Banking Procurement and Third-Party Risk Training Course

5 days Procurement Certificate on completion
Course codeSD-P-028
Duration5 days
LevelIntermediate to Advanced
CategoryProcurement
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Bank procurement teams must secure competitive value while proving that outsourced services, cloud providers, payment partners and critical suppliers can meet stringent resilience, security, conduct and regulatory expectations. A weak supplier assessment can expose the bank to operational disruption, data compromise, concentration risk, customer harm and difficult-to-defend procurement decisions. This course equips professionals to connect sourcing activity with third-party risk governance from initial demand through contract award, onboarding, monitoring and exit.

Participants learn to segment suppliers by criticality, map outsourced-service dependencies, build risk-based due diligence packs and evaluate bids beyond price. The course covers procurement controls, inherent and residual risk scoring, financial viability review, information-security assessment, sanctions and adverse-media screening, subcontractor governance, service-level design, business continuity testing and concentration-risk analysis. Participants practise translating risk findings into award recommendations, remediation requirements, contractual clauses and accountable approval routes.

Instructor-led workshops use a realistic banking outsourcing case involving a cloud-enabled payments service. Participants work with supplier scorecards, risk registers, control questionnaires, contract schedules and governance dashboards. By the end of the week, each participant produces a bank-ready third-party procurement pack: a supplier segmentation rationale, evaluation matrix, due diligence plan, risk treatment register, contract-control schedule and 90-day onboarding monitoring plan.

The programme is designed for experienced procurement, vendor-management, operational-risk, compliance, technology-risk and business-continuity professionals who influence supplier selection or oversee material third-party relationships in banks and regulated financial institutions.

Course objectives

By the end of this course, participants will be able to:

  • Classify banking suppliers using a criticality and inherent-risk segmentation model
  • Construct a weighted bid evaluation matrix that combines commercial, operational, cyber and resilience criteria
  • Perform supplier due diligence using financial, sanctions, information-security and subcontractor evidence
  • Calculate residual third-party risk and document risk acceptance, remediation and escalation decisions
  • Draft contractual control schedules covering audit rights, service levels, data protection, continuity and exit
  • Map fourth-party dependencies and identify concentration-risk exposures across critical services
  • Build a third-party risk register with owners, treatment actions, due dates and key risk indicators
  • Present a defensible sourcing recommendation to a procurement and risk approval committee

Benefits of attending

For you

  • Gain a repeatable method for defending supplier awards where risk considerations outweigh lowest price
  • Produce stronger procurement papers for material outsourcing and critical-service decisions
  • Build credibility with risk, compliance, cyber-security and legal stakeholders through shared control language
  • Learn to turn supplier assurance evidence into practical remediation, contract and monitoring actions
  • Prepare for senior procurement, vendor-risk or outsourcing-governance responsibilities in regulated banking

For your organisation

  • Improve consistency of risk-based sourcing decisions across business units and procurement categories
  • Reduce exposure to poorly assessed suppliers, hidden subcontractors and unmanaged fourth-party dependencies
  • Strengthen evidence trails for outsourcing governance, internal audit and regulatory examination
  • Embed contract controls and exit requirements before critical suppliers are onboarded
  • Create clearer ownership of supplier remediation, monitoring indicators and risk acceptance decisions

Target competencies

Supplier criticality assessmentRisk-based sourcingDue diligence designContract control draftingConcentration risk analysisVendor governance reporting

Who should attend

  • Bank Procurement Managers — who lead supplier selection and need to evidence risk-informed award decisions
  • Category Managers — who source technology, professional services or operational suppliers with material bank dependencies
  • Third-Party Risk Managers — who design due diligence, monitoring and escalation for vendor populations
  • Vendor Relationship Managers — who oversee supplier performance, remediation and renewal decisions
  • Operational Risk and Resilience Professionals — who assess outsourcing impacts on important business services
  • Information Security and Technology Risk Managers — who evaluate control evidence from cloud and technology providers

Requirements and prerequisites

Participants should have practical experience of procurement, supplier management, operational risk, information security, compliance or outsourcing governance in a bank or similarly regulated financial institution. They should understand the basic procurement lifecycle, RFPs, supplier due diligence, contracts and risk ratings, and be comfortable working with Excel-style scoring tables and policy documents. Familiarity with outsourcing guidance, business continuity or information-security questionnaires is useful but not essential. This is not a beginner procurement course: no prior use of SAP Ariba, RSA Archer or OneTrust is required, and no coding, audit qualification or legal drafting background is assumed.

Training methodology

The course combines instructor-led banking procurement sessions with document-based workshops and facilitated challenge panels. Participants analyse a realistic payments-service sourcing case, review supplier financial and assurance evidence, score competing bids, identify fourth-party dependencies and negotiate contract-control priorities. Small groups prepare approval-committee papers and test one another's recommendations against risk appetite, resilience requirements and commercial constraints. Each day closes with a practical artefact that feeds an end-of-course third-party procurement pack and a 90-day workplace application plan.

