Should TPRM and Procurement Sit Together? The Evolution of Third Party Management

Mike Day • 4 October 2026

Third Party Therapy Podcast — featuring Oliver Jones, H&Z

Third party risk management (TPRM) grew up as a subset of procurement — but does it still belong there? In this episode of Third Party Therapy, host Mike Day speaks with Oliver Jones of H&Z about how the relationship between TPRM and procurement has evolved, where organisations are getting the structure right (and wrong), and what technology could do to bring the two back together.
 
## From Procurement Subset to Parallel Discipline
 
Oliver, who moved from general procurement into TPRM-heavy roles at organisations including Coventry Building Society, Bank of Ireland and Santander International, sees the split happening for two main reasons: growing C-suite understanding of TPRM as a distinct discipline, and the sheer scope of what counts as a "third party" expanding well beyond traditional suppliers to include intra-group arrangements, which sit awkwardly within a conventional supplier relationship management (SRM) process. He's clear this isn't one-size-fits-all — for smaller or less global organisations, keeping TPRM embedded within a strategically-run procurement function can work perfectly well, provided the underlying framework and governance are solid.
 
## A Capacity Problem as Much as a Structural One
 
As regulatory requirements deepen — DORA, fourth party mapping, operational resilience — Oliver argues that asking a generalist procurement or SRM person to absorb this "side of desk" simply doesn't scale. Dedicated capacity becomes necessary once the depth of obligation increases, regardless of where the function formally sits.
 
## Should We Rebrand "Risk" as "Resilience"?
 
Mike raises a reframing some organisations have adopted: calling the function "third party resilience" rather than "third party risk management," on the basis that resilience carries more positive, visionary connotations. Oliver is sympathetic but cautious — in one conversation, an organisation keen to talk about "resilience" had very little actual framework in place to test. His analogy: it's a bit like calling a function a "centre of excellence" before it's genuinely excellent — aspirational language is fine, but only once the underlying capability can back it up.
 
## Where TPRM Sits in the Org Chart
 
Oliver and Mike compare notes on reporting lines they've each seen: procurement and TPRM under a CFO, a COO, a CIO, or increasingly under whichever executive holds the relevant Senior Management Function (SMF24) accountability to the regulator. Oliver notes that TPRM often occupies an ambiguous "line 1.5" position — more rigorous than pure first-line operational ownership, but rarely a fully resourced, independent second line function in its own right.
 
## The Technology Fragmentation Problem
 
One of the clearest practical frustrations Oliver raises: the same operational stakeholder can find themselves dealing with several different teams and tools for what feels, from the business's point of view, like one relationship — an enterprise risk repository for emerging risks, a ServiceNow-style workflow tool for audit trail, a source-to-contract procurement platform, and a separate contract repository. Multiply that by multiple regions in a global organisation, and the fragmentation compounds further.
 
## Who Should TPRM Recruit From?
 
Picking up a long-running debate, Mike shares that at one conference an audience vote came out strongly in favour of recruiting TPRM talent from risk and audit backgrounds over procurement — a view Mike admits he argued against. Oliver has seen both work, noting that candidates arriving from a second- or third-line risk or audit background bring a different, complementary strength to those with a procurement grounding.
 
## Reversing the Workflow: Should TPRM Be the Front Door?
 
Mike puts forward a provocative idea: given TPRM's scope now often exceeds procurement's (covering intra-group relationships and lower-value but still risky engagements procurement wouldn't touch), should the TPRM intake process become the organisation's genuine front door — triggering procurement as a downstream sub-process, rather than the reverse? Oliver agrees with the underlying principle of early, multi-criteria engagement, and points to Hellios FSQS as an example of a shared front-end assessment that already blends risk and commercial due diligence for suppliers common across the financial services buying community — benefiting both sides, since suppliers familiar with the standard question set are typically more comfortable and responsive.
 
