News & Analysis as of

Due Diligence Third-Party Service Provider

Walkers

Personal Information Protection Act deep dive

Walkers on

The Personal Information Protection Act ("PIPA") comes into full force on 1 January 2025. All organisations in Bermuda are expected to be in compliance with it by that date – time is running out! The Privacy Commissioner...more

Pillsbury - Global Sourcing Practice

Old Tricks for the New Dog: Why Traditional Technology Sourcing Best Practice Is Relevant for Cutting-Edge AI

Since the release of OpenAI’s ChatGPT, the intense hype around large language models (LLMs) and complex AI systems has exploded. Organizations have rushed to both try and buy these new tools. Along with it, a flood of...more

Mayer Brown

EU Cyber Legislation Puts Emphasis on Board Responsibility

Mayer Brown on

What is a Management Body? Under both DORA and NIS2, a management body can be a body with managerial and/or supervisory functions. The powers and structure of management bodies vary within the EU Member State, and managerial...more

The Volkov Law Group

A Deeper Dive into Supply Chain Transparency & Accountability

The Volkov Law Group on

The sheer proliferation of supply chain transparency and accountability regulations at international scale itself warrants a closer look at the level of scrutiny required of organizations with complex, multi-faceted, global,...more

Mitratech Holdings, Inc

Understanding 4th- and Nth-Party Risk: What Do You Need to Know?

Strategies for Mitigating Unseen Threats and Managing 4th- and Nth-Party Risk in Your Modern Business. Organizations today have transitioned from using on-site server rooms to relying on third-party services and cloud...more

Cozen O'Connor

Final Interagency Guidance on Managing Risks Associated with Third-Party Relationships

Cozen O'Connor on

On June 6, 2023, the Board of Governors of the Federal Reserve System, Office of the Comptroller of the Currency and Federal Deposit Insurance Corp. (collectively, the “Agencies”) issued final interagency guidance that...more

Epiq

Deepfakes Bring Deep Risk

Epiq on

Most people know what a deepfake is but have not put much thought into how it could affect business operations. Deepfakes are videos, pictures, or audio that have been convincingly manipulated to misrepresent a person saying...more

Nextpoint, Inc.

Managing Ediscovery In The Cloud: Essential Questions to Ask Potential Providers

Nextpoint, Inc. on

As we explained in our last post, managing ediscovery in the cloud is the only viable solution for dealing with the massive amount of electronic data involved in litigation today. Nextpoint has been an advocate for...more

Skadden, Arps, Slate, Meagher & Flom LLP

SEC Proposes Rule on Outsourcing by Investment Advisers

On October 26, 2022, the U.S. Securities and Exchange Commission (SEC) proposed a new Rule 206(4)-11 and amendments to Rule 204-2 under the U.S. Investment Advisers Act of 1940 (Advisers Act), as well as amendments to Form...more

Eversheds Sutherland (US) LLP

SEC proposes service provider oversight requirements for investment advisers

On October 26, 2022, the Securities and Exchange Commission (SEC) proposed new Rule 206(4)-11 under the Investment Advisers Act of 1940 (Advisers Act), which would prohibit SEC-registered investment advisers from outsourcing...more

ArentFox Schiff

SEC Proposes New Oversight Requirements for Certain Services Outsourced by Investment Advisors

ArentFox Schiff on

On October 26, 2022, the US Securities and Exchange Commission (SEC) proposed a new rule and rule amendments under the Investment Advisors Act that, if passed, would prohibit registered investment advisors from outsourcing...more

Sheppard Mullin Richter & Hampton LLP

What Should We Do About the Draft CPRA Regulations?: Contracts

In this third post of our ongoing series, we examine key takeaways for companies in light of the recently released draft CPRA regulations. Today’s focus is on contractual requirements. (Visit here for information about...more

Esquire Deposition Solutions, LLC

Exercising Due Diligence in the Selection of a Tech Vendor

The task of conducting due diligence in the selection of technology vendors is a critical component of the lawyer’s ethical obligation to maintain reasonable security over client confidential information. However, for several...more

Eversheds Sutherland (US) LLP

TCPA Insurance? A new database offers a wider shield from liability through due diligence

The Telephone Consumer Protection Act (TCPA) poses a constant threat to companies that wish to communicate with existing and prospective customers because the statute imposes strict liability on companies that call or text...more

Mitratech Holdings, Inc

What is a Vendor Risk Assessment?

We recently dove into what vendor risk and vendor risk management entails. Once you understand that this is the risk that results from vendors, it’s simple to extend this and establish that vendor risk assessment (VRA), or...more

BCLP

Supervision of Vendors When Outsourcing - The Buck Stops with FINRA Member Firms

BCLP on

Key Takeaways: ..On August 13, 2021, FINRA issued Regulatory Notice 21-29 (“RN 21-29”) to remind member firms that they must establish and maintain an adequate supervisory system, including written supervisory procedures...more

Mitratech Holdings, Inc

What is Vendor Risk & Vendor Risk Management (VRM)?

Vendor risk management (VRM), or third-party risk management, is the management, monitoring, and evaluation of risks that result from third-party vendors and suppliers of products and services. It’s a crucial initiative...more

Sheppard Mullin Richter & Hampton LLP

Federal Agencies Request Comments on Risk Management Guidance for Third-Party Relationships

On July 13, the Federal Reserve, FDIC, and OCC proposed risk management guidance to help banking organizations manage risks related to third-party relationships, including relationships with vendors, FinTech companies,...more

Society of Corporate Compliance and Ethics...

[Webinar] Update on China and Russia: Restrictions and Best Practices - June 1st, 12:00 pm - 1:30 pm CDT

Learning Objectives: - Develop greater understanding of the main US trade restrictions on China and Russia - Gain familiarity into key compliance issues under current restrictions, including related to exports, supply...more

Hinshaw & Culbertson - Privacy, Cyber & AI...

Connecticut Extends Deadlines to Comply with Insurance Data Security Law, New York Approved as a Safe Harbor Jurisdiction

We previously reported that the Connecticut Insurance Department had issued Bulletin IC-42 to all licensees, providing guidance for compliance with the State's Insurance Data Security Law (the Act). However, in light of the...more

Manatt, Phelps & Phillips, LLP

Third-Party Vendor Management Remains a Critical Issue for Banks

More than ever before, banks are relying on third-party vendors for important services such as marketing, underwriting assistance, technology, collections, settlement services and even outsourcing of product lines. These...more

Hudson Cook, LLP

Vendor Service Contracts - Not Just Arm's Length Transactions Anymore

Hudson Cook, LLP on

The Consumer Financial Protection Bureau's Compliance Bulletin and Policy Guidance; 2016-02, Service Providers addresses the CFPB's expectation that companies oversee their business relationships with service providers in a...more

Morgan Lewis

Contract Corner: Required Consents Analysis in Due Diligence

Morgan Lewis on

Are you about to sign a service agreement with a third-party service provider under which it will access and use technology of your company? Have you checked your applicable third-party contracts to see if you need any...more

Foodman CPAs & Advisors

Who are you partnering with for your Financial Institution’s BSA/AML Independent Testing?

Financial Institutions ought to design and evaluate compliance programs to meet BSA/AML requirements and to satisfy Bank Examiner expectations. A Financial Institution’s Compliance Programs must comply with the requirements...more

Reveal

The eDiscovery Impostor and How to Spot Them

Reveal on

“To err is human,” but in an industry as seemingly driven by precision as eDiscovery, errors are all too common. Yes, mistakes are going to happen. Which is why we can fall back on processes and procedures to ensure that even...more

48 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide