Nigerian Seminars and Trainings

Search all upcoming seminars, conferences, short management courses and training in Nigeria and around the World

business logo

Third-Party and Vendor Risk Management

By: Lexar Business Support Limited

Lagos State, Nigeria

15 - 16 Sep, 2026  2 day

Follow Event

Delivery Mode: Physical

  

NGN 250,000

Venue: 17th floor western house, 8/10 broad street, Lagos state.

Event Location

The increasing outsourcing of business processes, technology, cloud services, payment platforms, cybersecurity solutions, logistics, professional services and other critical activities has made organisations increasingly dependent on external vendors and service providers.

While third-party relationships can provide organisations with specialised expertise, cost efficiencies, scalability, innovation and operational flexibility, they also transfer or introduce risks that may be difficult for the organisation to control directly. Financial institutions, for example, may rely on vendors for payment processing, IT infrastructure, cybersecurity, AML monitoring, cloud services, customer support and other critical functions.

The Financial Stability Board has noted that growing reliance on third-party providers can create risks to critical services and operational resilience if these relationships are not properly managed.

Modern vendor risk management has therefore evolved beyond simply checking whether a supplier can deliver a product or service. Organisations are expected to assess the full lifecycle of the vendor relationship from initial selection and due diligence through contracting, onboarding, performance monitoring, incident management and eventual termination.

For Nigerian financial institutions, this is particularly relevant. The CBN's Risk-Based Cybersecurity Framework requires relevant financial institutions to implement third-party risk management processes covering vendor selection, due diligence, contract negotiations, ongoing monitoring and incident response. It also addresses contractual audit rights, regulatory standards, business continuity testing and third-party assessments.

International regulatory expectations similarly emphasise risk-based due diligence, contractual controls, continuous monitoring, operational resilience and effective exit arrangements.

This course is therefore designed to equip participants with the knowledge and practical tools required to establish, strengthen and manage an effective Third-Party and Vendor Risk Management (TPVRM) framework.

Course Objectives

At the end of the training, participants will be able to:

  1. Understand the fundamentals of Third-Party and Vendor Risk Management and its importance to organisational resilience.
  2. Identify the major risks associated with third-party relationships, including:
    • Operational risk
    • Cybersecurity risk
    • Data privacy risk
    • Financial risk
    • Legal and regulatory risk
    • Reputational risk
    • Strategic risk
    • Concentration risk
    • Business continuity risk
    • Supply-chain and fourth-party risk.
  3. Develop a risk-based vendor classification and segmentation framework for identifying critical and non-critical vendors.
  4. Conduct effective vendor due diligence and pre-contract risk assessments.
  5. Evaluate vendors' financial stability, operational capability, cybersecurity controls, regulatory compliance and business continuity arrangements.
  6. Develop appropriate vendor risk assessment criteria, scoring models and risk-rating methodologies.
  7. Understand how to incorporate risk requirements into vendor contracts, Service Level Agreements (SLAs) and other contractual arrangements.
  8. Establish effective mechanisms for ongoing vendor monitoring and performance management.
  9. Understand how to manage cybersecurity and data protection risks arising from third-party access to organisational systems and information.
  10. Develop appropriate controls for incident notification, escalation and response when a vendor experiences a disruption, cyberattack or data breach.
  11. Understand fourth party and supply-chain risks, including risks arising from a vendor's own suppliers.
  12. Develop effective Business Continuity and Disaster Recovery requirements for critical vendors.
  13. Establish appropriate vendor audit, assurance and compliance-monitoring mechanisms.
  14. Understand how to manage vendor relationships throughout their complete lifecycle—from onboarding to offboarding.
  15. Develop effective vendor exit and transition strategies, including data return/destruction and revocation of system access.
  16. Strengthen governance, accountability and reporting around third-party risk.

Key Benefits to Participants

Participants will gain practical knowledge that they can immediately apply within their organisations.

