Third Party Labs Academy core course | Risk and Compliance seat
TPRM Foundations: APAC Financial Services
Practitioner-depth third-party risk management (TPRM) for the people who design the program, set the standard and challenge the rest of the organisation when the standard is not met. Built for Asia-Pacific (APAC) financial services. Six modules with Emery, a graded final assessment, a course e-book with the governance, monitoring and contract tools the modules teach, and hours you can record as continuing professional development (CPD).
Prices in Australian dollars. Third Party Labs is not registered for GST; no GST is charged. Buying for five or more people? Ask us.
Who it is for
Built for the Risk and Compliance seat.
Risk professionals, compliance officers, third-party governance and relationship managers, and operational risk practitioners working at or supporting regulated financial services organisations across the Asia-Pacific region. If you own the TPRM policy, classify third parties, sit on the third-party risk committee or brief the board, this course is written for your seat.
By the end of the course you will be able to
Outcome
Describe the governance a credible program needs (policy, ownership, committee oversight and board reporting) and set out what APAC regulators require at each level.
Outcome
Set a monitoring rhythm that is proportionate to classification, explain the role key performance indicators (KPIs) and service level agreements (SLAs) play in the governance of a third party, and score your monitoring against the Third Party Labs maturity model.
Outcome
Identify the contract provisions APAC regulators require for material arrangements, and explain how to review a contract for the gaps that create regulatory exposure.
Curriculum
Three shared foundations, then three modules built for your seat.
The first three modules are shared across all four Academy core courses, because third-party risk is a shared responsibility and the foundations are the same whichever seat you hold. Module 03 comes in two parts: the eight risk domains, then the eight lifecycle stages. Modules 04 to 06 are written for Risk and Compliance. Take the modules in the order you choose.
- WWelcome
Welcome
Emery welcomes you, shows you your seat at the table, and explains how the course runs and how the certificate is earned. Free to preview.
- 01Module
Third-Party Risk: Where It Sits, Who Owns It, and Why Now
Emery places third-party risk inside the risks your organisation already manages, introduces the four seats at the table, and shows through three verified APAC cases why regulators are raising the standard now.
- 02Module
The APAC Regulators of Third Party Risk Management
A reference module. Thirteen jurisdictions, one panel each: the regulator, the framework, the core considerations and the date that matters. Then the five obligations that recur across almost every APAC framework.
- 03Module
Eight Risk Domains and the Third-Party Lifecycle
One framework, two parts. Part A: the eight risk domains, what each one covers, and the one question each raises about any third party. Part B: the eight lifecycle stages, what each is for, and how the domains and stages work together.
- 04Module
Policy, Ownership, Oversight and Reporting
Built for your seat. Draw your organisation's third-party risk governance on one page: policy, owner, committee, board. What the policy must contain, who approves it, and what the committee, the board and the regulator each see.
- 05Module
Ongoing Monitoring and Program Maturity
Stage seven of the lifecycle. Set a monitoring rhythm that is proportionate to classification, documented and followed. What key performance indicators (KPIs) and service level agreements (SLAs) tell you about how an arrangement is governed. Score your monitoring against the Third Party Labs maturity model and choose three priority actions.
- 06Module
The Contract Provisions APAC Regulators Require, and How to Find the Gaps
Stage five of the lifecycle, seen from the risk and compliance seat. The six provisions APAC regulators expect in a material third-party contract, weak versus strong in plain language, and the method for finding gaps: map, read, rate, escalate.
Presented by Emery, the Third Party Labs Academy presenter, speaking in the voice of Kimberly Brooks. Kimberly is the founder of Third Party Labs and wrote the course from more than 20 years in procurement and third-party risk, at Accenture and PwC and in executive roles at Commonwealth Bank and Westpac working on third-party risk transformation.
How it runs
Self-paced. Assessed. Certificate on passing.
Knowledge checks
A short check after each module
Four questions drawn from a pool of eight, ungraded, with instant feedback. You assess a short scenario the way you would at work. Take the modules in the order you choose.
Final assessment
20 questions, pass mark 70 percent
Questions are drawn from a pool, and a retake gives you different questions. Three attempts. Completion is recorded when you pass.
Certificate
Module-level objectives and CPD hours
Your certificate records your name, the full course title, the completion date, the module learning objectives and your CPD hours.
Course e-book and CPD
Tools you use the day you finish the module.
- Course e-book, read inside the course: a companion page for each module, ten tools, check-in questions for the Responsible Party, three team emails and the sources behind the courseAll modules
- Governance on one page template (Word and Excel)Module 04
- Monitoring Maturity Self-Assessment template (Word and Excel)Module 05
- Contract review worksheet template (Word and Excel)Module 06
- Check-in questions for the Responsible Party (Word and Excel)After the course
Third Party Labs is a risk practice, not a law firm. Use our content to brief your legal team, not to replace them.
This course comprises 3.5 hours of structured, assessed learning: video modules, knowledge checks, practical activities and a graded final assessment (pass mark 70 percent).
Claim 3.5 hours with bodies that use a 60-minute hour, including the Institute of Internal Auditors (IIA) and the Securities and Futures Commission (SFC) in Hong Kong. Claim 4.25 continuing professional education (CPE) hours with ISACA (50-minute basis). Check your own body's rules on self-directed, verifiable CPD before claiming.
Enrol in TPRM Foundations: APAC Financial Services
AUD 249. Start any time, with the Welcome section free to preview. Presented by Emery at Third Party Labs Academy.
Also from Third Party Labs