Vendor Due Diligence and Third-Party Risk Management Training Course

The Vendor Due Diligence and Third-Party Risk Management Training Course by Oxford Training Centre is designed to develop practical skills for identifying, assessing, and managing risks associated with vendors, suppliers, contractors, and other third parties. As part of the Legal, Contracts and Procurement Training Courses, this programme explores vendor due diligence and third-party risk, supplier screening, risk scoring, compliance verification, contractual controls, and ongoing monitoring. Participants will learn how to establish effective third-party risk management processes and make informed decisions when onboarding and managing external business relationships.

Objectives

By the end of this vendor due diligence and third-party risk course, participants will be able to:

  • Understand the principles of vendor due diligence and third-party risk management.
  • Identify financial, operational, legal, regulatory, reputational, and cybersecurity risks associated with third parties.
  • Develop effective supplier screening procedures.
  • Apply practical techniques for third-party risk identification and assessment.
  • Use risk scoring methodologies to classify vendors according to their risk profiles.
  • Conduct effective compliance verification and background checks.
  • Assess vendor ownership, financial stability, regulatory status, and business credentials.
  • Establish appropriate due diligence requirements based on vendor risk levels.
  • Develop contractual controls and risk mitigation measures.
  • Implement ongoing vendor monitoring and periodic reassessment.
  • Maintain appropriate documentation and audit trails for due diligence activities.
  • Improve the management of third-party relationships throughout the vendor lifecycle.

Target Audience

This course is suitable for:

  • Procurement and purchasing professionals
  • Vendor and supplier relationship managers
  • Contract managers and administrators
  • Compliance and risk professionals
  • Legal and corporate governance professionals
  • Internal auditors
  • Supply chain professionals
  • Third-party risk management specialists
  • Procurement managers and officers
  • Finance and commercial professionals
  • Business continuity and operational risk professionals
  • Professionals responsible for vendor onboarding and monitoring

Course Content

Module 1: Fundamentals of Vendor Due Diligence and Third-Party Risk

  • Principles of vendor due diligence
  • Understanding third-party risk
  • Vendor and supplier lifecycle management
  • Common third-party risk categories
  • Roles and responsibilities in vendor risk management

Module 2: Vendor Risk Identification and Assessment

  • Identifying inherent vendor risks
  • Financial and operational risk
  • Legal and contractual risk
  • Regulatory and compliance risk
  • Reputational risk
  • Cybersecurity and data protection considerations

Module 3: Supplier Screening and Background Checks

  • Developing effective supplier screening processes
  • Vendor identity and business verification
  • Ownership and beneficial ownership checks
  • Financial background assessment
  • Litigation and regulatory checks
  • Adverse media and reputational screening

Module 4: Third-Party Risk Scoring

  • Principles of vendor risk scoring
  • Developing risk assessment criteria
  • Risk categorisation and segmentation
  • High-, medium-, and low-risk vendor classification
  • Quantitative and qualitative risk factors
  • Applying risk scoring models

Module 5: Compliance Verification

  • Regulatory compliance requirements
  • Licences, certifications, and registrations
  • Sanctions and restricted-party screening
  • Anti-bribery and anti-corruption considerations
  • Data protection and privacy requirements
  • Conducting effective compliance verification

Module 6: Financial and Operational Due Diligence

  • Assessing vendor financial health
  • Credit and financial risk indicators
  • Business continuity capabilities
  • Operational capacity and resilience
  • Supply chain dependencies
  • Evaluating vendor performance and reliability

Module 7: Contractual Risk Controls

  • Incorporating due diligence requirements into contracts
  • Key vendor risk clauses
  • Compliance obligations and representations
  • Audit and inspection rights
  • Data protection and confidentiality provisions
  • Indemnities, insurance, and liability considerations
  • Termination and remediation provisions

Module 8: Third-Party Cybersecurity and Data Risks

  • Assessing vendor cybersecurity controls
  • Third-party access to systems and data
  • Information security requirements
  • Data privacy risks
  • Cybersecurity questionnaires and assessments
  • Incident notification and response obligations

Module 9: Ongoing Vendor Monitoring and Review

  • Continuous third-party risk monitoring
  • Periodic due diligence reviews
  • Vendor performance monitoring
  • Trigger events and risk reassessment
  • Managing changes in vendor ownership or operations
  • Maintaining accurate vendor risk records

Module 10: Third-Party Risk Mitigation and Governance

  • Developing vendor risk management frameworks
  • Risk treatment and mitigation strategies
  • Escalation and remediation processes
  • Governance and reporting structures
  • Internal controls and audit readiness
  • Measuring the effectiveness of third-party risk programmes

FAQs

1. What is vendor due diligence and third-party risk?

Vendor due diligence and third-party risk management involves assessing external suppliers and business partners to identify, evaluate, and mitigate financial, legal, operational, compliance, reputational, and other risks.

2. What will I learn about supplier screening?

You will learn how to establish structured supplier screening processes covering business credentials, ownership, financial information, regulatory records, reputation, and other relevant risk indicators.

3. How does risk scoring help with vendor management?

Risk scoring helps organisations classify vendors according to their risk exposure and determine the appropriate level of due diligence, monitoring, controls, and management oversight.

4. What is compliance verification in vendor due diligence?

Compliance verification involves checking whether vendors meet applicable legal, regulatory, contractual, licensing, certification, and internal compliance requirements.

5. Who should attend this vendor due diligence course?

The course is suitable for procurement professionals, contract managers, compliance officers, risk specialists, auditors, legal professionals, supply chain managers, and vendor relationship managers.

6. Does the course cover third-party risk assessment?

Yes. Participants learn how to identify and assess financial, operational, legal, regulatory, reputational, cybersecurity, and other risks associated with third-party relationships.

7. Does the course cover vendor contracts?

Yes. The programme examines contractual risk controls, compliance obligations, audit rights, data protection requirements, liability provisions, insurance, indemnities, and termination clauses.

8. Does the course include ongoing vendor monitoring?

Yes. The course covers continuous monitoring, periodic reassessment, performance reviews, trigger events, risk updates, remediation, and escalation processes.

9. How can organisations improve their vendor due diligence process?

Organisations can improve their process by using risk-based supplier screening, consistent risk scoring, thorough compliance verification, appropriate contractual controls, reliable documentation, and ongoing monitoring.

Course Dates

September 21, 2026
December 21, 2026
March 22, 2027
June 21, 2027

Register

Register Now