Dear CEO - Mitigating IT Outsourcing Risk



Similar documents
Specialist Cloud Services Lot 4 Cloud EDRM Consultancy Services

Specialist Cloud Services Lot 4 Cloud Printing and Imaging Consultancy Services

DESIGNING A VIRTUAL FAMILY OFFICE

Session 402- Contract Management: What is Realistic for My Department?

Crosswalk Between Current and New PMP Task Classifications

Procurement Outsourcing and. Shared Service Centers. SANFORD INTERNATIONAL I Global Sourcing I Supply Chain I Procurement I.

EuroCloud Star Audit. A strong partnership that provides you with a competitive advantage

How To Reduce Cost Of A Project

Our risk management framework Reviewed quarterly by our executive committee

On Premise Vs Cloud: Selection Approach & Implementation Strategies

How To Improve Your Business

Infrastructure Services Sourcing

Recruitment Process: Why Outsource?

Overview. Service Description: BCP & DR Strategy (L6)

Cybersecurity Framework. Executive Order Improving Critical Infrastructure Cybersecurity

Data Centre Networks Overview

IT Governance. What is it and how to audit it. 21 April 2009

CLOUD ERP AND ACCOUNTING: SELECTION AND PLANNING GUIDE

Moving PeopleSoft to the Cloud

UC San Diego Commodity Strategy and Spend Analysis

FIXED SCOPE OFFERING FOR ORACLE FUSION TALEO CLOUD

Driving Ongoing Success with the Coupa Customer Team

White paper. Reverse e-auctions. A Recipe for Success

Identifying and Managing Third Party Data Security Risk

Placing Your Applications in the Best Cloud Model

Step by Step Project Planning

Chapter 6 Implementation Planning

ISO20000: What it is and how it relates to ITIL v3

TELECOMS Expense management. Considerations for Large Enterprises Operating in South Africa

G-Cloud. Lifting the digital cloud

for Analysing Listed Private Equity Companies

Getting Started with Business Intelligence

UNSOLICITED PROPOSALS

Dodging Breaches from Dodgy Vendors: Tackling Vendor Risk Management in Healthcare

Supplier Relationship Management. ISM Philadelphia, Inc. September 12, 2013

OIM Business Acceleration. On-boarding Six Hundred Applications in Oracle Identity Management

Negotiating Vendor Contracts. Key Initiative Overview

8 Techniques to Improve Your Bank s Vendor Management Program. IBAT TechMecca

U.S. Department of Housing and Urban Development Data Center Consolidation Plan

WIRELESS INFRASTRUCTURE & MOBILE DEVICE MANAGEMENT REQUEST FOR INFORMATION (RFI)

Software Asset Management (SAM) and ITIL Service Management - together driving efficiency

Domain 1 The Process of Auditing Information Systems

Fact Sheet: Accounting Software RFI/RFP Template

BEST PRACTICES: Ten Steps to Selecting the Right Human Resources Software

An ITIL Perspective for Storage Resource Management

Any business relationship between a bank and another entity, by contract or otherwise

Bud Porter-Roth Porter-Roth Associates

HIT System Procurement Issues and Pitfalls Session 2.03

Chapter 11 IT Procurement Planning and Strategic Sourcing

IT Service Management tools - Acquisition and implementation

Business Continuity Planning Workshop Michael Kirk The CIPSA Public Sector Procurement Forum May 25 th, Canberra

INTERNATIONAL NETWORK FOR QUALITY ASSURANCE AGENCIES IN HIGHER EDUCATION

NSW Government. Data Centre & Cloud Readiness Assessment Services Standard. v1.0. June 2015

24/7 Monitoring Pro-Active Support High Availability Hardware & Software Helpdesk. itg CloudBase

Utilizing Needs Assessment and Benchmarking Tools to Evaluate and Improve Revenue Cycle Management Practices. Jim Knight CEO, ACU Serve Corp.

