Calendar·Risk Management·Operational Risk
Vendor and Third-Party Risk Management
FACULTY OF RISK MANAGEMENTOperational Risk • ~30 min

How to manage the risks that arise from vendor and third-party relationships in Canadian organizations — due diligence, contractual protections, ongoing monitoring, and what to do when a vendor fails.

Vendor and Third-Party Risk Management

Price
$79
Lessons
4
Enroll
Share
EmailLinkedIn

What this course covers

01Third-Party Risk: Why Vendor Relationships Create Organizational Exposure
02Vendor Due Diligence: What to Assess Before Engaging a Critical Supplier
03Contractual Protections: The Provisions That Actually Reduce Third-Party Risk
04Ongoing Monitoring and What to Do When a Vendor Fails

Scenario

A regional healthcare network operating 4 outpatient clinics across southern Ontario discovered during a routine audit that patient billing records processed by its external billing services provider contained errors affecting approximately 1,200 accounts over a 7-month period. The billing provider, engaged 3 years earlier to handle all patient invoicing, insurance claims processing, and collections, had undergone a change in ownership 14 months into the relationship. The new ownership had subsequently migrated the billing platform to a different cloud infrastructure provider and reduced staffing levels by roughly 30 percent, changes the healthcare network learned about only after the audit findings emerged.

The healthcare network had originally selected the billing provider following a competitive procurement process that evaluated 5 candidate firms. The selection committee, comprising the network's chief financial officer, its operations director, and an external consultant, had assessed each candidate's financial statements, client references, data security certifications, and proposed service delivery model. The successful vendor had demonstrated ISO 27001 certification, carried professional liability coverage of $5 million per occurrence, and provided audited financial statements showing 4 consecutive years of profitability. At the time of engagement, the vendor appeared to represent a low-risk, cost-effective solution for a function the healthcare network had struggled to perform efficiently in-house.

The master services agreement executed between the parties ran to 47 pages and included standard provisions addressing confidentiality, indemnification, and termination. The agreement required the vendor to maintain "commercially reasonable" data security practices and to provide 60 days' notice before any material change in service delivery. It did not define what constituted a material change, did not require notification of ownership transitions, and did not establish specific performance metrics against which the vendor's work could be measured. The healthcare network had not requested a right-to-audit clause during negotiations and had not conducted any formal review of the vendor's operations since the initial engagement.

The billing errors had resulted in delayed insurance reimbursements, patient complaints regarding incorrect balances, and at least 3 formal inquiries from the provincial health insurance plan regarding claims discrepancies. The healthcare network now faces questions about how to assess the full scope of the problem, what remedies exist under the current contract, whether to continue the vendor relationship or transition to an alternative provider, and what changes to its vendor management practices might prevent similar situations in future engagements.

More in this program

Operational Risk: Definition, Sources, and Exposure
~30 min · $79
Process Failure and Control Breakdowns
~50 min · $149
Incident Response and Post-Incident Review
~50 min · $149

Rate this course

Complete the course to share your rating and feedback.