Accessibility Statement Skip Navigation
  • Resources
  • Investor Relations
  • Journalists
  • Agencies
  • Client Login
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • English-only
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business & Money
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Overseas Real Estate (non-US)
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Congressional & Presidential Campaigns
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • U.S. State Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

      • In-Language News

      • Arabic
      • español
      • português
      • Česko
      • Danmark
      • Deutschland
      • España
      • France
      • Italia
      • Nederland
      • Norge
      • Polska
      • Portugal
      • Россия
      • Slovensko
      • Suomi
      • Sverige
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Hamburger menu
  • PR Newswire: news distribution, targeting and monitoring
  • Send a Release
    • ALL CONTACT INFO
    • Contact Us

      888-776-0942
      from 8 AM - 10 PM ET

  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business & Money
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • Explore Our Platform
  • Plan Campaigns
  • Create with AI
  • Distribute Press Releases
  • Amplify Content
  • All Products
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices
  • Send a Release
  • Client Login
  • Resources
  • Blog
  • Journalists
  • RSS

Survey Reveals Significant Risk Gaps between Companies and Their Vendors, According to Study from Protiviti and Shared Assessments

Shared Assessments and Protiviti benchmark current industry practices and find serious vulnerabilities; improvements needed in governance, policies, standards, and procedures

Protiviti logo. (PRNewsFoto/Protiviti) (PRNewsFoto/)

News provided by

Protiviti

May 19, 2014, 01:00 ET

Share this article

Share toX

Share this article

Share toX

SANTA FE, N.M. and MENLO PARK, Calif., May 19, 2014 /PRNewswire/ -- Organizations are failing to adequately address information technology and security risks that emerge from outsourcing and partnering with third-party vendors, according to a new survey by Shared Assessments Program (http://SharedAssessments.org/) and global consulting firm Protiviti (www.protiviti.com) that examines organizations' current vendor risk management programs.

Continue Reading
Organizations are failing to adequately address information technology and security risks that emerge from outsourcing and partnering with third-party vendors, according to a new survey by Shared Assessments Program http://SharedAssessments.org/) and global consulting firm Protiviti (www.protiviti.com) that examines organizations’ current vendor risk management programs. The study benchmarks current industry practices and find serious vulnerabilities; improvements needed in governance, policies, standards, and procedures. Download a complimentary copy of the survey at www.protiviti.com/vendor-risk. (PRNewsFoto/Protiviti)
Organizations are failing to adequately address information technology and security risks that emerge from outsourcing and partnering with third-party vendors, according to a new survey by Shared Assessments Program http://SharedAssessments.org/) and global consulting firm Protiviti (www.protiviti.com) that examines organizations’ current vendor risk management programs. The study benchmarks current industry practices and find serious vulnerabilities; improvements needed in governance, policies, standards, and procedures. Download a complimentary copy of the survey at www.protiviti.com/vendor-risk. (PRNewsFoto/Protiviti)

Despite the extensive range of standards and regulations in the business environment today, and the need for increased vigilance due to highly publicized data breaches and cyber threats, the benchmarking study, titled 2014 Vendor Risk Management Benchmark Study (www.protiviti.com/vendor-risk), found that companies lack mature vendor risk management practices and do not have the necessary resources and staff to meet best practice standards.

"Managing the risks associated with outsourced services and vendor relationships is one of the many challenges facing organizations when it comes to data security," said Rocco Grillo, a managing director with Protiviti and the firm's global leader for incident response and forensic investigations. "Many companies aren't adequately or effectively protecting themselves from exposure to vendor outsourcing risks. This could result in their potential exposure to system compromise, fraudulent abuse of data and, in some cases, regulatory exposures and fines, which could have significant impact on their brands and reputations."

Nearly 450 IT and risk management professionals rated their organizations on the Vendor Risk Management Maturity Model (VRMMM), a best practice tool from Shared Assessments that measures the quality and maturity of an existing risk management program. Respondents scored more than 100 characteristics about their organizations' vendor risk management strategies on a maturity scale of 1 to 5 (lowest to highest) across eight categories (average scores shown below):

  • Program Governance (2.9)
  • Policies, Standards and Procedures (2.9)
  • Contracts (3.0)
  • Vendor Risk Identification and Analysis (2.7)
  • Skills and Expertise (2.3)
  • Communication and Information Sharing (2.6)
  • Tools, Measurement and Analysis (2.4)
  • Monitoring and Review (2.9)

"While the needs to manage vendor risk vary by specific company profile and needs, we found that organizations are still falling short of best practice recommendations," said Catherine Allen, chairman and CEO of The Santa Fe Group, which manages the Shared Assessments Program.  "The increased use of third parties could create a wider gap for risk managers that can only be addressed through closer attention to consistency in policies, procedures and governance. Failing to include the necessary components may result in vendor risks going undetected, with potentially devastating results."

Key Findings from the Survey

  • Financial Services Organizations Outperform Other Industries. Although all companies had ratings that were below the desired range, the financial services industry had more mature risk management programs across key categories than other sectors. This is largely driven by stricter guidelines for companies in the sector and by the highly regulated nature of the industry.
  • Lackluster Procedures for Assessing Vendors. Organizations fail to have mature processes in place for reviewing vendors periodically through the course of an engagement, as well as for establishing criteria and process around the end of a vendor relationship. Given the potential risk involved with third parties, companies should have stronger policies and guidelines to ensure they are protected at the beginning of an engagement, through the course of the relationship via ongoing risk reviews, and during the exit process.
  • A Need for Training, Staffing and Resources. Companies don't spend enough time assessing their own skill sets and deficiencies in terms of vendor risk management – nor are they proactive about training and improving areas where employees' knowledge is inadequate. The overall investment in resources to better manage vendor risk is below average for most companies.

