2019 Protiviti and Shared Assessments Survey Finds Board Involvement a Key Indicator of Vendor Risk Management Maturity; Most Organizations Will Drop Vendors to De-Risk - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
April 9, 2019 Newswires
Share
Share
Post
Email

2019 Protiviti and Shared Assessments Survey Finds Board Involvement a Key Indicator of Vendor Risk Management Maturity; Most Organizations Will Drop Vendors to De-Risk

PR Newswire

SANTA FE, N.M. and MENLO PARK, Calif., April 9, 2019 /PRNewswire/ -- Global consulting firm Protiviti and the Shared Assessments Program, the member-driven leader in third-party risk assurance, have released findings of their 2019 "Vendor Risk Management Benchmark Study: Running Harder to Stay In Place," the fifth such extensive study of organizational risk posture assessed by industry sector and program criteria.

Protiviti logo. (PRNewsFoto/Protiviti)

"The threat landscape is evolving daily, and new risk vectors – from nation state bad actors, data thefts and high-impact cyberattacks to business model viability and regulatory non-compliance – are making comprehensive vendor risk management programs all the more crucial to organizational stability and continuity," said Paul Kooney, a managing director in Protiviti's security and privacy practice. "This year's benchmark study analyzes more than 200 detailed criteria of a comprehensive vendor risk management program. Our survey findings underscore the fact that all risk management programs are running harder just to stay in place, and those that aren't rapidly advancing are falling behind. This has major potential impact on management goals, security postures and, very often, on regulatory mandates."

Survey results show that vendor risk management (VRM) programs in the technology and insurance/healthcare payer sectors have achieved the greatest levels of program maturity overall; however, no sector reported more than 50 percent of respondents at a mature level with regard to managing vendor risk. The technology and insurance sectors also led in fourth-party VRM, confirming companies in these sectors, on average, most carefully assess the risk postures of their vendors' full ecosystem, including subcontractor relationships.

Among other key survey findings:

  • Strong correlation exists between engagement at the board of directors level and VRM program maturity: 57 percent of organizations reporting high levels of board engagement also report fully functional and advanced VRM programs.
  • Assessing board engagement levels by industry, the tech sector leads, followed by manufacturing and healthcare providers.
  • The tech and insurance sectors lead in fourth-party program maturity, assessing their vendors' vendors and full ecosystem for risk management practices.
  • Continuous Monitoring, an important aspect to VRM program maturity, lags across all sectors. Only 38 percent of respondents report that their organizations have controls in place to ensure ongoing monitoring of vendor relationships.
  • All sectors cite resource allocation as a substantial challenge. The technology sector ranks slightly higher in overall maturity, but no sector is at an optimal level.
  • All sectors report strong progress in assessing and managing critical vendors. Forty-one percent have fully mature processes in place to identify and manage their most critical vendors, while only 7 percent of respondents report that they have not yet begun to identify and separately manage critical vendors.

The survey polled 554 risk management practitioners and C-suite executives on the detailed criteria in the Shared Assessment Vendor Risk Management Maturity Model (VRMMM), an industry standard framework for evaluating the maturity of vendor risk programs, including cybersecurity, IT, privacy, data security and business resiliency controls. Broken into eight categories, the model explores 211 program elements that should form the basis of a robust, well-run VRM program. 

The 2019 survey added 81 new practice measures or criteria, in line with the 2019 VRMMM, including those focusing on continuous monitoring, the risk assessment of fourth-party vendor relationships and privacy, thus reflecting the expanding threat landscape and global regulatory compliance demands. 

"This comprehensive study codifies what recent news events have shown: the threat landscape is morphing almost daily, with nation state threats, advanced cyberattacks, new forms of activism, potential liability shifts and other factors bringing new importance to vendor risk management practices and programs," said Shared Assessments Chairman and President Catherine A. Allen. "This benchmark study and the member-driven Shared Assessments Program's vendor risk management tools, best practices, certifications and shared knowledge form the intelligence ecosystem for vendor risk management that's relied upon by leading consulting organizations and risk management practitioners around the world."

Resources Available
The 2019 "Vendor Risk Management Benchmark Study: Running Harder to Stay in Place" report is available complimentary on the Shared Assessments site and on the Protiviti site, along with an infographic of survey highlights and a podcast. A free one-hour webcast featuring Paul Kooney and Gary Roboff, senior advisor, The Santa Fe Group, Shared Assessments Program, discussing the survey findings and sharing practical ways to improve vendor risk, will be held on May 1 at 11:00 a.m. PDT. Please click here to register.

About Protiviti
Protiviti (www.protiviti.com) is a global consulting firm that delivers deep expertise, objective insights, a tailored approach and unparalleled collaboration to help leaders confidently face the future. Through its network of more than 80 offices in over 20 countries, Protiviti and its independently owned Member Firms provide clients with consulting solutions in finance, technology, operations, data, analytics, governance, risk and internal audit.

