DB FPX 8650 Assessment 3

Assessment Overview

DB FPX 8650 Assessment 3: identifies a measurable third-party/vendor risk-management gap at a regional financial institution (HarborTrust Financial): inconsistent vendor risk assessment and lifecycle management has allowed critical vendors with weak controls to remain in production, exposing the firm to operational, compliance, and reputational loss. 

What’s Included:

Sample Assessment Paper

Specific Business Problem

HarborTrust relies on dozens of third-party providers (payments, document processing, cloud hosting, contact center). Vendor onboarding and oversight are fragmented: some vendors have completed thorough risk assessments and contractual controls, while others—including vendors accessing sensitive customer data—were onboarded with minimal due diligence. This inconsistency has produced unmanaged concentration risk, unclear remediation responsibilities, and reactive vendor remediation after incidents (e.g., late vendor security patches and inadequate business-continuity commitments).

Gap in Practice

The gap in practice is the lack of a formalized, risk-tiered Third-Party Risk Management (TPRM) lifecycle. Specific deficiencies include no standardized risk-scoring model to tier vendors by criticality; inconsistent due-diligence questionnaires and evidence collection; weak contractual security and SLAs for higher-risk vendors; infrequent performance/risk reviews (especially for mid/high-tier suppliers); poor linkage between vendor risk results and remedial action tracking; and limited escalation to senior leadership when remediation fails.

Why the Specific Gap in Practice Was Chosen

Third-party exposures are a leading source of operational and regulatory risk for financial firms. The gap explains recurring vendor-related incidents, slow remediation, and inadequate contingency planning. It is measurable (percent of vendors with completed assessments, percent of high-risk vendors with remediation plans closed on time, number of vendor incidents, vendor-concentration exposure) and actionable (implement tiering, standardize assessments, strengthen contract clauses, establish remediation SLAs and governance). Regulators increasingly expect proactive TPRM, making remediation urgent.

Research and Effectiveness of Chosen Gap in Practice

Industry guidance (FFIEC, OCC, and ISO 31000 adaptations for TPRM) and practitioner frameworks show that a lifecycle TPRM program—onboarding risk assessment, contract requirements aligned to risk tier, periodic monitoring, issue remediation tracking, and executive reporting—reduces incidents and shortens remediation times. Risk-tiering focuses resources on the most critical vendors; contractual SLAs and right-to-audit clauses materially improve control posture; and centralized remediation tracking plus governance (TPRM committee) ensures issues escalate and close. Implementations that pair TPRM tooling with clear roles and repeatable processes show faster vendor remediation and fewer service disruptions.

DB FPX 8650 Assessment 3: Project of Interest

“VendorShield TPRM Pilot”—a 5-month program to build a repeatable TPRM lifecycle for HarborTrust’s vendor base, piloting on vendors supporting payments, cloud hosting, and customer data services. Core components:

  1. TPRM governance & owner—appoint a TPRM lead in Risk, form a cross-functional TPRM committee (procurement, IT/security, legal, operations), and define escalation rules.
  2. Risk-tier model—develop a simple risk score (access to sensitive data, criticality to customer service, financial stability, regulatory impact) and classify vendors as low/medium/high.
  3. Standardized due diligence—create tiered questionnaires and evidence checklists (security controls, BC/DR, SOC reports, SSAE 18, penetration-test results). Automate intake via a central intake form.
  4. Contract strengthening—build contract templates with security, BC/DR, SLAs, notification obligations, right-to-audit, and remediation timelines for medium/high vendors.
  5. Monitoring & remediation—implement a centralized tracker for vendor findings, assign remediation owners, set SLAs for remediation closure, and require quarterly reviews for high vendors.
  6. Concentration & dependency analysis—identify single-point suppliers and quantify business-impact exposure to drive contingency or diversification decisions.
  7. Reporting & escalation—weekly TPRM dashboard for operational owners and monthly executive summary to the risk committee for unresolved high-risk items.
    Expected outcomes: 100% of pilot vendors tiered and assessed, all high vendors contracted to standard clauses or with remediation plans, measurable reduction in average remediation time, and clear contingency plans for high-impact dependencies.

Observations within My Workplace

  • Procurement teams have negotiated commercial terms but not always the security/BC clauses required by Risk.
  • Several critical vendors lack recent SOC/ISO attestations or have overdue remediation items that are only tracked in email threads.
  • Legal involvement is often late in the process, slowing contract changes; IT/security receives limited standardized evidence up front.
  • No centralized view exists to quantify how many critical services rely on the same upstream provider.
    These process gaps produce blind spots that allow vendor weaknesses to persist.

Personal Biases

I favor formal processes, checklists, and centralized tracking, which may underweight flexible commercial realities (e.g., fast pilots with innovative vendors). I must balance rigorous controls with pragmatic onboarding for low-risk partners and ensure the program does not become an unnecessary bottleneck.

Reflection

This assessment highlighted that effective TPRM is a mix of standardized process, contractual leverage, and practical governance. Quick wins—tiered questionnaires, a remediation tracker, and contract clause templates—create immediate risk reduction. Embedding TPRM into procurement and change management prevents future drift and supports regulator expectations.

References

  • FFIEC IT Examination Handbook—Third-Party Relationships: Risk Management. http://hbr.org/
  • ISO 31000 / COSO ERM adaptations for vendor risk guidance (industry whitepapers). https://sloanreview.mit.edu/
  • Shared Assessments / SIG (Standardized Information Gathering) framework for vendor due diligence. https://www.ft.com

Step-by-Step Guide

  1. Secure sponsor & pilot scope (Weeks 0–2)—Obtain executive sponsorship, appoint TPRM lead, and select pilot vendors (payments, cloud hosting, and customer data services).
  2. Design risk-tier model & intake (Weeks 2–4)—Define simple scoring criteria and build a central vendor intake form to capture tiering inputs.
  3. Create due-diligence packages (Weeks 4–6) — Develop low/medium/high questionnaires and evidence checklists; prepare contract clause templates for medium/high.
  4. Assess & contract (Weeks 6–10) — Tier and assess pilot vendors, negotiate contract amendments for high vendors, or obtain formal remediation plans with SLAs.
  5. Implement remediation tracker & governance (Weeks 8–14)—Launch centralized tracker, assign owners, set remediation SLAs, and run weekly TPRM committee reviews for open items.
  6. Concentration analysis & contingency (Weeks 10–16)—Map dependencies to identify single points of failure; develop contingency/alternate sourcing plans for critical dependencies.
  7. Monitor & report (Weeks 12–20) — Publish weekly operational dashboards and a monthly executive summary; measure the percentage of vendors assessed, remediation aging, and open critical findings.
  8. Evaluate & scale (Weeks 18–24) — Evaluate pilot impact (reduction in remediation time, contractual coverage), refine model, and plan rollout across vendor base.

Frequently Asked Questions (FAQs)

Integrity Note

Use this example for learning and structure only. Do not submit as your own work.
We are an independent resource and are not affiliated with any university.

Essay-Writing-Service-For-Students-Best-Essay-Writer-Online.png

“I paid the service to write my research paper.” They wrote an excellent paper with a lot of research and correct citations. “Great excellent work!”

Order ID # 00889

BSN - Capella University

Jonathan Nicole

⭐⭐⭐⭐⭐

Experience : 10+ Years in Nursing.
Specialization : BSN, MSN

Jessica Walker

⭐⭐⭐⭐⭐

Experience : 10+ Years in Nursing.
Specialization : MSN, DNP

Denis Peterson

⭐⭐⭐⭐⭐

Experience : 10+ Years in Nursing.
Specialization : DNP, PSY

How it Works

We provide services to registered nurses who are taking classes toward their BSN or MSN degrees.

You cannot copy content of this page

Nursing Papers Help even with a 3-hour deadline!

Get Any Assessment For Free

Verification is required to avoid bots.