Resources Available to Learn More

The 2014 Vendor Risk Management Survey precedes the seventh annual Shared Assessments Summit, to be held in Boston on May 19 – May 21, 2014. Protiviti's Rocco Grillo will be a panelist in the session titled, "Shared Assessments Program 2014: Moving Beyond the Tools" on Tuesday, May 20.

Additionally, Protiviti will host a complimentary webinar, led by Grillo and Brad Keller, senior vice president and program director of The Santa Fe Group (which manages the Shared Assessments Program), to discuss the results of the survey on June 3, 2014, at 10:00 a.m. PDT. They will be joined by guest speaker Tom Garrubba, senior privacy manager with CVS Caremark. To register, visit www.protiviti.com/vendor-risk. Grillo and Keller have also recorded a podcast in which they offer insights into what companies can do to raise their vendor risk management maturity levels.

To download a complimentary copy of the survey report, 2014 Vendor Risk Management Benchmark Study, please visit: www.protiviti.com/vendor-risk. The site also hosts an infographic of the survey's highlights and a benchmarking tool to compare the user's results to the survey respondents' results.

About the Shared Assessments Program

The Shared Assessments Program is the trusted source in third-party risk management, with resources to effectively manage the critical components of the vendor risk management lifecycle, creating efficiencies and lowering costs for all participants. The Program keeps current with regulations, industry standards and guidelines, and the current threat environment. It is adopted globally across a broad range of industries, both by service providers and their customers. Through membership and use of the Shared Assessments Program Tools (the Agreed Upon Procedures, Standard Information Gathering questionnaire and Vendor Risk Management Maturity Model), Shared Assessments offers companies and their service providers a faster, more efficient and less costly means of conducting rigorous assessments of controls for IT and data security, privacy and business continuity. The Shared Assessments Program is managed by The Santa Fe Group (www.santa-fe-group.com), a strategic consulting company based in Santa Fe, New Mexico.

Shared Assessments Program members are national and international organizations of all sizes that understand the importance of comprehensive standards for managing third-party risk. They include financial institutions, healthcare organizations, energy/utility providers, retailers and telecommunications companies. They are service providers of all sizes, consulting companies, and assessment firms. They are the best in their class, members of a global community of vendor risk management professionals who understand the value of implementing efficient and effective industry-standard practices.

About Protiviti
Protiviti (www.protiviti.com) is a global consulting firm that helps companies solve problems in finance, technology, operations, governance, risk and internal audit, and has served more than 40 percent of FORTUNE 1000® and FORTUNE Global 500® companies. Protiviti and its independently owned Member Firms serve clients through a network of more than 70 locations in over 20 countries. The firm also works with smaller, growing companies, including those looking to go public, as well as with government agencies.

Protiviti is a wholly owned subsidiary of Robert Half (NYSE: RHI). Founded in 1948, Robert Half is a member of the S&P 500 index.

Protiviti is not licensed or registered as a public accounting firm and does not issue opinions on financial statements or offer attestation services.

Photo - http://photos.prnewswire.com/prnh/20140519/88921
Logo - http://photos.prnewswire.com/prnh/20090115/AQTH541LOGO

SOURCE Protiviti

21%

more press release views with 
Request a Demo

Modal title

Also from this source

Nearly 70% of Global Executives Are Optimistic About Growth Opportunities in Next 2-3 Years, Protiviti and NC State ERM Initiative Reveal in Global Survey

Nearly 70% of Global Executives Are Optimistic About Growth Opportunities in Next 2-3 Years, Protiviti and NC State ERM Initiative Reveal in Global Survey

Despite economic uncertainty, geopolitical tensions and rapid tech disruption, global business leaders are looking ahead with confidence. According...

Protiviti Receives 2025-2026 Microsoft AI Business Solutions Inner Circle Award

Protiviti Receives 2025-2026 Microsoft AI Business Solutions Inner Circle Award

Global consulting firm Protiviti has been selected for the AI Business Solution's 2025-2026 Microsoft Inner Circle. Participation within Inner Circle ...

More Releases From This Source

Explore

Computer & Electronics

Computer & Electronics

High Tech Security

High Tech Security

Surveys, Polls and Research

Surveys, Polls and Research

News Releases in Similar Topics

Contact PR Newswire

  • Call PR Newswire at 888-776-0942
    from 8 AM - 9 PM ET
  • Chat with an Expert
  • General Inquiries
  • Editorial Bureaus
  • Partnerships
  • Media Inquiries
  • Worldwide Offices

Products

  • For Marketers
  • For Public Relations
  • For IR & Compliance
  • For Agency
  • All Products

About

  • About PR Newswire
  • About Cision
  • Become a Publishing Partner
  • Become a Channel Partner
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Italy
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United Kingdom
  • Vietnam

My Services

  • All New Releases
  • Platform Login
  • ProfNet
  • Data Privacy

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact PR Newswire

Products

About

My Services
  • All News Releases
  • Platform Login
  • ProfNet
Call PR Newswire at
888-776-0942
  • Terms of Use
  • Privacy Policy
  • Information Security Policy
  • Site Map
  • RSS
  • Cookies
Copyright © 2025 Cision US Inc.