Managing the contract risk process
Summarize
Summary of Managing the Contract Risk Process
The contract risk process is crucial for protecting an organization's interests during third-party negotiations. As a contract negotiator, you utilize the Third-party Risk Management application to incorporate specific provisions that address identified risks. Notifications are automated upon the completion of necessary approvals, allowing you to manage due diligence requests effectively.
Show less
Key Features
- Access to Vendor Management Workspace for tracking tasks and due diligence requests.
- Ability to review internal and external questionnaire responses, risk intelligence scores, and supporting documents related to due diligence requests.
- Options for managing contracts, including executing, skipping, rejecting, or terminating contracts during the risk process.
- Email notifications for the completion of the contract risk process.
Key Outcomes
Upon completion of the contract risk process, you can expect:
- Successfully executed contracts with set start and expiration dates, ensuring clarity on engagement terms.
- Clear communication regarding the status of engagements, including rejections or requests for additional due diligence.
- Streamlined management of third-party risks, enhancing your organization's compliance and risk mitigation efforts.
Protect your organization's interests, as the Third-party risk contract negotiator, often the corporate counsel, by incorporating specific contractual provisions so that you can address the risks identified using the Third-party Risk Management application.
If a contract is being negotiated with the engagement or third party, the due diligence request enters the Contract risk process state after all approvals have been processed. If you’re the assigned contract negotiator, you're notified through an automated email when all the approvals have been processed.
The following infographic shows the contract risk process.
To view the Task page, select , and then select the tasks icon .
To view your assigned requests, select Due diligence requests for Negotiator.
To view Due diligence requests for Negotiator in the VRM Classic user interface, select
- Review the internal questionnaire responses.
Navigate to the Due diligence request record page by selecting the Due Diligence Request (DDR) number. You can view the related internal questionnaire responses by selecting the Internal assessment (INA) number on the Internal assessments tab. For more information, see IRQ process management.
- Review the risk intelligence scores.
Navigate to the Due diligence request record page by selecting the DDR number. You can view the related risk intelligence scores by selecting the Risk intelligence scores tab. For more information, see Viewing risk intelligence scores.
- Review the external questionnaire responses and supporting documents.
Navigate to the Due diligence request record page by selecting the DDR number. View the related external questionnaire responses and supporting documents by selecting the Third-party risk assessment (VRA) number on the External assessments tab. For more information, see Third-party (external) risk assessment management.
- Contract Risk process (Only if the engagement is contracted)
If the engagement includes a contract, as the contract negotiator, you prepare the contract and do the following actions:
- Access all data that is generated during the Request, IRQ, Due Diligence, and Approval processes to design and settle the contract and assess the following items:
- Initial Inherent Risk Questionnaire (IRQ) responses and comments by the Third-party risk assessor. For more information, see IRQ process management.
- Risk data from the risk intelligence providers. For more information, see Viewing risk intelligence scores.
- Responses to third-party questionnaires and engagement questionnaires. For more information, see Third-party (external) risk assessment management.
- Issues and tasks for the third-party contacts that were assigned to you by the Third-party risk manager. Assigned issues and tasks are listed on the tasks page.
- After the contract is fully signed by all parties (executed), attach the contract and activate the engagement by selecting Contract executed and then complete the following actions from
the Details tab on the due diligence request record page:
- Set the Contract start date for the engagement.
- Set the Contract start date for the third party if not set previously.
- Set the Contract expiration date for the engagement to the requested end date.
- Update the due diligence request's state from Contract risk process to Engagement contract executed.
After the contract is executed, the Contract start date and Contract expiration date fields are read-only and available to view from the Details tab for the third party and engagement in the Vendor Management Workspace.
Note:After opening an assigned task, select Browse in the Attachments section to select and add a contract. If you want the contract to appear in the Documents related list, select Documents and on the Documents page select New to add a new contract document or Link Documents to attach an existing contract document. For more information about the Document Management system, see Document Management system in Third-party Risk Management.- Access all data that is generated during the Request, IRQ, Due Diligence, and Approval processes to design and settle the contract and assess the following items:
Follow the same process in step 2 to activate an engagement for due diligence requests, onboard an engagement, and reassess an engagement for contract renewal.
- Contract Risk process (contract is skipped)
If the engagement doesn’t require a contract, you can skip the contract by selecting Skip contract from the Details tab on the due diligence request record page.
The following changes take place:- The Contract start date is changed to Engagement start date.
- The Contract end date is changed to Engagement expiration date.
- A required Justification field appears. Enter an explanation for skipping the contract.
- The due diligence request's state is updated from Contract risk process to Contract risk process skipped.
- After the owner closes the request, the engagement is Active.
The following examples show the contract start and expiration date before and after you select the skip contract risk process.
The following example shows the available selections and where the required justification box appears.
- Contract Risk process (Not contracted, onboarding engagement is rejected)
If an issue can't be resolved or the due diligence request is canceled, you can reject the engagement by selecting Not contracted from the Details tab on the due diligence request record page.
The following actions take place:- A required Justification field appears. You must enter an explanation for rejecting the engagement.
- The due diligence request's state is updated from Contract risk process to Not contracted.
- After the owner closes the request, the due diligence request changes from Not contracted to Rejected.
- All stakeholders are notified that the engagement isn’t contracted and onboarding is rejected.
The owner can reopen the request and the due diligence request's state will update to the Ready for TPRM approval state.
- Contract Risk process (Contract terminated)
- When the engagement is being offboarded and a contract is no longer required, you can approve the termination of the contract by selecting Contract terminated. The following actions then take place:
- The due diligence request's state is updated from Contract risk process to Contract terminated.
- The Termination date is updated with the current date.
- Contract Risk process (Contract not terminated)
If the engagement is being offboarded (relationship terminated) and the contract can’t be terminated, you can reject the request by selecting Contract not terminated from the Details tab on the due diligence request record page.
The following actions then take place:- A required Justification field appears. You must enter an explanation for rejecting the request.
- The due diligence request's state is updated from Contract risk process to Contract not terminated.
- After the owner closes the request, the engagement is Rejected and all stakeholders are notified that the contract isn’t terminated.
- Contract Risk process (Contract not renewed)
If the engagement is being reviewed for renewal and the contract can’t be renewed, you can reject the engagement by selecting Contract not renewed.
The following actions then take place:- A required Justification field appears. You enter an explanation for rejecting the engagement.
- The due diligence request's state is updated from Contract risk process to Contract not renewed.
- After the owner closes the request, the engagement is Rejected and all stakeholders are notified that the contract isn’t renewed.
- Contract Risk process (Request additional due diligence)
-
If you require additional due diligence, you can reject the engagement by selecting Request additional due diligence from the Details tab on the due diligence request record page.
The following actions then take place:- A required Justification field appears. You must enter an explanation for requesting additional due diligence.
- The due diligence request's state is updated from Contract risk process to Due diligence.
- After the owner closes the request, it’s updated to the Due diligence process state and all stakeholders are notified that the engagement requires additional due diligence.
- Either you, as the contract negotiator, or the owner can reopen the assessment and attach a new questionnaire to restart the process.
After the contract risk process is completed, the owner receives an email notification. Only the Third-party risk manager or owner can close a due diligence request.