Skip to main content
Image coming soon

The Bank Third Party Risk Tiering and Continuous Monitoring Course

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

The Bank Third Party Risk Tiering and Continuous Monitoring Course

A working method for the third party risk manager who needs the tier-1 inventory, the continuous monitoring queue, and the regulator-ready file to line up in one cycle.

The tier-1 vendor inventory the examiner asks for first is not the alphabetical list the GRC tool exports.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

Third party risk managers at US banks sit between three groups that do not naturally agree. The first line owns the vendor relationship and wants the contract signed this quarter. The second line owns the methodology and wants tiering, diligence, and continuous monitoring evidence that holds up under interagency guidance. The examiner wants the file. The working day collapses into reconciling the GRC tool inventory with the procurement spend file, chasing SOC 2 bridge letters that have aged past the attestation window, recalculating concentration risk on the core processor and the cloud provider, and explaining to a line-of-business head why a vendor moved from tier 2 to tier 1 after a fourth-party finding. Continuous monitoring is supposed to be a cadence, not a fire drill, but the cadence keeps slipping. The board reporting pack ends up as a backwards-looking issues list rather than the forward inventory of concentration, resiliency, and exit risks the risk committee actually wants to read.

What you walk away with

  • Produce a tier-1 vendor inventory that an examiner can read top-to-bottom without follow-up questions.
  • Run a continuous monitoring queue prioritised by criticality and concentration, not by alphabetical accident.
  • Make and defend tier reclassifications with the line-of-business owner using evidence, not opinion.
  • Map fourth-party exposure on the core processor, cloud, and payments stack and present it to the risk committee.
  • Ship a board reporting pack that names concentration, resiliency, and exit risk before any examiner does.

The 12 modules

Module 1. Criticality scoring rubric a US bank can defend
Build a tiering rubric that distinguishes inherent criticality from residual risk, ties the scoring inputs to interagency third party guidance language, and produces a tier assignment that can be reconstructed from the same data three quarters from now. Includes the rubric template, the scoring rationale field, and the recalculation cadence so reassignments are routine rather than escalations.
Module 2. Tier-1 vendor inventory the examiner reads first
Reconcile the GRC tool extract with the procurement spend file and the contract repository so the tier-1 inventory is one list, not three. The module walks the fields the examiner expects (legal entity, criticality, services, residual risk, residency, fourth parties, last assessment date, next monitoring event) and shows how to keep the list current without a quarterly fire drill.
Module 3. Onboarding diligence for tier-1 and high-risk vendors
A diligence pack that scales by tier instead of the same questionnaire for every vendor. Covers financial condition review, information security and SOC 2 scope coverage, business continuity testing evidence, fourth-party disclosure, and the residency and access controls the examiner asks about. Includes the diligence checklist, the evidence index, and the standard exceptions log.
Module 4. Contract terms the second line will sign off on
The right-to-audit clause, the subcontractor notification clause, the breach notification window, the resiliency and exit assistance language, and the data and access provisions a US bank needs in tier-1 contracts. The module gives the clause library, the negotiation fallback positions, and the redline log you can hand to legal so the second-line review takes hours not weeks.
Module 5. Fourth-party mapping for core, cloud, and payments
Map the fourth-party stack underneath the core processor, the cloud platform, and the payments rails so the bank knows which dependencies sit two layers down. Includes the fourth-party disclosure questionnaire, the concentration view, and the reporting line into the operational resiliency programme so a fourth-party incident becomes a known scenario, not a surprise.
Module 6. Continuous monitoring cadence by criticality
Replace the alphabetical monitoring queue with a cadence driven by tier, residual risk, and event triggers. The module sets the monitoring calendar, the SOC 2 and bridge-letter tracking, the financial-condition watchlist, the news and adverse-media feed integration, and the escalation thresholds so the queue is a working list the second line can run.
Module 7. Concentration risk on processor, cloud, and payments
Quantify concentration on the core processor, the primary cloud, and the payments and card-network providers, both at the vendor and the fourth-party level. Covers the concentration metric, the appetite statement language, the heat-map view the risk committee expects, and the mitigation actions the second line can credibly propose without forcing a re-platforming conversation.
Module 8. Resiliency and exit testing the examiner will ask about
Move from a paper exit plan to a tested exit and resiliency posture for tier-1 vendors. The module covers the resiliency requirements clause, the exit plan template, the tabletop exercise script, the recovery time objective evidence, and the documentation the examiner expects to see for the most critical relationships, including the core processor and the cloud platform.
Module 9. Issue management and remediation tracking
A single issue log that ties vendor findings (from diligence, monitoring, audits, incidents) to remediation owners, due dates, and risk acceptance language the second line can defend. Includes the issue triage rubric, the remediation cadence, the closure evidence standard, and the link into the operational risk and audit issue universes so the same finding is not tracked in three places.
Module 10. Incident response with third parties
The playbook for the morning a tier-1 vendor calls about an incident. Covers the notification clauses you negotiated upstream, the internal escalation, the customer and regulator notification triggers under the relevant supervisory expectations, the evidence collection from the vendor, and the post-incident review that feeds the issue log and the next monitoring cycle.
Module 11. Board and risk-committee reporting
Build a reporting pack the risk committee will read end-to-end. The module gives the standard one-page tier-1 dashboard, the concentration view, the resiliency posture, the top issues by criticality, the forward calendar of monitoring events, and the narrative that frames third party risk as a managed posture rather than a backwards-looking issues list.
Module 12. Examiner readiness and the request-list response
Pre-build the file the examiner asks for so the response is hours, not weeks. The module covers the standard request list, the document index, the inventory, policy, methodology, monitoring, issue and incident artefacts the examiner expects, and the rehearsal walkthrough so the third party risk manager owns the narrative when the request lands.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Module 1 to 3 cover the methodology and onboarding posture the second line and the examiner expect to see documented.
Module 4 to 7 cover the tier-1 working surface: contracts, fourth parties, continuous monitoring, and concentration.
Module 8 to 10 cover resiliency, issues, and incidents, the parts that turn paper programmes into tested ones.
Module 11 to 12 cover the reporting and examiner-readiness work that lets the programme be judged on the file, not the conversation.

