Third Party Cyber Risk Management for Procurement Professionals Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-051
Duration5 days
LevelIntermediate to Advanced
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Procurement teams increasingly make award, renewal and sourcing decisions that introduce cyber exposure long before a supplier connects to systems or handles data. Security questionnaires, supplier assurances and contract clauses are often treated as administrative steps, leaving procurement professionals unable to distinguish a material control gap from an acceptable exception. This course equips participants to challenge supplier evidence, align cyber requirements to the purchase being made, and document risk-based decisions that can withstand review by information security, legal, audit and senior management.

Participants learn how to segment suppliers by inherent cyber risk; define proportionate due-diligence requirements; interpret responses to security questionnaires; evaluate evidence such as ISO 27001 certificates, SOC 2 reports, penetration-test summaries and incident-response procedures; and score findings using a repeatable risk methodology. The course covers security requirements in RFPs, supplier selection criteria, data-processing and subcontractor controls, remediation plans, contractual obligations, monitoring triggers and offboarding considerations. Participants practise converting technical cyber concerns into commercial requirements, approval papers and supplier negotiation positions.

Teaching combines instructor-led analysis with procurement-led casework, supplier-document reviews, scoring workshops and contract-clause exercises. Working in teams, participants assess a simulated high-risk supplier for a cloud-enabled procurement, identify evidence gaps, build a risk register and agree a treatment plan with escalation thresholds. Each participant leaves with a reusable third-party cyber-risk assessment pack containing a supplier segmentation model, due-diligence checklist, scoring matrix, issue log, contract requirements schedule and 90-day implementation plan.

The course is designed for experienced procurement, sourcing, vendor-management and contract-management professionals who work with IT, data-processing, cloud, operational technology or business-critical suppliers. It is equally valuable for procurement leaders seeking a consistent, defensible approach to cyber-risk decisions across categories and regions.

Course objectives

By the end of this course, participants will be able to:

  • Segment suppliers using an inherent-risk model based on data access, system connectivity, service criticality and subcontracting exposure
  • Draft cyber-security requirements for RFPs, supplier questionnaires and evaluation scorecards
  • Interpret ISO 27001 certificates, SOC 2 reports, penetration-test summaries and control evidence for procurement decisions
  • Score supplier control gaps using likelihood, impact, residual-risk and risk-acceptance criteria
  • Build a third-party cyber-risk register with owners, remediation actions, deadlines and escalation thresholds
  • Negotiate contractual controls covering incident notification, audit rights, data handling, subcontractors and exit support
  • Create proportionate supplier remediation plans and monitor closure through governance checkpoints
  • Present a risk-based supplier award or renewal recommendation to security, legal and executive stakeholders

Benefits of attending

For you

  • Gain the confidence to challenge vague supplier security claims without needing to be a cyber-security specialist
  • Build a portfolio-ready third-party risk assessment pack that can be adapted for live procurement categories
  • Strengthen credibility with information security and legal teams by using their evidence and risk language accurately
  • Make defensible award and renewal recommendations where commercial value must be balanced against residual cyber risk
  • Prepare for senior procurement, supplier-risk and technology-sourcing roles with accountability for critical vendors

For your organisation

  • Introduce consistent cyber-risk segmentation before suppliers enter costly tender, award or onboarding stages
  • Reduce reliance on blanket questionnaires by matching due diligence effort to data, connectivity and service criticality
  • Improve supplier selection decisions through evidence-based scoring rather than unverified security assertions
  • Create stronger contractual leverage for incident reporting, remediation, subcontractor control and audit access
  • Provide audit-ready records of accepted risks, mitigation owners, approval routes and supplier follow-up actions

Target competencies

Supplier risk segmentationCyber evidence assessmentSecurity requirements draftingResidual risk scoringContractual control negotiationRemediation governance

Who should attend

  • Procurement Managers — who set sourcing controls and approve supplier award recommendations
  • Strategic Sourcing Specialists — who run RFPs for technology, cloud, data and business-critical services
  • Vendor Management Professionals — who oversee supplier performance, renewals and remediation commitments
  • Contract Managers — who negotiate enforceable security, data-protection and audit provisions
  • Category Managers — who buy complex services and need proportionate cyber due diligence by spend category
  • Procurement Risk and Governance Leads — who design assurance workflows and escalation routes across procurement

Requirements and prerequisites

Participants should have practical experience of sourcing, supplier onboarding, tender evaluation, contract management or vendor governance. They should understand core procurement concepts such as RFPs, evaluation criteria, supplier due diligence, contract schedules and approval gates. Familiarity with basic cyber terms—confidentiality, integrity, availability, access control, incident response, encryption and data classification—is expected; participants do not need to be security engineers. No coding, penetration-testing experience, security certification or prior use of a third-party risk platform is required. A laptop with spreadsheet and document-editing capability is needed for workshops and template development.

Training methodology

The five days combine focused instructor-led teaching with procurement scenarios drawn from cloud, software, managed-service and data-processing contracts. Participants review realistic supplier questionnaires, certificates, SOC reports, incident clauses and remediation evidence rather than abstract control descriptions. Small groups conduct a supplier assessment, compare scoring decisions and defend their recommendation in a simulated award board. Individual work converts the methods into category-specific templates and a 90-day application plan, with instructor feedback on risk logic, escalation wording and the practical usability of each deliverable.

