Achieving Executive Alignment on Third-Party Risk Management through Technology

Wednesday, September 30, 2026 | 2:15PM–3:00PM MT
Session Type: Breakout Session
Delivery Format: Presentation
Third parties power higher education IT—from cloud learning platforms to managed security services—but they also introduce shared risk that rarely fits cleanly into one function. In practice, CIO/CISO, Procurement, and Legal often struggle to operate as one team because they measure success differently (speed and outcomes vs. risk, reduction vs. contract defensibility), use different systems of record, and hand work off through email-driven workflows that blur accountability. This session explores why that misalignment persists and how technology can create a single, auditable third party operating rhythm. The session will explore practical approaches such as intake and triage workflows, standardized due diligence questionnaires, automated evidence collection, risk tiering, contract clause libraries and playbooks, exception tracking; and dashboards that connect vendor risk, contracting status, and procurement milestones. We will also discuss integration patterns across vendor risk management (VRM), governance/risk/compliance (GRC), contract life cycle management (CLM), ERP/procurement suites, and identity/security tooling so that stakeholders can see the same facts at the same time. Attendees will leave with the ability to articulate the commonly experienced pain points, how each can be addressed, and considerations when solutioning.

Presenters

  • Jake Braunsdorf

    Senior Manager, Deloitte
  • Jake Lord

    Manager, Deloitte