Skip to content

Third-Party Due Diligence & Risk-Based Supplier Management Training Course

The Third-Party Due Diligence & Risk-Based Supplier Management Training Course provides a comprehensive framework for conducting effective due diligence and managing suppliers according to their risk profile, business…

TGR · Third-Party & Supply Chain Risk ManagementAll LevelsClassroomEnglish , Arabic
Duration
5 Days
Download Brochure

Course Overview

The Third-Party Due Diligence & Risk-Based Supplier Management Training Course provides a comprehensive framework for conducting effective due diligence and managing suppliers according to their risk profile, business criticality, and strategic importance. The course moves beyond basic supplier qualification to establish a structured approach for understanding who third parties are, what risks they present, how those risks should be assessed, and what controls should be applied throughout the supplier relationship. Participants will examine the complete due diligence lifecycle, covering supplier identification, prequalification, ownership and management checks, financial and operational assessment, regulatory and compliance screening, reputational considerations, cybersecurity and data risks, conflicts of interest, subcontracting, and other relevant risk factors. Particular emphasis is placed on gathering reliable information, validating evidence, identifying red flags, and making proportionate risk-based decisions. The program also explores risk-based supplier management after onboarding, including supplier segmentation, risk classification, contractual requirements, performance monitoring, periodic reassessment, issue management, remediation, escalation, and relationship termination. Participants will learn how to differentiate monitoring intensity and control requirements according to supplier criticality, inherent risk, service scope, access to information or systems, geographic exposure, and business dependency. Through practical case studies, supplier assessment exercises, risk-rating simulations, and scenario-based workshops, participants will develop the skills required to establish a consistent due diligence process and integrate risk considerations into procurement, supplier selection, contracting, ongoing management, and supplier performance governance.

Learning Objectives

  • By the end of the course, participants will be able to:
  • Analyze the strategic role of third-party due diligence within supplier risk management.
  • Identify key risk factors requiring assessment before engaging a supplier.
  • Develop structured and proportionate supplier due diligence processes.
  • Classify suppliers according to criticality, inherent risk, and business dependency.
  • Evaluate supplier ownership, management, financial stability, and operational capability.
  • Assess regulatory, legal, compliance, reputational, and ethical risks.
  • Identify potential conflicts of interest, integrity concerns, and other supplier red flags.
  • Evaluate cybersecurity, information security, privacy, and technology-related supplier risks.
  • Apply risk-based supplier segmentation and monitoring methodologies.
  • Develop supplier risk-rating models and assessment criteria.
  • Establish appropriate documentation and evidence requirements for due diligence.
  • Integrate due diligence findings into supplier selection and contracting decisions.
  • Develop risk-based contractual controls and supplier obligations.
  • Establish ongoing supplier monitoring and periodic reassessment processes.
  • Manage supplier issues, remediation actions, exceptions, and escalation effectively.
  • Develop a practical risk-based supplier management framework for organizational implementation.

Who Should Attend

This course is designed for professionals responsible for supplier management, procurement, strategic sourcing, vendor management, third-party risk, due diligence, supplier governance, contract management, and supply chain risk. It is particularly relevant to procurement managers, supplier relationship managers, vendor risk specialists, sourcing professionals, category managers, contract managers, procurement analysts, and supplier performance professionals. The program is also suitable for professionals working in enterprise risk, operational risk, compliance, legal, internal audit, cybersecurity, information security, data protection, finance, business continuity, internal controls, and governance, as well as managers and decision makers involved in supplier approval, onboarding, contracting, monitoring, or renewal. The course is applicable to government entities, ministries, banks, financial institutions, insurance companies, oil and gas organizations, telecommunications companies, technology firms, healthcare organizations, manufacturing companies, utilities, construction and engineering organizations, multinational corporations, and large enterprises that manage significant supplier and third-party networks.

Learning Outcomes

  • Upon successful completion of the course, participants will be able to:
  • Build a structured due diligence process for new and existing suppliers.
  • Determine the appropriate level of due diligence based on supplier risk and criticality.
  • Conduct supplier risk profiling using consistent assessment criteria.
  • Identify ownership, control, management, and affiliation risks.
  • Evaluate supplier financial and operational resilience.
  • Assess regulatory, legal, compliance, ethical, and reputational exposure.
  • Identify red flags requiring enhanced review or escalation.
  • Evaluate supplier cybersecurity, data protection, and technology risks.
  • Assess risks associated with subcontractors and extended third-party relationships.
  • Develop supplier risk scores and risk classifications.
  • Determine appropriate approval and escalation thresholds.
  • Integrate due diligence findings into sourcing and supplier selection decisions.
  • Establish risk-based contractual requirements and ongoing controls.
  • Develop supplier monitoring plans based on risk level and business criticality.
  • Manage supplier remediation, exceptions, performance concerns, and emerging risks.
  • Prepare an integrated risk-based supplier management framework and implementation roadmap.

