A focused course, tailored for you
The Bank Third Party Risk Tiering and Continuous Monitoring Course
A working method for the third party risk manager who needs the tier-1 inventory, the continuous monitoring queue, and the regulator-ready file to line up in one cycle.
The tier-1 vendor inventory the examiner asks for first is not the alphabetical list the GRC tool exports.
Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.
Why this course
Third party risk managers at US banks sit between three groups that do not naturally agree. The first line owns the vendor relationship and wants the contract signed this quarter. The second line owns the methodology and wants tiering, diligence, and continuous monitoring evidence that holds up under interagency guidance. The examiner wants the file. The working day collapses into reconciling the GRC tool inventory with the procurement spend file, chasing SOC 2 bridge letters that have aged past the attestation window, recalculating concentration risk on the core processor and the cloud provider, and explaining to a line-of-business head why a vendor moved from tier 2 to tier 1 after a fourth-party finding. Continuous monitoring is supposed to be a cadence, not a fire drill, but the cadence keeps slipping. The board reporting pack ends up as a backwards-looking issues list rather than the forward inventory of concentration, resiliency, and exit risks the risk committee actually wants to read.
What you walk away with
- Produce a tier-1 vendor inventory that an examiner can read top-to-bottom without follow-up questions.
- Run a continuous monitoring queue prioritised by criticality and concentration, not by alphabetical accident.
- Make and defend tier reclassifications with the line-of-business owner using evidence, not opinion.
- Map fourth-party exposure on the core processor, cloud, and payments stack and present it to the risk committee.
- Ship a board reporting pack that names concentration, resiliency, and exit risk before any examiner does.
The 12 modules
How this addresses your situation
Specific modules that map to what you said you are dealing with.
What you get with this course
- Twelve written modules in the Art of Service learning environment.
- Downloadable templates for the tiering rubric, the tier-1 inventory, the diligence pack, the clause library, the fourth-party map, the monitoring calendar, the issue log, the exit-plan tabletop, the reporting pack, and the examiner request-list response.
- Worked examples drawn from US bank third party programmes at multiple asset-size bands.
- A hand-built implementation playbook tuned to the buyer's portfolio mix and tier-1 vendor stack.
- Lifetime access and free updates as supervisory guidance and the underlying templates evolve.
What you will have in hand by Day 1, Week 1, Month 1
Within 24 hours your account in the learning environment is provisioned and the hand-built implementation playbook is delivered alongside it.
Self-paced thereafter. Most third party risk managers work through the twelve modules across four to six weeks alongside the day job.
Before and after
Tier-1 inventory lives in a GRC tool extract that does not reconcile to procurement, the continuous monitoring queue runs alphabetically, fourth-party concentration on the core processor is qualitative, and the board pack is a backwards-looking issues list. Examiner requests trigger a multi-week reconstruction.
Tier-1 inventory reconciles cleanly across GRC, procurement, and contracts, the monitoring queue is sorted by criticality and event triggers, fourth-party concentration is quantified on the processor, cloud, and payments stack, and the risk-committee pack is a forward view of resiliency and concentration. Examiner requests are answered from a pre-built file.
What happens if you do not address this
The next examination cycle finds the tier-1 list out of date, fourth-party concentration on the core processor undocumented, and continuous monitoring evidence inconsistent across the inventory. Findings cluster in the third party domain, remediation pulls the programme off the forward calendar, and the risk committee's confidence in the second line erodes precisely when supervisory attention on operational resiliency is rising.
Who it is for
A third party risk manager, vendor risk officer, or operational risk lead inside a US bank or bank holding company who owns or contributes to the tier-1 vendor inventory, the criticality scoring rubric, the continuous monitoring cadence, and the board or risk-committee reporting pack on third party and operational resiliency. Comfortable inside a GRC tool, working with procurement, line-of-business owners, business continuity, information security, and the second line, and accountable when the examiner asks to see the file.
How it arrives
Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.
Time investment. Roughly thirty to forty hours across the twelve modules including template work, paced to fit alongside a full third party risk caseload.
Why $199 is the right number
Generic vendor risk courses from training vendors stop at definitions and questionnaires. Big-firm advisory engagements deliver a methodology deck and an invoice and rarely leave a working inventory behind. Internal build-from-scratch consumes second-line time over multiple quarters. This course gives the same artefacts as the advisory engagement, tuned to the buyer's portfolio, at a price the line manager can sign off without procurement.
FAQ
30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.