Send us Fan Mail

Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable.

Key topics

  • Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question: are financial institutions truly reducing vendor risk or mainly satisfying examiners?
  • Michael Berman shares his background as a recovering attorney turned entrepreneur, plus 17 years leading End Contracts and prior experience handling third-party risk as general counsel.
  • Michael says his morning routine is cardio for fitness and stress relief, and he identifies as a technology enthusiast who enjoys learning how new tech works.
  • The conversation opens with Michael's book, The Upside of Third Party Risk Management, which argues that risk management can be an organizational advantage instead of just a fear-driven obligation.
  • Michael says third-party risk is improving, but many programs still overfocus on point-in-time assessments instead of real-world monitoring and response.
  • He uses the Dwell AI startup controversy as an example of why trust but verify matters, especially when funding, AI outputs, and vendor claims collide.
  • Greg and Michael compare vendor reviews to employee reviews, arguing that vendors deserve at least as much ongoing attention as internal staff because they often have deeper access to data and systems.
  • Michael explains the gap between traditional GRC and threat hunting: one asks whether a vendor was secure at onboarding, while the other asks whether something is happening right now that needs action.
  • He emphasizes that organizations need both approaches, plus a shared taxonomy between cybersecurity teams and compliance teams, so risk ratings and threat intelligence align.
  • Michael describes how vendor management must shift from static questionnaires to real-time governance, especially when incidents like MoveIt show the value of knowing which vendors and fourth parties are affected immediately.
  • On fourth party and shadow AI risk, Michael says the governance perimeter has dissolved because vendors now rely on cloud, model providers, subprocessors, APIs, and other hidden dependencies.
  • He recommends expanding governance from just the vendor to the data flows themselves, with continuous discovery, clear escalation paths, and the ability to cut off risky tools quickly.
  • For AI vendors, Michael recommends stronger contractual controls, including notice of material model changes, AI incident notifications, clarity on subprocessors and model providers, and audit or evidence rights.
  • Greg suggests using the term security assessment instead of audit in some cases to reduce friction, and Michael agrees that evidence rights are especially important.
  • Michael cautions that startups can be attractive but risky if they cannot provide maturity, controls, or evidence comparable to more established vendors.
  • Greg adds that vendor requirements should be positioned as business guardrails, not just a flat no, especially when regulators and enterprise risk thresholds are involved.
  • Michael closes by noting that risk leaders should focus first on contractual controls and a usable framework, since those two tools can reduce the need for constant manual intervention.

Timestamps

00:00 - Guest introduction and why third-party risk matters

01:14 - The upside of third-party risk management

02:08 - Why Michael would have chosen medicine

02:28 - Technology as Michael's unexpected hobby

02:59 - Favorite place to unplug by the ocean

03:29 - A recent non-business book recommendation

04:11 - Are banks reducing risk or just satisfying examiners?

05:00 - Why vendor failures and fourth parties matter more now

06:14 - Vendor reviews should be as routine as employee reviews

07:22 - Moving from static compliance to active threat hunting

08:14 - Point-in-time assessments versus live monitoring

09:22 - Cyber, financial, and business continuity risks are connected

10:50 - Turning vendor data into action instead of overload

11:43 - Shared taxonomy between security and compliance teams

12:17 - Real-time governance for critical vendors

13:14 - Why MoveIt showed the weakness of one-time vendor questions

14:03 - Why contract terms matter when breaches happen

14:59 - AI is making third-party governance much harder

17:44 - Why AI dissolves the governance perimeter

18:37 - Shadow AI and incomplete vendor inventories

20:02 - Why vendors may not understand their own AI supply chain

21:01 - Expand governance from vendors to data flows

21:57 - Continuous discovery and escalation paths

23:24 - Evidence requirements for AI vendors

24:53 - Material model-change notice and incident notification

25:55 - Security assessment versus audit language

26:52 - Evidence rights and documented validation

27:22 - Why startup AI vendors may be too immature

28:27 - How to push back when the business wants a risky vendor

29:25 - Regulators still show up after a breach

30:16 - Not every AI tool is equally critical

31:12 - Why leaders should not wait for regulation

32:14 - Pick a defensible AI risk framework and stick to it

33:23 - Final advice: contract controls plus a framework

Key frameworks

  • Point-in-time vendor assessment versus continuous threat hunting
  • Governance should cover both vendors and data flows
  • Contractual controls should be built at relationship inception
  • AI risk management should be supported by evidence rights, notice obligations, and escalation paths
  • Risk treatment should be proportional to the use case, not just the presence of AI

Notable quotes

  • "You might have eight hundred vendors, but that doesn't mean I need to do threat monitoring for eight hundred vendors."
  • "If it wasn't documented, it wasn't done."
  • "Think about what contractual controls you can put in place at the inception of relationships to make your life easier."

Action items

  • Review vendor contracts for AI-specific notice, incident, and evidence obligations.
  • Identify which vendors are critical enough to justify continuous monitoring.
  • Build a shared taxonomy between security, compliance, procurement, and legal teams.
  • Treat data flow visibility as part of vendor governance.
  • Pick one defensible AI risk framework and apply it consistently.

It works because the title and sectioning make the episode feel practical and high-value, while the timestamps and action items create instant scanability for busy LinkedIn readers.



Support the show

Podden och tillhörande omslagsbild på den här sidan tillhör Gregory Rasner . Innehållet i podden är skapat av Gregory Rasner och inte av, eller tillsammans med, Poddtoppen.