To discuss how we can deliver your thought-leadership at the event, help you generate leads, and provide you with unique networking and branding opportunities, please contact [email protected] or call us on (0) 207 600 3543 more information.
Vendor & Third Party Risk Amsterdam Agenda
More to come…
Stay informed about updates to the Vendor & Third Party Risk Amsterdam agenda and speaker line-up by registering your interest.
Breakfast and registration
DORA – PANEL DISCUSSION
It’s here– but are you ready?
Session details: Clarifying third-party compliance obligations post-DORA implementation
- Efficiently applying new DORA requirements across the ICT supply chain
- Preparing for DORA audits and cross-functional regulator reviews
- Incorporating DORA requirements, including broader ICT coverage and stressed scenarios
- Updating legacy contracts to reflect resilience, data, and AI risk
- Understanding DORA’s requirements for threat-led penetration testing
IT DEPENDENCIES OF THE FINANCIAL SECTOR – A REGULATORY PERSPECTIVE
Session details: How to deal with non-European IT dependencies of the financial sector?
- The dependency of the financial sector on IT third party providers – nothing new
- The changing geopolitical landscape
- New risks, new challenges
- Short-term and long-term actions
- A regulatory perspective
Morning refreshment break and networking
CONCENTRATION RISK
Managing increased concentration risk in extended supply chains
- Identifying the different types of concentration risk
- Understanding regulatory requirements and ensuring compliance
- Tools and techniques to address concentration risk effectively
- Real life case study of failure to manage this risk
Navigating AI in Third-Party Risk Management
Session details: An update on the innovation waves of AI
- Understanding the key waves of AI from machine learning to AI agents to Agentic AI
- Decipher the hype from reality on what each type provides
- What are the third-party risk workflows where AI can have impact
- What are the cautions and risks to be aware of for your own AI implementation
INCIDENT REPORTING
When the unexpected hits – will your vendor notify you?
Session details: Ensuring contractual requirements for incident notification are clear and enforceable
- Aligning internal policies to escalate supplier issues rapidly
- Facilitating transparency without triggering reputational panic
- Creating joint playbooks between firms and vendors for incident response
- Documenting root cause analysis and actions post-incident for audit readiness
Pre-luncheon briefing: Continuous Monitoring using AI
Lunchbreak and networking
Keep the conversation going - Grab a bite to eat and build new connections
BUILDING YOUR “DATA FIRST” TPRM STRATEGY - FIRESIDE CHAT
Turning regulatory challenges into operational reality
Session details: Leveraging Deloitte’s Global TPRM Survey 2025 findings to embed objective data, unlock risk insights, and operationalise compliance
- Interpreting EBA guidance, EU DORA, and AI Acts through stronger collaboration between Risk and Operational Resilience teams
- Blending AI, existing technology, in-house expertise and managed services to focus in on high impact risks across the ecosystem
- Simplifying compliance and strengthening resilience through a “data-first” TPRM strategy
RISK ASSESSMENTS – FIRESIDE CHAT: INTERACTIVE SESSION
Transforming risk assessments: Automate, Align Action
Session details: Automating the risk assessment lifecycle while maintaining accuracy and governance
- Aligning risk profiling and assessment depth across critical and non-critical services
- Overcoming documentation challenges and interpreting technical reports effectively
- Embedding RCSA, compliance, and penetration testing into business-as-usual
- Supporting non-experts in navigating risk decisions with practical frameworks
- Building scalable, cost-efficient models that reduce friction and staffing pressure
GEOPOLITICS – PANEL DISCUSSION
Resilience without boarders: Geopolitics in the TPRM era
Session details: Building resilient third-party strategies amid shifting global power dynamics
- Assessing concentration risk across cloud and SaaS providers
- Mapping supplier geographies and factoring in geopolitical instability
- ‘’America First” tariff regimes, international conflicts
- Planning exit strategies for politically sensitive jurisdictions
- Navigating regulatory scrutiny around US-based tech vendors
- Balancing cost-efficiency with resilience in offshoring decisions
- Creating regional backup strategies for U.S reliant cloud infrastructure
Afternoon refreshment break and networking
STRESSED EXIT PLANNING
Session title: Demonstrating successful stressed exit planning with software escrow
- Disruption as usual
- Severe but plausible risks: Supplier failure, service deterioration and concentration risk
- Global regulatory alignment: Stressed exit planning
- The temporary stages: Escrow's role
FOURTH- AND NTH-PARTY RISK MANAGEMENT
Chain reaction: Controlling the ripple effect of Nth party downfalls
