Third Party Labs Academy | Risk and Compliance seat
Practitioner-depth third-party risk management for the people who design the program, set the standard and answer the regulator. Six modules, one graded final assessment, and the contract, governance and monitoring tools you will use on Monday.
Australian dollars. Australian buyers: GST is added at checkout where applicable. Team pricing for six or more seats on request.
Who it is for
Risk professionals, compliance officers, supplier governance and relationship managers, and operational risk practitioners working at or supporting regulated financial services organisations across the Asia-Pacific region. If you own the TPRM policy, run the classification, sit on the supplier risk committee or brief the board, this is your course.
By the end of the course you will be able to
Outcome
Design an ongoing monitoring framework calibrated to risk classification, and assess a TPRM program against a maturity model to find its priority improvements.
Outcome
Describe the governance structures a credible program needs (policy, ownership, committee oversight, board reporting) and explain what APAC regulators expect to see at each of them.
Outcome
Identify the contract provisions APAC regulators require for material arrangements, and review a contract to find the gaps that create regulatory exposure.
Curriculum
The first three modules are shared across all four Academy courses, because third-party risk is a shared responsibility and the foundations are the same whichever seat you hold. Modules four to six are written for Risk and Compliance.
Welcome to TPRM Foundations: APAC Financial Services
Emery names the course, shows you your seat at the table, states the three course outcomes and explains how the certificate is earned.
Third-Party Risk: Where It Sits, Who Owns It, and Why Now
Third-party risk placed inside the risks your organisation already manages. The four seats at the table. Three verified APAC cases (Singapore data centre outage 2023, CrowdStrike 2024, Latitude Financial 2023) and the sentence every regulator agrees on: the organisation cannot outsource its accountability.
The APAC Regulatory Map: Who Sets the Rules and What They Have in Common
Seven jurisdictions in ten minutes: APRA, MAS, HKMA, RBNZ, BNM, the Japan FSA and RBI, with one framework and one distinguishing feature each. The five obligations that recur across the region, and the cross-border data rule: check both jurisdictions before signature.
Eight Risk Domains, Eight Lifecycle Stages: The Third Party Labs Framework
The controlled vocabulary for the rest of the course. Eight risk domains, eight lifecycle stages from planning to exit, governance as the wrapper. Pick one supplier you know and place it on the framework.
Ongoing Monitoring and Program Maturity
Monitoring cadence by classification, KRIs and KPIs, event-driven review triggers, and a maturity model you apply to your own program with the downloadable self-assessment worksheet.
Program Governance: Policy, Ownership, Oversight, and Reporting
What the TPRM policy must contain and who approves it. First-line and second-line ownership models. Committee oversight and board reporting, and what APAC regulators expect to see at each.
Contract Provisions APAC Regulators Require, and How to Find the Gaps
Six provisions in locked order: audit and regulator access, data handling and location, subcontracting consent, incident notification, business continuity, exit and data return. A four-step gap review you can run on a live contract.
How it runs
Knowledge checks
A short check after each module
Three to five questions, not graded, with feedback on every answer. Each check unlocks the next module.
Final assessment
20 questions, pass mark 70 percent
Questions are drawn from a pool. Three attempts, then a 24-hour lockout before further attempts. Completion is recorded only when you pass.
Certificate
Module-level objectives and CPD hours
Your certificate records your name, the full course title, the completion date, the learning objectives you met and your CPD hours.
Downloads and CPD
This course comprises 3.5 hours of structured, assessed learning (video, knowledge checks, activities and a graded final assessment, pass mark 70 percent).
Claim 3.5 hours with bodies that use a 60-minute hour, including IIA and SFC Hong Kong. Claim 4.25 CPE with ISACA (50-minute basis). Check your own body's rules on self-directed, verifiable CPD before claiming.
AUD 199. Start any time. Presented by Emery at Third Party Labs Academy.
Also from Third Party Labs