A successful vendor relationship begins well before the contract is signed.
Insurance companies depend on third parties for systems, data, financial reporting, claims processing, cybersecurity, professional services, and major implementation projects. But choosing a vendor is not simply a matter of comparing features, reviewing a SOC report, or selecting the strongest sales presentation. Organizations first need to understand what they need, how the vendor’s work will fit into their operations, and who will remain responsible for the decisions and results.
This course follows the vendor relationship from beginning to ongoing management. It explains how to prepare before approaching the market, evaluate vendor claims and demonstrations, negotiate practical contract protections, establish roles and decision authority, and manage the relationship with both trust and accountability.
Regulatory compliance, cybersecurity, data protection, SOC reports, and third-party controls are included as important parts of that process—not as substitutes for sound procurement, contracting, and relationship management.
By the end of this course, you will be able to:
Major vendor problems rarely begin with a single technical failure. They often begin much earlier—with incomplete requirements, misplaced trust, different assumptions, unrealistic estimates, weak contract terms, unclear authority, or a failure to address poor performance.
In an insurance environment, those problems can affect far more than the vendor relationship. They can produce project delays, budget overruns, inaccurate data, financial-reporting problems, cybersecurity exposure, operational disruption, and regulatory scrutiny.
This course helps organizations manage the entire relationship—not merely the compliance checklist. The goal is to choose vendors based on a clear understanding of what they can deliver, protect the organization through practical agreements and controls, and build working relationships in which trust and accountability operate together.
None. Designed for cross-functional teams working with third-party vendors.
A Basic, all-lines governance course within the Risk, Compliance & Regulatory Readiness track.
Complements MAR Compliance, Preparing IT for a DOI Exam, and ERM courses.
ERM Program Development 1
ERM 1 moves from managing third-party/vendor risk into the broader question of how an organization identifies risks, assigns ownership, and establishes governance.