automate

More information

The Business Continuity Maturity Continuum

The Business Continuity Maturity Continuum The Business Continuity Maturity Continuum Nick Benvenuto & Brian Zawada Protiviti Inc. 2004 Protiviti Inc. EOE Agenda Terminology Risk Management Infrastructure Discussion A Proposed Continuity Maturity

More information

Managed Services - Driving Business Value in Banking

Managed Services - Driving Business Value in Banking White Paper Managed services for credit solutions: Driving business value in banking Business solutions through information technology Entire contents 2005 by CGI Group Inc. All rights reserved. Reproduction

More information

Vendor Management Program Office Onshore or offshore?

Vendor Management Program Office Onshore or offshore? Vendor Management Program Office Onshore or offshore? Deloitte s previous article 1 discusses the five most common challenges which have prohibited clients from optimizing their Vendor Management (VM)

More information

Accelerate Your Enterprise Private Cloud Initiative

Accelerate Your Enterprise Private Cloud Initiative Cisco Cloud Comprehensive, enterprise cloud enablement services help you realize a secure, agile, and highly automated infrastructure-as-a-service (IaaS) environment for cost-effective, rapid IT service

More information

SAP Managed Services SAP MANAGED SERVICES. Maximizing Performance and Value, Minimizing Risk and Cost

SAP Managed Services SAP MANAGED SERVICES. Maximizing Performance and Value, Minimizing Risk and Cost SAP Managed Services SAP MANAGED SERVICES Maximizing Performance and Value, Minimizing Risk and Cost WE RE FOCUSED ON YOUR GOALS Increase productivity with fewer resources. Optimize IT systems while cutting

More information

Address IT costs and streamline operations with IBM service desk and asset management.

Address IT costs and streamline operations with IBM service desk and asset management. Asset management and service desk solutions To support your IT objectives Address IT costs and streamline operations with IBM service desk and asset management. Highlights Help improve the value of IT

More information

Solution brief. HP solutions for IT service management. Integration, automation, and the power of self-service IT

Solution brief. HP solutions for IT service management. Integration, automation, and the power of self-service IT Solution brief HP solutions for IT service management Integration, automation, and the power of self-service IT Make IT indispensable to the business. Turn IT staff into efficient, cost-cutting rock stars.

More information

COMMUNIQUE. Information Technology (IT) Governance Guidance

COMMUNIQUE. Information Technology (IT) Governance Guidance COMMUNIQUE 14-COM-002 July 14, 2014 Information Technology (IT) Governance Guidance The Credit Union Prudential Supervisors Association (CUPSA) has established an IT Risk Working Group to focus on IT governance

More information

IT SERVICE MANAGEMENT POLICY MANUAL

IT SERVICE MANAGEMENT POLICY MANUAL IT SERVICE MANAGEMENT POLICY MANUAL Version - 1.0 SATYAM COMPUTER SERVICES LIMITED Satyam Infocity Unit 12, Plot No. 35/36 Hi-tech City layout Survey No. 64 Madhapur Hyderabad - 500 081 Andhra Pradesh

More information

Right-Sizing Electronic Discovery: The Case For Managed Services. A White Paper

Right-Sizing Electronic Discovery: The Case For Managed Services. A White Paper Right-Sizing Electronic Discovery: The Case For Managed Services A White Paper 1 2 Table of Contents Introduction....4 An Overview of the Options...4 Insourcing: Bringing E-Discovery Processes In-House....4

More information

How Can I Better Manage My Software Assets And Mitigate The Risk Of Compliance Audits?

How Can I Better Manage My Software Assets And Mitigate The Risk Of Compliance Audits? SOLUTION BRIEF CA SERVICE MANAGEMENT - SOFTWARE ASSET MANAGEMENT How Can I Better Manage My Software Assets And Mitigate The Risk Of Compliance Audits? SOLUTION BRIEF CA DATABASE MANAGEMENT FOR DB2 FOR

More information

Contracts Management Software as a Tool for SOX Compliance

Contracts Management Software as a Tool for SOX Compliance Contracts Management Software as a Tool for SOX Compliance White Paper (281) 334-6970 sales@prodagio.com www.prodagio.com In 2002, following the scandals involving corporations such as Enron, WorldCom,

