KNOW YOUR THIRD PARTY



Similar documents
THOMSON REUTERS ACCELUS

Simplify the Complexity of Managing 3rd Party Anti-Bribery / FCPA Compliance

DRUG DEVELOPMENT AND MANUFACTURING: UNCOVERING THE HIDDEN RISKS

Beyond Compliance: Building a Robust Ethics and Compliance Program

Fifth annual survey. Look before you leap Navigating risks in emerging markets

ACCELUS ORG ID KYC MANAGED SERVICE

FRANCHISORS AND FRANCHISEES: UNDERSTANDING COMPLIANCE RISKS

SPECIAL REPORT: KYC AND AML POLICY IMPLEMENTING BEST PRACTICE IN AN EVER-CHANGING REGULATORY ENVIRONMENT

WHITE PAPER Third-Party Risk Management Lifecycle Guide

ACCELUS ORG ID FOR CLIENTS OF FINANCIAL INSTITUTIONS

COMPLIANCE MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS COMPLIANCE MANAGEMENT SOLUTIONS

IDENTITY MONITORING: KEEPING A FINGER ON THE PULSE OF CLIENT IDENTITY CHANGES

APEC General Elements of Effective Voluntary Corporate Compliance Programs

Forensic Services. Third Party Risks. March 2013

THOMSON REUTERS ACCELUS. Know Your Customer (KYC), Kontrol Your Costs (KYC) and Keep Your Customers (KYC) happy

Product. AML Risk Manager for Life Insurance Complete End-to-End AML Coverage for Life Insurance

At Risk. In this Issue: Avoiding a world of hurt: Knowing your counterparties before you engage. Volume 8, No. 1. kpmg.ca/atrisk.

SUPPLY CHAIN RISK MANAGEMENT THE COMPLEXITIES OF MANAGING RISKS IN COMPLEX GLOBAL SUPPLY CHAINS

Tapping the benefits of business analytics and optimization

IT-Based Anti-Money Laundering and Anti-Fraud in Banks and Insurance Companies

ACCELUS COMPLIANCE MANAGER FOR FINANCIAL SERVICES

Complete Financial Crime and Compliance Management

INTERNATIONAL CORRESPONDENT BANKS. Knowing Your Customer (KYC) Anti-Money Laundering Prevention of Terrorist Financing

building a business case for governance, risk and compliance

LexisNexis UK Anti-Money Laundering (AML) White paper

Anti-Money Laundering and Counter- Terrorism Financial Policy

An Oracle White Paper October An Integrated Approach to Fighting Financial Crime: Leveraging Investments in AML and Fraud Solutions

Precious Metals Supply Chain Policy

DOUBLECHECK VENDOR MANAGEMENT

THOMSON REUTERS ACCELUS. The FCA: A Game Changer

Reducing Regulatory Risk in an Era of Intensified Enforcement

Value of a Purpose-Built Third-Party Compliance Solution

PROTIVITI FLASH REPORT

Guidance ETHICAL PROCUREMENT AND SUPPLY

BDO NORDIC. Investigation, fraud prevention and computer forensics. You can guess. You can assume. Or you can know. And knowing is always better.

HIGH-RISK COUNTRIES IN AML MONITORING

IBM Global Business Services Microsoft Dynamics AX solutions from IBM

We believe successful global organisations can confront fraud, corruption and abuse PwC Finland Forensic Services

Oracle Financial Services Broker Compliance

2014 Financial Services Industry Compliance Benchmark Study

Fraud Solution for Financial Services

White Paper: The Seven Elements of an Effective Compliance and Ethics Program

Qualification in Internal Audit Leadership (QIAL ) Exam Syllabus

Risk Considerations for Internal Audit

one admin. one tool. Providing instant access to hundreds of industry leading verification tools.

CLIENT ON-BOARDING: THE SOLUTION LANDSCAPE

Foreign business partners under the FCPA

PROTIVITI FLASH REPORT

AN INTEGRATED APPROACH TO COMPLIANCE AND RISK MANAGEMENT IS THE BEST WAY FORWARD BY MARTIN WOODS OCTOBER 2011

Corporate Compliance Australia. 5 Essential Elements of Compliance

Sarbanes-Oxley: Beyond. Using compliance requirements to boost business performance. An RIS White Paper Sponsored by:

ENTERPRISE MANAGEMENT AND SUPPORT IN THE TELECOMMUNICATIONS INDUSTRY

A Comprehensive FATCA Solution

Transform Invoice Management with a Hybrid of Cloud and On-Premise Software

PEPs and the FCPA. Presented to 10 th Puerto Rican Symposium of Anti Money Laundering. February 28 March 1, 2013