  • Better Vendor Selection: Participants will learn how to evaluate potential vendors beyond price and service capability, ensuring that suppliers meet the organisation's risk, security, compliance and operational requirements.
  • Improved Due Diligence: Participants will understand how to perform structured vendor due diligence before entering a relationship.
  • Reduced Operational Risk: Effective vendor monitoring can help organisations identify weaknesses before they develop into major operational failures.
  • Stronger Cybersecurity: Participants will learn how to assess vendors' cybersecurity controls and manage risks associated with third-party access to organisational systems and sensitive information.
  • Better Data Protection: The course will help organisations establish controls for protecting customer, employee and corporate data handled by third parties.
  • Stronger Contracts and SLAs: Participants will understand the risk provisions that should be considered in vendor contracts, including audit rights, reporting obligations, security requirements, service levels, incident notification and termination provisions.
  • Improved Regulatory Compliance: Participants will gain a stronger understanding of regulatory expectations surrounding third-party relationships. This is particularly important for regulated sectors such as banking and financial services. CBN guidance, for example, expects third parties to be assessed and contractual obligations to be monitored.
  • Improved Business Continuity: Participants will learn how to assess whether critical vendors can continue providing essential services during disruptions and how to incorporate vendors into business continuity and recovery planning.
  • Better Vendor Performance: The training will help organisations establish KPIs, SLAs, risk indicators and monitoring mechanisms for measuring vendor performance.
  • Improved Incident Response: Participants will learn how to establish appropriate escalation and response procedures when vendors experience cyber incidents, outages, breaches or other disruptions.
  • Better Management of Critical Vendors: Participants will learn how to identify vendors whose failure could significantly affect the organisation and apply stronger controls to those relationships.
  • Management of Fourth-Party Risk: Participants will understand how risks can extend beyond their direct vendors to the vendors' own suppliers and technology providers. This is increasingly recognised as an important component of third-party risk management.
  • Stronger Audit & Assurance: Participants will learn how to use audits, assessments, certifications, reports and other assurance mechanisms to evaluate vendor controls.
  • Effective Vendor Exit Management: Participants will understand how to safely terminate vendor relationships while protecting organisational data, systems and business operations.
  • Enhanced Organisational Resilience: Ultimately, the training helps organisations become more resilient by ensuring that dependence on external providers does not become an unmanaged source of operational, financial or reputational risk.

Who Should Attend?

This programme is particularly suitable for:

  1. Risk & Compliance
    • Chief Risk Officers
    • Risk Managers
    • Enterprise Risk Professionals
    • Operational Risk Officers
    • Compliance Officers
    • Compliance Managers
    • Regulatory Affairs Professionals
  2. Procurement & Vendor Management
    • Procurement Managers
    • Procurement Officers
    • Vendor Managers
    • Supplier Relationship Managers
    • Contract Managers
    • Strategic Sourcing Professionals
    • Supply Chain Managers
  3. IT & Cybersecurity
    • Chief Information Officers
    • Chief Information Security Officers
    • IT Managers
    • IT Risk Professionals
    • Cybersecurity Professionals
    • Information Security Officers
    • Technology Risk Managers
    • Data Protection Officers
  4. Audit & Assurance
    • Internal Auditors
    • External Auditors
    • IT Auditors
    • Information Systems Auditors
    • Forensic Auditors
    • Internal Control Professionals
  5. Banking & Financial Services
    • Bank Executives
    • Credit & Operations Managers
    • Fintech Professionals
    • Payment Service Providers
    • Microfinance Institutions
    • Insurance Professionals
    • Investment and Asset Management Professionals
  6. Management & Leadership
    • CEOs
    • Managing Directors
    • Executive Directors
    • General Managers
    • Department Heads
    • Business Unit Managers
    • Senior Management Professionals
  7. Legal & Corporate Governance
    • Legal Officers
    • Corporate Lawyers
    • Company Secretaries
    • Corporate Governance Professionals
    • Contract Lawyers
  8. Other Professionals
    • Business Continuity Managers
    • Business Resilience Professionals
    • Project Managers
    • Operations Managers
    • Finance Managers
    • Data Governance Professionals
    • Information Governance Professionals
    • Professionals responsible for outsourcing and third-party relationships.

Course Booking

Please use the "Book Now" or "Inquire" buttons on this page to reserve your space or request for more information

17th floor western house, 8/10 broad street, Lagos state. Sep 15 - 16 Sep, 2026

Registration: 00:00:am - 11:00:am

Class Session: 09:00:am - 03:00:am

NGN 250,000.00 + 12,500.00 (VAT)(online:200000)
(Convert Currency)

Amarachi Ekele 07015929935

Lexar