Third Party Risk Management > Best Practices in Risk Assessment

1. How does your firm perform third-party due diligence risk assessment re-reviews? 

2. If you are performing risk assessments on third-parties, do you re-assess these third-parties after the initial risk assessment? 

3. If so, how often are you performing re-reviews? 

4. What do these re-reviews consist of? 

5. Are you asking the same set of initial due diligence questions, or are you simply confirming there's been no changes since prior assessment? Or, is it a hybrid of these approaches?

The full content of this page is only available to SIG Members.

Forums: