Should TPRM and Procurement Sit Together? The Evolution of Third Party Management
Third Party Therapy Podcast — featuring Oliver Jones, H&Z
Third party risk management (TPRM) grew up as a subset of procurement — but does it still belong there? In this episode of Third Party Therapy, host Mike Day speaks with Oliver Jones of H&Z about how the relationship between TPRM and procurement has evolved, where organisations are getting the structure right (and wrong), and what technology could do to bring the two back together.
## From Procurement Subset to Parallel Discipline
Oliver, who moved from general procurement into TPRM-heavy roles at organisations including Coventry Building Society, Bank of Ireland and Santander International, sees the split happening for two main reasons: growing C-suite understanding of TPRM as a distinct discipline, and the sheer scope of what counts as a "third party" expanding well beyond traditional suppliers to include intra-group arrangements, which sit awkwardly within a conventional supplier relationship management (SRM) process. He's clear this isn't one-size-fits-all — for smaller or less global organisations, keeping TPRM embedded within a strategically-run procurement function can work perfectly well, provided the underlying framework and governance are solid.
## A Capacity Problem as Much as a Structural One
As regulatory requirements deepen — DORA, fourth party mapping, operational resilience — Oliver argues that asking a generalist procurement or SRM person to absorb this "side of desk" simply doesn't scale. Dedicated capacity becomes necessary once the depth of obligation increases, regardless of where the function formally sits.
## Should We Rebrand "Risk" as "Resilience"?
Mike raises a reframing some organisations have adopted: calling the function "third party resilience" rather than "third party risk management," on the basis that resilience carries more positive, visionary connotations. Oliver is sympathetic but cautious — in one conversation, an organisation keen to talk about "resilience" had very little actual framework in place to test. His analogy: it's a bit like calling a function a "centre of excellence" before it's genuinely excellent — aspirational language is fine, but only once the underlying capability can back it up.
## Where TPRM Sits in the Org Chart
Oliver and Mike compare notes on reporting lines they've each seen: procurement and TPRM under a CFO, a COO, a CIO, or increasingly under whichever executive holds the relevant Senior Management Function (SMF24) accountability to the regulator. Oliver notes that TPRM often occupies an ambiguous "line 1.5" position — more rigorous than pure first-line operational ownership, but rarely a fully resourced, independent second line function in its own right.
## The Technology Fragmentation Problem
One of the clearest practical frustrations Oliver raises: the same operational stakeholder can find themselves dealing with several different teams and tools for what feels, from the business's point of view, like one relationship — an enterprise risk repository for emerging risks, a ServiceNow-style workflow tool for audit trail, a source-to-contract procurement platform, and a separate contract repository. Multiply that by multiple regions in a global organisation, and the fragmentation compounds further.
## Who Should TPRM Recruit From?
Picking up a long-running debate, Mike shares that at one conference an audience vote came out strongly in favour of recruiting TPRM talent from risk and audit backgrounds over procurement — a view Mike admits he argued against. Oliver has seen both work, noting that candidates arriving from a second- or third-line risk or audit background bring a different, complementary strength to those with a procurement grounding.
## Reversing the Workflow: Should TPRM Be the Front Door?
Mike puts forward a provocative idea: given TPRM's scope now often exceeds procurement's (covering intra-group relationships and lower-value but still risky engagements procurement wouldn't touch), should the TPRM intake process become the organisation's genuine front door — triggering procurement as a downstream sub-process, rather than the reverse? Oliver agrees with the underlying principle of early, multi-criteria engagement, and points to Hellios FSQS as an example of a shared front-end assessment that already blends risk and commercial due diligence for suppliers common across the financial services buying community — benefiting both sides, since suppliers familiar with the standard question set are typically more comfortable and responsive.
## Business Partnering and the "Amazon-Like Experience"
Both agree the ambition should be a single, intuitive third party intake experience — regardless of whether the eventual process branches into procurement, TPRM, data privacy or elsewhere — so the business doesn't experience friction from dealing with multiple teams asking overlapping questions. Oliver references early-stage "agentic" intake tools he's seen demonstrated that adapt their questions based on context (spend threshold, data sharing, deployment model), directing a request down the right path automatically.
## Post-Award: Keeping the Relationship Joined Up
The conversation turns to the ongoing lifecycle after contract signature — renewal negotiation, periodic due diligence, and performance management are all interlinked in practice, even when owned by separate teams. Oliver notes that most contracts run for around three years while the sourcing process itself might only take six months — meaning the overwhelming majority of value (and risk) accrues in a period that gets comparatively little structured attention.
*Editorial note: the "around three years" average contract duration and "six months" sourcing timeline are illustrative figures used by Oliver Jones in conversation, not independently verified statistics.*
## The Danger of "Low Risk" Suppliers That Grow
Oliver flags a genuine blind spot: organisations invest heavily in classifying suppliers at onboarding, but rarely revisit that classification, even as a "low risk" supplier's usage and dependency grows substantially over time. The biggest risk, in his view, isn't a risk event itself — it's TPRM's own classification process not being rigorous or current enough to have flagged it. He advocates periodically self-challenging past classifications — a "friendly audit" — rather than waiting for a formal internal audit review, which he notes is rarely deeply specialised in third party risk specifically.
## Lessons Learned
Oliver shares two cautionary examples: a client who attempted a TPRM transformation without external input, misinterpreted regulatory requirements, and had to unwind and restart elements of their policy and classification framework; and a rollout where a new assessment and questionnaire were pushed out to hundreds of operational stakeholders with poor change communication and no guidance embedded in the questions themselves — damaging internal goodwill towards the function before it had even properly started.
## Getting Started
Oliver's recommended first step for any organisation looking to realign TPRM and procurement: go directly to stakeholders and map root causes of friction — where the pain points genuinely are — rather than assuming the fix is People, Process or Technology in isolation. From there, look specifically at synergies in the post-award, supplier relationship management space, and consider whether a single, consistent voice to the business (whichever function leads it) would reduce duplicated effort and frustration.
---
**Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit [thirdpartytherapy.com](https://thirdpartytherapy.com) to subscribe to the mailing list.**
---
### Tags
#ThirdPartyTherapy #TPRM #ProcurementAndTPRM #ThirdPartyRiskManagement #SupplierRelationshipManagement #OperationalResilience #RiskClassification #VendorRiskManagement #DORA #SS221 #TechnologyOrchestration #BusinessPartnering #ConcentrationRisk #RiskManagementPodcast #ShouldTPRMSitWithProcurement #HowToStructureTPRM #TPRMPodcast