Course outline

Day 1: Banking procurement governance and supplier criticality

  • Bank procurement lifecycle from demand intake to supplier exit
  • Outsourcing, third-party and fourth-party risk definitions
  • Critical-service identification and important business service mapping
  • Supplier segmentation by spend, access, substitutability and service criticality
  • Inherent-risk scoring criteria for banking supplier categories
  • Three-lines-of-defence roles in sourcing approvals
  • Risk appetite statements and procurement decision thresholds

Workshop: Participants classify a supplier portfolio and produce a criticality matrix with proposed due diligence tiers.

Day 2: Risk-based sourcing and supplier due diligence

  • Risk requirements in RFI, RFP and tender documentation
  • Weighted evaluation matrices for price, capability, resilience and controls
  • Supplier financial viability and going-concern assessment
  • Sanctions, adverse-media and beneficial-ownership screening
  • Information-security due diligence using control questionnaires
  • Data location, cross-border processing and confidentiality assessment
  • Subcontractor disclosure and fourth-party transparency requirements

Workshop: Participants evaluate three RFP responses and produce a weighted supplier shortlist with evidence gaps and clarification questions.

Day 3: Third-party risk assessment and treatment

  • Inherent versus residual risk calculation
  • Control design and operating-effectiveness evidence
  • Risk registers, issue taxonomy and remediation tracking
  • Business continuity and disaster-recovery assurance review
  • Cyber incident notification and breach-management controls
  • Concentration risk across suppliers, regions and technology platforms
  • Risk acceptance, escalation and approval documentation

Workshop: Participants complete a residual-risk assessment and treatment register for a proposed cloud-enabled payments supplier.

Day 4: Contract controls, onboarding and supplier governance

  • Audit rights, access rights and regulatory cooperation clauses
  • Service-level agreements, key performance indicators and service credits
  • Data protection, retention, encryption and deletion schedules
  • Business continuity, testing and recovery obligations
  • Subcontracting consent and flow-down control clauses
  • Termination assistance, transition planning and exit management
  • Supplier onboarding controls and first-90-day monitoring plans

Workshop: Participants draft a contract-control schedule and onboarding governance plan for the selected supplier.

Day 5: Committee decisions and sustainable third-party oversight

  • Procurement approval papers and risk narrative structure
  • Executive dashboards for supplier risk and remediation status
  • Key risk indicators and early-warning threshold design
  • Supplier performance reviews and control-attestation cycles
  • Material change management for mergers, incidents and new subcontractors
  • Renewal, re-tender and exit decision triggers
  • Lessons-learned reviews following supplier incidents

Workshop: Participants present a complete sourcing recommendation to a simulated bank approval committee and finalise their 90-day application plan.

Tools & standards covered

SAP Ariba, RSA Archer, OneTrust Third-Party Risk Management, ISO/IEC 27001:2022

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You should understand the basic procurement lifecycle and have some exposure to suppliers, contracts, risk assessments or outsourcing decisions. The course assumes professional experience rather than specialist legal or technical expertise, and it builds the banking-specific risk methods during the week.

A laptop is recommended for working on the scoring matrices, risk registers and contract-control templates used in the workshops. Access to your employer's SAP Ariba, RSA Archer or OneTrust environment is not required; training materials use realistic examples and reusable templates.

It is most suitable for procurement, vendor-management, operational-risk, resilience, compliance and technology-risk professionals in banks. It is particularly relevant for staff involved in material outsourcing, cloud sourcing, payment services and critical operational suppliers.

The course focuses on the controls and evidence needed when a bank appoints and oversees third parties, not merely on negotiation, savings or supplier relationship techniques. It links sourcing decisions to criticality, operational resilience, cyber assurance, concentration risk, contractual rights and governance approvals.

Participants can use the supplier segmentation model, weighted evaluation matrix, due diligence plan, risk register and contract-control schedule in active sourcing events. The final 90-day plan identifies a specific supplier, procurement process or governance improvement to address after the course.

You leave with a completed third-party procurement pack developed through the banking case study. It includes a supplier criticality rationale, bid evaluation matrix, due diligence checklist, risk treatment register, contract-control schedule and onboarding monitoring plan.

Upcoming sessions

  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Cape Town · USD 4,200
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book
  • 02 – 06 Nov 2026
    Nairobi · USD 3,000
    Book
  • 09 – 13 Nov 2026
    Live Online · USD 1,500
    Book
  • 09 – 13 Nov 2026
    Kigali · USD 3,500
    Book
  • 16 – 20 Nov 2026
    Live Online · USD 1,500
    Book
  • 23 – 27 Nov 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Procurement

5 Days Certificate

Procurement Negotiation Skills for Strategic Buyers Training Course

Strategic buyers often negotiate agreements that affect cost, continuity of supply, quality performance, innovation access and working capit…

5 Days Certificate

Procurement Contract Management for Procurement Officers Training Course

Procurement officers are often expected to move quickly from supplier selection to contract award, yet the greatest commercial exposure freq…

5 Days Certificate

Kraljic Portfolio Matrix for Procurement Planning Training Course

Procurement teams often apply the same sourcing approach to every category, despite major differences in supply risk, spend exposure, market…

5 Days Certificate

Oil and Gas Procurement and Materials Management Training Course

Oil and gas procurement decisions are made under conditions that amplify cost, schedule and operational risk: long-lead rotating equipment, …