More information

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility

What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility Your Guide to Cost, Security, and Flexibility What You Need to Know About Cloud Backup: Your Guide to Cost, Security, and Flexibility 10 common questions answered Over the last decade, cloud backup, recovery

More information

Simplify the Complexity of Managing 3rd Party Anti-Bribery / FCPA Compliance

Simplify the Complexity of Managing 3rd Party Anti-Bribery / FCPA Compliance Simplify the Complexity of Managing 3rd Party Anti-Bribery / FCPA Compliance Arm Stakeholders with Critical Information to Assess 3rd Party Relationships and Comply with the Foreign Corrupt Practices Act

More information

Value of a Purpose-Built Third-Party Compliance Solution

Value of a Purpose-Built Third-Party Compliance Solution Value of a Purpose-Built Third-Party Compliance Solution Introduction Multinational corporations routinely engage third parties such as sales agents, consultants, brokers, distributors, resellers, suppliers,

More information

Picasso Recommendation

Picasso Recommendation Picasso Recommendation Mission The School of Dentistry for the University at Buffalo (UB) uses a custom application called Picasso to manage their clinic operations. Developed by two engineers in 1997,

More information

Third-Party Risk Management: Busting Myths and Telling Truths

Third-Party Risk Management: Busting Myths and Telling Truths Third-Party Risk Management: Busting Myths and Telling Truths Richik Sarkar, Esq. McDonald Hopkins LLC 600 Superior Avenue, East, Suite 2100 Cleveland, OH 44114 (216) 430-2009 rsarkar@mcdonaldhopkins.com

More information

Digital Asset Manager, Digital Curator. Cultural Informatics, Cultural/ Art ICT Manager

Digital Asset Manager, Digital Curator. Cultural Informatics, Cultural/ Art ICT Manager Role title Digital Cultural Asset Manager Also known as Relevant professions Summary statement Mission Digital Asset Manager, Digital Curator Cultural Informatics, Cultural/ Art ICT Manager Deals with

More information

Vendor Risk Management Financial Organizations

Vendor Risk Management Financial Organizations Webinar Series Vendor Risk Management Financial Organizations Bob Justus Chief Security Officer Allgress Randy Potts Managing Consultant FishNet Security Bob Justus Chief Security Officer, Allgress Current

More information

Outsourced Third Party Relationship Management/ Vendor Management. TTS Webinar July 15, 2015 Susan Orr CISA, CISM, CRISC, CRP

Outsourced Third Party Relationship Management/ Vendor Management. TTS Webinar July 15, 2015 Susan Orr CISA, CISM, CRISC, CRP Outsourced Third Party Relationship Management/ Vendor Management TTS Webinar July 15, 2015 Susan Orr CISA, CISM, CRISC, CRP 1 Risk Management Guidance 2 3 Appendix J: 4 - Key Elements Third Party Management

More information

OBLIGATION MANAGEMENT

OBLIGATION MANAGEMENT OBLIGATION MANAGEMENT TRACK & TRACE: CONTRACTUAL OBLIGATIONS Better Visibility. Better Outcomes RAMESH SOMASUNDARAM DIRECTOR, IT VENDOR MANAGEMENT SERVICES MARCH 2012 E N E R G I C A Governance Matter

More information

Driving AP Automation Efficiencies Through Payments Transformation. Minnesota AFP April 19, 2011

Driving AP Automation Efficiencies Through Payments Transformation. Minnesota AFP April 19, 2011 Driving AP Automation Efficiencies Through Payments Transformation Minnesota AFP April 19, 2011 Zorica Stojanovic Vice President Lawrence Heavey Senior Vice President Agenda Payments Transformation Challenges

More information

II. Compliance Examinations - Compliance Management System. Compliance Management System. Introduction. Board of Directors and Management Oversight

II. Compliance Examinations - Compliance Management System. Compliance Management System. Introduction. Board of Directors and Management Oversight Compliance Management System Introduction Financial institutions operate in a dynamic environment influenced by industry consolidation, convergence of financial services, emerging technology, and market

More information

MAXIMIZING VALUE FROM SAP WITH SUPPLY CHAIN COLLABORATION IN A SOFTWARE-AS-A-SERVICE MODEL. An E2open White Paper. Contents.

