Industries

Helping clients meet their business challenges begins with an in-depth understanding of the industries in which they work. That’s why KPMG LLP established its industry-driven structure. In fact, KPMG LLP was the first of the Big Four firms to organize itself along the same industry lines as clients.

How We Work

We bring together passionate problem-solvers, innovative technologies, and full-service capabilities to create opportunity with every insight.

Learn more

Careers & Culture

What is culture? Culture is how we do things around here. It is the combination of a predominant mindset, actions (both big and small) that we all commit to every day, and the underlying processes, programs and systems supporting how work gets done.

Learn more

Board oversight of third-party risk management

The increasing complexity and range of third-party risks poses a significant oversight challenge for boards.

While many companies have robust third-party risk management (TPRM) programs in place as a strategic imperative, ensuring that TPRM processes keep pace with the rapidly changing risk, regulatory, and compliance environment is a significant challenge.

For boards overseeing management’s efforts to maintain effective TPRM programs, key areas of focus should include:

  • Third-party cybersecurity and data privacy risks
  • Risks posed by use of third-party artificial intelligence tools
  • Third-party climate, sustainability, and other ESG risks
  • Management’s projects to address business operations vulnerabilities and improve resilience and sustainability

The following are questions for boards and board committees to keep in mind as they reassess how they can effectively oversee third-party risk:

  • Do the management team members responsible for specific risks understand the scope and magnitude of the risk being managed by third parties and whether that risk is appropriately managed and controlled in line with the company’s policies?
  • Does management have a complete risk-ranked inventory of critical services provided by third parties, including subcontractors?
  • How often does the board want updates on third-party risk from management? How is the information provided? Is data available in real time?
  • Where should board oversight of third-party risk be housed—full board, risk committee, or another committee? Does the audit committee have responsibility for supply chain risks by design or by default?
  • Is the TPRM program approached holistically, as an enterprisewide activity (versus silo-driven) and effectively integrated with risk management and compliance functions?
  • Do the TPRM team and other functions have sufficient skills/talent, funding, and technology to keep pace?

When should the board be involved in the oversight and approval of large or complex services involving third parties ?

Dive into our thinking :

Board oversight of third-party risk management

Download PDF

Meet our team

Image of John Rodi
John Rodi
Leader, KPMG Board Leadership Center, KPMG US
Image of Greg Matthews
Greg Matthews
Partner, KPMG US

Receive the latest insights from the Board Leadership Center

Sign up to receive Board Leadership Weekly and Directors Quarterly

Thank you

Thank you for subscribing. We're excited to welcome you to our community. You can now look forward to the latest news, trends, upcoming events, and thought leadership delivered directly to your inbox.

Subscribe to insights from KPMG Board Leadership Center

Board Leadership Weekly - A weekly email providing the latest news, trends, upcoming events, and thought leadership focused on the board and C‑suite from KPMG, the BLC, and other leading sources. 

Directors Quarterly - A compilation of articles, insights, and upcoming events.

Select publications you want to receive and any topics of interest below. Select all that apply.

By submitting, you agree that KPMG LLP may process any personal information you provide pursuant to KPMG LLP's Privacy Statement.

An error occurred. Please contact customer support.

Thank you!

Thank you for contacting KPMG. We will respond to you as soon as possible.

Contact KPMG

Use this form to submit general inquiries to KPMG. We will respond to you as soon as possible.

By submitting, you agree that KPMG LLP may process any personal information you provide pursuant to KPMG LLP's Privacy Statement.

An error occurred. Please contact customer support.

Job seekers

Visit our careers section or search our jobs database.

Submit RFP

Use the RFP submission form to detail the services KPMG can help assist you with.

Office locations

International hotline

You can confidentially report concerns to the KPMG International hotline

Press contacts

Do you need to speak with our Press Office? Here's how to get in touch.

Headline