Why should you attend?
CeFPro are pleased to announce the launch of our 9th Annual of Vendor and Third Party Risk Congress in New York City on June 5-6, 2024. Selling out yearly and highly anticipated, Vendor & Third Party Risk USA is the must-attend conference for TPRM professionals to expand their knowledge.
The agenda for 2024 has been re-vamped after much demand for increased focus on resilience and some of the regulatory changes that have increased the prominence of TPRM over the last year. The agenda features two streams, the first being the main event, the second a breakout on resilience, including a number of regulatory initiatives.
As an attendee you will gain insight from 40+ TPRM professionals as they delve into key challenges being faced within the industry through in-depth presentations and lively panel discussions.
Over 30 sessions across 2 interactive workstreams:
THIRD PARTY RISK MANAGEMENT
RESILIENCE
- TPRM
- Due Diligence
- Fourth Party Risk
- Vendor management capabilities
- Vendor Relationships
- Contract Management
- AI
- ERM
- Interagency Guidance
- Resilience
- Critical Relationships
- BCM
- Cyber Resilience
- Ransomware
- Technology
- Exit Planning
Interact with industry front-runners paving the way in third party risk
Industry leading interactive agenda spread across 2 days
With the demand of resilience within firms and from regulatory expectations CeFPro has revamped its previous events to include two interactive workstream’s focusing on third party risk management and resilience.
Gain in-depth knowledge from an extensive line up of subject matter experts
Be part of North America’s industry leading vendor and third party risk congress, where you will hear from 40+ industry professionals sharing their knowledge on top of mind challenges.
7+ hours of available networking opportunities
Continue conversations from inside the auditorium over coffee, lunch, and at our complimentary drinks reception. Make meaningful career-long industry connections to use to your professional advantage.
Key speakers for the 2024 Congress
Dolly Singh
MD, Global Head of Third Party Oversight
JPMorgan Chase
Tom Kartanowicz
Regional CISO, Europe and Americas
Standard Chartered Bank
Melissa Mellen
Head of Third Party risk Management
Federal Reserve Bank of New York
Scot Lynch
Executive Director
Morgan Stanley
Kristen Schneider
Director, Business Strategy and Planning
USAA
Kholofelo Mothibi
Head of TPRM
Corebridge Financial
David N. Braxton
SVP, Global Third Party Risk
Bank of America
Sri Intan
Head of Vendor Risk Management for North America
Commerzbank AG
Spruille Braden
Enterprise Head of Operational Resilience
Citi
Preety Tulsian
Head of Third-Party Risk US, Enterprise Risk
Scotiabank
Session previews and related insights
Get an insight of what to expect from the Congress with our past and present speaker session previews.
Beyond the scoring: Managing the third and fourth party attack surface
Beyond the scoring: Managing the third and fourth party attack surface Will Gray, Area Director Europe North, SecurityScorecard Below is an insight into what can be expected from Will's session at Vendor & Third Party Risk Europe. {{ vc_btn: title=Find+out+more+about+CeFPro%27s+Vendor+%26amp%3B+Third+Party+Risk+Europe+2024&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-europe%252F }} The views and opinions expressed in this article are those of the thought leader as an
Enhancing due diligence and assessment practices to obtain and develop actionable insights
Enhancing due diligence and assessment practices to obtain and develop actionable insights Codee Woo, Third Party Risk Management Lead, Legal & General Laura Faure, Third Party Risk Manager, Legal & General Below is an insight into what can be expected from Codee's session at Vendor & Third Party Risk Europe. {{ vc_btn: title=Find+out+more+about+CeFPro%27s+Vendor+%26amp%3B+Third+Party+Risk+Europe+2024&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-europe%252F }} The views and
Increasing collaboration across teams to monitor risk throughout the lifecycle
Increasing collaboration across teams to monitor risk throughout the lifecycle Simon Shepherd, Managing Director, MYRIAD Group Technologies Below is an insight into what can be expected from Simon's session at Vendor & Third Party Risk Europe. {{ vc_btn: title=Find+out+more+about+CeFPro%27s+Vendor+%26amp%3B+Third+Party+Risk+Europe+2024&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-europe%252F }} The views and opinions expressed in this article are those of the thought leader as an
The ever-changing role of third party risk management
The ever-changing role of third party risk management Branan Cooper, TPRM Consultant Below is an insight into the role of third party risk management, with a highlight into how the it has developed over the years. Discover more at Vendor & Third Party Risk USA. {{ vc_btn: title=Find+out+more+about+CeFPro%27s+Vendor+%26amp%3B+Third+Party+Risk+USA+2024&style=outline-custom&outline_custom_color=%23001c64&outline_custom_hover_background=%23001c64&outline_custom_hover_text=%23ffffff&link=url%3Ahttps%253A%252F%252Fwww.cefpro.com%252Fforthcoming-events%252Fvendor-third-party-risk-usa%252F }} The views and opinions expressed in
Take a look at what was said about last year’s event
Get an insight of what to expect from the Congress with our past and present speaker session previews.
I enjoyed this immensely, sharing the stage with many amazing thought leaders and industry practitioners to address the challenges and uncover opportunities to solve TPRM pain points… Lots of great dialogue and collaboration to move the industry forward!
Our team was able to attend the CeFPro TPRM USA: Cross Industry conference… The conversations were fantastic and the networking opportunities even better.
Great event discussing TPRM transformation and supply chain resiliency… Always great to learn from industry experts…
Would your organization like to partner with us on this event?
To discuss how we can deliver your thought-leadership at the event, help you generate leads, and provide you with unique networking and branding opportunities, please contact sales@cefpro.com or call us on +1 888 677 7007 for more information.
2024 Sponsors
Co-sponsors
Associate sponsors
Content and media partners
Agenda
8:00 – 8:50
Registration and breakfast
8:50 – 9:00
Chair’s opening remarks
9:00 – 9:45
REGULATION – PANEL DISCUSSION
Understanding and effectively managing multiple regulatory agendas and managing third party risk
View Session Details
- Overcoming and managing risk in a space with a heavy focus on compliance
- Reviewing the current regulatory expansion on third party risk
- Realigning procedures and policies to meet regulatory demands
- Fed requirements for increased governance on risk reporting
- Reviewing SEC proposal for conflict of interest in the third party risk space
- Basel committee consultation on outsourcing principles
- Managing the NYDFS cybersecurity regulation
- Finalization of FSB’s third party risk management toolkit
|
Melissa Mellen, Head of Third Party Risk Management, Federal Reserve Bank of New York |
|
Stuart Hoffman, Bank Examiner, OCC |
|
Babette Reynolds, Compliance Senior Director, Head of Enterprise Compliance Program Office, Truist |
9:45-10:20
THIRD PARTY RISK MANAGEMENT
Reviewing how to develop current third party risk programs to enhance maturity and risk mitigation
View Session Details
- Understanding the interconnectedness of third parties used
- Leveraging risk intelligence to effectively manage third party risk
- Reviewing enhanced monitoring requirements of third parties
- Ensuring effective oversight of third parties
- Enhanced expectations of a third party deemed critical at the system level
- Improving value proposition in third party risk programs
- Responsibility of reporting risks found in the program
10:20-10:50
Morning refreshment break and networking
TPRM
10:50-11:35
FOURTH PARTY RISK – PANEL DISCUSSION
Developing capabilities to monitor and review the increased risk across fourth parties
View Session Details
- Expanding programs to include fourth, fifth and nth parties
- Ensuring a sufficient inventory list of your fourth parties
- Assurance of fourth parties through tools and third parties
- Advancing policies and procedures around fourth parties
- Utilizing data gathered from fourth parties
- Assessing vulnerabilities of fourth parties
- Enforcing controls with a fourth party
|
Madiha Fatima, Executive Director, JP Morgan |
|
Kholofelo Mothibi, Head of TPRM, Corebridge Financial |
|
David N. Braxton, SVP, Global Third Party Risk, Bank of America |
RESILIENCE
10:50-11:35
BCM – PANEL DISCUSSION
Collaborating with third parties to ensure business continuity and stability across the supply chain
View Session Details
- Effectively reviewing third party business continuity controls
- Integration of business continuity plans between the client and third parties
- Importance of an effective business continuity plan on supply chains
- Challenges of fully integrating continuity between different systems
- Importance of a fully integrated business continuity playbook
- Purpose of sharing access to individual networks
|
Spruille Braden, Enterprise Head of Operational Resilience, Citi |
|
Olga Voytenko, Managing Director, Head of Operational Resilience, |
|
Brett Turk, Global Head of Business Continuity and Crisis Management, Vangaurd |
|
Industry Expert, Fusion Risk Management |
11:35-12:10
TPRM IN AN UNSTABLE WORLD
Assessing the results of Aravo’s third party risk maturity survey and report
View Session Details
- Review overall survey results and what they mean for the industry
- Determine the current maturity of TPRM programs in the marketplace and why it may be a concern