Session details: Gaining visibility beyond immediate vendors
- Mapping dependencies across SaaS, cloud, and critical tech infrastructure
- Enforcing disclosure through contracts and onboarding
- Challenges with audit rights and vendor cooperation
- Balancing oversight with operational feasibility
Chair’s closing remarks
End of day one and networking drink’s reception
Debrief with your new connections in a relaxed settings and get ready for day two
Registration and breakfast
Chair’s opening remarks
ESG MANDATES & INTEGRATION
From Obligations to Outcomes: Operationalising ESG Across the Third-Party Lifecycle
Session details: Embedding CSRD, CSDDD & ESG Metrics into Third-Party Risk Programs
- Translating CSRD and CSDDD into actionable third-party oversight
- Embedding ESG criteria into onboarding, selection, and monitoring
- Managing risk across extended vendor chains, including fourth- and fifth-parties
- Handling ESG misalignment with non-EU vendors contractually
- Fostering cross-functional collaboration to align with firmwide goals
AI USAGE BY THIRD PARTIES
Ai in the shadows: Ensuring responsible use by your third parties
Session details: Understanding how third parties are using AI across service delivery
- Updating contracts to reflect AI transparency, disclosure, and change notifications
- Assessing risk from unvalidated or biased models impacting operations
- Establishing data governance strategies to prevent data loss and reputational damage
- Embedding ongoing AI usage reviews into monitoring frameworks
- Requiring AI governance frameworks and validation evidence from vendors
Morning refreshment break and networking
TPRM & CYBERSECURITY RESILIENCE
Cyber resilience starts with your third parties
Session details: Aligning cybersecurity and third-party risk management frameworks – Cloud Service Provider Audits
- Responding to increasing cyberattacks by better aligning your controls and your vendor’s controls
- Going beyond SOC reports by exercising your right to audit
- The benefits of using a common framework – the Cloud Service Provider use case
The anatomy of a supply chain attack
- How exactly a vendor compromise can become a downstream incident
- Early indicators of compromise that often go unnoticed
- Practical ways to assess and prioritise third-party risk, and some rapid response practices for third‑party incidents
- What metrics to track and improve supply chain cyber resilience
Lunchbreak and networking
TECHNOLOGY ENABLEMENT - PANEL DISCUSSION
Tech that talks: Seamless risk integration across TPRM
Session details: Evaluating third-party platforms for scalability and usability
- Integrating TPRM tools with procurement, legal, and security systems
- Using AI and analytics to triage risk and flag anomalies
- Ensuring vendors contribute directly through portals and uploads
- Supporting change management when moving off spreadsheets
VENDOR ONBOARDING
The new standard for vendor onboarding: Fast. Aligned. Tiered
Session details: Automating the onboarding journey from intake to risk profiling
- Defining tiering methodologies and assigning criticality
- Ensuring cross-functional input on classification decisions
- Linking classification to assessment depth and contract terms
- Reassessing vendor tiering post-incident or post-service change
Afternoon refreshment break and networking
Intergrating TPRM
Integrating TPRM into enterprise risk management framework What is covered?
- Strategic Alignment: Integrating TPRM into ERM Governance and Risk Appetite
- Incorporate third-party risk into risk identification, assessment, monitoring, and reporting processes.
- Align reporting to present a comprehensive view of third-party exposure across the organization
FUTURE TRENDS & STRATEGIC RESILIENCE – PANEL DISCUSSION
Looking ahead, acting now: Prepare TPRM for tomorrow’s challenges
Session details: Predicting how AI, geopolitical tensions, and regulatory change will shape TPRM
- Designing future-ready TPRM strategies that support agility
- Embedding third-party risk into broader enterprise risk frameworks
- Maintaining resilience despite constrained budgets and talent shortages
- Driving board-level understanding and commitment to TPRM evolution
Chair’s closing remarks
End of day one Vendor & Third Party Risk Amsterdam
Receive Vendor & Third Party Risk Amsterdam Agenda Updates
This is just the start!
We’ll be adding more as we get closer to the event:
- New Speakers
- Additional Sessions
- Even more ways to enhance your experience
Stay in the loop — register your interest using the form on the side.
Speaking Opportunities
Would you like to join the agenda?
If you would like to be part of the Climate Risk and Stress Testing agenda or have any questions regarding the agenda and speaker lineup, please contact the producer of the event through [email protected] or call us at (0) 207 600 3543 for more information.
Upcoming events
Contact Us
Contact Us
[email protected]
+1 888 677 7007
+44 (0)207 600 3543
