Wow, who would have thought that I would leave a conference hosted by a supplier and feel better about the world and the impact we can have on it? That is exactly the way I felt not once, but twice, at SAP Ariba Live in Texas and in Barcelona. While I adore Tifenn Dano Kwan’s influencer team, particularly Amisha Gandhi, who is the Vice President of Influencer Marketing, and Gale Daikoku, the Global Communities and Ambassador Program Lead, the person who struck a chord most deeply with me was Padmini Ranganathan. She’s the Global Vice President of Sustainability and Risk with SAP Ariba. What first struck me as odd was the combination of “sustainability” and “risk” in her title.
Often when people think of sustainability, they think of one of these two definitions:
In the global supply chain landscape, cybersecurity threats are increasing exponentially. Fortune 500 companies’ sensitive information is leaked because hackers target their vendors and business partners, and organizations that might not be as secure as their corporate buyers. Every supplier and business partner can become an added risk. Working with global companies big and small, one of the most significant opportunities that I've observed is managing multi-tier suppliers and mitigating risk. We can support all our suppliers through secured technology and the principle of “unconditional procurement.”
Daryl Hammett, CSMP, CSP, C3PRMP, General Manager/Chief Operating Officer, ConnXus
When the future you expect never arrives and business predictions fall short of their mark, the culprit is—more often than not—bad or missing data. Procurement staff must ensure their data is accurate from start to finish so that their forecasts have the desired outcomes.
Idioms abound about how to tackle future challenges such as “past results do not guarantee future performance” or conversely, “those who do not learn history are doomed to repeat it.” We have all seen or heard these intuitive phrases. On the surface, they would seem to be at odds. In reality, they address two different concepts associated with using the past (data) to understand, predict and influence the future.
Similarly, when it comes to projects that involve the need for data, whether it is to predict sales to manage inventories or to train a system to automate a process, success hinges on having the right set of data to use as input to the decision making process. Today, where machines are often making decisions, the notion of “right set of data” becomes a lot harder to understand. This is because machines learn in a different way and the rationale for the output they produce is difficult to reconstruct.
Machines do not have the intuition or the critical reasoning that can help to elevate or discount one data point over another. Input data must be accurate, representative, and free from bias so here are some key guidelines about your data to help ensure successful projects:
1. Accurate Data. Having accurate data is essential because a machine can learn on both accurate and inaccurate data, but only accurate data provides the desired results: a machine that provides output, which is reliable.
Greg Council, Vice President of Product Management, Parascript
As a Director in SC&H Group’s Contract Compliance Audit Services practice, Patrick has a few key professional motivations with all of his clients: increasing third-party transparency, optimizing supplier relationships, and improving governance. He works with Fortune 100 companies to evaluate contract compliance in categories such as marketing and advertising, contingent staffing, facilities management, construction, computer hardware/software, MRO, security, events, and office supplies. Projects under Patrick’s leadership have resulted in client savings of over $150 million in addition to practical control developments, valuable process improvements, enhanced earnings, and proven cost-savings initiatives. He is very passionate about helping to influence the operations and cultures of global enterprises, and one of his greatest professional achievements was being able to hand over a $1 million recovery check to his client.
It was the very best one-day event I have attended in my life! The Midwestern Regional SIGnature Event, held on March 6 at the Minneapolis Central Library, was attended by 66 extraordinary third-party risk management and sourcing professionals. Not only was the agenda amazing, but every speaker delivered insightful content and engaged the audience. At the Executive Roundtable, we had thoughtful conversations about many issues. Tom Lutz from U.S. Bank led a “day in the life” discussion that lasted almost 45 minutes because so many people wanted to discuss what he was doing, and it prompted other conversations as well.
In our opening session, Linda Tuck Chapman, a Sourcing Supernova Hall of Fame inductee, knocked it out of the park by delivering an interactive workshop on third-party risk management. People said that their two hours of training FLEW BY. When the group joined back together, we had an incredible presentation by Rohan Ranadive from BB&T about building an AI-powered digital workforce which prompted so many questions, I had to stop them to stay on agenda! Then we had an absolutely inspiring one-hour talk by Nancy Brooks, the CPO of Best Buy. Nancy shared that she had declined previous invitations to speak, because she doesn’t care for speaking engagements, but she agreed to speak at SIG’s event because she had a story that needed to be shared about her team. We are thrilled that she joined us. She engaged everyone with Best Buy’s story the entire time and Nancy’s team was so proud to be there.
Hundreds, thousands, or even tens of thousands of third parties power your company every minute of every day, in all your markets and geographies, for every product and service. Third parties are everywhere, in virtually every part of your business. You have less control over third parties than over your internal operations, so getting this right is essential for your company’s success.
Third-party relationships are complicated. But the “right” third parties, if thoughtfully evaluated, managed and controlled, deliver what you contracted for and serve up many opportunities to be better. Better means new products, services and markets. Better means access to specialized top talent, processes and technology. Better means less risk.