- Identifying critical elements for maturing and enhancing TPRM programs
- Understanding the strategic value of investing in a competent, adaptable, and resilient TPRM progran
- Examining how leadership defines performance, priorities, and next steps
- Assessing the measurability and impact of mature TPRM programs on the business
|
Loren Johnson, Director of Product Marketing, Aravo |
11:35-12:10
INCIDENT MANAGEMENT
Developing effective response plans to manage incidents from vendors under attack
View Session Details
- Ensuring better understanding around a vendors incident response
- Reviewing incidents to potentially identify vulnerabilities
- Joint testing incident management with vendors
- Keeping up with the pace of incidents
- Demand for more timely updates on incidents
- Reviewing the increase of incidents due to cyber activity
12:10 – 12:45
TPRM STRATEGY
Strategically positioning third party risk programs to align with strategic goals
View Session Details
- Understanding long term risks failure to align strategic goals with outsourcing
- Importance of aligning goals with risk appetite when outsourcing
- Correlation between aligning goals when outsourcing with a firm’s maturity
- Managing a lack of maturity in programs to align strategic goals
- Reducing unnecessary outsourcing
- Neglection of planning outsourcing from firms and its impacts
- Effective due diligence in planning and selecting a correct vendor
|
Jeffrey Wheatman, Cyber Risk Evangelist, BlackKite |
12:10-12:45
INTERAGENCY GUIDANCE – JOINT PRESENTATION
Leveraging interagency guidance as a framework to effectively set up and manage third party risk management programs
View Session Details
- Alignment and clear understanding of guidelines
- Increased continuous monitoring requirements
- Understanding the broader definition of a third party
- Increased board oversight on critical relationships
- Impact of guidance on smaller-mid-sized firms
- Preparing for implementation deadline of inter-agency guidance
- Impacted of guidance on current third party risk programs
|
Tausif Khan, Director, Third Party Risk, DTCC |
|
Kristin L. Ciridon, Head of Third Party Risk, DTCC |
12:45-1:45
Lunch break and networking
1:45-2:20
VENDOR MANAGEMENT CAPABILITIES
Reviewing the evolution of vendor management: Understanding what it takes for firms to be “brilliant at the basics”
View Session Details
- Ensuring clear alignment and understanding of what “good vendor management” looks like
- Importance of winning trusted advisor status with stakeholders
- Overcoming the challenges when building a relationship vendor management team
- Skills, mindset and culture
- Investing in process and platforms to ensure performance goals are achieved
- Understanding the importance of balancing supplier risk vs. supplier commercials
|
Naveen Balakrishnan, Head of Third Party Risk Management, |
1:45-2:20
CRITICAL RELATIONSHIPS
Assessing the maturity of third parties and updating processes for effective oversight of critical relationships
View Session Details
- Assessing a firms resilience when outsourcing to critical third party relationships
- Addressing the influence the UK critical third party regimes will have on US firms
- Determining the definition of a critical third party
- Enhancing operating models to better manage critical relationships
- Overcoming difficulties of identifying critical third parties
- Critical relationship approval requirements from the board
|
Donovan Tanner, Third Party Industry Expert |
2:20-3:05
VENDOR RELATIONSHIPS – PANEL DISCUSSION
Managing and monitoring third party relationships in line with policy requirements and contractual agreements
View Session Details
- Expanding focus and control to better manage non-traditional contracted vendors
- Identifying and mitigating risks beyond traditional contracted vendors
- Adaptation of relationship management as outsourcing increases
- Importance of relationship manager monitoring changes to a third party
- Challenges of actively managing complex vendor relationships
- Developing a managed service model to improve vendor relationships
- Increased credible challenges on issues identified
|
Thomas Brandt, Chief Risk Officer / Director, Office of Planning and Risk, Federal Retirement Thrift and Investment Board |
|
Charmi Patel, VP, Vendor Risk Management, Israel Discount Bank of New York |
|
Chelsea Tieken, Business Strategy and Planning Director, TPRM Strategy and Initiatives, USAA |
|
Andrew Moyad, Chief Executive Officer, Shared Assessments |
2:20-3:05
SUPPLY CHAIN – PANEL DISCUSSION
Assessing and mitigating the risks of upcoming supply chain crisis
View Session Details
- Interconnected nature of third parties impact on supply chain
- Formulation of principles around supply chain at the global and jurisdictional level
- Understanding the impact geopolitical risk has on supply chains
- Effectively managing cybersecurity risk across the supply chain
- Applying a proportionate risk based approach to supply chain risk management
- Difficulties with subcontracting supply chain risk management
- Introduction of supply chain consultation in June 2024
- Mitigating strategies to ensure operational resilience in your supply chain
- Importance of nearshoring to avoid supply chain risks
|
Penny Cagan, former Managing Director, Americas Head of Operational Risk, UBS |
|
Carl Miller, Head of Change Management & Third Party Management, |
3:05-3:40
CONTRACT MANAGEMENT
Monitoring contracts to ensure adherence to and maintenance of terms
View Session Details
- Ensure all parties within a contract comply with contract terms
- Amending agreements to ensure ‘right to ask’ for certain information
- Demand for increased assessments on contract terms
- Enforcing contractual agreements on your third parties to disclose required information
- Business continuity and information security of contract management
- Difficulty with managing scale of terms and conditions in a contract
|
James McPherson, Director & Counsel, Credit Agricole |
3:05-3:40
RESILIENCE
Incorporating additional testing expectations on operational resilience
View Session Details
- Ensuring contracts are effective and supportive of resilience
- Aligning contract resilience between firm and vendor
- Ensuring resilience of vendors can withstand a stress event
- Testing resilience with vendors to and ensure capabilities are met
- Developing and creating new testing programs on firm and vendor side
- Use of resilience testing to address supplier vulnerabilities
- Relationship between operational resilience and third party risk management
|
Spruille Braden, Enterprise Head of Operational Resilience, Citi |
3:40-4:10
Afternoon refreshment break and networking
4:10-4:45
STRATEGIC RISK
Reviewing evolving third party risk management to effectively address strategic risks
View Session Details
- Identifying the impact of emerging strategic risks for third party risk management
- Geopolitical, cloud concentration, resilience, data protection
- Understanding the disruption and delays of strategic risk on third party risk management
- Importance of approaching strategic risks holistically
- Establishing risk appetite for strategic risks taking
- Overcoming a lack of clarity around outsourcing trade offs
|
Stefan Smith, Director, Enterprise Risk Office and Head of Third Party Risk, |
4:10-4:45
GEOLOCATION
Leveraging vendors in different jurisdictions and offshoring to mitigate the impact of unforeseen risks
View Session Details
- Effective support from vendors in different geolocations
- Reviewing business continuity of locations used for outsourcing
- Monitoring locations where critical vendors are based
- Lack of data to determine where third parties are located
- Impact of outsourcing to a vendor with geolocational risks e.g. hurricanes, floods
- Assessing the impact of geolocation challenges on supply chain
- Importance of sharing vendor geolocation data with other arms of the firm
4:45-5:20
ERM
Reviewing how vendor risk is being integrated to observe at the enterprise level
View Session Details
- Importance and benefits of viewing third party risk across the business
- Ensuring organizations holistically understand TPRM goals
- Introducing a holistic model for risk teams to develop management of all risks
- Reviewing how third party information can support other areas of the business
- Scaling outsourcing to the enterprise level
- Case study of effective integration
|
Preety Tulsian, Head of Third Party Risk US, Enterprise Risk, Scotiabank |
4:45-5:20
TECHNOLOGY
Reviewing the technology landscape and its impact on the resilience of third party risk
View Session Details
- Managing enhanced technology requirements requiring more timely and transparent reporting
- Exploring new technologies to improve efficiencies
- Timeliness of notification of technology subcontractors in the supply chain
- Increased concern of technology outsourcing longer chains and widely spread risks
- Data challenges of using vendor technology
- Pushback from technology suppliers on what data they are willing to share
|
Scot Lynch, Executive Director, Morgan Stanley |
5:20-5:30
Chair’s closing remarks
5:30
End of day one and networking drinks reception
8:00 – 8:50
Registration and breakfast
8:50 – 9:00
Chair’s opening remarks
9:00 – 9:45
GEOPOLITICAL – PANEL DISCUSSION
Assessing the impact of global volatility on third parties and managing uncertainty
View Session Details
- Understanding how geopolitical risks are impacting global and regional supply chains
- Carrying out geopolitical analysis on where your third parties are centered
- Assessing why geopolitical risk have been overlooked by firms
- Impact of geopolitical conflicts on vendor services provided
- Anticipating how future geopolitical crisis can impact your firm
