-
Actuarial
Grant Thornton Bermuda offers a broad range of actuarial services spanning life insurance, non-life insurance, and health insurance. Offering actuarial expertise and integrated services across the evolving data analytics and modelling universe, Grant Thornton’s team of experts and strong international network can provide a range of solutions tailored to your actuarial requirements.
-
Business Risk Services
Grant Thornton can help your organisation successfully manage risk, while embracing innovation and harnessing the right technology to deliver effective customer centric solutions tailored to your specific needs.
-
Consulting
The Grant Thornton FS Consulting team have a wealth of experience across a wide range of issues. From banks to insurance companies, the FS Consulting team have branched into all areas of Financial Services. Our FS Consulting team can help you with an array of issues, and guide you through the journey.
-
Corporate Finance
Grant Thornton’s Corporate Finance team has built up a vast range of experience providing a range of transaction, valuation, deal advisory and restructuring services to clients for the past two decades.
-
Data Analytics
Grant Thornton has the expertise required to ensure you succeed in your analytics proposition. We combine excellent technical skills in data analytics and machine learning, with a deep understanding of your business and the insurance industry.
-
Digital Risk
Grant Thornton provides a range of solutions to the digital risk issues facing organisations today. Our highly-qualified and experienced security experts can assist by advising you on your specific requirements, giving you peace of mind that your cyber risks are minimised.
-
Digital Transformation
Our Digital Transformation team works closely with business leaders to develop and deliver digital strategies and operating models (enterprise-wide, specific functions or shared services) providing new or enhanced capabilities, while driving efficiency.
-
FinTech
Grant Thornton’s cross-functional, dynamic team of specialists can help with your FinTech needs. Whether in supporting existing market participants looking to innovate in products and services, or new entrants seeking to upscale their FinTech businesses within the complex financial services environment, we have the solution for you.
-
Forensic Accounting
Organisations may undergo some type of dispute or internal investigation during their lifetime. Our Forensic Accounting team can seek evidence that can make the difference between finding the truth or being left in the dark.
-
Objectives and Key Results (OKRs)
Objectives and Key Results (OKRs) is a goal setting framework that helps teams, individuals and organisations set and track measurable goals. At Grant Thornton we understand the highly competitive and increasingly demanding environment in which your organisation operates, along with constant pressures to grow and innovate.
-
People and Change Consulting
Grant Thornton engages with clients to effectively build and implement the learning, development and career progression frameworks necessary to attract and retain first-rate talent in today’s dynamic workplace.
-
Prudential Risk
Our Prudential Risk Advisory Team of specialists engages with clients on a broad range of issues within the financial services sector, developing and implementing tailored strategies to manage and mitigate many types of financial risk.
-
Quantitative Risk Services
Our Quantitative Risk team comprises more than 20 specialists educated to postgraduate level in relevant disciplines including Mathematics, Statistics, Engineering, Computer Science and Econometrics.
-
Sustainability Desk
Grant Thornton’s team of experts provides a wide range of sustainability solutions, combining our knowledge of sustainability with our deep experience in providing professional services.

When you have a dependence on third parties, you need a dedicated approach to third-party risk management (TPRM). TPRM programs manage the risks that can be introduced through third-party relationships, including brand and reputation risks through data leaks, disruptions to customer service, supply chain risks and even financial fraud. When your service provider uses downstream entities for extended service and support, you also need to consider the risks from a fourth party (a subcontractor to your third party).
The realities of third-party risks are important in the boardroom. The board’s oversight of the risk function is important to making sure all bases of the risk profile are covered. That’s especially true for private companies, where risks might be greater due to less regulatory mandated oversight.
How can you find the capacity and skills for additional TPRM when you form a significant new third-party relationship?
Internal audit (IA) can play a critical role in responding to this risk environment, and IA is keenly aware of third-party risk. In a recent survey from the Institute for Internal Auditors, third-party risk was identified as one of the top three areas of concern. The internal audit team brings an independent perspective to process, risks and controls, along with experience in reporting to senior leadership, all of which can be key to designing your TPRM program.