How To Write An Anti Corruption Policy For A Company

FCPA COMPLIANCE: THE BENEFITS OF AUTOMATING THIRD-PARTY DUE DILIGENCE

Any business relationship between a bank and another entity, by contract or otherwise

Managing TPPPs and TPSs in the Current Regulatory Environment

CARIBBEAN DEVELOPMENT BANK STRATEGIC FRAMEWORK FOR INTEGRITY, COMPLIANCE AND ACCOUNTABILITY (2015)

INTERNATIONAL CORRESPONDENT BANKING

1 Copyright 2011, Oracle and/or its affiliates. All rights reserved.

Deloitte Forensic. Deloitte Forensic. Capability Statement

LANTHEUS HOLDINGS, INC. Foreign Corrupt Practices Act and Anti-Bribery Compliance Policy

The Wolfsberg Group Anti-Money Laundering Questionnaire. Financial Institution Name. 8 Canada Square, London E14 5HQ

DRAFT. Anti-Bribery and Anti-Corruption Policy. Introduction. Scope. 1. Definitions

Anti-Money Laundering controls in Mergers & Acquisitions

REGULATORY COMPLIANCE SOFTWARE SOLUTIONS. Dynamic Solutions. Superior Results.

Key Trends, Issues and Best Practices in Compliance 2014

REUTERS/Issei Kato. Global Tax Solutions For Corporate Tax & Accounting Professionals

TCO Certified Self-assessment Questionnaire

BEST PRACTICES IN CYBER SUPPLY CHAIN RISK MANAGEMENT

INTEGRITY DUE DILIGENCE GUIDELINES FOR LENDING TRANSACTIONS

An Oracle White Paper January Access Certification: Addressing & Building on a Critical Security Control

For Private circulation only Creative. Clear. Focused. Forensic Services

Adopted by the Board of Directors of the Nordic Investment Bank on 17 December 2009 COMPLIANCE POLICY

REGULATORY COMPLIANCE. Dynamic Solutions. Superior Results.

SEMGROUP CORPORATION. Anti-Corruption Compliance Policy August, 2011

LATEST ON THE DODD-FRANK ACT AND INTERNATIONAL COMPLIANCE RISKS

KPMG Internal Audit 2015: Top 10 considerations for private equity firms. kpmg.com

MPS GROUP GLOBAL ANTI-MONEY LAUNDERING POLICY

agility made possible

White Paper Achieving GLBA Compliance through Security Information Management. White Paper / GLBA

Business Information Services. Product overview

Can CA Information Governance help us protect and manage our information throughout its life cycle and reduce our risk exposure?

An Oracle White Paper November Financial Crime and Compliance Management: Convergence of Compliance Risk and Financial Crime

CONNECT SIMPLIFY PERFORM

Preemptive security solutions for healthcare

COMPLIANCE: THE NEW INTERNATIONAL LAW

The proposed Fourth Money Laundering Directive

IDENTIFYING VENDOR RISK THE CRITICAL FIRST STEP IN CREATING AN EFFECTIVE VENDOR RISK MANAGEMENT PROGRAM

Financial services regulatory compliance. Changing demands require the right perspective

COMPLIANCE MANAGEMENT SOLUTIONS THOMSON REUTERS ACCELUS COMPLIANCE MANAGEMENT SOLUTIONS

ASTRAZENECA GLOBAL POLICY SAFEGUARDING COMPANY ASSETS AND RESOURCES

Reaching New Heights: Providing Consistent and Sustainable High Performance at the State Level

Network Management Services: A Cost-Effective Approach to Complexity

You Can t Afford the Risks

Optimizing government and insurance claims management with IBM Case Manager

Managing bribery and corruption risk in commercial insurance broking

The Long Arm of the U.S. Foreign Corrupt Practices Act: Complying with the FCPA in the Vietnamese Landscape

Transcription:

Thomson Reuters KNOW YOUR THIRD PARTY

EXECUTIVE SUMMARY The drive to improve profitability and streamline operations motivates many organizations to collaborate with other businesses, increase outsourcing of non-core activities and to expand their global footprint into unknown territories. While these decisions can and do result in economic benefits, attention must be given to the potential increased costs to ensure those third parties adhere to legal requirements as well as implied standards of conduct. In today s business environment organizations are held responsible for the actions of suppliers, vendors and partners in addition to their own internal activities. Knowledge and understanding of supplier and third party risk is of the utmost importance. Therefore it is critical that a robust risk management program includes due diligence in the selection of business partners and third parties as well as on-going monitoring activities. CONNECT, SIMPLIFY, PERFORM Thomson Reuters offers intelligent market leading data and software as part of our unified platform approach. At the same time, products are modular and can be adopted as point solutions to meet specific needs. At whichever stage your organization finds itself, Thomson Reuters will complement your current third party risk mitigation program to enhance efficiencies and maximize your risk based approach. 2

