Courses
DR-301Third-party riskExpert

ICT third-party risk and register of information

The most underestimated deliverable in the regulation

Build and maintain the register of information, assess concentration, bring contracts into line with Article 30, and document testable exit strategies.

Learning objectives

  • Produce a register matching the authorities' template
  • Assess and document concentration risk
  • Upgrade a contract portfolio
  • Draft and test an exit strategy

Intended audience

  • Procurement
  • Legal
  • Compliance
  • Third-party risk

Prerequisites

  • ICT risk management framework

Detailed curriculum

Module 1

Register, concentration, contracts

The real work behind Chapter V.

Module 2

Concentration and exit

Article 29 and upgrading an existing contract portfolio.