Unfortunately, risk is everywhere and even though technology is advancing in leaps and bounds, operational ecosystems are growing more complex every day. Consequently, risk events, cyber attacks, fraud, data corruption and privacy breaches are becoming commonplace, and are too often the fault of a careless third party. The proliferation of third-party relationships and new technologies means that it’s hard for companies to stay on top of third-party risks, and even harder to implement effective controls, monitoring and oversight.
Management of third-party risk is a relatively new discipline – involving a new set of skills, rigorous methodologies, well-crafted tools and advanced technologies. But proactive professionals need to learn the language of risk and learn it quickly because everyone is now a risk manager and everyone is responsible for effective and efficient risk management, particularly for critical third parties.
Linda Tuck Chapman, Third Party Management advisor, author, popular speaker & President, Ontala
Keynote speakers, thought leaders and industry publications show no signs of slowing when it comes to evangelizing the benefits of the supply chain’s digital transformation. With its promises to save you time and money, the market has exploded with offerings of cloud-based solutions, IoT devices and a legion of outsourced practitioners who can make all of your spend visibility and risk management dreams come true. But for all the benefits touted, what is often left out of the conversation is the topic of security, especially as it relates to third-party vendors.
The Path of Least Resistance
As hackers become cleverer in their approaches, they’ve moved from directly attacking large organizations to exploiting vulnerabilities and penetrating third-party cloud software, apps and IoT devices to implant malware directly into the software or steal login credentials. “The challenge with supply chains is that they are multifaceted and there are many places where a hacker can enter,” says Brandon Curry, Senior Vice President with NTT Communications. Curry, who is also a Certified Ethical Hacker, frequently reports on trends in cloud and supply chain software security. He notes that the top cost of a supply chain breach is legal and reputational costs, with software supply chain attacks costing an average $1.1 million per attack globally.
Compromised software is one of the primary causes of supply chain software breaches, and the damage isn’t limited to grabbing customer credit card numbers or personally identifiable information (PII). Hackers are also looking to steal intellectual property, mine your customer base, counterfeit your product and take over your market share.
Think environmental, social and governance (ESG) factors only matter to specialist investors? While ESG standards may have been the exclusive purview of sustainability investors a few decades ago, that is no longer the case. “Only two decades ago, concerns about climate change, water scarcity, exposure to corruption, working conditions in the supply chain and gender equality were barely on the agenda of company executives. They were considered externalities or were dealt with through philanthropic approaches with little or no impact on the bottom line,” noted Harvard Professor of Management Practices Dr. Robert Eccles, and former United Nations Global Compact Executive Director Georg Kell. But times have changed.
Just two years ago, the Organization for Economic Co-operation and Development (OECD) began promoting “responsible business conduct for institutional investors” in its Policy Framework for Investment. In it, the OECD encourages investors to engage with corporate leadership on ESG risk and contends that ESG issues represent part of a company’s fiduciary duty when evaluating long-term value. It’s an approach that more institutional investors are taking to heart. In an article on EthicalBoardroom.com, Michelle Edkins, a Managing Director and Global Head of Investment Stewardship at BlackRock writes, “An emphasis on investing for the long-term, changing client and societal expectations, and better data, reporting and research have all influenced a steady mainstreaming of ESG considerations by investors.”
There’s a lot of talk regarding all the ways technology is going to revolutionize procurement. Blockchain can increase supply chain visibility, the Internet of Things (IoT) can change the way our business devices communicate with each other, etc…But what type of innovations are available at the sourcing level?
From paper RFPs to conferences, it seems the way we source business has largely remained the same. Procurement teams are limited to siloed, outdated supplier databases and incomplete business information when attempting to make business decisions. It’s expensive and time-consuming to get a holistic picture of a supplier’s business health and mitigate third-party risk. How can we adapt today’s technology for tomorrow’s sourcing needs? Here are a few innovative ways that your organization can source business:
Daryl Hammett, CSMP, CSP, General Manager/Chief Operating Officer, ConnXus
With the rapid acceleration of cloud software, Internet of Things (IoT) and advancements in FinTech, the financial and technology industries saw significant increases in cyberattacks over the past year. Attackers find vulnerabilities in supply chains and software, capitalize on lax security updates and use social engineering to manipulate end-users.
As hackers become more creative in their subversive techniques, businesses need to become more proactive in educating their workforce and stepping up their cyber incident response plans. Businesses should consult with their vendors, third-party suppliers and stakeholders in every business unit to ensure continuity, mitigate risk and verify that security measures are being employed and regularly updated.
Below are summarized findings from the recent NTT Security Global Threat Intelligence Report that focus specifically on the finance and technology sectors in the Americas, which account for the most highly targeted attack sectors in this region. Recommendations from the National Institute of Standards and Technology Framework are included here as well. Organizations can also look to the Department of Homeland Security’s National Cyber Incident Response Plan for guidance on dealing with and addressing cyber incidents.
Finance and Technology Top the List of Targets
Attacks to the finance sector nearly tripled, accounting for 43 percent of attacks compared with 15 percent the previous year. Attacks targeted at the technology industry sector increased to 27 percent of attacks, up from 11 percent in the previous year. For comparison, manufacturing was the most attacked sector in 2016, with 23 percent of attacks, but has since fallen to five percent of attacks in 2017.