Tag Archive for: Third-Party Risk Management

Resilience Leadership Newsletter – News from the World of Business Continuity – #7-2026
The July 2026 issue of Resilience Leadership is dedicated to Supply Chain Resilience and Third-Party Risk Management. It explores structural volatility, hidden dependencies, NIS2 and DORA, the Jaguar Land Rover case study, the TPRM lifecycle, industrial risk prevention, and the new DRI certifications.

Supply Chain: When Volatility Becomes Structural
Supply chain disruptions are no longer occasional events. This article compares the World Economic Forum’s *Global Value Chains Outlook 2026* with the *Allianz Risk Barometer 2026* and identifies four priorities for managing dependencies, critical suppliers, and business interruption scenarios.

What Keeps the Resilience Manager Up at Night? Two Providers, One Dependency
Having two suppliers does not necessarily mean having two alternatives. Both may depend on the same manufacturer, logistics operator, cloud provider, or infrastructure node. This article examines how to identify hidden concentrations and incorporate this information into business continuity planning.

NIS2 and DORA: From Contractual Clause to Proof of Effectiveness
NIS2 and DORA require a structured approach to supplier management. Risk assessment must translate into verifiable contractual requirements, periodic monitoring, and concrete evidence. This article analyzes the new ACN FAQs on the supply chain and the Register of Information required by DORA.

The Technical Corner – From Inventory to Release: The TPRM Lifecycle
An effective third-party risk management program must govern the entire lifecycle of the supplier relationship. This article examines seven phases: inventory, classification, due diligence, risk assessment, contract management, monitoring, and exit management.

From DRI International – Supply Chain Resilience Becomes a Professional Specialization
DRI International has introduced a professional track dedicated to Supply Chain Resilience, consisting of the SCLE 2000 course and the ASCRP and CSCRP certifications. The initiative recognizes the management of supply chain dependencies as a distinct specialization within the field of organizational resilience.

From NFPA – Supplier resilience also depends on industrial risk prevention
The assessment of critical suppliers cannot be limited to cybersecurity, contracts, and financial stability. The NFPA report on ASRS shows how fires and physical vulnerabilities in automated warehouses can disrupt entire supply chains. NFPA 1660 links these risks to business impact analysis and continuity strategies.

Reading Materials and Podcasts to Learn More About Supply Chain Resilience
A selection of books and podcasts to explore supply chain resilience, understand critical dependencies, and improve supply chain risk management.
