The Third Party Risk Institute Podcast cover art

The Third Party Risk Institute Podcast

The Third Party Risk Institute Podcast

By: Linda Tuck Chapman
Listen for free

LIMITED TIME OFFER | £0.99/mo for the first 3 months

Premium Plus auto-renews at £8.99/mo after 3 months. Terms apply.

About this listen

Go beyond the headlines with The Third Party Risk Institute Podcast, the official podcast of Third Party Risk Institute.


Each episode brings you into the room with top experts in third-party risk, cybersecurity, procurement, governance, and compliance. Hear how risk leaders tackle real-world challenges, share lessons learned, and stay ahead of evolving threats.


We explore the strategies that work, the mistakes that teach, and the insights you won’t hear anywhere else.


Perfect for risk professionals, procurement leaders, auditors, and decision-makers who want to lead with confidence.


🎧 Subscribe now, new episodes drop monthly on Spotify, Apple Podcasts, YouTube Music, and Amazon Music.

© 2025 Third Party Risk Institute Ltd.
Economics Management Management & Leadership
Episodes
  • Why One Vendor Can Shut Down Your Entire Business | A must know in 2026
    Jan 7 2026

    2025 reshaped how organizations view third-party cyber risk. In this deep-dive episode, we analyze the real incidents that caused operational shutdowns across healthcare, aviation, manufacturing, and financial services.

    You’ll hear how:

    • The Change Healthcare ransomware attack exposed up to 190 million records and triggered a multi-billion-dollar disruption
    • Jaguar Land Rover suffered a six-week global production halt due to a vendor cyber incident
    • Airlines faced airport gridlock after a single IT supplier failure
    • Cloud misconfigurations leaked millions of healthcare records
    • Stolen credentials and MFA bypass techniques accelerated account takeovers
    • CLOP ransomware exploited zero-day vulnerabilities in file transfer and ERP systems
    • Regulators enforced DORA and NIS2 accountability for vendor risk
    • AI-driven cyber attacks are emerging as the next threat wave

    This episode connects cyber risk directly to business continuity, operational resilience, regulatory compliance, and vendor governance, critical insights for risk leaders, CISOs, compliance teams, procurement professionals, and third-party risk practitioners.

    🎧 Listen to understand why vendor ecosystems now represent the single largest source of enterprise risk and what organizations must prioritize going into 2026.

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    Show More Show Less
    15 mins
  • DORA 2026: Exposing Critical Gaps in Financial Third-Party Risk Management (TPRM)
    Dec 17 2025

    In this in-depth episode of The Third Party Risk Institute Podcast, we take a hard look at how the Digital Operational Resilience Act (DORA) is fundamentally changing expectations for third-party risk, cybersecurity, procurement, compliance, and governance teams.

    Rather than treating DORA as another regulatory checkbox, this episode focuses on what DORA will expose inside most third-party risk management programs including gaps that many organizations are not yet prepared to defend during regulatory inspections.

    This conversation goes beyond regulatory summaries. We break down the organizational, operational, and technical impact of DORA, and explain why many existing TPRM programs will struggle to meet the “prove it” resilience standard regulators are now enforcing.

    Together, we unpack:

    • Why DORA is not just an ICT regulation, but a resilience mandate
    • How third-party risk programs are being stress-tested for the first time
    • Where vendor oversight, incident response, and exit strategies fall short
    • Why policies alone will no longer satisfy regulators
    • How real third-party failures explain why DORA exists

    We also examine real-world third-party incidents and outages to show how concentration risk, fourth-party exposure, and untested recovery assumptions can quickly become systemic failures.

    What We Cover in This Episode

    • What DORA will expose in most third-party risk management programs
    • Why operational resilience is replacing checkbox compliance
    • How DORA reshapes expectations for vendor oversight and governance
    • The most common gaps in third-party risk, incident response, and resilience testing
    • Why dependency mapping and critical service identification are failing points
    • How vendor concentration and fourth-party risk are coming under scrutiny
    • What regulators expect organizations to prove, not just document
    • Why exit strategies and substitutability matter more than ever
    • Lessons from real-world third-party outages and cyber incidents
    • How organizations should prepare for DORA inspections and audits

    This Episode Is Essential For:

    • Chief Risk Officers (CROs) and Operational Resilience Leaders
    • Third-Party Risk and Vendor Risk Management Professionals
    • Cybersecurity and ICT Risk Teams
    • Procurement and Strategic Sourcing Leaders
    • Compliance and Governance Professionals
    • Executives accountable for regulatory readiness and resilience

    If your intrested in learning about DORA and getting certified check out our upcoming live class: https://thirdpartyriskinstitute.com/dora/

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    Show More Show Less
    16 mins
  • From Algorithms to Enterprise Risk: How AI Is Reshaping Procurement & Third-Party Oversight
    Nov 27 2025

    In this landmark episode of The Third Party Risk Institute Podcast – The Executive Edge, we sit down with Nathan Spielberg, Co-Founder and Chief Technology Officer of Tamarin AI, for an in-depth and highly practical conversation on how artificial intelligence is truly built, trained, and deployed in enterprise procurement and third-party risk environments.

    With a PhD from Stanford University, a Master’s in Mechanical Engineering and Machine Learning, and an undergraduate degree from MIT, Nathan brings rare technical depth combined with real-world enterprise application experience. His work spans machine learning, autonomous systems, reinforcement learning, and AI-driven procurement intelligence.

    This episode goes far beyond surface-level AI discussions. Together, we unpack:

    • How AI models are actually built
    • Why data quality determines everything
    • How algorithms, training, and evaluation really work
    • Where the biggest hidden enterprise risks live
    • Why “AI inside your organization” does NOT automatically mean it is secure

    We also explore how AI is reshaping procurement decision-making, where organizations are unknowingly exposed through fourth-party AI model dependencies, and why explainability and continuous validation are becoming regulatory and board-level concerns.

    What We Cover in This Episode

    • How AI models, algorithms, and data interact inside enterprise systems
    • The real difference between supervised, unsupervised, and reinforcement learning
    • Why most organizations underestimate AI risk inside their procurement and vendor platforms
    • How training, fine-tuning, retrieval, and model evaluation actually work
    • Why “garbage in, garbage out” is the single biggest AI failure point
    • The hidden fourth-party risk created by outsourced AI models
    • Why explainability remains one of the hardest unresolved challenges in AI
    • How organizations should think about continuous AI testing and performance drift
    • The growing importance of AI bills of materials and model transparency
    • Key public AI risk intelligence sources every risk leader should monitor

    This Episode Is Essential For:

    • Chief Risk Officers (CROs) and Chief Information Officers (CIOs)
    • Chief Procurement Officers and Strategic Sourcing Leaders
    • Third-Party Risk and Vendor Risk Management Professionals
    • Cybersecurity, Data Governance, and Model Risk Teams
    • Compliance Leaders preparing for AI regulatory expectations
    • Executives evaluating AI-enabled procurement and vendor platforms

    🎧 Enjoying the podcast?
    Explore more resources, expert insights, and certification programs at www.thirdpartyriskinstitute.com

    📱 Follow us on LinkedIn for real-world conversations and industry trends: Third Party Risk Institute Ltd.

    📬 Have a question or topic you'd like us to cover?
    Email us at: info@thirdpartyriskinstitute.com

    Show More Show Less
    55 mins
No reviews yet