- Reviewing the impact of the 2024 US election result on vendor and TPRM programs
- Mitigating the impact of increased geopolitical risks
|
Kristen Schneider, Director, Business Strategy and Planning, USAA |
|
Nita Kohli, Board Advisor & former Global Head of Enterprise Resilience, Citi |
|
Roger Parsley, MD, Global Head of Technology and Cybersecurity Risk Governance, State Street |
9:45-10:20
AI USE
Reviewing practical uses of generative AI to further advance third party risk teams
View Session Details
- Leveraging efficiencies of AI to enhance internal processes
- Ensuring workforce in place can understand AI and how to assess it
- Providing AI services and support to clients and customers
- Generative AI use through third party risk programs
- Data gathering on third parties
- Ensuring AI understands risk appetite and tolerances
- Policy and procedure alignment with the use of AI
- Effectively assessing AI data sets
- Partnering with vendors to enhance AI use in industry
10:20-10:50
Morning refreshment break and networking
TPRM
|
Nicholas Kula, Global TPRM and Resilience Leader, Archer |
10:50-11:35
AI EXTERNAL – PANEL DISCUSSION
Reviewing the evolving AI landscape and oversight of use of AI by third parties
View Session Details
- Reviewing the evolving AI landscape and use of AI by third parties
- Importance and difficulties with validating AI use by vendors
- Data privacy concerns with the use of AI by third parties
- Ensuring governance on AI use by third parties and vendors
- Effectively integrating AI into the vendor risk management process
- Monitoring the use of AI across the supply chain
- Anticipating laws and legislation on the horizon
- Ensuring solutions meet with policies and risk tolerances
|
Dolly Singh, MD, Global Head of Third Party Oversight, |
|
Sonia Jarvis, Director, Quantitative Modeling, Fannie Mae |
|
Sri Intan, Head of Vendor Risk Management for North America, |
RESILIENCE
10:50-11:35
EXIT PLANNING – PANEL DISCUSSION
Enhancing exit strategies in the event of planned and unplanned exits
View Session Details
- Ensuring effective design of an exit strategy
- Understanding the importance of developing exit strategies
- Incorporating geopolitical conflicts into exit strategies
- Assessing business continuity of third parties when exit planning
- Effectively aligning risk appetite when exit planning
- Determining stress points of an exit plan
|
Rick Cech, Senior Bank Manager, Federal Reserve Bank |
|
David LaFalce, SVP & Global Head of Operational Resilience, |
|
Jeannie Pumphrey, Head of Third Party Risk and Change Management, MUFG |
11:35-12:10
DATA
Monitoring and tracking accessibility and access to data across third parties
View Session Details
- Overcoming the challenges of external data use
- Adhering to varying data requirements in different jurisdictions
- Improving use of data provided by vendors
- Ensuring data compliance with CIPRA
- Accessibility and security of data to third parties and vendors
- Reviewing rapid evolution and increased sophistication of ratings service providers
11:35-12:10
CONCENTRATION RISK
Mitigating the varying types of concentration risks a firm can face
View Session Details
- Assessing the risk of concentration with current vendors and third parties
- Leveraging vendor concentration to manage multiple risk types
- Effective reporting around concentration risk
- Data requirements to understand and identify concentration risks
- Correlation between concentration and geopolitical risk
- Impact of conflict risk on your vendor concentration
12:10-1:10
Lunch break and networking
1:10-1:55
ESG – PANEL DISCUSSION
Assessing the current ESG landscape and understanding what it means for vendors and third party risk programs
View Session Details
- Addressing a lack of legislation and guidance on ESG
- Restriction ESG is putting on outsourcing activities
- Impact of ESG in the context of responsible supply chain
- Balancing level of protection and service whilst ensuring supplier diversity
- Identifying verifiable data points
|
Javier Ortiz, Principal Technical Leader, Non-Financial Risk, Inter-American Development Bank |
|
Leidy Anderson, Third-Party Risk Director, Western Alliance Bancorporation |
|
Ken Wolckenhauer, Head of Vendor Risk, Nordea Bank |
1:10-1:55
CYBER RESILIENCE – PANEL DISCUSSION
Effectively monitoring cyber threats across the supply chain to drive resilience
View Session Details
- Assessing if providers are effectively protecting confidential information against cyber attacks
- Obtaining timely and accurate security information from third party vendors
- Importance of continuous monitoring of cyber risks
- Managing cyber security stresses across third parties
- Importance of data use to combat cyber attacks
- Ensuring cybersecurity resilience
- Benefits on partnering with vendors and sharing technologies
- Impact of SEC guidance on CISO’s
|
Tom Kartanowicz, CISO, Europe and Americas, Standard Chartered Bank |
|
Mahi Dontamsetti, EVP, Global Head of Non Financial Risk & CTRO, State Street |
|
Marta Palanques, Director, Methodologies and Practices, Technology Risk Management, Capital One |
1:55-2:30
DUE DILLIGENCE
Utilizing due diligence assessments as a tool to better understand and manage risk
View Session Details
- Defining a standard of effective due diligence on firms
- Moving away from a ‘one size fits all’ approach
- Wider regulatory expectation when carrying out due diligence
- Importance of timely information when conducting due diligence
- Leveraging AI to better carry out due diligence
- Overcoming lack of cooperation to obtain data
- Raised due diligence concern with increased technology outsourcing
- Focusing on inherent risks of vendors when carrying out due diligence
|
Brennan Lodge, Head of Analytics Engines, Cybersecurity, HSBC |
1:55-2:30
RANSOMWARE
Managing the increased risk of ransomware breaches and vulnerabilities firms are facing
View Session Details
- Protection against ransomware attacks in a technologically enhanced environment
- Keeping ahead of sophisticated ransomware attacks
- Ensuring data is secure and protected against ransomware attacks
- Understanding how ransomware attacks can impact your supply chain
- Mitigating vulnerabilities to protect against ransomware
- Importance of understanding if you have been impacted by a ransomware attack
- Impact, escalation channels, mitigation plan, disconnect and reconnect timelines
|
Fabian De Jesus, Director, Information Security Officer, Capital One |
2:30-3:05
FINTECH
Managing the opportunity and balancing the risk of leveraging fintech’s as a third party
View Session Details
- Working with organizations with less developed controls
- Assessing the opportunities of enhanced controls and security on a fintech
- Ensuring fintechs meet the standard of traditional third parties
- Improved guidance to understand what regulations must be adhered to
- Ensuring policies and procedures extend to fintechs as third party vendors
- Mitigating an increased risk exposure to cybersecurity attacks
|
Firas Mustapha, Senior Director of Compliance, Arvest Bank tbc |
2:30-3:05
CONTINUOUS MONITORING
Importance of continuous monitoring to move beyond point in time assessments
View Session Details
- Assessing best practice within the industry
- Ensuring data quality and availability for continuous monitoring tools
- Leveraging to better identify vulnerabilities in vendor data
- Extracting value from continuous monitoring
- Comparing effectiveness of continuous monitoring with due diligence
- Use of continuous monitoring to identify threat intelligence
|
Patricia Catharino, Head of Risk Management & Internal Controls, U.S. and Caribbean, SVP, Banco Itau International |
3:05-3:35
Afternoon refreshment break
3:35-4:10
THE BOARD
Enhancing board reporting and defining information required to communicate risk
View Session Details
- Regulatory influence on how firms report to the board
- Leveraging due diligence to better report to the board
- Assessing what risks are considered a board level concern
- Reporting residual risk from vendors to the board
- Efficiently reporting important information to ensure the board can make strategic decisions
- Difficulty of creating processes around board approvals
|
Karina Volvovsky, Senior Vice President, Business Control Officer for Entertainment, City National Bank |
4:10-4:45
CLOUD
Overcoming the complexity of cloud computing and the concentration of providers
View Session Details
- Ensuring compliance with vendors operating under Europe’s DORA Act
- Assessing how implementation of DORA in Europe will impact US firms
- Reviewing implementation requirements
- Overcoming additional governance and document requirements
- Alignment with other regulatory initiatives
4:45-4:55
Chair’s closing remarks
4:55
End of Vendor and Third Party Risk Management USA 2024 Congress
Speakers
Leidy Anderson
Third-Party Risk Director
Western Alliance Bancorporation
Leidy Anderson
With over 15 years of experience in financial services, I’ve had the privilege of serving in various capacities at four major financial institutions, primarily focusing on the second line of defense since 2014. My expertise lies in enterprise risk management (ERM), operational risk, and third-party risk management. I hold the CTPRP certification. I have a genuine passion for environmental, social, and governance (ESG) initiatives and business continuity, which is deeply rooted in personal experiences. Coming from Colombia, I’ve witnessed the adverse effects of coal mining on the native population of my family’s hometown, Barrancas Guajira. These experiences have humbly inspired me to champion stronger governance practices for the well-being of communities and businesses alike.
