Third-Party Risk Management: When to Accept or Reject Vendor Documentation episode artwork

EPISODE · Mar 27, 2025 · 53 MIN

Third-Party Risk Management: When to Accept or Reject Vendor Documentation

from GRC Uncensored

On a recent episode of GRC Uncensored, host Troy Fine and producer Elliot Volkman were joined by guest Stanley Krochik, a now seasoned GRC professional and former city security program manager, to discuss the realities of third-party risk Management (TPRM). The conversation focused on the growing issue of low-quality audits, the challenge of assessing vendor security postures, and the dilemma risk managers face when reviewing third-party documentation.04:43 The Importance of Third Party Risk Management05:45 Challenges with Low Quality Audits07:45 Evaluating SOC 2 Reports12:55 Issues with Sales-Focused GRC Tools14:44 The Need for Better Compliance Programs27:50 High-Risk Vendor Architecture Review29:07 SOC 2 Reports and Vendor Risk Management31:50 Challenges with SOC 2 and Auditor Quality36:49 Financial Impact of Data Breaches38:10 Differences in Security Between Old and New Systems47:43 Proactive vs. Reactive Security Measures Hosted on Acast. See acast.com/privacy for more information.

Episode metadata supplied by the publisher feed · Published Mar 27, 2025

Embed this episode

NOW PLAYING

Third-Party Risk Management: When to Accept or Reject Vendor Documentation

0:00 53:43

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of GRC Uncensored?

This episode is 53 minutes long.

When was this GRC Uncensored episode published?

This episode was published on March 27, 2025.

Can I download this GRC Uncensored episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!