Banking Procurement and Third-Party Risk Training Course
| Course code | SD-P-028 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Procurement |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Bank procurement teams must secure competitive value while proving that outsourced services, cloud providers, payment partners and critical suppliers can meet stringent resilience, security, conduct and regulatory expectations. A weak supplier assessment can expose the bank to operational disruption, data compromise, concentration risk, customer harm and difficult-to-defend procurement decisions. This course equips professionals to connect sourcing activity with third-party risk governance from initial demand through contract award, onboarding, monitoring and exit.
Participants learn to segment suppliers by criticality, map outsourced-service dependencies, build risk-based due diligence packs and evaluate bids beyond price. The course covers procurement controls, inherent and residual risk scoring, financial viability review, information-security assessment, sanctions and adverse-media screening, subcontractor governance, service-level design, business continuity testing and concentration-risk analysis. Participants practise translating risk findings into award recommendations, remediation requirements, contractual clauses and accountable approval routes.
Instructor-led workshops use a realistic banking outsourcing case involving a cloud-enabled payments service. Participants work with supplier scorecards, risk registers, control questionnaires, contract schedules and governance dashboards. By the end of the week, each participant produces a bank-ready third-party procurement pack: a supplier segmentation rationale, evaluation matrix, due diligence plan, risk treatment register, contract-control schedule and 90-day onboarding monitoring plan.
The programme is designed for experienced procurement, vendor-management, operational-risk, compliance, technology-risk and business-continuity professionals who influence supplier selection or oversee material third-party relationships in banks and regulated financial institutions.
Course objectives
By the end of this course, participants will be able to:
- Classify banking suppliers using a criticality and inherent-risk segmentation model
- Construct a weighted bid evaluation matrix that combines commercial, operational, cyber and resilience criteria
- Perform supplier due diligence using financial, sanctions, information-security and subcontractor evidence
- Calculate residual third-party risk and document risk acceptance, remediation and escalation decisions
- Draft contractual control schedules covering audit rights, service levels, data protection, continuity and exit
- Map fourth-party dependencies and identify concentration-risk exposures across critical services
- Build a third-party risk register with owners, treatment actions, due dates and key risk indicators
- Present a defensible sourcing recommendation to a procurement and risk approval committee
Benefits of attending
For you
- Gain a repeatable method for defending supplier awards where risk considerations outweigh lowest price
- Produce stronger procurement papers for material outsourcing and critical-service decisions
- Build credibility with risk, compliance, cyber-security and legal stakeholders through shared control language
- Learn to turn supplier assurance evidence into practical remediation, contract and monitoring actions
- Prepare for senior procurement, vendor-risk or outsourcing-governance responsibilities in regulated banking
For your organisation
- Improve consistency of risk-based sourcing decisions across business units and procurement categories
- Reduce exposure to poorly assessed suppliers, hidden subcontractors and unmanaged fourth-party dependencies
- Strengthen evidence trails for outsourcing governance, internal audit and regulatory examination
- Embed contract controls and exit requirements before critical suppliers are onboarded
- Create clearer ownership of supplier remediation, monitoring indicators and risk acceptance decisions
Target competencies
Who should attend
- Bank Procurement Managers — who lead supplier selection and need to evidence risk-informed award decisions
- Category Managers — who source technology, professional services or operational suppliers with material bank dependencies
- Third-Party Risk Managers — who design due diligence, monitoring and escalation for vendor populations
- Vendor Relationship Managers — who oversee supplier performance, remediation and renewal decisions
- Operational Risk and Resilience Professionals — who assess outsourcing impacts on important business services
- Information Security and Technology Risk Managers — who evaluate control evidence from cloud and technology providers
Requirements and prerequisites
Participants should have practical experience of procurement, supplier management, operational risk, information security, compliance or outsourcing governance in a bank or similarly regulated financial institution. They should understand the basic procurement lifecycle, RFPs, supplier due diligence, contracts and risk ratings, and be comfortable working with Excel-style scoring tables and policy documents. Familiarity with outsourcing guidance, business continuity or information-security questionnaires is useful but not essential. This is not a beginner procurement course: no prior use of SAP Ariba, RSA Archer or OneTrust is required, and no coding, audit qualification or legal drafting background is assumed.