Naveen Balakrishnan
Head of Third Party Risk Management
TD Bank
Naveen Balakrishnan
Naveen Balakrishnan is currently Head of Third Party Management at TD. In his current role, Naveen is responsible for managing the commercial relationship and risk management of TD’s global supply chain.
Previously he has held several leadership roles at TD Securities helping drive product and technology strategies for the Global Markets and Investment Banking lines of businesses.
Prior to joining TD, Naveen has held senior roles at BMO Capital Markets supporting the CEO and COO with strategy development and transformation.
Naveen holds an Honours BComm from the University of Toronto, an MBA from Wilfrid Laurier University and is a Certified Professional Accountant.
Additionally, Naveen is a long-standing community builder with strong ties to non-profit organizations focused on child welfare and education and he is currently serving as a Board of Director with Education Bank, Toronto District School Board, Laurier University and University of Toronto, Scarborough.
Spruille Braden
Enterprise Head of Operational Resilience
Citi
Spruille Braden
Spruille Braden is a seasoned profession in the Financial Services industry with subject matter expertise in many critical functions at top tier banks. Spruille is the Enterprise Head of Operational Resilience at Citi. Prior to Citi, he was the Head of Operational Resilience at Sumitomo Mitsui Banking Corporation (SMBC) where led the development and implementation of the function at the firm.
Prior to SMBC, Spruille spend nearly 15 years at UBS where he held several roles that spanned all three lines of defense. Notably, Spruille was the Americas Head of Business Continuity Management (BCM) at UBS for 6 years where he led a team of Risk professionals tasked with ensuring the resiliency of their Americas-based operations. As a member of the COO Group, he drove strategic programs and initiatives that often spanned multiple competency areas. He helped develop the Operational Resilience program that encompassed Business, Cyber, Technology and Third Party Risk Management strategies in accordance with internal and external drivers. Spruille was a co-chair for SIFMA’s “Resilience Forum” where he helped shape responses to regulatory guidance through the collaborative peer industry group.
Spruille lives in Connecticut with his wife Jamie and three daughters Emma, Elodie and Hailey (ages 11, 8 and 8, respectively).
Thomas Brandt
Chief Risk Officer / Director, Office of Planning and Risk
Federal Retirement Thrift and Investment Board
Thomas Brandt
Tom Brandt is a risk management practitioner in the federal government. With nearly three decades of federal service, he is currently the Chief Risk Officer (CRO) and Director of Planning and Risk for the Federal Retirement Thrift Investment Board. He previously served as CRO for the IRS. He is a fellow with the National Academy of Public Administration, a past president of the Association for Federal Enterprise Risk Management (AFERM), and also served as chair of the OECD Forum on Tax Administration’s ERM Community of Interest from 2018–2021.
David N. Braxton
SVP, Global Third Party Risk
Bank of America
David N. Braxton
David Braxton leads a Global Third-Party Program Risk Management team at Bank of America (BofA) supporting the Global Operations business segment, and he reports to the bank’s Chief Procurement Officer (CPO). He is responsible for leading a team that design and execute third-party risk management strategies, optimize third-party services and initiatives, and facilitate robust third- party risk mitigation activities aimed at managing over $2.5 Billion in annual third party spend. As a thir- party program leader, he recruits and develops sourcing and third-party management professionals to apply skills and competencies required to meet business requirements and expectations while mitigating third-party risk to the bank. David is a subject matter expert for the bank as it relates to the implementation and management of third-party outsourcing and offshoring solutions as well as other large enterprise strategic third-party relationships.
Prior to joining Bank of America, David’s was a Strategic Sourcing Executive at SunTrust Banks, Inc. (now Truist) reporting directly to the Chief Procurement Officer. His team was accountable for governing third party risk while sourcing services related to more than $2 billion in annual third party spend. David managed teams that supported strategic sourcing for the bank’s Information Technology (IT) segment to include offshore contingent workers, Consumer and Small Business Banking, Mortgage Line of Business, Loan & Credit Card Processing, Branch Banking, Capital Markets, Wealth/Investment Processing, and Business Process Outsourcing (BPO).
Additionally, David has work experience with three (3) additional Fortune 500 companies. He was Vice President of Customer Service & Corporate Sales at Toys “R” Us, Inc. where he managed a multi-channel Global Customer Service Delivery infrastructure and the Commercial Stored Value Card (Gift Cards) Sales & Marketing Program. He managed an internal and external staff of over 700 during the crucial holiday season peak period. David was also a Vice President at American Express where he managed an internal staff of over 2,500 across North America delivering on the all important American Express customer experience. Lastly, as Regional Call Center Sales Director for Verizon, David managed and led the consolidation of four (4) operation centers staffed by more than 2,500 union affiliated employees. David served in the US Army as an military officer. He served his country in Afghanistan and is a Bronze Star recipient resulting from his successful service in a combat zone.
David holds a PhD from Northcentral University, MBA from Wake Forest University, Master’s in Management from Fayetteville State University, and an undergraduate degree in Business from South Carolina State University.
Penny Cagan
former Managing Director, Americas Head of Operational Risk
UBS
Penny Cagan
Penny Cagan is an experienced risk professional with a career that has spanned Operational Risk, Compliance, Consulting, Research and Risk Technology. She is considered a pioneer in the field of Operational Risk Management and has received industry recognition, including achievement awards for her service to the risk management field.
Penny most recently served as Managing Director and Head of Operational Risk for UBS Americas, where she was responsible for managing the operational risk and control environment in the region. Penny previously served as Head of Operational Risk Governance at MUFG Americas, where she was responsible for overseeing the bank’s operational risks in the region. She has also worked as a consultant at Ernst and Young where she led a variety of projects in the risk and compliance disciplines, she served in a global Operational Risk senior oversight role at JPMorgan Chase and founded a Compliance Analytics team at Citigroup.
Penny is an adjunct professor at Columbia University and teaches in its Enterprise Risk Management Master’s program, where she is dedicated to nurturing the next generation of risk leaders.
Patricia Catharino
Head of Risk Management & Internal Controls, U.S. and Caribbean, SVP
Banco Itau International
Patricia Catharino
Patricia has over 25 years of Corporate Level experience in the Legal, Auditing, Risk and Compliance departments. Patricia began her career working as a Lawyer and Auditor for Serv Cadastro e Cobranca Ltda responsible for legal coordination and implementing internal auditing in its departments in Brazil. She joined Itaύ Unibanco in 2000 starting in Audit and moving to areas such as Compliance and Internal Controls. Patricia has led teams and implemented new methodologies to mitigate risk and increase innovation and efficiency. In 2014, Patricia began her International experience with Itaύworking with Itaύ Caribbean and Miami responsible for the Internal Controls department. In 2017, Patricia became the Head of Risk and Internal Controls for Itaύ U.S overseeing Financial & Operational Risk and Internal Controls, working with several jurisdictions as USA, Bahamas, Cayman Islands, Chile and Mexico. In 2021, Fiduciary Risk in Asset Management was included in her activities, as well as oversight of Client Risk. In 2023, she was nominated Chief Compliance Officer for Nassau Branch.