MAXIMIZING VALUE FROM SAP WITH SUPPLY CHAIN COLLABORATION IN A SOFTWARE-AS-A-SERVICE MODEL. An E2open White Paper. Contents. White Paper MAXIMIZING VALUE FROM SAP WITH SUPPLY CHAIN COLLABORATION IN A SOFTWARE-AS-A-SERVICE MODEL An E2open White Paper 2 2 4 6 Contents Executive Overview Issues and Challenges Resolution Plan for

More information

Services. Hospital Solutions: Integrated Healthcare IT and Business Process Solutions that Achieve Breakthrough Results

Services. Hospital Solutions: Integrated Healthcare IT and Business Process Solutions that Achieve Breakthrough Results Services Hospital Solutions: Integrated Healthcare IT and Business Process Solutions that Achieve Breakthrough Results Hospital Solutions Overview Hospital Solutions Backed by more than 20 years of strength

More information

Risk Management of Outsourced Technology Services. November 28, 2000

Risk Management of Outsourced Technology Services. November 28, 2000 Risk Management of Outsourced Technology Services November 28, 2000 Purpose and Background This statement focuses on the risk management process of identifying, measuring, monitoring, and controlling the

More information

Service Design, Management and Composition: Service Level Agreements Objectives

Service Design, Management and Composition: Service Level Agreements Objectives Objectives! motivation for service level agreements! definition / measurement of levels! management of SLAs! formal representation 2 Content! definition! example! metrics! negotiation! optimization! monitoring!

More information

Global Headquarters: 5 Speen Street Framingham, MA 01701 USA P.508.872.8200 F.508.935.4015 www.idc.com

Global Headquarters: 5 Speen Street Framingham, MA 01701 USA P.508.872.8200 F.508.935.4015 www.idc.com WHITE PAPER Monetizing the Cloud: XaaS Opportunities for Service Providers Sponsored by: EMC Brad Nisbet March 2011 Global Headquarters: 5 Speen Street Framingham, MA 01701 USA P.508.872.8200 F.508.935.4015

More information

GUIDANCE FOR MANAGING THIRD-PARTY RISK

GUIDANCE FOR MANAGING THIRD-PARTY RISK GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,

More information

IT ASSET MANAGEMENT SELECTED BEST PRACTICES. Sherry Irwin

IT ASSET MANAGEMENT SELECTED BEST PRACTICES. Sherry Irwin IT ASSET MANAGEMENT SELECTED BEST PRACTICES Sherry Irwin IT ASSET MANAGEMENT SELECTED BEST PRACTICES By Sherry Irwin INTRODUCTION As the discipline of IT asset management (ITAM) began to evolve in the

More information

Whitepaper: 7 Steps to Developing a Cloud Security Plan

Whitepaper: 7 Steps to Developing a Cloud Security Plan Whitepaper: 7 Steps to Developing a Cloud Security Plan Executive Summary: 7 Steps to Developing a Cloud Security Plan Designing and implementing an enterprise security plan can be a daunting task for

More information

Effectively Managing Employee Absence

Effectively Managing Employee Absence Effectively Managing Employee Absence Leveraging Internal and External Resources Winter 2011 Effectively Managing Employee Absence Leveraging Internal and External Resources Employees who take family FMLA

More information

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data

CRISC Glossary. Scope Note: Risk: Can also refer to the verification of the correctness of a piece of data CRISC Glossary Term Access control Access rights Application controls Asset Authentication The processes, rules and deployment mechanisms that control access to information systems, resources and physical

More information

Corporate Challenges in Model Risk Management : Moving Beyond Model Inventory. Iain Wright Ian Francis, IBM 4 June 2015

Corporate Challenges in Model Risk Management : Moving Beyond Model Inventory. Iain Wright Ian Francis, IBM 4 June 2015 Corporate Challenges in Model Risk Management : Moving Beyond Model Inventory Iain Wright Ian Francis, IBM 4 June 2015 Corporate Challenges in the Development and Implementation of Effective Model Risk

More information

Connecting data initiatives with business drivers

Connecting data initiatives with business drivers Connecting data initiatives with business drivers TABLE OF CONTENTS: Introduction...1 Understanding business drivers...2 Information requirements and data dependencies...3 Costs, benefits, and low-hanging

