code grc

Third-Party Risk, End to End

The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.

  • trending_upIntermediate
  • schedule7h 21m
  • menu_book12 bài học
  • publicEnglish
  • workspace_premiumBasic

Tóm tắt

Somebody in your organisation has bought something this month that holds customer data, and procurement has never heard of it. It was thirty pounds on a card, it was signed up for with a work email address, and there is no contract. That supplier is now inside your risk position and outside your register. Most third-party risk work fails there, before any questionnaire is sent. This segment is the lifecycle. You build a register from the card statement and the sign-in logs rather than from procurement, because those two sources know things procurement does not. You write a tiering rule that decides for you, so the level of diligence a supplier gets is not negotiated afresh every time somebody is in a hurry. You cut a question set down until it is short enough to actually come back, and you learn what a returned questionnaire is: a statement of intent, written by somebody who wants the deal, about a state of affairs nobody independent has checked. You get the handful of contract clauses that change what happens on a bad day, and you leave the rest to counsel, because contracts are legal territory and this segment says so in every lesson that touches one. You then handle nine months of evidence arriving at a mailbox nobody reads. Finally you map what is behind your suppliers, discover that four of them stop at the same moment for the same reason, and write an exit plan for the one you are leaving, whose administrator account is still active five months after the contract ended. A programme that produces a two-hundred-question spreadsheet has failed. It has externalised weeks of work onto suppliers who cannot afford it, selected for the ones with a compliance team rather than the ones with good practice, and produced no decision anybody changed. The test applied throughout this segment is narrower and harder: what would this question, if answered honestly, change about what we do? If the answer is nothing, the question comes out. You finish with five artefacts: a supplier register with owners and review dates, a written tiering rule, a question set of fifteen with a closing artefact against each one, a clause list with what each clause buys you, and an exit plan. None of them is long. All of them are the sort of thing that has to survive somebody else picking it up while you are on holiday. Every money figure, count and date in this segment is illustrative. The numbers are shaped so the arithmetic behaves realistically; none of them is a claim about what anything costs or how long anything takes in the real world. Nothing in this segment is legal advice: contract and data-protection content is legal territory, and the learner's own counsel decides.

Nội dung khóa học · 4 mô-đun

lockMở khóa với quyền truy cập
  1. 01 The Register, Built From What You Can See
    3 bài học·1h 36m

    Ask procurement for the supplier list and you will get a list of things bought through procurement. That is not the same set. The card statement knows about the thirty-pound recurring charges. The…

  2. 02 How Much Diligence Is This Worth
    3 bài học·1h 59m

    The four-person supplier cannot answer two hundred questions. They will try, take seven weeks over it, answer sixty, and you will approve them anyway because the project needed them in March.…

  3. 03 The Contract, and the Evidence That Keeps Arriving
    3 bài học·1h 40m

    A clause does not stop the incident. What it buys you is notice, an evidence right, and a way out. That is worth having and it is worth knowing what it is, because a right to audit that nobody will…

  4. 04 Fourth Parties, Concentration, and Getting Out
    3 bài học·2h 6m

    You have four suppliers in four functions and you are comfortable because that is diversification. Then you read the four sub-processor lists and three of them sit in the same place. Concentration is…

Các câu hỏi thường gặp

Tôi sẽ học gì trong Third-Party Risk, End to End?
The whole supplier lifecycle, not the questionnaire. Finding the suppliers nobody told you about, deciding how much diligence each one is worth, getting the few clauses that matter, reading the evidence that keeps arriving, finding the four suppliers who turn out to be one, and getting out cleanly.
Tôi có cần kinh nghiệm trước đó không?
Nên có một số kiến thức trước đó trước khi bắt đầu Third-Party Risk, End to End.
Third-Party Risk, End to End mất bao lâu?
Third-Party Risk, End to End bao gồm 4 mô-đun và 12 bài học. Bạn học theo tốc độ của riêng mình.
Làm cách nào để tôi có quyền truy cập?
Third-Party Risk, End to End được bao gồm trong bất kỳ gói đăng ký nào.

Thêm trong Lập trình

AI Without the Hype
Beginner AI Without the Hype What the model is actually doing when it answers you, why that produces something that looks like thinking, why it invents citations, and the cost mechanic almost nobody explains: a chat resends the entire conversation on every single turn. You will do the arithmetic yourself.
First Program — Scratch for ages 5–9
Beginner First Program — Scratch for ages 5–9 Nine Scratch blocks, three sessions of about twenty-five minutes, and one small program a child of five to nine builds themselves. Written for the parent sitting beside them: what to click, what they will get stuck on, what to say when it goes wrong, and when to keep your hands off the mouse.
Binary, Hex and Data Units
Beginner Binary, Hex and Data Units The topic that costs more marks than any other on the paper, taught by hand. Bits and bytes, binary and hex in all six directions, the 1000-versus-1024 trap, file sizes, transmission times, overflow, two's complement and character sets. Every module ends in a timed drill marked the way an examiner marks it.
Python From a White Sheet
Beginner Python From a White Sheet The exact sequence nine students have already walked, from a blank file to a program that asks questions, checks the answers and refuses bad input. No prior programming. No maths. You will break it repeatedly, on purpose.
IGCSE and GCSE Computer Science — Theory That Actually Gets Marked
Intermediate IGCSE and GCSE Computer Science — Theory That Actually Gets Marked The theory half of the paper, taught so it survives the exam room. The memory hierarchy and what actually happens at boot. Compilers, interpreters and assemblers, including the answer that sounds right and scores nothing. Databases from a spreadsheet up to keys and normalisation. DNS and the full path between pressing Enter and seeing the page. Systems software, and the ethical and legal section that is the easiest ten marks on the paper.
Programming for the Exam — Python Answers That Score
Intermediate Programming for the Exam — Python Answers That Score The programming half of the paper, taught at exam pitch. Pseudocode translated both ways, because the mark scheme is written in a notation nobody practises. Trace tables done column by column, including the ones with a loop and a condition inside it. Linear and binary search, bubble and insertion sort, what each costs and the comparison questions boards love. Validation against verification, and the boundary test data everybody forgets. Procedures against functions, and a systematic method for finding your own error with four minutes left.