Outsourced Third Party Relationship Management/ Vendor Management. TTS Webinar July 15, 2015 Susan Orr CISA, CISM, CRISC, CRP

QTC Training & Education. Certificate IV of Project Management BSB41507 Study by Correspondence

451 s Procurement and Vendor Management Capability Development Program

An example ITIL -based model for effective Service Integration and Management. Kevin Holland. AXELOS.com

Ministry Of Health Registration of Interest

Supplier Management for Complex Outsourced Services: A Strategic Framework

The Cloud-Enabled Enterprise Developing a Blueprint and Addressing Key Challenges

Make or Buy? How to face the strategic dilemma. GW ref. 9021X258 - version 2.0. Supply chain management. Assets & facilities

CORL Dodging Breaches from Dodgy Vendors

A new paradigm for EHS information systems: The business case for moving to a managed services solution

UNIFORM ECONOMIC TRANSACTION PROTOCOL. Payments and transactions several perspectives Utrecht, February 2 nd, 2015

Cloud Computing Adoption in the Financial Services Industry

Grant Programme Guidelines Community Development Grants Programme

Lessons Learned in Software Project Outsourcing

Commercial Payment Solutions RFP Guide:

The Board reviews risks to the Company s business plan at its scheduled meetings.

Cloud Business Case G-Cloud 5 Framework

OC Chapter. Vendor Risk Management. Cover the basics of a good VRM program, standards, frameworks, pitfall and best outcomes.

PSPPROC506A Plan to manage a contract

Client Communication Portal Project

CENTRAL ONTARIO HEALTHCARE PROCUREMENT ALLIANCE QUESTIONS AND ANSWERS

Software as a Service Decision Guide and Best Practices

Project Management Guidebook

Vendor Management. Outsourcing Technology Services

The Do s and Don ts of Outsourcing Your Call Center William D. Puso, Vice President & Managing Partner, The INSIGHT Group

Cloud Computing. Making legal aspects less cloudy. Erik Luysterborg Partner Cyber Security & Privacy Belgium EMEA Data Protection & Privacy Leader

Vendor Management Best Practices

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Using SharePoint 2013 for Managing Regulated Content in the Life Sciences. Presented by Paul Fenton President and CEO, Montrium

10 top tips to reviewing recruitment software (0)

Introduction to Vendor Management

CHANGE MANAGEMENT PLAN WORKBOOK AND TEMPLATE

Transcription:

Dear CEO - Mitigating IT Outsourcing Risk Choosing an Institutional Quality IT Vendor Alexander Brown Technology Partner, Simmons & Simmons Ray Bricknell Managing Director, Behind Every Cloud

Dear CEO - Choosing an Institutional Quality IT Vendor Context : IT Outsourcing within Dear CEO concerns Is it in Scope? Impact of growing trend toward Cloud Operational IT Risk Mitigation Local and Endemic What does a rigorous IT Vendor Selection Process look like? IT Vendor Selection Criteria Areas for Improvement: Endemic Market Risk Mitigation Cloud Vendor input? Cloud Vendor selection: A better way? Panel Discussion (Please hold questions until this session) What constitutes an Institutional Quality IT Vendor?

Is IT Outsourcing In Scope for FCA Dear CEO Concerns? Concern driver: endemic risk through financial interdependence But reading with IT Outsourcing and especially Cloud in mind Surely Outsourced IT is a critical activity in the support of regulated activities?

Is IT Outsourcing In Scope for FCA Dear CEO Concerns? IT Outsourcing Operational Risk: Local versus Endemic Local e.g. Infrastructure Platform Event i.e. Single Vendor, Single Fund Endemic e.g. Major Vendor Liquidation or BCP Event i.e. Single Event affects Multiple Funds - and even Wider Markets With CLOUD (vs. On Premise or Co-Lo/Mgd Service on own kit) these two risk exposures begin to grow and merge UK Asset Management IT Outsourcing Market: Small number of providers; Shared risks (e.g. E14 Flood) Hundreds of funds: Shared Vendor exposure; Shared BCP exposure So BEC View: If it isn t already in scope it should be!! Partially mitigated by thorough and ongoing Due Diligence

The Good (hopefully) 6 4 Internet The typical IT Vendor Selection process: Identify Vendors Word of Mouth Expos & Conferences Events Webex s Free trials Experience High-Level Assessmen t Provider Meetings CTO Discussions Technology Reviews Demo s Follow-up Meetings 1000.ppt slides Business Case Formal RFI/ RFP Business Requirements RFI Development RFI s Out / In / Review Data Capture RFP Creation Solutioning Workshops Reference Site Visits RFP Out / In / Review Solution Presentations Contract Negotiations Final Vendor Selection Highly prone to Garbage In- Garbage Out 2 0 The Bad 6 4 2 0 The Downright Ugly! 6 4 2 0 Far too little Open Market Feedback