## Business Partnering and the "Amazon-Like Experience"
 
Both agree the ambition should be a single, intuitive third party intake experience — regardless of whether the eventual process branches into procurement, TPRM, data privacy or elsewhere — so the business doesn't experience friction from dealing with multiple teams asking overlapping questions. Oliver references early-stage "agentic" intake tools he's seen demonstrated that adapt their questions based on context (spend threshold, data sharing, deployment model), directing a request down the right path automatically.
 
## Post-Award: Keeping the Relationship Joined Up
 
The conversation turns to the ongoing lifecycle after contract signature — renewal negotiation, periodic due diligence, and performance management are all interlinked in practice, even when owned by separate teams. Oliver notes that most contracts run for around three years while the sourcing process itself might only take six months — meaning the overwhelming majority of value (and risk) accrues in a period that gets comparatively little structured attention.
 
*Editorial note: the "around three years" average contract duration and "six months" sourcing timeline are illustrative figures used by Oliver Jones in conversation, not independently verified statistics.*
 
## The Danger of "Low Risk" Suppliers That Grow
 
Oliver flags a genuine blind spot: organisations invest heavily in classifying suppliers at onboarding, but rarely revisit that classification, even as a "low risk" supplier's usage and dependency grows substantially over time. The biggest risk, in his view, isn't a risk event itself — it's TPRM's own classification process not being rigorous or current enough to have flagged it. He advocates periodically self-challenging past classifications — a "friendly audit" — rather than waiting for a formal internal audit review, which he notes is rarely deeply specialised in third party risk specifically.
 
## Lessons Learned
 
Oliver shares two cautionary examples: a client who attempted a TPRM transformation without external input, misinterpreted regulatory requirements, and had to unwind and restart elements of their policy and classification framework; and a rollout where a new assessment and questionnaire were pushed out to hundreds of operational stakeholders with poor change communication and no guidance embedded in the questions themselves — damaging internal goodwill towards the function before it had even properly started.
 
## Getting Started
 
Oliver's recommended first step for any organisation looking to realign TPRM and procurement: go directly to stakeholders and map root causes of friction — where the pain points genuinely are — rather than assuming the fix is People, Process or Technology in isolation. From there, look specifically at synergies in the post-award, supplier relationship management space, and consider whether a single, consistent voice to the business (whichever function leads it) would reduce duplicated effort and frustration.
 
---
 
**Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit [thirdpartytherapy.com](https://thirdpartytherapy.com) to subscribe to the mailing list.**
 
---
 
### Tags
 
#ThirdPartyTherapy #TPRM #ProcurementAndTPRM #ThirdPartyRiskManagement #SupplierRelationshipManagement #OperationalResilience #RiskClassification #VendorRiskManagement #DORA #SS221 #TechnologyOrchestration #BusinessPartnering #ConcentrationRisk #RiskManagementPodcast #ShouldTPRMSitWithProcurement #HowToStructureTPRM #TPRMPodcast