3

The importance of knowing your third parties All companies and organizations are at risk from the intentional or unwitting actions of third parties, both in terms of indirect liability and the reputational damage that can be incurred by association. Building and extending relationships with third parties in order to achieve long term business goals usually creates complex supply chains that, over time, more accurately resemble interconnected webs. Knowing who you are dealing with within these webs becomes increasingly more difficult, yet increasingly more important in order to satisfy regulators, meet shareholder and customer expectations, and prevent financial and reputational damage. The Foreign Corrupt Practices Act (FCPA) and Conflict Minerals Rule (Dodd Frank Section 1502) in the US, Bribery Act and the Modern Day Slavery Act in the UK, in addition to a host of other global regulations, have increased the importance of establishing an effective third party compliance program. The rate at which these regulations are introduced will only increase as governments, civil society and consumers put anti-corruption, transparency and sustainability at the core of what they do. Under these regulations, an organization s management of third party business relationships should be of equal importance to managing customer business relationships as regulators are increasingly focusing on holding individuals liable for non-compliance. Shareholders and customers are demanding greater transparency and more responsible corporate behavior, in the interests of both reputational integrity and good investment practice. *OVER THE NEXT 12 MONTHS I EXPECT THE AMOUNT OF REGULATORY INFORMATION PUBLISHED BY REGULATORS AND EXCHANGES TO BE: 42% 24% 28% 1% 5% *OVER THE NEXT 12 MONTHS I EXPECT THE PERSONAL LIABILITY OF COMPLIANCE PROFESSIONALS TO BE: 44% 2% 15% 39% SIGNIFICANTLY MORE THAN TODAY SLIGHTLY MORE THAN TODAY THE SAME AS TODAY SLIGHTLY LESS THAN TODAY SIGNIFICANTLY LESS THAN TODAY SIGNIFICANTLY MORE THAN TODAY SLIGHTLY MORE THAN TODAY THE SAME AS TODAY SLIGHTLY LESS THAN TODAY *Thomson Reuters Cost of Compliance Survey 2015 4

Common risks and a framework to mitigation While there is no one-size-fits all guidance to supplier and third party risk management, each organization must know its business well enough to understand where risks may materialize and employ processes to detect them; risks such as Bribery and corruption Extortion and illegal money lending Organized crime Fraud Counterfeiting Illicit trade Environmental crime Conflict minerals Human rights abuses Slavery and human trafficking Often what leads to mishaps is not the complexity of supply chains but the lack of management, transparency and monitoring which is fundamental from the beginning of the supply chain through to the end consumer. In order to prevent, detect and investigate supplier and third party risk, a simple Know Your Third Party (KY3P) framework can be implemented. Train and educate educate and raise awareness about the threats posed by bribery and corruption DEVELOP Develop your program define and establish policies, procedures and controls in all levels of the business, with owners for each Review and align take timely corrective and disciplinary action for violations of the program, continually evaluate and adjust to ensure alignment with changes in risk profile Monitor and report extract reports for proof of due diligence and continuously monitor to detect future risks EDUCATE REVIEW MONITOR EVALUATE BUILD DETECT Build and operate controls implement the policies into business operations Detect the risks screen against your third parties to ensure legitimacy and sustainability Evaluate remediate the results and carry out further investigation when necessary 5

One solution to a multitude of challenges There is no doubt that third party relationships play a key role in the success of an organization. Instead of enlarging the workforce which requires investment in infrastructure, engaging third parties to help the organization meet its objectives can help to save on costs and optimize resources. But these relationships can also introduce substantial risk and need to be carefully managed, never more so than now. As the regulatory environment continues to demand increasing scrutiny and control of third party relationships, the complexity of this management challenge looks set to increase in the coming years. Companies need to be able to contain these complex relationships and ensure that their response to increasing regulatory pressure is proactive and not ad hoc. This can heavily impact on cost control especially when their third party risk management solutions are fragmented and come from multiple vendors. There is a great advantage of using one service that incorporates all aspects of a best practice third party management solution. With the components designed to work together, it s much easier to fit the service to the unique needs of the organization, to streamline resources and control costs. Knowing how to effectively manage the risks that third parties pose is the key to a good KY3P program. 6

