独立调查_如何管理第三方业务关系中的风险(英文版)_26页_1mb
报告摘要
Third Party Risk: Exposing the Gaps Summary
Core Content
This report, commissioned by Thomson Reuters and conducted by an independent agency in late 2016, examines how organizations manage third party risks in their supply chains and business relationships. It highlights the growing complexity and regulatory scrutiny of third party engagements, as well as the challenges organizations face in identifying and mitigating these risks.
Main Findings
- Third Party Risk Awareness: Organizations recognize the importance of managing third party risks, but many lack sufficient knowledge and resources to do so effectively.
- Regulatory Environment: The regulatory landscape is expanding, with more stringent laws and higher penalties for non-compliance, such as the Foreign Corrupt Practices Act (FCPA), UK Bribery Act, and Dodd-Frank Act Section 1502.
- Due Diligence Practices: Only 62% of third parties are subjected to due diligence, with the US having a higher rate at 74%. However, only 36% of organizations fully monitor ongoing risks.
- Risk Perception vs. Reality: While 56% believe they are unlikely to be prosecuted for breaching regulations, the report shows that enforcement actions often lead to increased compliance spending.
- Reputational Risk: Reputational damage is a significant concern, with 53% of respondents identifying it as a key reason for conducting due diligence. Companies are increasingly aware that their reputation is a major asset.
- UBO Knowledge: Only 11% of respondents have sufficient knowledge about Ultimate Beneficial Ownership (UBO), with the US and Singapore being the least informed.
Key Information
Industry and Region Insights
- Industries: TMT (19%), Financial Industry (11%), Industrials (12%), Construction (8%), Professional Services (8%), Retail (6%), Automobile/Parts/Industrial Engineering (9%), Other (13%).
- Regions: Sub-Saharan Africa is perceived as the highest risk area by 54% of respondents, with 65% of those in the region identifying it as high risk.
Job Function Distribution
- Operations: 22%
- Sourcing/Procurement: 23%
- Compliance/Risk: 26%
- Treasury Finance: 13%
- CSR: 11%
- Legal: 10%
- Other: 14%
Due Diligence and Risk Screening
- Due Diligence Conducted: 62% of third parties are assessed.
- Risk Screening: Financial Crime (47%), Bribery and Corruption (42%), UBO (29%), and Slavery/Forced Labour (16%) are the least screened.
- Construction leads in screening for Bribery and Corruption, Forced Labour, and Conflict Minerals.
- Financials are ahead in screening for Financial Crime and UBO.
Gaps and Challenges
- Knowledge Gaps: Nearly half (49%) of respondents feel they are not sufficiently knowledgeable about the risks they face.
- Regulatory Awareness: 14% do not use the FCPA to inform their decisions, and 24% do not use the UK Bribery Act.
- Lack of Resources: 65% of respondents believe the current economic climate encourages taking regulatory risks to win new business.
- Detection Challenges: Nearly two-thirds of respondents know where risks may occur but struggle to detect them due to a lack of budget, time, and data.
- Internal Reporting: 66% of respondents would report a breach internally, while 11% would report externally and 4% would do nothing.
Future Outlook
- Increased Risk Exposure: With more regulation and public awareness, third party risks are expected to rise.
- Growth in Compliance Spending: 92% of organizations increased compliance spending after an enforcement action.
- Personal Liability: 80% of compliance professionals believe their personal liability will increase over the next 12 months.
- Due Diligence Expansion: 77% expect to increase spending on third party due diligence next year.
Recommendations
- Improve Knowledge: Organizations should invest in understanding the full scope of third party risks, including Slavery and Forced Labour, Environmental Crime, and Conflict Minerals.
- Enhance Monitoring: Ongoing monitoring of third parties is essential to detect changes in ownership or operations.
- Localize Risk Management: While centralized programs are common, local presence is needed to address region-specific risks.
- Training and Awareness: Training programs for both corporate staff and third parties are critical, especially for SMEs which lag behind large corporations in implementation.
Conclusion
Despite awareness of the risks and benefits of third party relationships, many organizations still struggle with effective risk management. The report underscores the need for a more comprehensive and proactive approach to due diligence and monitoring, with a focus on regulatory compliance, reputational protection, and the identification of hidden risks.
试读结束,高清完整版pdf/doc/ppt,请点下载