Auditing Third Party Risk - IT

As organizations further their reliance on third party service providers, regulatory bodies around the world have increased their level of scrutiny regarding third party provider’s abilities to properly protect sensitive and internally used data and information assets. Today’s organizations are expected to demonstrate strong, third-party governance and risk management. Organizations that establish a third-party management program gain and maintain a clear understanding of their external provider’s controls and shortcomings through analysis of Statement of Control (SOC) reports, contract administration, service level agreement (SLA) reporting, and annual third-party risk assessments. Internal auditors need a basic understanding of third party risk. Without this knowledge, internal auditors may not fully comprehend IT objectives and the associated risks inherent in using third parties, and may lack the ability to assess or audit the design or effectiveness of controls related to those risks. The self-study Auditing Third-Party IT Risk course delivers an introduction to third-party risk concepts, and emphasizes the significant role that the business units and IT play in establishing and maintaining third-party relationships. Further, this course guides internal auditors in building proficiencies for assessing third-party vendors.
SKU: 1010.LMS.LM01.D045.01.01
$79.00
Your price: $79.00

As organizations further their reliance on third party service providers, regulatory bodies around the world have increased their level of scrutiny regarding third party provider’s abilities to properly protect sensitive and internally used data and information assets. Today’s organizations are expected to demonstrate strong, third-party governance and risk management. Organizations that establish a third-party management program gain and maintain a clear understanding of their external provider’s controls and shortcomings through analysis of Statement of Control (SOC) reports, contract administration, service level agreement (SLA) reporting, and annual third-party risk assessments. Internal auditors need a basic understanding of third party risk. Without this knowledge, internal auditors may not fully comprehend IT objectives and the associated risks inherent in using third parties, and may lack the ability to assess or audit the design or effectiveness of controls related to those risks. The self-study Auditing Third-Party IT Risk course delivers an introduction to third-party risk concepts, and emphasizes the significant role that the business units and IT play in establishing and maintaining third-party relationships. Further, this course guides internal auditors in building proficiencies for assessing third-party vendors. Learning Objective(s): List the elements and attributes of third-party risk management. Explain risks and controls associated with contracting third parties. Describe the areas where internal audit can monitor third parties. Identify the types of third-party risk management governance structures. Recognize key elements of Type 1 and Type 2 assurance reports for the operation of critical third-party organizations. Describe evaluation criteria for engagements of third parties. Discuss third-party due diligence policies and procedures. Identify the testing phase and essential criteria element(s) for evaluating the organization’s third-party risk management framework and process.

Customers who bought this item also bought

IT General Controls Certificate Examination

$125.00

Auditing Market Risk

Market risk is a key risk for financial services organizations. Regulators and their supervisors focus on this risk, emphasizing the necessity of having accurate models that can measure the capital impact of market activities on the financial viability of the institution. Regulatory requirements and supervisors’ expanded expectations are giving internal audit a more relevant and active role in the assessment of market risk. In addition, an organization’s board has direct responsibility on market risk oversight and governance, so internal audit should provide it with independent assurance in conformance with the Standards. This course provides internal auditors with a baseline skill-set necessary to test and evaluate the effectiveness of the organization’s market risk management framework and processes.
$79.00

The Role of Internal Audit in Insurance Organizations

The insurance industry, which includes complex products such as property and casualty insurance, life insurance, health insurance, and variable annuities, is part of the larger financial services industry. While the two industries share some common characteristics, insurance organizations also face unique governance, risk management, and control issues. This course provides a strong foundation for understanding the role of internal audit in insurance organizations. Participants will be introduced to basic terminology, the regulatory environment, risk governance, and risk management issues relative to the insurance industry. Finally, the course presents best practices for managing the internal audit activity in insurance organizations.
$59.00

Auditing Culture and Conduct

Culture and conduct play a pivotal role in the well-being of an organization. Organizations with a culture based on strong values have a higher probability of successfully achieving their business objectives and retaining high-performance employees. One of internal audit’s key responsibilities is to assess the adequacy and effectiveness of the internal control environment directly impacted by culture, as well as the conduct that arises from employees acting out and exhibiting their interpretation of the values of that culture. Internal audit, as the third line of defense in an organization’s governance framework, is uniquely positioned to assist an organization in establishing a strong tone-at-the-top by evaluating and reporting on its culture and conduct. This course is intended to assist internal auditors in understanding and evaluating the overarching culture of an organization and using their knowledge to provide value-added insight to various stakeholders.
$79.00