Course Outline

Course Outline

Day 1

Foundations of Third-Party Due Diligence & Supplier Risk

  • Strategic importance of supplier due diligence
  • Understanding third-party and supplier risk
  • Supplier lifecycle and risk exposure points
  • Supplier criticality and business dependency
  • Inherent versus residual supplier risk
  • Key supplier risk categories
  • Governance, roles, responsibilities, and accountability
  • Supplier inventory and risk mapping
  • Risk appetite and supplier approval principles
  • Risk-based approaches to supplier management
  • Designing a proportionate due diligence framework
  • Practical Application:
  • Participants map a supplier lifecycle and identify the key risk and due diligence requirements at each stage.
Day 2

Supplier Due Diligence, Screening & Risk Assessment

  • Supplier prequalification and onboarding
  • Ownership and management structure assessment
  • Financial and commercial due diligence
  • Operational capability and capacity assessment
  • Regulatory and legal compliance checks
  • Ethical conduct and integrity considerations
  • Reputational risk and adverse information
  • Conflicts of interest and related-party concerns
  • Sanctions and restricted-party screening where applicable
  • Cybersecurity and information security due diligence
  • Data privacy and information-handling risks
  • Geographic and jurisdictional exposure
  • Subcontractor and fourth-party risks
  • Practical Application:
  • Participants perform a supplier due diligence assessment using a simulated supplier profile, available evidence, screening results, and identified risk indicators.
Day 3

Risk-Based Supplier Segmentation, Scoring & Decision-Making

  • Principles of risk-based supplier segmentation
  • Supplier criticality assessment
  • Developing supplier risk-rating models
  • Risk scoring criteria and weighting
  • Risk matrices and prioritization
  • Low, medium, high, and critical supplier classifications
  • Enhanced due diligence for higher-risk suppliers
  • Approval thresholds and escalation criteria
  • Risk acceptance and exception management
  • Linking risk assessment to procurement decisions
  • Supplier selection and award decisions
  • Documenting risk-based decisions
  • Practical Application:
  • Participants develop a supplier segmentation and risk-scoring model and use it to determine appropriate approval, due diligence, and monitoring requirements.
Day 4

Risk-Based Supplier Management, Contracts & Monitoring

  • Transitioning from due diligence to ongoing supplier management
  • Risk-based supplier governance
  • Contractual risk controls and supplier obligations
  • Audit and assurance rights
  • Service-level requirements and performance measures
  • Compliance, security, privacy, and reporting provisions
  • Ongoing supplier monitoring
  • Periodic risk reassessment
  • Key risk and performance indicators
  • Supplier incidents and control failures
  • Remediation and corrective action management
  • Managing exceptions and risk acceptance
  • Supplier relationship and performance reviews
  • Practical Application:
  • Participants develop a risk-based supplier monitoring plan covering contractual controls, performance indicators, reassessment frequency, remediation, and escalation.
Day 5

Supplier Governance, Emerging Risks & Continuous Improvement

  • Supplier governance frameworks and oversight
  • Management reporting and supplier risk dashboards
  • Portfolio-level supplier risk analysis
  • Identifying emerging and changing supplier risks
  • Monitoring changes in ownership, financial condition, operations, and subcontracting
  • Business continuity and supplier resilience
  • Exit and transition planning for critical suppliers
  • Internal audit and assurance over supplier management
  • Measuring supplier risk management effectiveness
  • Improving due diligence efficiency and data quality
  • Digital tools and automation for supplier risk management
  • Supplier risk program maturity assessment
  • Continuous improvement and lessons learned
  • Final Workshop:
  • Participants develop an integrated Third-Party Due Diligence & Risk-Based Supplier Management Framework covering supplier classification, due diligence, risk scoring, approval, contractual controls, monitoring, reassessment, remediation, escalation, resilience, reporting, and continuous improvement.

Upcoming Dates

No upcoming events are currently scheduled.

Request a Date

Related Courses

Ready to Elevate Your Team's Capabilities?

Speak with our advisors about upcoming programmes or a bespoke corporate training plan.