Following her graduation with a Law Degree from the Universidade Estadual de Londrina, Patricia obtained a Corporate and Economic Law Post graduation Degree from Fundacao Getulio Vargas in SP. In addition, Patricia attained an LLM in Financial and Capital Markets Law from IBMEC/Insper, and an LLM in Corporate Law. Patricia is also a Certified Internal Auditor (CIA) and a Certified Control Self Assessment (CCSA).
Rick Cech
Senior Bank Manager
Federal Reserve Bank of New York
Rick Cech
Rick is a Senior Bank Examiner at the Federal Reserve Bank of New York in Operational Risk Supervision, a member of the LISCC (Large Institution Supervisory Coordinating Committee) group. He received a B.A. (Economics) and M.A. (Organizational Behavior) from Yale University. Rick was a member of J.P. Morgan’s original operational risk development team in the late 1990s, specializing in loss event data group. He was involved in early industry initiatives to define standard taxonomy for operational risk, and later consulted on risk framework development. Today, Rick supervises operational risk and governance practices at complex financial institutions.
Kristin L. Ciridon
Head of Third Party Risk
DTCC
Kristin L. Ciridon
Biography coming soon
Mahi Dontamsetti
EVP, Global Head of Non Financial Risk & CTRO
State Street
Mahi Dontamsetti
Mahi Dontamsetti is executive vice president and global head of Non-Financial Risk and Chief Technology Risk Officer (CTRO) at State Street. He is responsible for oversight of non-financial risk (i.e., technology, cyber, operational, resilience and third-party risk) for the enterprise. Part of his responsibilities include owning the board level risk appetites, risk and reporting frameworks as well as driving risk remediation prioritization, across the firm, ultimately improving our global risk posture. He is a key regulatory partner and sits on numerous risk committees including the Technology & Operations Committee (TORC) and the Technology and Operations Board Committee. Mahi is a champion of inclusion and diversity and participates in our mentorship program.
Mahi has over 25 years of experience in intrapreneurial and entrepreneurial roles, across a range of industries including banking, financial services, defense, telco and mobile/data in both Fortune 500 firms and startups. Prior to State Street, he held executive leadership positions at DTCC, Barclays, Lockheed Martin and various startups. He has spent his career focused on building enterprise-wide programs that focus on execution excellence, driven by innovation and fiscal discipline, that have won several awards and have been recognized as best-in-class amongst peer firms.
Mahi is the author of three books on risk and technology. He also served on the board of advisors for the Center for Satellite and Hybrid Communication Networks, NASA Commercial Space Center Venture and OWASP, the world’s largest non-profit dedicated to software security.
Mahi has a Master of Science degree in computer science and telecommunications from University of Missouri-Kansas City and a Bachelor of Science in mechanical engineering from India. Currently, Mahi serves on the Board of Trustees of two charities.
Fabian De Jesus
Director, Information Security Officer
Capital One
Fabian De Jesus
Technology and Cyber executive, Certified Information Systems Security Professional (CISSP), Cloud Certified Security Practitioner (CCSP) with over 20 years of experience. A trusted advisor with a reputation for understanding business goals and delivering innovative organizational and client solutions.
Madiha Fatima
Executive Director
JP Morgan
Madiha Fatima
Madiha Fatima is an Executive Director – Operational and Outsourcing Risk Management at JP Morgan, where she leads the second line of defense function for operational and outsourcing risk overseeing Third Party Risk Management, Sourcing, Procurement and Inter-Affiliate Management. Previously, Madiha was the Head of Third Party Risk Management Department at Angelo Gordon where she was responsible for development of Third Party Risk Management Framework while enabling businesses to achieve their strategic objectives from utilizing vendors. Prior to joining Angelo Gordon, Madiha Fatima served as the Third Party Risk Governance & Oversight Lead at DTCC. Madiha is a Certified Third Party Risk Professional (CTPRP). Madiha earned a Bachelors of Science degree in Financial and Capital Markets from Rutgers Business School.
Stuart Hoffman
Bank Examiner
OCC
Stuart Hoffman
Stuart is a Policy Analyst with the OCC’s Bank Supervision Policy division, specializing in governance and operational risk policy. He is also a Bank Information Technology examiner, specializing in cybersecurity and information technology risk / information security. He supports international efforts as the OCC’s interim representative to the Basel Committee on Banking Supervision (BCBS) Operational Resilience Group. Stuart joined the OCC as an industry hire in June of 2013. Prior to joining the OCC, Stuart held IT risk management related positions at Citigroup, Cisco, and GE. His career also includes management consulting experience at Deloitte. He has substantial experience in regulatory examinations, technology audits, IT certification efforts, and cross-border initiatives from both the regulatory and business perspectives. Stuart completed his BA and MBA at NYU and holds several industry-recognized credentials, including the CISA, CISSP, and CRISC.
Sri Intan
Head of Vendor Risk Management for North America
Commerzbank AG
Sri Intan
Sri leads the Vendor Risk Management Program for North America at Commerzbank where she is responsible for establishing and overseeing an appropriate and effective vendor risk management in the region. Her previous experiences include managing global change management efforts for Citigroup’s Third Party Management Program and leading various business intelligence & analytics solution efforts.
Sonia Jarvis
Director, Quantitative Modeling
Fannie Mae
Sonia Jarvis
Sonia Jarvis leads model validation of third-party products at Fannie Mae. Previously, Sonia led model validation teams for commercial risk scoring and PPNR at Bank of America. She also represented the Board of Governors of the Federal Reserve System at the Basel Working Group on Operational Risk and assessed bank performance as an examiner for the Office of the Comptroller of the Currency. Sonia has diverse consulting and model development experience in commercial and non-profit applications, including fraud detection, law enforcement, market research, human resources, and natural resource management. Sonia holds a Ph.D. in Natural Resource Economics from the University of Maryland.
Loren Johnson
Director of Product Marketing
Aravo
Loren Johnson
Loren Johnson leads Aravo’s product marketing function, covering how Aravo builds, markets, and sells its market-leading third-party risk management solution. Driven by a passion for innovation and solving business challenges, Loren brings an international business perspective and desire to deliver measurable customer success. Loren is a long-term TPRM advocate with an MBA in International Management from Thunderbird, and more than 30 years working in the technology sector. With eight years in the GRC market, Loren brings enthusiasm and an informed perspective to his work with Aravo.
Tom Kartanowicz
CISO, Europe and Americas
Standard Chartered Bank
Tom Kartanowicz
Tom Kartanowicz has been working in IT and information security for over 20 years with experience in cyber risk management, regulatory compliance, systems administration, network security and security awareness. As CISO for SCB Europe and Americas, Tom leads the information security function across ten markets and previously worked at Commerzbank and Natixis North America. Tom has also lectured in IT Risk at Columbia University.
Tom holds a Master of Science in IT from the University of Maryland and a Bachelor of Arts in Computer Science from New York University. He is a member of ISSA, ISC2 and ISACA. Tom has appeared as a panelist at the NYIT Global Cybersecurity Conference, OpRisk North America, Gartner, Columbia University and other
Tausif Khan
Director, Third Party Risk
DTCC
Tausif Khan
Tausif leads the Third Party Risk Governance and Reporting group of DTCC. He is responsible for managing the Third Party Risk Management framework and lifecycle specifically focusing on Critical Third Parties, firmwide awareness of responsibilities, due diligence of 4th/nth parties, governance for monitoring and oversight, and regulatory responses. Tausif holds a BS in Finance from the University of South Florida and is currently pursuing his MS in Cybersecurity from Virginia Tech.
Nita Kohli
Board Advisor & former Global Head of Enterprise Resilience
Citi
Nita Kohli
Nita Kohli is an accomplished Operational Resilience Executive with over 25 years of distinguished service in the financial services sector. Renowned for her strategic acumen, she most recently served as the Global Head of Enterprise Resilience at Citi, driving a transformative shift to fortify safety and stability. Her expertise spans pivotal roles, including steering Freddie Mac through the pandemic and navigating multiple crisis events over the past decade.
In addition to her executive roles, Nita actively contributes to the risk management landscape, serving on the Executive Advisory Board of a risk management company and lending her expertise as a strategic advisor to FinTechs.
Recognized as an authoritative voice in Operational Resilience, Nita is a sought-after keynote speaker and panelist at industry conferences. Nita’s exceptional leadership, Nita was honored as one of the Top 50 Outstanding Asian Americans in Business in 2022.
Currently engaged in authoring a comprehensive book on Operational Resilience, slated for publication in early 2024, Nita continues to spearhead pioneering endeavors in the financial sector.
Nicholas Kula
Global TPRM and Resilience Leader
Archer
Nicholas Kula
Nicholas Kula is a TPRM and Resilience subject matter leader. He has over 20 years of risk and cybersecurity professional experience – most recently in the business consulting practice of Ernst & Young LLP and prior almost fifteen years with Protiviti, Inc. He has a background in developing, selling, and delivering technology and services in several areas including supplier risk /management, cyber security /data protection, technology enablement and user experience, regulatory compliance, process development, and organizational governance and program maturity. Nicholas has primarily worked within the financial services, insurance, and healthcare industries but has experience across all sectors.
Nick lives in Bloomfield Hills, MI with his wife Justine and their three children – Cecilia (5), Thomas (3.5), and Leo (18 months). Nick was born and raised in the Chicago area and continues to support his Chicago sports teams. As a family they find time for travel, good food and wine, and sports – especially golf.
David LaFalce
SVP & Global Head of Operational Resilience
Wells Fargo
David LaFalce
Biography coming soon.
Brennan Lodge
Head of Analytics Engines, Cybersecurity
HSBC
Brennan Lodge
Brennan Lodge is currently enriching and researching cybersecurity risk and defense through his role as an Professor at New York University. His professional experience is highlighted by his achievements as Global Head of Analytic Engines for Cyber Security at HSBC and Head of Data Science for the Security Incident Response Team at Goldman Sachs. Brennan’s profound understanding and application of AI in cybersecurity defense are recognized in the industry, with significant contributions to publications, research and practical applications to advancing AI-driven cybersecurity strategies.
Scot Lynch
Executive Director
Morgan Stanley
Scot Lynch
Scot Lynch spent 6 years in the United States Navy as a technician and security specialist and is a graduate of Columbia University. He has worked in Wall Street technology firms since 1995. His roles include Windows developer at Popkins Software, Development and Support Manager at Swiss Bank/UBS, and Operational Risk Officer and Operations Officer at Morgan Stanley.
He teaches Hakko Ryu JuJitsu, coaches military veterans (via American Corporate Partners) on transitioning to corporate life, and has participated in the Navy Seal Hudson River Swim since 2021.
James McPherson
Director & Counsel
Credit Agricole
James McPherson
James McPherson is Director & Counsel at Credit Agricole Corporate and Investment Bank in New York. He is a member of the Regulatory Group and his work includes reviewing and negotiating a broad range of commercial agreements for the Bank, including contracts for a variety of technology and trading related services. He also participates in various steering committees related to the procurement and ongoing monitoring of the Bank’s various service providers and outsourcing initiatives, including the Bank’s Vendor Management Committee.
Melissa Mellen
Head of Third Party Risk Management
Federal Reserve Bank of New York
Melissa Mellen
Melissa Mellen is the Director of Third-Party Risk Management within the Federal Reserve Bank of New York. In this capacity, Melissa manages Bank wide strategic priorities, such as the Third-Party Risk Management Risk and Control Unit, Policy, Governance, and Compliance across TPRM & Procurement, and Supplier Diversity.
Prior to joining the Federal Reserve Bank of New York, Ms. Mellen spent fifteen years in the private sector, specializing in Third Party Risk Management program design, development implementation, and oversight for firms such as: MUFG Union Bank, JP Morgan Chase, Oppenheimer Funds, and Mizuho Bank, Ltd. Ms. Mellen received her bachelor’s degree in philosophy from SUNY Albany, and holds a MBA with a concentration in Risk Management from Saint Peter’s University. She is a Certified Third-Party Risk Professional (CTPRP) and holds a Professional Certificate in Diversity, Equity & Inclusion from Cornell University.
Melissa lives in Northern New Jersey with her husband Kevin, and Pitbull Viggo. She is a certified yoga instructor affiliated with both the Dharma Yoga Center of New York City, as well as Yoga Alliance.
Carl Miller
Head of Change Management & Third Party Management
Western Alliance Bank
Carl Miller
Biography coming soon
Kholofelo Mothibi
Head of TPRM
Corebridge Financial
Kholofelo Mothibi
Kholofelo Mothibi is a risk leader with 17 years’ experience in auditing, compliance, controls assurance, and third-party risk management in the Technology and Financial sector. Prior to joining Corebridge Financial she worked at Barclays and IBM where she held various positions in IT Security, Compliance, Internal Audit, Procurement, and the Chief Security Office. She’s from Johannesburg, South Africa and, in 2015 during her tenure at Barclays, she accepted an opportunity to move to the US to support efforts of establishing a centralized TPRM function.
She’s successfully led implementation of Third-Party Risk Management processes and managed the delivery of several control remediation projects, program implementation which helped to streamlined and standardize governance processes, reporting and quality controls. She’s also participated in TPRM industry working groups to explore collaborative approach for managing third party risk.
Recipient of a Barclays Diversity Award and named Empower 100 Ethnic Minority Future Leaders 2021 for delivering several programs aimed at colleague engagement, supporting recruitment efforts, and raising funds for non-profit organizations.
Kholofelo is also a board member at Arete Education, which is non-profit in the Bronx, New York which partners with community based organizations and local schools to provide academic and artistic enrichment programs.
Andrew Moyad
Chief Executive Officer
Shared Assessments
Andrew Moyad
Andrew is an accomplished leader and trailblazer in third party risk management. As a practitioner and a senior risk management executive, he has driven a culture of accountability and diligence in safeguarding information. Andrew has more than 25 years in risk management and information security. He has contributed greatly to the transformation and advancement of risk management as a strategic function that intersects with and helps guide all aspects of organizations.
Most recently, Andrew served as Senior Vice President, Vendor Risk Management at Blackstone, where he led a team of risk professionals responsible for overseeing all phases of the vendor lifecycle at the firm, including risk assessments, control diligence, contract reviews, financial checks, performance monitoring, issue tracking, and management reporting. Prior to Blackstone, he served as a director and global head of vendor risk management and BlackRock and Senior Vice President for Citigroup, where he was a Business Information Security Officer in Global Fixed Income and led third party risk assessments for several years.
Andrew holds a Bachelor of Arts Degree in Natural Sciences from Harvard University and a Master of Science Degree in Information Systems from the Stevens Institute of Technology.
Firas Mustapha
Senior Director of Compliance
Arvest Bank tbc
Firas Mustapha
Biography Coming soon.
Javier Ortiz
Principal Technical Leader, Non-Financial Risk
Inter-American Development Bank
Javier Ortiz
Javier Ortiz brings over 25 years of progressive experience working with financial institutions in business consulting, operational risk management, process reengineering, and Internal Controls over Financial Reporting (ICFR).
At the Risk Management Office of the Inter-American Development Bank (IDB), Javier currently leads, and coordinates activities related to non-financial risk management including, the development of new or revised tools, methodologies, processes, and policies. He has also implemented and led the bank-wide Operational Risk Management Framework and launched the Socioenvironmental Risk Management Unit, as a second line of defense function.
Before joining the Risk Management Office Javier held various positions within the IDB’s Finance Department, his last position was Principal Accountant within the Accounting Control Group, where he implemented and led the process for the assessment of ICFR.
Prior to his career at the IDB, Javier worked for auditing and consulting firms in Argentina, providing services to financial institutions across Latin America.
Marta Palanques
Director, Methodologies and Practices, Technology Risk Management
Capital One
Marta Palanques
Marta Palanques is a seasoned Security and Risk professional, specializing in integrating risk management practices and processes to effectively support decision making with meaningful data while minimizing the overhead and meeting regulatory expectations, and in communicating security and risk to technical and non-technical executive stakeholders.
In her current role as a Director of Risk Methodologies at Capital One’s Technology Risk Management team, Marta is responsible for defining methodology and practices for risk and controls management, and providing risk intelligence to benchmark risk analysis and monitoring. Her team also oversees technology and cyber risk compliance requirements and monitors adherence to those requirements. Her previous experience in the industry ranges from IT audit and risk functions at Deloitte to conducting research in cybersecurity at Barcelona Digital Technology Center and includes defining and implementing an integrated risk management framework as a Director of Enterprise Risk Management at ADP, and building a program to support a single reporting platform that enabled exploration of multiple data sources and provided ADP’s executive leadership with visibility and insight into the security and risk program.