Course outline

Day 1: Cyber risk in the procurement lifecycle

  • Third-party attack paths across cloud, SaaS, managed service and data-processing suppliers
  • Procurement accountability within the three-lines risk model
  • Inherent risk factors: data sensitivity, connectivity, criticality and supplier dependency
  • Supplier segmentation tiers and proportionate assurance requirements
  • Mapping cyber checkpoints to source-to-contract and procure-to-pay stages
  • Cyber risk appetite, tolerance statements and approval authorities
  • Stakeholder roles for procurement, security, legal, privacy and business ownership

Workshop: Participants map a sample procurement lifecycle and produce a supplier-tiering decision for six vendor profiles.

Day 2: Due diligence and evidence evaluation

  • Designing risk-based security questionnaires using the Shared Assessments SIG
  • Using NIST Cybersecurity Framework 2.0 to organise supplier control questions
  • Interpreting ISO/IEC 27001 certification scope, statement of applicability and surveillance status
  • Reading SOC 2 Type II reports, complementary user entity controls and exceptions
  • Assessing penetration-test summaries, vulnerability management evidence and remediation claims
  • Validating cloud security attestations, data-flow diagrams and shared-responsibility boundaries
  • Identifying evidence gaps, contradictions and unsupported supplier assertions

Workshop: Participants review a supplier evidence pack and produce an evidence-gap log with follow-up questions and priority ratings.

Day 3: Risk assessment, scoring and decision making

  • Building a third-party risk register with clear risk statements and affected assets
  • Likelihood and impact scoring for confidentiality, integrity, availability and regulatory exposure
  • Control-effectiveness assessment and residual-risk calculation
  • Risk treatment options: accept, mitigate, transfer, avoid and defer
  • Defining remediation milestones, evidence requirements and accountable owners
  • Establishing escalation thresholds for award, renewal and go-live decisions
  • Preparing risk-acceptance papers for delegated approval authorities

Workshop: Participants score a high-risk cloud supplier, build a residual-risk register and draft an award recommendation for a risk committee.

Day 4: Security requirements and contract controls

  • Translating risk assessments into mandatory, weighted and desirable RFP requirements
  • Writing security schedules aligned to data classification and service criticality
  • Incident-notification timeframes, communication obligations and forensic cooperation clauses
  • Audit rights, assurance reporting and access to independent assessment evidence
  • Subprocessor approval, supply-chain flow-down and location-control provisions
  • Business continuity, disaster recovery, resilience testing and service restoration commitments
  • Exit management, secure data return, deletion certification and transition assistance

Workshop: Participants redline a supplier contract schedule and produce a negotiated cyber-control position for a managed-service engagement.

Day 5: Ongoing monitoring and operating model implementation

  • Configuring supplier records, assessments and issues in OneTrust Third-Party Risk Management
  • Monitoring triggers for material changes, incidents, acquisitions and service-scope expansion
  • Supplier remediation governance, action tracking and overdue-issue escalation
  • Cyber performance indicators and supplier risk dashboards for procurement leadership
  • Renewal reviews and reassessment cadence by supplier risk tier
  • Offboarding controls for access removal, data destruction and retained-record verification
  • Designing a procurement cyber-risk operating model and 90-day rollout plan

Workshop: Participants assemble their complete third-party cyber-risk assessment pack and present a 90-day implementation plan to a simulated procurement leadership panel.

Tools & standards covered

OneTrust Third-Party Risk Management, Shared Assessments SIG, NIST Cybersecurity Framework 2.0, ISO/IEC 27001

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course is designed for procurement professionals who need to make or support supplier decisions involving cyber risk. You should understand basic security terms, but the emphasis is on interpreting evidence, setting requirements and managing decisions rather than configuring technical controls.

Bring a laptop with spreadsheet and document-editing software for scoring, clause-drafting and template exercises. OneTrust Third-Party Risk Management is demonstrated through course materials; participants do not need a live organisational licence or administrator access.

It is most relevant to procurement managers, strategic sourcing specialists, category managers, vendor managers and contract managers buying technology-enabled or data-handling services. Risk and governance leads will also benefit where they are standardising supplier assurance processes.

General cyber courses explain security concepts or management-system requirements. This programme concentrates on the procurement decisions surrounding suppliers: what to ask, how to assess the answers, when to escalate, and how to convert findings into tender and contract requirements.

Participants can use the supplier-tiering model, due-diligence checklist, scoring matrix and issue log on current sourcing events or upcoming renewals. The course also shows how to route exceptions and residual-risk decisions through existing procurement and security governance.

You will leave with a completed third-party cyber-risk assessment pack developed during the course. It includes a segmentation model, evidence checklist, risk register, remediation tracker, contract requirements schedule and a 90-day implementation plan.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Cyber Security Governance for Government and Public Sector Teams Training Course

Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while work…

5 Days Certificate

Okta Identity Engine Access Management Security Training Course

Okta administrators and identity security teams are often expected to strengthen access controls without creating sign-in friction, breaking…

5 Days Certificate

IBM QRadar SIEM Administration and Offence Investigation Training Course

IBM QRadar administrators and SOC analysts are expected to turn high-volume event data into defensible security decisions. That requires mor…

5 Days Certificate

Advanced Cyber Threat Hunting and Incident Response Training Course

Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…