by Mike Day • 4 October 2026
Third Party Therapy Podcast — featuring Dharminder Mehmi, third party risk specialist, Legal & General
by Mike Day • 4 October 2026
Third Party Therapy Podcast — featuring Harj Mattu, Partner, Deloitte
by Mike Day • 4 October 2026
Third Party Therapy Podcast — featuring Nathan Hopkins, Chief Revenue Officer, the escrow company
by Mike Day • 4 October 2026
Inside the Recruitment Market for Third Party Risk Talent - Third Party Therapy Podcast — featuring Jack Birch, Head of Interim Management Practice, and Will Cook, Senior Consultant, Procurement Heads
by Mike Day • 4 October 2026
Third Party Therapy Podcast — featuring Stephen Boyer, Co-Founder and Chief Innovation Officer, BitSight. Why Static Binary Analysis Is the Missing Piece in Software Supply Chain Risk
Third Party Therapy logo
by Mike Day • 14 September 2026
BitSight's Stephen Boyer on why annual cyber assessments aren't enough, and how continuous monitoring catches risks like MoveIt and CrowdStrike fast.
Third Party Therapy logo
by Mike Day • 14 September 2026
Emerging tech adviser Ian Ellis on how corporate TPRM processes look from a startup's side, and how slow due diligence can cost you the best suppliers.
Third Party Therapy logo
by Mike Day • 14 September 2026
Zurich's Gemma Stewart on building a concentration risk programme from scratch: geographic, fourth party and cloud risk, and why data must come first.
by Mike Day • 14 September 2026
Third Party Therapy Podcast — featuring Aki Eldar, co-founder of Mirato
by Mike Day • 14 September 2026
Third Party Therapy Podcast — Series 1, Episode 1 — featuring Paul Huggett, Managing Director, Helios For the very first episode of Third Party Therapy, host Mike Day speaks with Paul Huggett, Managing Director at Helios and a former head of third party risk management (TPRM) at Lloyds Banking Group, Bank of Ireland and Nationwide Building Society. Having sat on both sides of the fence — as a buyer of pooled due diligence for over a decade, and now as a provider of it — Paul offers a rare, grounded view of what community due diligence really delivers, and where its limits are. From "Poacher" to "Gamekeeper" to Provider Paul's career path is itself a neat illustration of how TPRM as a discipline emerged almost by accident. Starting in operational and IT project management in the early 1990s, he moved into outsourcing project delivery — describing himself at the time as a "poacher," someone focused purely on moving functions quickly, for whom procurement was simply an obstacle. A move into internal audit at Lloyds Banking Group — auditing the sourcing and property functions — turned him into a "gamekeeper," and from there he spent a decade running third party risk functions across three major financial institutions, all of which were customers of Helios's FSQS scheme, before joining Helios itself roughly 18 months ago. Ten Years of Change in TPRM Paul's account of how far the discipline has moved is stark. His first supplier management audit revealed that "due diligence" at the time amounted to a signed letter from the supplier saying "everything's fine, thank you." The regulatory framework consisted of a handful of bullet points essentially saying "you can't outsource the risk." The period from roughly 2015 to 2018 — driven by GDPR, the growth of cloud outsourcing, and European regulators waking up to the risk — triggered rapid change, followed by growing UK regulatory focus (SS2/21 and PS7/21) on operational resilience, conduct risk, and more recently ESG, which Paul says has moved from "almost at the bottom of the pile" to near the top of the risk league table. What Pooled Due Diligence Actually Is Paul's explanation is refreshingly plain: the traditional model is a "many-to-many mesh" — every buyer individually asking every one of their suppliers largely the same questions, repeatedly. Pooled or community due diligence flips this into a one-to-many model: a supplier answers a shared, standardised question set once, and that data is made available (with the supplier's consent and quality-checked) to every buyer in the community who needs it. The win is symmetric. Suppliers spend less time repeatedly answering near-identical questionnaires from dozens of buyers. Buyers get a faster start, a broader pool of pre-assessed suppliers, and — critically — a question set that reflects a decade of collective input from the buying community, not just their own risk team's best guess. As Paul puts it, being able to tell your board "this is good enough for [named peer firms], therefore we believe it's good enough for us" is valuable air cover for a new entrant to the model. From Niche to Mainstream When Lloyds Banking Group first adopted the model, it was the only buying firm in the community — making it a hard sell to suppliers. Today, Helios's UK community includes just under 70 buying firms, plus roughly 20 more across Europe, spanning tiny building societies through to major international investment banks. Paul attributes the shift to sustained pressure on TPRM budgets and headcount ("you never get, as a TPR person, someone come to you and say... would you like some more people?"), combined with a regulatory turning point around 2018-2019 when European regulation first explicitly acknowledged shared assurance as acceptable — provided the buyer using it still applies its own risk appetite to the results, rather than simply outsourcing the decision. Confidentiality and Competition Law Two objections