More information

IT Governance Regulatory. P.K.Patel AGM, MoF

IT Governance Regulatory. P.K.Patel AGM, MoF IT Governance Regulatory Perspective P.K.Patel AGM, MoF Agenda What is IT Governance? Aspects of IT Governance What banks should consider before implementing these aspects? What banks should do for implementation

More information

White Paper Achieving GLBA Compliance through Security Information Management. White Paper / GLBA

White Paper Achieving GLBA Compliance through Security Information Management. White Paper / GLBA White Paper Achieving GLBA Compliance through Security Information Management White Paper / GLBA Contents Executive Summary... 1 Introduction: Brief Overview of GLBA... 1 The GLBA Challenge: Securing Financial

More information

Designing an Operational Risk Program for a Community Bank Stephan Salvador Managing Director, Risk Management Consulting

Designing an Operational Risk Program for a Community Bank Stephan Salvador Managing Director, Risk Management Consulting Consulting and Professional Services Designing an Operational Risk Program for a Community Bank Stephan Salvador Managing Director, Risk Management Consulting Designing an Operational Risk Program for

More information

A Practical Guide for Creating an Information Management Strategy and Strategic Information Management Roadmap

A Practical Guide for Creating an Information Management Strategy and Strategic Information Management Roadmap A Practical Guide for Creating an Information Management Strategy and Strategic Information Management Roadmap Principal Author Sam McCollum, CRM, MBA Director of End User Consulting Parity Research LLC

More information

Request for Proposal for Application Development and Maintenance Services for XML Store platforms

Request for Proposal for Application Development and Maintenance Services for XML Store platforms Request for Proposal for Application Development and Maintenance s for ML Store platforms Annex 4: Application Development & Maintenance Requirements Description TABLE OF CONTENTS Page 1 1.0 s Overview...

More information

BY GARY DONALDSON. The City of Atlanta Shares Insights for Increasing Revenue

BY GARY DONALDSON. The City of Atlanta Shares Insights for Increasing Revenue BY GARY DONALDSON The City of Atlanta Shares Insights for Increasing Revenue Asignificant number of local governments have experienced declines in their property tax base in recent years, caused by the

More information

Cloud-Based Project Information Management from Aconex: A Guide for IT Professionals

Cloud-Based Project Information Management from Aconex: A Guide for IT Professionals Cloud-Based Project Information Management from Aconex: A Guide for IT Professionals Adopting an Aconex SaaS Solution It s the job of CIOs and IT managers to ensure that their organizations adopt secure

More information

A Tipping Point for Automation in the Data Warehouse. www.stonebranch.com

A Tipping Point for Automation in the Data Warehouse. www.stonebranch.com A Tipping Point for Automation in the Data Warehouse www.stonebranch.com Resolving the ETL Automation Problem The pressure on ETL Architects and Developers to utilize automation in the design and management

More information

Boost BCM Program Maturity: Arm Your Team with the Right Tools. Jason Zimmerman Vice President Operations

Boost BCM Program Maturity: Arm Your Team with the Right Tools. Jason Zimmerman Vice President Operations Boost BCM Program Maturity: Arm Your Team with the Right Tools Jason Zimmerman Vice President Operations Gartner Rates Incident Management Systems Benefit High In their 2014 Hype Cycle Report, Gartner

More information

Cloud Computing Risks in Financial Services Companies: How Attorneys Can Best Help In An Increasingly SaaS-ified World

Cloud Computing Risks in Financial Services Companies: How Attorneys Can Best Help In An Increasingly SaaS-ified World Cloud Computing Risks in Financial Services Companies: How Attorneys Can Best Help In An Increasingly SaaS-ified World July 30, 2015 Sutherland Webinar Michael Steinig 202.383.0804 Michael.Steinig@sutherland.com

More information

IDENTIFYING VENDOR RISK THE CRITICAL FIRST STEP IN CREATING AN EFFECTIVE VENDOR RISK MANAGEMENT PROGRAM

IDENTIFYING VENDOR RISK THE CRITICAL FIRST STEP IN CREATING AN EFFECTIVE VENDOR RISK MANAGEMENT PROGRAM IDENTIFYING VENDOR RISK THE CRITICAL FIRST STEP IN CREATING AN EFFECTIVE VENDOR RISK MANAGEMENT PROGRAM HEADQUARTERS 33 Bradford Street Concord, MA 01742 PHONE: 978-451-7655 THE CRITICAL FIRST STEP IN

