The Third Party Risk Institute Podcast

Linda Tuck Chapman

Go beyond the headlines with The Third Party Risk Institute Podcast, the official podcast of Third Party Risk Institute. Each episode brings you into the room with top experts in third-party risk, cybersecurity, procurement, governance, and compliance. Hear how risk leaders tackle real-world challenges, share lessons learned, and stay ahead of evolving threats. We explore the strategies that work, the mistakes that teach, and the insights you won’t hear anywhere else. Perfect for risk professionals, procurement leaders, auditors, and decision-makers who want to lead with confidence. 🎧 Subscribe now, new episodes drop monthly on Spotify, Apple Podcasts, YouTube Music, and Amazon Music.

Episodes

  1. 4d ago

    Governing AI Risk: The RIVER Charter, Third-Party Risk & Enterprise Resilience with Alex Golbin

    What happens when AI capabilities advance faster than the organizations adopting them? In this episode of The Third Party Risk Institute Podcast, Linda Tuck Chapman sits down with Alex Golbin, author and senior financial services executive with more than two decades of experience across enterprise risk, technology and data transformation, operational resilience, regulatory remediation, and AI governance.  The conversation centers on Alex’s new book, Governing AI Risk: The River Charter – An Enterprise Resilience Standard, which combines business fiction with practical risk-management concepts for boards, executives, and risk professionals. The story looks at how seemingly reasonable decisions made today accepting workarounds, relying on third parties, delaying remediation, or giving AI systems greater autonomy can accumulate into interconnected dependencies and future enterprise risk.  Alex’s central argument is not that organizations should slow down AI adoption. Instead, organizations need governance and resilience structures capable of making that speed survivable.  What we cover in this episode: Why AI capability can develop faster than an enterprise's data, governance, controls, operating models, and resilience.The RIVER Charter and its five pillars: Resolve Convergence, Integrate Hybrid Cognition, Validate Risk Debt, Elevate Data Capital, and Reinforce Resilience. What risk debt means and how small risk decisions, exceptions, workarounds, and deferred remediation can accumulate over time.Why traditional vendor assessments need to expand to include AI models, cloud providers, data sources, APIs, material fourth parties, autonomous agents, and other dependencies.Alex’s concept of All Entity Risk Management (AERM) and why organizations may need to look beyond conventional vendor boundaries to understand what their critical business outcomes actually depend on. Why annual questionnaires and point-in-time assessments may not provide enough assurance for rapidly changing AI dependencies and the growing importance of telemetry, control evidence, change signals, outcome monitoring, and reassessment triggers. Where accountability sits when a third-party AI system or autonomous agent contributes to a consequential failure.Why simply having a “human in the loop” may not be enough, and how Alex’s cognitive handshake concept focuses on meaningful collaboration between human judgment and AI while preserving accountability. This episode goes beyond a discussion of AI technology. It examines what AI means for third-party risk management, operational resilience, enterprise risk management, governance, data, accountability, and the extended enterprise. For third-party risk, operational risk, cybersecurity, compliance, governance, procurement, audit, technology risk, and enterprise risk professionals, this conversation raises an increasingly important question: Are our existing risk practices evolving quickly enough for an environment where vendors, models, data, platforms, people, and autonomous AI agents are becoming deeply interconnected? If your intrested in Alex's book here is the link to it: https://www.amazon.com/Governing-Risk-RIVER-Charter-Enterprise/dp/1041095651/ref=tmm_pap_swatch_0?_encoding=UTF8&dib_tag=se&dib=eyJ2IjoiMSJ9.GXtSzMAgRAR2dHq_QLc78Q.rnNTGsUkShYwPWVZOj-yYbE9n46zkO1wMSpX8uk3v_U&qid=1777308121&sr=8-1 🎧 Enjoying the podcast? Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com 📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd. 📬 Have a question or topic you'd like us to cover?  Email us at: info@thirdpartyriskinstitute.com

    Governing AI Risk: The RIVER Charter, Third-Party Risk & Enterprise Resilience with Alex Golbin
  2. Aug 5

    AI Governance That Stands Up to Audit: Evidence, Controls & Third-Party Risk with Dasha Gorovenco