Named to the 2019 Fortune 100 Best Companies to Work For® list, Protiviti has served more than 60 percent of Fortune 1000® and 35 percent of Fortune Global 500® companies. The firm also works with smaller, growing companies, including those looking to go public, as well as with government agencies. Protiviti is a wholly owned subsidiary of Robert Half (NYSE: RHI). Founded in 1948, Robert Half is a member of the S&P 500 index.

About the Shared Assessments Program
As the only organization that has uniquely positioned and developed standardized resources to bring efficiencies to the market for more than a decade, the Shared Assessments Program has become the trusted source in third party risk assurance. Shared Assessments offers opportunities for members to address global risk management challenges through committees, awareness groups, interest groups and special projects. Join the dialog with peer companies and learn how you can optimize your compliance programs while building a better understanding of what it takes to create a more risk sensitive environment in your organization.

About The Santa Fe Group
The Santa Fe Group's risk management experts work collaboratively with organizations worldwide to identify valuable trends, risks, and vulnerabilities, and to advise, educate, and empower organizations in the areas of cybersecurity, third party risk, emerging technologies, and program management. The Santa Fe Group is the managing agent of the membership-based Shared Assessments Program, which helps many of the world's leading organizations manage and protect against third party IT security risks.

Protiviti is not licensed or registered as a public accounting firm and does not issue opinions on financial statements or offer attestation services.

Editor's note: Photos available on request.

 

Cision View original content to download multimedia:http://www.prnewswire.com/news-releases/2019-protiviti-and-shared-assessments-survey-finds-board-involvement-a-key-indicator-of-vendor-risk-management-maturity-most-organizations-will-drop-vendors-to-de-risk-300827875.html

SOURCE Protiviti

Older

Ely man accused of fleeing, stealing car after crash that injured woman

Advisor News

  • Gov. Kim Reynolds signs health insurance premium tax increase into law
  • Gov. Reynolds signs temporary tax hike to address Iowa Medicaid shortfall
  • Temporary tax hike to fill Medicaid gap heads to governor
  • Iowa Senate sends health insurer tax increase to governor’s desk
  • Temporary tax hike to fill Iowa Medicaid gap heads to governor’s desk
More Advisor News

Annuity News

  • Corebridge, Equitable merge to create potential new annuity sales king
  • LIMRA: Final retail annuity sales total $464.1 billion in 2025
  • How annuities can enhance retirement income for post-pension clients
  • We can help find a loved one’s life insurance policy
  • 2025: A record-breaking year for annuity sales via banks and BDs
More Annuity News

Health/Employee Benefits News

  • New Managed Care Study Results Reported from Yale University School of Medicine (Association of Social Determinants of Health with Utilization of SGLT2 Inhibitors and GLP1 Receptor Agonists: A Systematic Review and Meta-Analysis): Managed Care
  • How Federal Funding Cuts Will Cost 500,000 New Yorkers Their Health Insurance
  • Small business owners are state's backbone but obstacles to growth remain: DiNapoli
  • Providence Health Plan Trademark Application for “AVIDA HEALTH PLAN” Filed: Providence Health Plan
  • Data from Guangdong Medical University Broaden Understanding of Chronic Disease (Study on Quality Evaluation of Community Health Service of Patients with Multiple Chronic Diseases Based on Ratchet Effect: Taking Medical Insurance as a Moderator …): Disease Attributes – Chronic Disease
More Health/Employee Benefits News

Life Insurance News

  • Corebridge, Equitable Merger Creates $1.5tr Platfrom
  • AM Best Removes from Under Review with Positive Implications and Affirms Credit Ratings of Sompo Seguros Mexico S.A. de C.V.
  • Corebridge, Equitable merge to create potential new annuity sales king
  • Aflac adds new long-term care rider
  • AM Best Affirms Credit Ratings of Nan Shan General Insurance Co., Ltd.
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

Your Cap. Your Term. Locked.
Oceanview CapLock™. One locked cap. No annual re-declarations. Clear expectations from day one.

Ready to make your client presentations more engaging?
EnsightTM marketing stories, available with select Allianz Life Insurance Company of North America FIAs.

Unlock the Future of Index-Linked Solutions
Join industry leaders shaping next-gen index strategies, distribution, and innovation.

Press Releases

  • RFP #T01725
  • Insurate expands workers’ comp into: CA, FL, LA, NC, NJ, PA, VA
  • LifeSecure Insurance Company Announces Retirement of Brian Vestergaard, Additions to Executive Leadership
  • RFP #T02226
  • YourMedPlan Appoints Kevin Mercier as Executive Vice President of Business Development
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet