← Courses
DR-301Third-party riskExpert
ICT third-party risk and register of information
The most underestimated deliverable in the regulation
Build and maintain the register of information, assess concentration, bring contracts into line with Article 30, and document testable exit strategies.
Learning objectives
- Produce a register matching the authorities' template
- Assess and document concentration risk
- Upgrade a contract portfolio
- Draft and test an exit strategy
Intended audience
- Procurement
- Legal
- Compliance
- Third-party risk
Prerequisites
- ICT risk management framework
Detailed curriculum
Module 1
Register, concentration, contracts
The real work behind Chapter V.
Module 2
Concentration and exit
Article 29 and upgrading an existing contract portfolio.