The Two Stage Formal RFI & RFP Process: RFI/RFP Scope Agreed - Approval to Proceed Identify Wide Range of Potential Vendors Desk Based Analysis of Vendors / Offerings Select Long List Target 10 12 Vendors Execute Non Disclosure Agreements Issue RFI Multi-Vendor Briefing Presentation and Open Q&A Develop RFI Content 1 1 Review Indicative Cost Models Develop RFP Response Template Develop Capture and Collection System Closed 1:1 Vendor Q&A Sessions Expect Approx. 2 No-Bids Review Formal RFI Responses Select Short List Target 4 to 6 Vendors Release RFP to Short List Vendor Q & A Cycle Review RFP Submissions Review Product Collateral Develop RFP Content Agree Selection Criteria and Weightings 2 Review Public Domain Collateral

RFI & RFP Process (cont.) Develop Like-For- Like Cost Models Legal Terms and Conditions HL Review Financial Due Diligence Client Side Q&A Cycle Select Internal Short List for Presentations and Due Diligence Vendor Presentatio ns (4-6) Review, Analyse, Score and Report Reduce Internal Short List to 2-3 Vendors Site Visits * 3 per Vendor (DC s and NOC) 3 Conduct Security Audit 3 Review, Analyse, Score and Report Now 2 Preferred Vendors High Level Design Finalisation Commercial Negotiations Contractual Negotiations Announce Final Successful Vendor Decision Conduct Technical Due Diligence Average Timeframe and Internal/Consultancy Cost: 4 6 Months 100k 150k

IT and Cloud Outsourcing Vendor Selection Criteria e.g.: Pre- Requisites Assessment of Key Risks and Issues Internal Requirements Definition Internal Cost Model ( Like for Like ) Strategy Incl. Technical; Incl. Tactical Incl. Timing and Resourcing Business Case Approval Selection Criteria (for panel discussion later) Regulation and Compliance Clients Profile Breakdown incl. By Size By Revenue Client References - ALL Financial Viability Revenue and Profitability Profile Business Model Ownership Independent Accreditations Contractuals i.e. T&C's Flexibility and Scalability Topology (Local / Global) Sector Alignment Risk Profile Technical Teams (Support/Migration/Management) Platform Components Onion Layers Vendor Relationships Active-Active => Always On Application Layer Support

Dear CEO - Choosing an Institutional Quality IT Vendor Areas for Future Focus and Improvement Endemic Market Risk Mitigation Cloud Vendor input to potential solutions? Whole of Market Cloud Vendor Dependency Data Cloud Vendor selection: A better way? The Clover tm Cloud Vendor Rating Engine

Constant Immersion in the Cloud Ecosystem Buying Cycle 50+ Suppliers Analysed (and counting ) Data Ratified Bi-Annually Existing Asset Management Customer Feedback IT Strategy & Business Case The CLOVER Cloud Vendor Rating Engine Detailed Client Output Vendor Feedback - 3 * Recommended: - The Good - The Good - The Good Requirements Gathering & Service Catalogue Client Specific Inputs External Financial s & Media Multiple RFI s & RFP s Regular Vendor Self- Updates via Portal + Qualified Leads Customer Confidential

Dear CEO - Choosing an Institutional Quality IT Vendor Interactive Panel Discussion: What constitutes an Institutional Quality IT Vendor? Your Panellists: Ian Bowell CTO Prologue Capital Alex Brown, Technology Partner - Simmons and Simmons Mark Fowle CEO and co-founder Attenda Jon Gasparini Financial Services CTO Fujitsu Alex Parker CTO Commensus Roy Wood Sales and Marketing Director Advanced 365 Chair: Ray Bricknell MD Behind Every Cloud

Dear CEO - Choosing an Institutional Quality IT Vendor Thank you for your time, please join us for coffee outside. Contacts for any follow up questions: Alex Brown, Technology Partner - Simmons and Simmons Alexander.Brown@simmons-simmons.com Ray Bricknell MD Behind Every Cloud Ray@BehindEveryCloud.co.uk