Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable.
Key topics
Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question: are financial institutions truly reducing vendor risk or mainly satisfying examiners?
Michael Berman shares his background as a recovering attorney turned entrepreneur, plus 17 years leading End Contracts and prior experience handling third-party risk as general counsel.
Michael says his morning routine is cardio for fitness and stress relief, and he identifies as a technology enthusiast who enjoys learning how new tech works.
The conversation opens with Michael's book, The Upside of Third Party Risk Management, which argues that risk management can be an organizational advantage instead of just a fear-driven obligation.
Michael says third-party risk is improving, but many programs still overfocus on point-in-time assessments instead of real-world monitoring and response.
He uses the Dwell AI startup controversy as an example of why trust but verify matters, especially when funding, AI outputs, and vendor claims collide.
Greg and Michael compare vendor reviews to employee reviews, arguing that vendors deserve at least as much ongoing attention as internal staff because they often have deeper access to data and systems.
Michael explains the gap between traditional GRC and threat hunting: one asks whether a vendor was secure at onboarding, while the other asks whether something is happening right now that needs action.
He emphasizes that organizations need both approaches, plus a shared taxonomy between cybersecurity teams and compliance teams, so risk ratings and threat intelligence align.
Michael describes how vendor management must shift from static questionnaires to real-time governance, especially when incidents like MoveIt show the value of knowing which vendors and fourth parties are affected immediately.
On fourth party and shadow AI risk, Michael says the governance perimeter has dissolved because vendors now rely on cloud, model providers, subprocessors, APIs, and other hidden dependencies.
He recommends expanding governance from just the vendor to the data flows themselves, with continuous discovery, clear escalation paths, and the ability to cut off risky tools quickly.
For AI vendors, Michael recommends stronger contractual controls, including notice of material model changes, AI incident notifications, clarity on subprocessors and model providers, and audit or evidence rights.
Greg suggests using the term security assessment instead of audit in some cases to reduce friction, and Michael agrees that evidence rights are especially important.
Michael cautions that startups can be attractive but risky if they cannot provide maturity, controls, or evidence comparable to more established vendors.
Greg adds that vendor requirements should be positioned as business guardrails, not just a flat no, especially when regulators and enterprise risk thresholds are involved.
Michael closes by noting that risk leaders should focus first on contractual controls and a usable framework, since those two tools can reduce the need for constant manual intervention.
Timestamps
00:00 - Guest introduction and why third-party risk matters
01:14 - The upside of third-party risk management
02:08 - Why Michael would have chosen medicine
02:28 - Technology as Michael's unexpected hobby
02:59 - Favorite place to unplug by the ocean
03:29 - A recent non-business book recommendation
04:11 - Are banks reducing risk or just satisfying examiners?
05:00 - Why vendor failures and fourth parties matter more now
06:14 - Vendor reviews should be as routine as employee reviews
07:22 - Moving from static compliance to active threat hunting
08:14 - Point-in-time assessments versus live monitoring
09:22 - Cyber, financial, and business continuity risks are connected
10:50 - Turning vendor data into action instead of overload
11:43 - Shared taxonomy between security and compliance teams
12:17 - Real-time governance for critical vendors
13:14 - Why MoveIt showed the weakness of one-time vendor questions
14:03 - Why contract terms matter when breaches happen
14:59 - AI is making third-party governance much harder
17:44 - Why AI dissolves the governance perimeter
18:37 - Shadow AI and incomplete vendor inventories
20:02 - Why vendors may not understand their own AI supply chain
21:01 - Expand governance from vendors to data flows
21:57 - Continuous discovery and escalation paths
23:24 - Evidence requirements for AI vendors
24:53 - Material model-change notice and incident notification
25:55 - Security assessment versus audit language
26:52 - Evidence rights and documented validation
27:22 - Why startup AI vendors may be too immature
28:27 - How to push back when the business wants a risky vendor
29:25 - Regulators still show up after a breach
30:16 - Not every AI tool is equally critical
31:12 - Why leaders should not wait for regulation
32:14 - Pick a defensible AI risk framework and stick to it
33:23 - Final advice: contract controls plus a framework
Key frameworks
Point-in-time vendor assessment versus continuous threat hunting
Governance should cover both vendors and data flows
Contractual controls should be built at relationship inception
AI risk management should be supported by evidence rights, notice obligations, and escalation paths
Risk treatment should be proportional to the use case, not just the presence of AI
Notable quotes
"You might have eight hundred vendors, but that doesn't mean I need to do threat monitoring for eight hundred vendors."
"If it wasn't documented, it wasn't done."
"Think about what contractual controls you can put in place at the inception of relationships to make your life easier."
Action items
Review vendor contracts for AI-specific notice, incident, and evidence obligations.
Identify which vendors are critical enough to justify continuous monitoring.
Build a shared taxonomy between security, compliance, procurement, and legal teams.
Treat data flow visibility as part of vendor governance.
Pick one defensible AI risk framework and apply it consistently.
It works because the title and sectioning make the episode feel practical and high-value, while the timestamps and action items create instant scanability for busy LinkedIn readers.
Podden och tillhörande omslagsbild på den här sidan tillhör
Gregory Rasner . Innehållet i podden är skapat av Gregory Rasner och inte av,
eller tillsammans med, Poddtoppen.