Third Party Engagement Use Case Design

Architecture diagram

The following diagram shows the relationships between the applications in the Third Party Engagement use case.

Third Party Governance use case architecture

Note:  

  1. Any connection to the perimeter of the Third Party Hierarchy means the connection could be to any of the three levels within the Hierarchy: Third Party Profile, Subsidiary, or Sub-Subsidiary.
  2. Findings are automatically generated within Issues Management for all Assessments. Findings can also be generated manually across the solution, where appropriate.

Applications and questionnaires

The use case provides the following applications and questionnaires.

Important: This list does not include any prerequisite use case applications or questionnaires. The Third Party Engagement use case requires the following prerequisite use cases: Issues Management and Third Party Catalog.

The following table describes the use case applications and questionnaires.

Application/Questionnaire

Description

Engagements

The Engagements application enables you to document all products and services delivered by a third party. You can assign engagements to business units, relationship managers, risk analysts, and to the contracts that establish the terms and conditions of the product and services being delivered.

Supplier Request Form

The Supplier Request Form application is the hub where all requests for new products and services are initiated, reviewed, and completed. The application enables the Procurement team to analyze prospective engagements and allows the business to provide final approvals. In addition, you can identify existing third party suppliers that are available to fulfill the request, or you can request to add a new supplier for evaluation.

Third Party Financial Viability Assessments

The Third Party Financial Viability Assessment enables you to assess the financial stability and viability of a third party.

Third Party Contract Reviews

The Third Party Contract Reviews questionnaire measures contract risk by assessing the provisions outlined in each of your third party contracts.

Subcontractors

The subcontractors application allows you to catalog and manage your supply chain from the 4th party to the nth level. It provides questions that can be used to calculate the inherent and residual risk of subcontractors. You can also link critical engagements that are supported by subcontractors, and provide high level information about the supplier.

Certificates of Insurance

The Certificates of Insurance application enables you to document whether or not a third party has provided proof of insurance commensurate with those preferences. The documents outline the types of and limits of insurance carried by the contractor, third party, or either party. In addition to the types and limits of insurance, the certificates list the name of the agent or broker, the insurer, and the effective dates of the policy. Omissions, exceptions, and expired insurance policies can also be monitored and managed. As third party engagements are documented, required certificates of insurance are automatically determined based on customer risk transfer preferences.

Master Services Agreement

The Master Service Agreements application houses the overall statements of liability. Each contract is subject to the terms and agreements stated in the Master Service Agreement (MSA). Each MSA is associated to one third party, and is tied to one or more contract. Not all contracts are governed by an MSA.

Business Processes

The Business Processes application captures the base data for a given process. A process may be assigned to a particular business unit or shared across multiple business units. A business process may also be referenced to one or multiple products or services. The application enables you to track the business processes personnel, criticality, recovery time objective (RTO) and ITIL category, and associate it with other aspects of the enterprise infrastructure.

Products and Services

The Products and Services application maintains all products and services provided within an organization. For example, a financial services firm provides a variety of products and services, such as banking, brokerage, and lending services.

Question Library

The Question Library application stores assessment questions that you can reference and copy into a questionnaire. Each question is stored as an individual record, and each record contains information including the question and answer text as well as information necessary to display and score the question. Depending on the solution that you have licensed, the Question Library contains a large set of pre-built questions by default. In addition, you can add new questions and store them in the Question Library.

Access roles and record permissions

For a complete list of access roles and detailed, page-level access rights, see the Data Dictionary.

For a complete list of application record permission fields, including which user/groups fields populate the fields and where the fields inherit permissions from, see the Data Dictionary.

Dashboards

The following table describes the use case dashboards.

Dashboard

Description

Third Party Task Driver

The Third Party Task Driver dashboard contains quick links for frequent tasks and features relevant metrics to the current user, such as supplier request forms, contract reviews, and expiring contracts that are pending action. This dashboard also uses interactive charts to display data, such as third parties by relationship manager and contracts by third party, status, and expiration date.

The Third Party Task Driver dashboard is available to all third party access roles because it is filtered by the current user.

Third Party Process Manager

The Third Party Process Manager dashboard displays items relevant to users such as relationship managers and procurement officers to help them determine how processes are functioning and identify areas for improvement. This dashboard features metrics, such as expiring contracts and contracts pending review. This dashboard also uses interactive charts to show data, such as third parties by status and engagement distribution per business unit.

Only users that are assigned to the Third Party: 1st Line of Defense, Third Party: Legal and Procurement, or Third Party: Administrator groups can view this dashboard.

Third Party Management

The Third Party Management dashboard provides critical third party information to help the executive team identify low-performing third parties and understand how third parties support crucial business processes. This dashboard uses interactive charts to display data, such as overall performance rating by third party, contract distribution by third party, and budgeted vs. actual annual engagement spend per business unit. This dashboard also features metrics for active and expired contracts to give insight on which items require immediate action.

Only users that are assigned to the Third Party: Administrator, Third Party: Executive Management, or Third Party: Read Only groups can view this dashboard.

Data Dictionary

The Third Party Engagement Data Dictionary contains configuration information for the use case.

You can obtain the Data Dictionary for the solution by contacting your Archer Account Representative.