Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

Third Party Risks

Posted on June 4, 2009 by Doug Cornelius
Print Friendly, PDF & Email

compliance-week-red

My notes, live, from Third Party Risks with Matt Tanzer of Tyco International and Chris Nowak of Wyndham Worldwide.

For Tyco they have 110,000 employees around the world, most outside the United States.  Their first step was to identify all of the third parties. This was a big task. They went to their master vendor lists and master customer lists. The the broke them into groups based on risks.

Then they conducted a preliminary risk assessment using a few factors, such as geography, types of payments and payment structure.  With all of that information they took the next step of rationalization and consolidation of the third parties. In higher risk areas, they want to reduce the number of third parties they work with. They will conduct enhanced due diligence on high risk third parties.

They have imposed stricter payment procedures. They require a valid tax invoice, wire transfers (no cash), and only to the actual service provider. It is key to look at the underlying contract to verify the payment amount and type of service.

They have a new program for new vendors:

  • Business Sponsor
  • Business Justification
  • FCPA Certification
  • Questionnaire
  • Risk Assessment/DD
  • Written Agreements
  • Training

Not all elements are required for all third parties. If it is a low-risk type of vendor in a low risk country, they will not require all. High risk parties in high risk parties get an enhanced look.

Chris took over to give his perspective. His company is dealing with land owners, hotel owners, time share owners and employees around the world.

Know your third party:

  • Screen the parties against the OFAC’s SDN list
  • Conduct reviews of their financial statements
  • Learn their reputation
  • Investigate litigation
  • Check for current licenses
  • Understand their Culture

Chris offered some mitigation techniques:

  • SAS 70 Certifications
  • Code of Conduct – The are putting together a code specifically for vendors
  • Other Policies – You want to make sure you understand local law
  • Good Behavior Certification – Failure to certify is a warning sign.
  • Training – You need face to face training to get attention, especially as you move up in corporate seniority
  • Contract language
  • Insurance
  • Stay Involved!!! You need to keep emphasizing the importance of good behavior.

Make sure that the questions you ask are questions that you are also willing to answer. Simply things to make sure you could certify if someone asked you.

(These notes are taken live, so I apologize if I left out anything or misquoted someone. Please forgive any typos or grammatical errors.)

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • When the Lawyer Is Breaking Bad
  • Will Investors Have an Appetite for Semi-Annual Reporting?
  • Special Forces Trading on Insider Knowledge
  • Prediction Markets and Compliance Programs
  • The One with the Line That Goes Straight Up and Right
  • The One with the Crypto Paying for a Mega-Shilling Package
  • The Performance of the SEC in 2025
  • More on the Downsizing of the SEC
  • SEC Enforcement Results for FY 2025
  • Proposed Fundamental Reforms to AML Programs

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.