Training methodology
The course combines instructor-led banking procurement sessions with document-based workshops and facilitated challenge panels. Participants analyse a realistic payments-service sourcing case, review supplier financial and assurance evidence, score competing bids, identify fourth-party dependencies and negotiate contract-control priorities. Small groups prepare approval-committee papers and test one another's recommendations against risk appetite, resilience requirements and commercial constraints. Each day closes with a practical artefact that feeds an end-of-course third-party procurement pack and a 90-day workplace application plan.
Course outline
Day 1: Banking procurement governance and supplier criticality
- Bank procurement lifecycle from demand intake to supplier exit
- Outsourcing, third-party and fourth-party risk definitions
- Critical-service identification and important business service mapping
- Supplier segmentation by spend, access, substitutability and service criticality
- Inherent-risk scoring criteria for banking supplier categories
- Three-lines-of-defence roles in sourcing approvals
- Risk appetite statements and procurement decision thresholds
Workshop: Participants classify a supplier portfolio and produce a criticality matrix with proposed due diligence tiers.
Day 2: Risk-based sourcing and supplier due diligence
- Risk requirements in RFI, RFP and tender documentation
- Weighted evaluation matrices for price, capability, resilience and controls
- Supplier financial viability and going-concern assessment
- Sanctions, adverse-media and beneficial-ownership screening
- Information-security due diligence using control questionnaires
- Data location, cross-border processing and confidentiality assessment
- Subcontractor disclosure and fourth-party transparency requirements
Workshop: Participants evaluate three RFP responses and produce a weighted supplier shortlist with evidence gaps and clarification questions.
Day 3: Third-party risk assessment and treatment
- Inherent versus residual risk calculation
- Control design and operating-effectiveness evidence
- Risk registers, issue taxonomy and remediation tracking
- Business continuity and disaster-recovery assurance review
- Cyber incident notification and breach-management controls
- Concentration risk across suppliers, regions and technology platforms
- Risk acceptance, escalation and approval documentation
Workshop: Participants complete a residual-risk assessment and treatment register for a proposed cloud-enabled payments supplier.
Day 4: Contract controls, onboarding and supplier governance
- Audit rights, access rights and regulatory cooperation clauses
- Service-level agreements, key performance indicators and service credits
- Data protection, retention, encryption and deletion schedules
- Business continuity, testing and recovery obligations
- Subcontracting consent and flow-down control clauses
- Termination assistance, transition planning and exit management
- Supplier onboarding controls and first-90-day monitoring plans
Workshop: Participants draft a contract-control schedule and onboarding governance plan for the selected supplier.
Day 5: Committee decisions and sustainable third-party oversight
- Procurement approval papers and risk narrative structure
- Executive dashboards for supplier risk and remediation status
- Key risk indicators and early-warning threshold design
- Supplier performance reviews and control-attestation cycles
- Material change management for mergers, incidents and new subcontractors
- Renewal, re-tender and exit decision triggers
- Lessons-learned reviews following supplier incidents
Workshop: Participants present a complete sourcing recommendation to a simulated bank approval committee and finalise their 90-day application plan.
Tools & standards covered
SAP Ariba, RSA Archer, OneTrust Third-Party Risk Management, ISO/IEC 27001:2022
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Cape Town · USD 4,200 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
02 – 06 Nov 2026Book
Nairobi · USD 3,000 -
09 – 13 Nov 2026Book
Live Online · USD 1,500 -
09 – 13 Nov 2026Book
Kigali · USD 3,500 -
16 – 20 Nov 2026Book
Live Online · USD 1,500 -
23 – 27 Nov 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Procurement
Proactis Purchase-to-Pay System User Training Course
Purchase-to-pay performance depends on more than policy: users must raise accurate requisitions, select compliant suppliers and catalogues, …
Basware Purchase-to-Pay Automation Training Course
Purchase-to-pay performance is often constrained by fragmented requisitioning, inconsistent approval routes, poor catalogue adoption, invoic…
Procurement Governance and Policy Design for Procurement Directors Training Course
Procurement directors are expected to deliver savings, continuity, compliance and responsible sourcing while operating across complex busine…
Three Lines Model for Procurement Governance Training Course
Procurement decisions are increasingly examined for fairness, delegated authority, conflict management, contract compliance, supplier risk a…