come up repeatedly with pooled models, and Paul addresses both directly. On confidentiality, where a supplier is unwilling to upload a sensitive document (such as a full cybersecurity policy) directly, Helios instead asks granular, structured yes/no questions about the specific controls contained within that document — meaning a buyer's risk specialist can still assess control coverage without the underlying document ever being shared. On competition law, Helios never discloses which buyers work with which suppliers to other buyers in the community, never comments on individual suppliers as a collective, and never directs buyers to take action against a specific supplier — all of which would risk anti-competitive behaviour. Not a Silver Bullet — Part of an Ecosystem Paul is careful to position pooled due diligence as one part of a wider TPRM toolkit, not a replacement for the buyer's own risk judgement. Helios provides primary, source-verified data (rather than scraped or blended third-party data), but the buyer still has to decide what matters to them and act on it. His framing: "we give you the information, but your job is to decide what to do with it." Real-World Stress Testing: Russia-Ukraine One of the clearest illustrations of the model's value came with the outbreak of the Russia-Ukraine conflict. Because Helios already held country of registration, operating location and fourth party data for its supplier community, buyer firms could establish their exposure "within about half an hour" of the event breaking — rather than manually cross-referencing finance systems to work out who they'd been paying, and where. Helios then issued a bespoke follow-up questionnaire to roughly 10,000 suppliers within about ten days, with an 80% response rate — giving buyers not just a static exposure map, but live intelligence on downstream impact. The same approach was repeated for the Israel-Gaza conflict and rolling energy blackouts. Where AI Fits — and Where Helios Is Deliberately Cautious Asked about AI, Paul draws a pointed comparison to cloud computing circa 2017-2018: a lot of noise, real underlying risk, but limited clarity on exactly where the exposure sits. Helios is building a new question set specifically to assess suppliers' use of AI, aligned to the EU AI Act's risk-based, proportionate approach. But Paul is candid that Helios itself is deliberately slow to deploy AI at scale in its own data pipeline, given its core value proposition rests on primary, verified data rather than scraped or AI-generated content — and flags the emerging industry concern that large language models may increasingly be trained on data that itself originated from other AI systems, creating a quality-degradation risk over time. Editorial note: the discussion of AI training data and model quality reflects Paul Huggett's own views and industry commentary referenced on the podcast, not an independently verified technical claim. Concentration Risk and the Regulator's Blind Spot Paul also touches on Critical Third Party (CTP) regulation and the new, more detailed outsourcing and DORA registers now required by UK and EU regulators — designed to help regulators identify concentration risk across the financial sector. He's candid that Helios, precisely because of the same competition and confidentiality constraints discussed earlier, cannot fill this gap entirely: it knows what a supplier does, but not what each buyer considers critical about that relationship, since criticality varies hugely between an insurer, a reinsurer, a building society and an investment manager. The Direction of Travel: From Data to Assurance Looking ahead, Paul sees the community model extending from data-gathering into genuine assurance — Helios has already introduced ESG benchmarking that lets suppliers see how they compare to peers, and has launched pooled, supplier-funded virtual site visits testing controls across the top operational risk domains. Notably, he observes that resistance to pooled assurance has historically come more from buyers wanting to "do things their way" than from suppliers, who are generally keen to spend less time on duplicate assurance requests. A Practical Starting Point For any organisation considering this path, Paul's advice is to look at your own organisation from the supplier's point of view: how many different, overlapping data requests are you sending out? Are you actually using everything you collect, or gathering data you never act on? And do you genuinely understand your broader (not just your most critical) supplier population — because, as Paul notes pointedly, "Covid did not care that it was taking out your workforce from a whole swathe of your medium risk suppliers." His clearest warning, drawn from watching organisations invest heavily in shiny new source-to-pay platforms: the technology is rarely the problem. "Systems and technology are not going to solve your problems. They're just going to give you a shinier problem to grapple with," unless matched with the cultural change and data discipline to actually populate and use them. Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list. Tags #ThirdPartyTherapy #TPRM #CommunityDueDiligence #PooledDueDiligence #VendorRiskManagement #ThirdPartyRiskManagement #FSQS #SharedAssurance #DueDiligence #FinancialServicesRegulation #ConcentrationRisk #CriticalThirdParty #DORA #SupplierRiskManagement #RiskManagementPodcast #WhatIsPooledDueDiligence #HowDoesCommunityDueDiligenceWork #TPRMPodcast