What you get with this course

  • Twelve written modules in the Art of Service learning environment.
  • Downloadable templates for the tiering rubric, the tier-1 inventory, the diligence pack, the clause library, the fourth-party map, the monitoring calendar, the issue log, the exit-plan tabletop, the reporting pack, and the examiner request-list response.
  • Worked examples drawn from US bank third party programmes at multiple asset-size bands.
  • A hand-built implementation playbook tuned to the buyer's portfolio mix and tier-1 vendor stack.
  • Lifetime access and free updates as supervisory guidance and the underlying templates evolve.

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the hand-built implementation playbook is delivered alongside it.

Self-paced thereafter. Most third party risk managers work through the twelve modules across four to six weeks alongside the day job.

Before and after

Before

Tier-1 inventory lives in a GRC tool extract that does not reconcile to procurement, the continuous monitoring queue runs alphabetically, fourth-party concentration on the core processor is qualitative, and the board pack is a backwards-looking issues list. Examiner requests trigger a multi-week reconstruction.

After

Tier-1 inventory reconciles cleanly across GRC, procurement, and contracts, the monitoring queue is sorted by criticality and event triggers, fourth-party concentration is quantified on the processor, cloud, and payments stack, and the risk-committee pack is a forward view of resiliency and concentration. Examiner requests are answered from a pre-built file.

What happens if you do not address this

The next examination cycle finds the tier-1 list out of date, fourth-party concentration on the core processor undocumented, and continuous monitoring evidence inconsistent across the inventory. Findings cluster in the third party domain, remediation pulls the programme off the forward calendar, and the risk committee's confidence in the second line erodes precisely when supervisory attention on operational resiliency is rising.

Who it is for

A third party risk manager, vendor risk officer, or operational risk lead inside a US bank or bank holding company who owns or contributes to the tier-1 vendor inventory, the criticality scoring rubric, the continuous monitoring cadence, and the board or risk-committee reporting pack on third party and operational resiliency. Comfortable inside a GRC tool, working with procurement, line-of-business owners, business continuity, information security, and the second line, and accountable when the examiner asks to see the file.

Who this is NOT for. Not for procurement category managers without risk accountability, not for general enterprise risk generalists with no banking exposure, and not for vendors selling third party risk software looking for talking points.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Roughly thirty to forty hours across the twelve modules including template work, paced to fit alongside a full third party risk caseload.

Why $199 is the right number

Generic vendor risk courses from training vendors stop at definitions and questionnaires. Big-firm advisory engagements deliver a methodology deck and an invoice and rarely leave a working inventory behind. Internal build-from-scratch consumes second-line time over multiple quarters. This course gives the same artefacts as the advisory engagement, tuned to the buyer's portfolio, at a price the line manager can sign off without procurement.

FAQ

Is this aligned to the current US interagency third party guidance?
Yes. The methodology, the rubric, the contract clauses, the monitoring cadence, and the reporting pack are built against the interagency guidance language and the supervisory expectations the prudential examiners apply at the relevant asset-size band.
Does it cover community-bank scope or large-bank scope?
Both. The templates flex by asset size. The implementation playbook is hand-built to the buyer's portfolio, so the worked examples reflect the right scale for the bank.
Will the templates integrate with the GRC tool we already run?
The templates are tool-agnostic spreadsheets and document formats designed to map onto the common GRC field structures so they can be loaded back into the system of record rather than living parallel to it.
Who fulfils the implementation playbook?
Gerard hand-builds the playbook against the buyer's specific portfolio mix, tier-1 vendor stack, and supervisory context. It is delivered alongside course access within 24 hours of purchase.
Is there a refund?
Yes. Thirty-day money-back guarantee, no questions, if the materials do not match the working surface described.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.