Roger Parsley
MD, Global Head of Technology and Cybersecurity Risk Governance
State Street
Roger Parsley
Accomplished, IT risk executive with 20+ years of industry-leading risk management experience in domestic and international financial markets. Results-orientated, decisive leader with proven success in developing world-class risk management organizations with particular focus on digital transformation, information security, third party / supplier risk, data privacy, information governance, regulatory compliance, and anti-financial crime. Sought after contributor at risk management industry conferences, thought-leadership groups, and international organizations.
Charmi Patel
VP, Vendor Risk Management
Israel Discount Bank of New York
Charmi Patel
Charmi began her vendor risk management career at Millennium Management LLC and then she transitioned to Federal Reserve Bank of New York.
Over the last year as head of vendor risk management at IDBNY, Charmi oversees risk and operational efficiencies of the entire portfolio of vendors and all the processes and procedures that are required for vendor risk management. She has a proven track record of implementing innovative and comprehensive vendor risk management programs for the IDBNY.
Charmi holds a Master’s degree in IT Project Management from Webster University, Florida.
Jeannie Pumphrey
Head of Third Party Risk and Change Management
MUFG
Jeannie Pumphrey
Biography coming soon
Babette Reynolds
Compliance Senior Director, Head of Enterprise Compliance Program Office
Truist
Babette Reynolds
Babette Reynolds is a global leader in banking compliance and operational risk management. She has over 25 years of experience building risk programs, including third party risk management programs, for large complex banks, including Bank of America, Citi, and Wells Fargo. Currently, Babette leads Truist’s Enterprise Compliance Program Office, where she and her team implement the compliance risk framework program.
Babette served for 6 years as a US Army Intelligence Officer. She is also a licensed attorney and practiced law with a focus in syndicated finance. She holds the following degrees: BA, Duke University; JD, University of North Carolina at Chapel Hill; MA, Boston University; and MS in Strategic Intelligence Studies, DoD National Intelligence University.
Kristen Schneider
Director, Business Strategy and Planning
USAA
Kristen Schneider
Kristen Schneider is an accomplished leader in the financial services industry with a background in third party risk management, procurement, operations, and corporate finance. Kristen currently leads a third party risk management strategy and initiatives team at USAA where her team supports optimization efforts based on industry best practices across people, process, and technology.
Kristen began her career in corporate finance and has held roles in operations finance in the technology industry for Intel Corporation and Rackspace Technology. She has a Bachelor’s degree from Cornell University and a Master of Business Administration from Rice University and currently resides in San Antonio, Texas.
Dolly Singh
MD, Global Head of Third Party Oversight
JPMorgan Chase
Dolly Singh
Dolly Singh has been with JPMorgan Chase for 19 years and currently serves as the Global Head of Third Party Oversight within Global Supplier Services (GSS). In her role, she is responsible for establishing and overseeing the Firm’s governance and risk management framework for both external suppliers and inter-affiliate relationships. Her remit also includes governance of the firmwide supplier control assessment function and supplier incident response management function. Additionally, Dolly leads the Third Party Oversight regulatory advocacy efforts.
Prior to joining her current role, Dolly held various leadership roles in JPMorgan Chase’s Corporate & Investment Bank and within Finance, Product Management & Risk Management.
Stefan Smith
Director, Enterprise Risk Office and Head of Third Party Risk
Bank of Canada
Stefan Smith
Stefan is an experienced Enterprise Risk Management professional and leader and has led the design and implementation of Risk Appetite, Strategic Risk Management, Enterprise Risk Reporting, Risk Policy & Frameworks and Third Party Risk Management programs in the Financial Services industry. His current focus is on digitalizing the Bank’s third party risk management program and leading strategic risk assessments across the Bank. Stefan holds a bachelor’s and master’s degrees in philosophy from the University of Western Ontario and lives outside of Ottawa where he tends to his many vegetable gardens and chickens with his family.
Donovan Tanner
Third Party Industry Expert
Donovan Tanner
Biography coming soon
Chelsea Tieken
Business Strategy and Planning Director, TPRM Strategy and Initiatives
USAA
Chelsea Tieken
Chelsea Tieken is a Business Strategy and Planning Director at USAA specializing in Enterprise Third Party Risk Management. In her role she leads impactful, cross-functional, third party risk strategy projects for the enterprise. Through these initiatives Chelsea aims improve and simplify Risk Management processes and technology for USAA. Chelsea has been an industry practitioner specializing in third party risk and supplier management for over 10 years.
Preety Tulsian
Head of Third-Party Risk US, Enterprise Risk
Scotiabank
Preety Tulsian
Preety Tulsian is the Head of Third Party Risk for Scotiabank US. In this role, she built a third party risk program for the Firm which led to resolution of long standing regulatory commitments. Preety brings over 15 years of experience in a variety of risk disciplines including operational risk, business continuity and most recently operational resilience. She’s also an attorney with notable experience in helping firms interpret and meet regulatory requirements.
Brett Turk
Global Head of Business Continuity and Crisis Management
Vangaurd
Brett Turk
Brett Turk is the Global Head of Business Continuity and Crisis Management at Vanguard. In this role he is responsible for preparing for and responding to significant business disruptions. Brett is a senior member of the leadership team within Vanguard’s Global Risk and Security division that focuses on developing an enterprise-wide view of resilience for its diverse global businesses.
Brett joined Vanguard in 2013. Prior to his current role he served in various leadership capacities across shared services, complex operations, and large-scale programs, most recently leading Vanguard’s global return to office efforts.
Before joining Vanguard, Brett worked in corporate finance and operations leadership roles in the financial services industry. Brett has an MBA from Arizona State University and a B.S. from Westminster College (PA).
Karina Volvovsky
Senior Vice President, Business Control Officer for Entertainment
City National Bank
Karina Volvovsky
Karina Volvovsky is a Senior Vice President of City National Bank. In her current role of Business Control Officer, she covers non-financial risks of Entertainment Banking within City National Bank. Prior to joining CNB, Karina was a Managing Director of Business Risk at Silicon Valley Bank, and spent 20+ years at JPMorgan Chase, where she held a myriad of leadership roles within 1st and 2nd lines of defence. Karina’s notable initiatives include SEC Regulation Best Interest response roll-out, resolution of regulatory matters related to Fiduciary governance and Conflict of Interest programs, development of escalation and risk reporting practices in Latin and Central America regions, among others. Karina lives in New York City with her husband and three children.
Olga Voytenko
Managing Director, Head of Operational Resilience
Forbright Bank
Olga Voytenko
Olga Voytenko serves as the Head of Operational Resilience at Forbright Bank.
Olga brings two decades of financial and non-financial risk management experience. Most recently, she led several global enterprise programs, including Operational Resilience and Third Party Risk Management for complex global and regional financial institutions. Before that, Olga held leadership positions in liquidity risk and resolution recovery planning teams.
She also managed investment finance operations and financial reporting teams. Olga started her career as an auditor overseeing operational risks.
Olga is energized by her proven track record of building sustainable programs and a passion for driving transformative risk management practices in the ever-evolving regulatory landscape.
Olga holds a Master of Science in Business Administration from Suffolk University and a Bachelor of Science from Boston University.
Jeffrey Wheatman
Cyber Risk Evangelist
BlackKite
Jeffrey Wheatman
A strategic thought leader with extensive expertise in cybersecurity, Jeffrey Wheatman is regarded foremost as an expert in guiding public sector clients and Fortune 500 companies in connection with their cyber risk management programs. In his current role as Cyber Risk Evangelist at Black Kite, Jeffrey works to get the message out about the business impact of third-party risk and solutions to treat those risks.
Prior to joining Black Kite, Jeffrey was a Vice President in Gartner’s Research and Advisory Group for 15 years, where he worked with clients to build and improve their security programs, assessing risk, focusing on reporting on program status, stakeholder engagement, and bridging the connection between technology and cybersecurity risk. Jeffrey has authored approximately 150 research notes read by more than 6,000 clients. For four years, Jeffrey also served as the Chair of the North America Security and Risk Management Summit, Gartner’s 2nd largest conference with 4000 attendees annually.
Earlier in his career, Jeffrey contributed as Practice Manager, Information Security for Gotham Technology Group, and as a Principal Consultant, Information Security, with ThruPoint, Inc.