More information

An Enterprise Resource Planning Solution for Mill Products Companies

An Enterprise Resource Planning Solution for Mill Products Companies SAP Thought Leadership Paper Mill Products An Enterprise Resource Planning Solution for Mill Products Companies Driving Operational Excellence and Profitable Growth Table of Contents 4 What It Takes to

More information

Infrastructure consulting. Global Infrastructure

Infrastructure consulting. Global Infrastructure Infrastructure consulting Global Infrastructure Services Operational costs systems availability compliance and security energy and power usage disaster recovery all contribute to today s increasingly complex

More information

Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level

Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level August 2013 Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level A Study Conducted by Oracle and the National Association of State Auditors, Comptrollers and Treasurers

More information

OCC 98-3 OCC BULLETIN

OCC 98-3 OCC BULLETIN To: Chief Executive Officers and Chief Information Officers of all National Banks, General Managers of Federal Branches and Agencies, Deputy Comptrollers, Department and Division Heads, and Examining Personnel

More information

BUYING AN ERP SYSTEM. How to avoid common pitfalls and maximize your ROI SHARE THIS EBOOK

BUYING AN ERP SYSTEM. How to avoid common pitfalls and maximize your ROI SHARE THIS EBOOK BUYING AN ERP SYSTEM How to avoid common pitfalls and maximize your ROI SHARE THIS EBOOK THE GROWING POPULARITY OF ERP SYSTEMS Market competition has transformed the modern business environment. Companies

More information

GETTING THE MOST FROM THE CLOUD. A White Paper presented by

GETTING THE MOST FROM THE CLOUD. A White Paper presented by GETTING THE MOST FROM THE CLOUD A White Paper presented by Why Move to the Cloud? CLOUD COMPUTING the latest evolution of IT services delivery is a scenario under which common business applications are

More information

iworks healthcare Managed IT services

iworks healthcare Managed IT services iworks healthcare Managed IT services SunGard s iworks HEALTHCARE: Managed IT Services Organizations around the globe face an array of critical issues in today s business environment. Economic conditions

More information

VMO Startup Guide: How to Launch a Vendor Management Office and Get It Right the First Time

VMO Startup Guide: How to Launch a Vendor Management Office and Get It Right the First Time A Rafael Marrero & Company White Paper VMO Startup Guide: How to Launch a Vendor Management Office and Get It Right the First Time By: Rafael Marrero, SCPM, CSSBB CEO Rafael Marrero & Company Garrison

More information

Case Study: ICICI BANK INTERNAL AUDIT DEPARTMENT PENTANA AUDIT WORK SYSTEM IMPLEMENTATION

Case Study: ICICI BANK INTERNAL AUDIT DEPARTMENT PENTANA AUDIT WORK SYSTEM IMPLEMENTATION Introduction Emerging trends in the banking sector due to globalisation, liberalisation, increasing environment complexity, regulatory requirements & accountability is driving banks in India to adopt &

More information

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered

What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered What you need to know about cloud backup: your guide to cost, security, and flexibility. 8 common questions answered Over the last decade, cloud backup, recovery and restore (BURR) options have emerged

More information

Helping Enterprises Succeed: Responsible Corporate Strategy and Intelligent Business Insights

Helping Enterprises Succeed: Responsible Corporate Strategy and Intelligent Business Insights I D C E X E C U T I V E I N S I G H T S Helping Enterprises Succeed: Responsible Corporate Strategy and Intelligent Business Insights May 2009 By Albert Pang, Research Director, Enterprise Applications

More information

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015

By: Tracy Hall. Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level. June 9, 2015 Community Bank Auditors Group Taking Your Business Continuity Plan To The Next Level June 9, 2015 By: Tracy Hall MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company,

More information

NEC Managed Security Services

NEC Managed Security Services NEC Managed Security Services www.necam.com/managedsecurity How do you know your company is protected? Are you keeping up with emerging threats? Are security incident investigations holding you back? Is

