Third Party and Vendor Risk Management
Delegates learn to manage the risks that arrive through suppliers, outsourcing partners, and other third parties. The course covers due diligence, contract risk clauses, ongoing monitoring, and the handling of concentration and fourth party risk. Practical exercises include tiering a vendor portfolio and building a proportionate assessment process.
Course outline
What this programme covers, module by module.
- 01Tiering third parties by risk and business criticality
- 02Conducting proportionate due diligence on vendors
- 03Embedding risk protections in supplier contracts
- 04Monitoring third party performance and risk over time
- 05Managing concentration and fourth party exposure
- 06Building a proportionate assessment process for the portfolio
What you will gain
- Tier third parties by risk and criticality
- Conduct proportionate due diligence
- Embed risk protections in contracts
- Monitor third party performance and risk
- Manage concentration and fourth party exposure
Who should attend
- Vendor and procurement risk staff
- Compliance and risk officers
- Outsourcing and contract managers
- Information security teams
Upcoming sessions
| Date | City | Duration | Fees | Book |
|---|---|---|---|---|
| 26 to 27 Oct 2026 | Cape Town | 2 Days | R10,000 | |
| 16 to 17 Nov 2026 | Johannesburg | 2 Days | R10,000 | |
| 7 to 8 Dec 2026 | London | 2 Days | US$1,100 | |
| 11 to 12 Jan 2027 | Dubai | 2 Days | US$1,100 | |
| 1 to 2 Feb 2027 | Pretoria | 2 Days | R10,000 | |
| 26 to 27 Apr 2027 | Durban | 2 Days | R10,000 | |
| 21 to 22 Jun 2027 | Cape Town | 2 Days | R10,000 |
Fees are per delegate and exclude VAT. Public intakes are confirmed once minimum numbers are met. We also deliver this course on your own schedule, in-house or live online.
Enquire about this course
Register your team or ask for a tailored in-house quote. We reply within one working day.
WhatsApp usCourse brochure (PDF)- Fees from
- R10,000 per delegate
- Duration
- 2 Days
- Field
- Governance, Risk & Compliance
- Formats
- In-house, public, online
More in Governance, Risk & Compliance
Enterprise Risk Management under ISO 31000
Delegates learn to build and run an enterprise risk management framework aligned with the principles and process of ISO 31000. The course covers risk appetite, identification, analysis, evaluation, and treatment, together with the governance and reporting that hold it all together. Practical sessions include building a risk register and calibrating a risk matrix for a real organisation.
Anti-Money Laundering and Financial Crime Compliance
This course equips compliance staff to detect, prevent, and report money laundering and related financial crime. Delegates study customer due diligence, sanctions screening, transaction monitoring, and suspicious activity reporting within a risk-based framework. The programme reflects the recommendations of the Financial Action Task Force and regional regulatory expectations.
Regulatory Compliance Management Frameworks
Delegates learn to design and operate a structured compliance function that keeps the organisation ahead of its legal and regulatory obligations. The course covers obligation registers, compliance risk assessment, monitoring and testing, and breach management. Emphasis is placed on embedding compliance into business processes rather than treating it as a separate policing activity.