Ken Wolckenhauer
Head of Vendor Risk
Nordea Bank
Ken Wolckenhauer
Ken Wolckenhauer is the Head of Vendor Management at Nordea Bank’s New York branch. Leading up to this position, Ken was as a subject matter expert, trainer, solutions provider, and consultant for FIS, the world’s largest global provider dedicated to banking and payments technologies. With FIS, Ken specialized in financial industry regulatory risk and compliance, mostly in the area of anti-money laundering and watchlist compliance. Nordea Bank leveraged Ken’s risk and compliance knowledge to build out the vendor management program for the New York branch, developing a program that would properly manage risk as well as gaining acceptance to the US regulators. The success of the US program is now being used to advise Nordea’s European branches on enhancements to its TPRM program. Ken is a graduate of Bucknell University and is a Certified Anti-Money Laundering Specialist.
Would your organization like to partner with us on this event?
To discuss how we can deliver your thought-leadership at the event, help you generate leads, and provide you with unique networking and branding opportunities, please contact sales@cefpro.com or call us on +1 888 677 7007 for more information.
2024 Sponsors
Co-sponsors
Aravo
Aravo delivers the market’s smartest third-party risk and performance management solutions, powered by intelligent automation. With Aravo, customers can work smarter, move faster, see clearer, and make better decisions about their extended enterprise – all in one place.
For more than 20 years now, Aravo’s combination of award-winning technology and unrivaled domain expertise has helped the world’s most respected brands accelerate and optimize their third-party management programs, delivering better business outcomes faster and ensuring the agility to adapt as programs evolve. Aravo is trusted by the world’s leading brands, helping them manage the risk and improve the performance of more than 5 million third parties, suppliers and vendors across the globe.
Black Kite
Black Kite is disrupting third-party risk management practices by providing security experts with the industry’s most accurate and comprehensive cyber intelligence, resulting in unparalleled visibility into vendor risk. The award-winning platform pushes the limits on predictive insights, delivering the highest quality intelligence to help organizations make better risk decisions.
Mirato
Don’t just automate workflow. Automate the remaining manual work.
Mirato’s TPRM intelligence platform elevates existing TPRM programs and
tools by streamlining an entire operation’s data into one smart platform. Using natural language processing (NLP) and advanced artificial intelligence (AI), Mirato validates and enriches this data, turning it into actionable insights. What was previously multi-destination, manual-intensive labor is now replaced by the Mirato platform and is easily managed from one dashboard. This saves time and money (up to 60% of assessment cost) while increasing an organization’s ability to mitigate risk in an ever-evolving risk landscape.
NCC Group
With over 30 years’ experience, NCC Group is a world-leading Software Resilience provider ensuring the continued availability of outsourced business-critical software and data through our Escrow and Verification services. Our Software Resilience services enable businesses to easily prepare for, respond to and recover from disruption to third-party services, strengthening operational resilience and satisfying business continuity planning, regulatory compliance and supply chain risk management requirements.
Security Scorecard
SecurityScorecard is the global leader in cybersecurity ratings and the only service with millions of organizations continuously rated. Our mission is to make the world a safer place by transforming the way organizations understand, improve, and communicate cybersecurity risk to their boards, employees, and vendors.
SecurityScorecard’s patented rating technology is used by thousands of organizations for enterprise cyber risk management, third-party risk management, board reporting, cyber insurance underwriting, and regulatory oversight to meet compliance mandates; making all organizations more resilient by allowing them to easily find and fix cybersecurity risks across their externally facing digital-footprint.
SecurityScorecard is the only provider of instant risk ratings that automatically map to vendor cybersecurity questionnaires and the largest ecosystem of integrations, providing a true 360-degree view of risk. But we don’t stop there. Through a customer-centric, solution-based commitment to our partners, we are transforming the digital landscape building a path toward resilience.
Associate sponsors
Archer
Archer, an RSA company, is a leader in providing integrated risk management solutions that enable customers to improve strategic decision making and operational resiliency. As true pioneers in GRC software, Archer remains solely dedicated to helping customers understand risk holistically by engaging stakeholders, leveraging a modern platform that spans key domains of risk and supports analysis driven by both business and IT impacts. The Archer customer base represents one of the largest pure risk management communities globally, with over 1,500 deployments including more than 90 of the Fortune 100.
Fusion Risk Management
Fusion Risk Management is a leading industry provider of cloud-based software solutions for business continuity, operational risk, IT disaster recovery, and crisis management. Our products empower your firm to make data-driven decisions with a comprehensive and flexible approach to achieve greater operational resilience and mitigate risk with your business.
PwC
PwC is a global leader in designing, implementing, and operating third party risk management (TPRM) programs. Our team applies innovative approaches and technologies that help our clients effectively manage their risk exposure so they can properly identify, mitigate and monitor the third-party risks most impactful to their operations. We help our clients design, build and manage fit-for-purpose third-party risk programs that protect their operations, brand and reputation at an optimal cost to operations. Supported by a dedicated risk management and compliance practice, with more than 15,000 professionals in the US and over 40,700 globally | Apply the latest industry practices, technology innovations, and regulatory feedback impacting our clients TPRM programs | Support through an end-to-end suite of TPRM design, implementation, technology enablement and managed services solutions with the same dedicated team | Proven accelerators built around the TPRM lifecycle and based on years of experience, providing a blueprint for success at each stage of the journey
Shared Assessments
Shared Assessments is a global membership organization dedicated to developing the best practices, education and tools to drive third party risk assurance. We are creators of the industry standard third party risk toolkit, used by over 15,000 organizations worldwide.
Content and media partners
CeFPro Connect
CeFPro Connect aims to connect industry experts through thought leadership content and timely news, written for the industry, by the industry. Gain unlimited access to CeFPro’s unparalleled library of resources including iNFRont Magazine, market intelligence reports, filmed presentations, insights Q&A’s, and much more.
Sign up for free.
iNFRont Magazine
iNFRont Magazine is a unique publication providing regular insight on the operational and non-financial risk (NFR) sector. Featuring contributions provided by leading industry figures and experts from around the world, iNFRont Magazine touches on the most critical themes and challenges currently affecting financial professionals.
Available to download for free.
Venue & FAQs
360 Madison Avenue | etc.venues
Madison Avenue
Midtown Manhattan
New York NY 10017
There is no accommodation available at the venue, however, there are plenty of hotels available nearby. If you would like to view nearby hotels, please click here or on the button below.
Frequently Asked Questions
Can I share my thought leadership at Vendor & Third Party Risk USA?
Will there be opportunities to network with other attendees?
- Breakfast, lunch and refreshment breaks
- Drinks reception at the end of day-1
- Q&A, panel discussions and audience participation technology
What is included within the registration fee?
Where can I find the Congress documentation and speaker presentations?
* Please note that our speakers often have to gain permission from their relevant compliance departments to release their presentations. On rare occasions compliance may not allow presentations to be distributed.
Will breakfast, lunch and refreshment be provided?
Are there any rules on dress code?
Are CPE Credits available?
Register - Launch Rate - Available until March 15
E.g. Bank, Insurance company, Asset manager, Regulator
E.g. Consultant, Vendor, Executive search firm, Law firm
Register
Register for Vendor & Third Party Risk USA today and join the likes of 150+ industry professionals and subject matter experts looking to engage in meaningful conversation and discuss the latest developments and challenges within the vendor and third party risk sector.
Register now and take advantage of our launch rate – our lowest rate available for this event.
Don’t miss out, we only have a limited number of tickets available.
Need assistance with your registration? Get in touch with us via email below, or call us on +1 888 677 7007.
*To qualify for the preferential ‘early bird’ rates, registration must be received by the close of the ‘early bird’ working day, and payment can be made at the time of registering, or up to a week after registration is made an invoice sent. CeFPro reserves the right to increase rates should payment be delayed significantly. For Group Rates to be valid, the whole group must register at the same time, though names can be changed at any time up to the event at no additional cost. Should a delegate register at a rate that is inaccurate, CeFPro reserves the right to issue an additional invoice for the outstanding amount.
Register your interest in Vendor & Third Party Risk USA
Please fill out the form below and register your interest for CeFPro’s Vendor & Third Party Risk USA and ensure your among the first to know about:
- Receive timely alerts upon event launch
- Stay updated with agenda updates
- Enjoy exclusive discounts
- Receive prompt speaker announcements
- Gain unique access to insights shared by industry experts
- Secure exclusive access to key sessions and high-profile speaker interviews
- Access presentation materials curated by speakers
- Obtain exclusive reports and market intelligence, and much more.