Components for a connected third party risk management solution Thomson Reuters offers an evolved approach to mitigating third party risk. We have created a global KY3P proposition, using a wide variety of trusted assets and leveraging upon our breadth and expertise that looks to identify risks when conducting business with a customer or third parties across many use cases or operations. This allows organizations to adopt a risk based approach by: Understanding risks and identifying opportunities Taking actions informed by industry-leading intelligence Helping navigate industry regulations Implementing best practices that drive value Maximizing operational efficiency and reducing costs Improving efficiency and effectiveness of existing supplier and third party compliance programs THOMSON REUTERS WORLD-CHECK World-Check reveals the risk hiding in business relationships and human networks. The result is highly structured intelligence profiles of heightened risk individuals and entities globally. With 240+ countries and territories covered in 60+ languages, our research analysts in all global regions, specialist research to include terrorism, organized crime, Middle East, we are able to satisfy demands for KYC, AML, CFT, and PEP due diligence. We monitor over 400 sanction, watch and regulatory enforcement lists and hundreds of thousands of information sources, often identifying high-risk entities months or years before they are listed. In 2014 alone we identified more than 202 entities before they appeared on the US Treasury Office of Foreign Assets Control (OFAC) list, and currently exceed terrorist coverage on the leading sanctions by more than 80,000 records. World-Check contains over 12,000 profiles linked to child and slave labor, migrant smuggling, sex trafficking and human trafficking. Screening using World-Check helps to minimize the cost of compliance. THOMSON REUTERS SCREENING RESOLUTION SERVICE Screening Resolution Service (SRS) offers a managed KYC screening service for your organization. Thomson Reuters can do the screening and hit remediation on your behalf, highlighting positive and possible matches for heightened risk individuals and entities. We are able to serve your organization s client on-boarding procedures, screen records against World-Check and Country Risk Ranking, perform EDD background checks on selected matches, ensure quality assurance processes are in place check-points at each step to lower your overall costs of operation whereby you are able to demonstrate a complete audit trail to regulators. THOMSON REUTERS COUNTRY RISK RANKING Compliance teams can define their risk based approach more efficiently with the availability of detailed country risk intelligence, while doing routine third party due diligence tasks using World-Check. When deciding to expand operations or do business with third parties outside of your territorial borders, Country Risk Ranking allows you to understand the associated risks. Develop an accurate view of your location-based risk to prove third party due diligence to your regulator. THOMSON REUTERS ENHANCED DUE DILIGENCE Enhanced Due Diligence (EDD) reports are a cost-effective method of obtaining detailed background and integrity checks on any entity or individual, no matter where they are located. Business conduct and reputation history can be analyzed and a thorough search made for unseen liabilities. Business intelligence is gathered from regulators, industry observers, suppliers, competitors, distributors, and customers both current and former. Our EDD reports cover specific risks relating to terrorism, bribery and corruption, PEPs, conflict minerals, slavery, arms and human trafficking. In Standard and Premium reports, our research analysts routinely search for these risk types flagged for individuals and entities globally. THOMSON REUTERS COMPLIANCE LEARNING Our Compliance Learning courses provide practical, interactive, customizable and cost-effective compliance training programs, which assist in changing behavior and supporting a culture of integrity. More than 800 ethics and compliance training courses delivered in over 42 different languages are powered by world-leading regulatory intelligence, which tracks over 500 regulators and exchanges globally. Our courses are deployed using a flexible and easy-to-use learning management system. This web-based solution optimizes the management, tracking and reporting of your compliance and risk training, and provides a full audit trail to demonstrate compliance. SUPPLIER ON-BOARDING QUESTIONNAIRE AND PLATFORM We have partnered with market leading third party on-boarding software platforms that can integrate our suite of products and services. This, along with their due diligence questionnaire and analytics, helps to assess and classify the risk found in supplier relationships, and can be aligned with the organizational risk appetite. Organizations choose our unified technology and information solution to help streamline their third party compliance processes and workflow, and to form a proactive, connected governance, risk and compliance strategy. 7

RISK MANAGEMENT SOLUTIONS FROM THOMSON REUTERS Risk Management Solutions bring together trusted regulatory, customer and pricing data, intuitive software and expert insight and services an unrivaled combination in the industry that empowers professionals and enterprises to confidently anticipate and act on risks and make smarter decisions that accelerate business performance. For more information, contact your representative or visit us online at risk.thomsonreuters.com 2015 Thomson Reuters GRC03003/6-15