More information

1 st to serve over 40 HBMA member companies

1 st to serve over 40 HBMA member companies 1 st to serve over 40 HBMA member companies 1 st offshore healthcare vendor with over 1600 employees 1 st offshore vendor with 125+ quality assurance and compliance personnel 1 st Offshore vendor to develop

More information

COGNOS PLAN-TO-PERFORM BLUEPRINTS CAPITAL EXPENDITURE PLANNING

COGNOS PLAN-TO-PERFORM BLUEPRINTS CAPITAL EXPENDITURE PLANNING BUSINESS VALUE GUIDE VOLUME 6 COGNOS PLAN-TO-PERFORM BLUEPRINTS EXPENDITURE PLANNING PLANNING EXPENDITURE PLANNING Capital Expenditure Planning helps companies manage crossenterprise capital expenditures

More information

ISSUE BRIEF. Cloud Security for Federal Agencies. Achieving greater efficiency and better security through federally certified cloud services

ISSUE BRIEF. Cloud Security for Federal Agencies. Achieving greater efficiency and better security through federally certified cloud services ISSUE BRIEF Cloud Security for Federal Agencies Achieving greater efficiency and better security through federally certified cloud services This paper is intended to help federal agency executives to better

More information

Team A SaaS Strategy

Team A SaaS Strategy Team A SaaS Strategy What is a strategy? Strategy is the direction and scope of an organization over the long-term term: : which achieves advantages for the organization through its configuration of resources

More information

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes.

CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. TECHNOLOGY BRIEF: REDUCING COST AND COMPLEXITY WITH GLOBAL GOVERNANCE CONTROLS CA HalvesThe Cost Of Testing IT Controls For Sarbanes-Oxley Compliance With Unified Processes. Table of Contents Executive

More information

Thought Leadership White Paper

Thought Leadership White Paper Thought Leadership White Paper Introduction Contracts form the foundation of all businesses and every business relationship. They define every aspect of a business s activities procurement, sales, marketing,

More information

VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium

VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium 1 VENDOR RISK MANAGEMENT UPDATE- ARE YOU AT RISK? Larry L. Llirán, CISA, CISM December 10, 2015 ISACA Puerto Rico Symposium 2 Agenda Introduction Vendor Management what is? Available Guidance Vendor Management

More information

How to Develop Successful Enterprise Risk and Vendor Management Programs

How to Develop Successful Enterprise Risk and Vendor Management Programs Project Management Institute New York City Chapter January 2014 Chapter Meeting How to Develop Successful Enterprise Risk and Vendor Management Programs Christina S. Kite Senior Vice President Corporate

More information

JOB DESCRIPTION/PERSON SPECIFICATION

JOB DESCRIPTION/PERSON SPECIFICATION JOB DESCRIPTION/PERSON SPECIFICATION A POSITION DETAILS DIVISION: Business Support JOB TITLE: MIS Security Analyst DEPARTMENT/BUSINESS SECTOR: MIS REPORTING TO: MIS Security Manager GRADE: 11 B KEY RESPONSIBILITIES

More information

Information Governance 2.0 A DOCULABS WHITE PAPER

Information Governance 2.0 A DOCULABS WHITE PAPER Information Governance 2.0 A DOCULABS WHITE PAPER Information governance is the control of an organization s information to meet its regulatory, litigation, and risk objectives. Effectively managing and

More information

Project and Operational processes, Key differences. Gotchas when deploying projects into operations

Project and Operational processes, Key differences. Gotchas when deploying projects into operations Project and Operational processes, Key differences. Gotchas when deploying projects into operations Purpose of this Presentation Assist the smooth implementation of projects into production I ve heard

More information

UNCOVER WHAT S HIDDEN IN YOUR SAP ERP DATA TO HELP CUT COSTS AND RAISE COMPLIANCE

UNCOVER WHAT S HIDDEN IN YOUR SAP ERP DATA TO HELP CUT COSTS AND RAISE COMPLIANCE UNCOVER WHAT S HIDDEN IN YOUR SAP ERP DATA TO HELP CUT COSTS AND RAISE COMPLIANCE UNCOVER WHAT S HIDDEN IN YOUR SAP ERP DATA TO HELP CUT COSTS AND RAISE COMPLIANCE Leverage the pre-packaged expertise in

More information