    In this episode of The Third Party Risk Institute Podcast, host Linda Tuck Chapman speaks with Dasha Gorovenco, Executive Director in EY Ireland’s audit practice, about what effective artificial intelligence governance looks like through an external auditor’s lens. Dasha explains why documentation is not the same as evidence, why AI ownership must exist in practice rather than only on paper, and why organizations need to know which AI systems are actually operating across their networks not simply which tools were approved or listed in a vendor contract. Together, Linda and Dasha discuss AI audit evidence, third-party and fourth-party AI risk, SOC and ISO compliance, AI inventories, model testing, regulatory readiness, data sovereignty, cybersecurity risk, and operational resilience. What we cover in this episode: • What external auditors assess when reviewing an AI governance program  • Why policies, contracts, meeting invitations, and process documents do not necessarily prove that controls are operating effectively  • How to define practical AI ownership across business teams, technology, risk, compliance, users, and senior leadership  • Why one Chief AI Officer or AI Risk Officer cannot own every aspect of AI risk  • How organizations can identify approved and unapproved AI within third-party products, software, cloud environments, and business processes  • How functionality-based questions can help identify AI embedded within vendor products and services  • Why SOC reports may not provide sufficient assurance over AI-specific controls  • The growing need for AI inventories, AI Bills of Materials, monitoring, and fourth-party visibility  • Why dynamic AI systems, large language models, algorithms, and automated decisions require ongoing testing  • How organizations can assess AI-generated errors, model bias, inconsistent outputs, and control failures  • What the EU AI Act, DORA, GDPR, and data-sovereignty requirements mean for global organizations  • How AI governance, cybersecurity risk, regulatory compliance, and operational resilience are connected This episode is perfect for: • Board members, Chief Risk Officers, Chief Audit Executives, CISOs, CIOs, and AI governance leaders  • Internal Audit, IT Audit, Risk, Compliance, GRC, and Assurance Professionals  • Third-Party Risk Management and Vendor Risk Management Professionals  • Procurement, Cybersecurity, Privacy, Data Governance, and Model Risk Teams  • Professionals responsible for AI controls, regulatory compliance, operational resilience, and third-party oversight  • Organizations implementing or purchasing AI-enabled products and services 🎧 Enjoying the podcast? Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com 📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd. 📬 Have a question or topic you'd like us to cover?  Email us at: info@thirdpartyriskinstitute.com

    AI Governance That Stands Up to Audit: Evidence, Controls & Third-Party Risk with Dasha Gorovenco
  3. Jun 29

    Stop Treating Every Vendor the Same: Daniel Liu on the Real Work of Third Party Risk

    In this episode of The Third Party Risk Institute Podcast, Linda Tuck Chapman speaks with Daniel Liu, Managing Director of Enterprise Risk Management at TMX Group, about what effective third-party risk management really looks like inside complex, regulated organizations. Daniel shares practical insights from his experience across enterprise risk management, operational risk, financial services, data analytics, and regulatory environments. The conversation explores how operational risk and TPRM functions should work together, why risk culture matters, and why risk teams must move beyond checklists, policies, and one-time due diligence. This episode covers key topics including third-party risk management, operational risk management, enterprise risk management, vendor segmentation, concentration risk, fourth-party risk, exit planning, regulatory expectations, operational resilience, OSFI expectations, first line and second line responsibilities, ongoing monitoring, and risk-based due diligence. Listeners will also hear why vendor segmentation should be based on criticality and inherent risk, not spend or relationship history, and why overlooked risks such as exit risk, subcontractor exposure, change in control, and scope creep can create serious operational and regulatory challenges. This is a valuable conversation for risk leaders, TPRM professionals, procurement teams, compliance officers, auditors, financial services executives, and anyone responsible for building stronger third-party risk and operational resilience programs. 🎧 Enjoying the podcast? Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com 📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd. 📬 Have a question or topic you'd like us to cover?  Email us at: info@thirdpartyriskinstitute.com

    Stop Treating Every Vendor the Same: Daniel Liu on the Real Work of Third Party Risk
  4. Jun 22

    Third-Party Risk Monitoring in 2026: Why Annual Vendor Reviews Are No Longer Enough

    Third-party risk is no longer something organizations can review once a year and file away for audit season. Vendor incidents now move in hours, regulators expect stronger oversight, and a single provider can disrupt hundreds of businesses at once. In this episode of the Third Party Risk Institute Podcast, we discuss why traditional annual questionnaires are falling short and why continuous third-party risk monitoring is becoming a core expectation for risk, procurement, compliance, cybersecurity, and vendor management teams. We cover what continuous monitoring really means, why security ratings should be treated as early-warning signals rather than final answers, and how organizations can monitor vendor risk across cybersecurity, operational resilience, financial health, concentration risk, fourth-party risk, and AI-related vendor exposure. You’ll also hear practical insights on DORA, NIST CSF 2.0, U.S. banking guidance, security ratings, KRIs, vendor risk dashboards, concentration risk, and the operating model needed to turn alerts into action. If your organization still relies heavily on point-in-time assessments, spreadsheets, or annual vendor reviews, this episode will help you rethink what effective third-party risk management should look like in 2026. 🎧 Enjoying the podcast? Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com 📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd. 📬 Have a question or topic you'd like us to cover?  Email us at: info@thirdpartyriskinstitute.com

About

Go beyond the headlines with The Third Party Risk Institute Podcast, the official podcast of Third Party Risk Institute. Each episode brings you into the room with top experts in third-party risk, cybersecurity, procurement, governance, and compliance. Hear how risk leaders tackle real-world challenges, share lessons learned, and stay ahead of evolving threats. We explore the strategies that work, the mistakes that teach, and the insights you won’t hear anywhere else. Perfect for risk professionals, procurement leaders, auditors, and decision-makers who want to lead with confidence. 🎧 Subscribe now, new episodes drop monthly on Spotify, Apple Podcasts, YouTube Music, and Amazon Music.

You Might Also Like