CBA upgrades its third-party risk management

By
Follow google news

Opens the door to AI optimisations.

In summary

  • CBA is five to six weeks from migrating 5000 suppliers onto ServiceNow's third-party risk management platform, completing a shift that began with non-supplier third-parties in April last year.
  • The uplift was driven partly by the CPS230 prudential standard, which requires institutions to manage vendor and third-party risk to the same standard as in-house systems.
  • Once suppliers and non-suppliers are both on the one platform, CBA intends to use Now Assist AI to help analyse compliance reports and guide risk assessments.
CBA upgrades its third-party risk management
(L-R) Greg Johnstone and Stephen Bombardiere.

CBA is weeks away from shifting 5000 suppliers across to a new third-party risk management platform it currently uses to manage risks associated with non-supplier third-parties to the bank.

The project, revealed at ServiceNow World Forum in Sydney at the end of last month, centralises vendor risk management and opens the door to using AI to assist with oversight and compliance.

The bank is using ServiceNow’s third-party risk management (TPRM) module as the technical basis of the platform, along with Now Assist for the AI use cases.

CBA initially started using ServiceNow in its procurement operations “several years ago”, according to executive product owner Greg Johnstone.

This saw the bank implement another ServiceNow module, SPO - sourcing and procurement operations.

“[SPO] was really brought in to address some challenges and complexities around supplier onboarding,” Johnstone said.

The advent of the CPS230 prudential standard, which directs institutions to have a better handle on vendor and third-party risk and to manage it to the same standard as in-house systems - drove the bank to review and uplift its third-party risk management.

Johnstone said that with significant “organisational trust” already built up in SPO, the bank elected to expand its use of ServiceNow to cover third-party risk management as well.

In shifting its vendor risk management to ServiceNow, the bank started with “non-supplier third-parties” - typically professional services type suppliers.

“We had a really strong supplier-focused third-party risk management product and processes, but we were a bit lacking in the non-supplier third-party space. Our non-suppliers were quite sporadically managed: different teams did it in different ways,” crew lead for business platforms in group corporate services Stephen Bombardiere said.

Johnstone concurred: “We were already relatively mature in the supplier space, so we decided to focus and tackle non-suppliers first.”

Risk management for non-supplier third-parties was centralised in ServiceNow’s TPRM module in April last year, “just before CPS230 went live,” Bombardiere said.

That enabled the bank to meet its CPS230 obligations, first and foremost, but also “to extend organisational confidence out of sourcing and procurement and into the third-party risk space,” Johnstone said.

“As we've migrated initially non-supplier, [we’re] now focused on our supplier migration, which … is hitting us in about five-to-six weeks, so we're in the absolute thick of it at the moment.”

“We're five weeks out from cutting over something like 5000 suppliers and [completing] the full migration [to ServiceNow TPRM],” Bombardiere said.

Once all risk management for suppliers and non-suppliers is run through the one platform, the intent is to start making use of AI to streamline risk assessment processes.

Bombardiere suggested that AI could help analyse compliance reports and provide guidance when assessing risks.

“Today, we might have a SOC2 report that comes through. Someone needs to read that top to bottom, understand what's in there, make a judgement and create controls,” he said.

“One of the goals for us is to use document ingestion from [ServiceNow’s] Now Assist to effectively cut out all of that hard work and give that analysis to a risk professional to assess.

“Some other stuff that we’re thinking about is if I'm completing a risk assessment, how I can have parallel advice when I'm responding - [such as] examples of how you might respond or where you're maybe missing the mark in terms of service descriptions or what it actually means. 

“A lot of the feedback we get is, 'I don't understand the questions, they're too risk-heavy. I'm doing this once'. So, where can AI plug those gaps and make it a more streamlined experience as [they] go through the process?”

Ry Crozier attended ServiceNow World Forum in Sydney as a guest of ServiceNow.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
© Digital Nation
Tags:

Most Read Articles

NAB's long-time technology executive Patrick Wright to retire

NAB's long-time technology executive Patrick Wright to retire

CBA's AI Companion is expected to face some hard questions

CBA's AI Companion is expected to face some hard questions

Westpac at work on a new agentic ecosystem

Westpac at work on a new agentic ecosystem

Suncorp drives AI more deeply into insurance processes

Suncorp drives AI more deeply into insurance processes

Log In

  |  Forgot your password?