Trends in TPRM
As you launch or improve your TPRM program, consider starting with an awareness of market trends. Some of the current trends include:
IA in evaluating TPRM readiness
Internal audit can help you provide a TPRM readiness assessment, which typically includes three phases:
- Planning and initiation:
IA can help evaluate the effectiveness of a TPRM program by selecting a framework that provides a comprehensive view of the TPRM program lifecycle and in defining the in-scope operating environment. - TPRM program assessment:
IA can help assess the governance and operating model, including TPRM program lifecycle to evaluate controls and to identify process gaps and opportunities for improvement. - Reporting:
IA can help prioritize any remediation needs with key stakeholders, develop a comprehensive program assessment and compile a report for board and executive leadership.
IA in assessing TPRM frameworks
There are essentially three TPRM program governance models to consider for your organization: centralized, federated, and de-centralized. The internal audit team can help determine which will work best in the structure of your organization, as each model comes with its own unique benefits and challenges to weigh.
Since internal auditors are independent and objective, they are often called upon to wear a consultant hat instead of an auditor hat. Their risk-based perspective can help determine the maturity level of the existing third-party risk management process, and what governance model and operating framework is the most appropriate. Their knowledge can help determine the appropriate controls for each relationship. IA knows the right questions to help ensure your organization gets the information it needs to select, monitor and manage third-party relationships.
For example, if a third party has access to the company’s data, you might need to ask:
- Is there a defined data classification policy? Does the policy clearly define how certain classes of data should be secured?
- Does the third party have privileged access or elevated privileges? If so, does it log and perform reviews of the activities it performs?
- Does the third party always have carte blanche access, or does it use a limited portal or channel?
- Is the third party being monitored by your organization?
IA can also ask important questions in each phase of the TPRM program. For instance, in contracts and negotiation, IA can make sure you include a “right to audit” clause so that your organization can perform its own investigation if necessary. It’s also important to assess how the third party might be able to grow with your organization in the future.
IA in every phase of TPRM program lifecycle
A TPRM program lifecycle is designed to maximize the business goals while minimizing the risks that arise from external relationships. The goals of the program should be to increase awareness of third-party management roles and responsibilities; establish coordination of third-party relationships; provide a clear understanding of risk; and deliver standardized risk classification and rating levels. The program lifecycle comprises four phases, and IA can play an important role in each one:
- Profiling and selection (due diligence):
IA can evaluate the profiling and selection process, along with adoption and consistency. IA can also assess the risk assessment process, including risk acceptance and exception. The exception process should depend on the risk level of the third party or vendor, require approval from designated authorities and identify compensating controls. - Contract negotiation:
IA can evaluate the entry criteria before a contract is negotiated, to determine if it was evaluated using appropriate mechanisms. A third party or vendor should only be on-boarded after the contractual obligations are met — or for exceptions, after risk mitigation strategies are in place to ensure compensating controls are implemented in a timely manner. - Managing and monitoring:
IA can review guiding principles for risk assessment and monitoring review frequency. These should be based on the nature of service provided and the risk exposure that the company faces when contracting with the third party or vendor. - Termination/off-boarding:
IA can review the process for off-boarding to ensure there is a comprehensive checklist, and appropriate controls and communications in situ.
Outlined below is a typical TPRM program framework, illustrating the business drivers, risk areas and program components over the four phases of the TPRM program lifecycle:
Third party risk management program framework
Third-party services can often help lower costs, improve efficiency, add skills, boost capacity and offer other benefits, but those benefits come with risks that should be managed.
That’s why it’s essential to have a comprehensive and well-designed TPRM program to provide ongoing control monitoring and risk oversight. Internal audit is a valuable partner in addressing these risks, from evaluating the TPRM program governance model to assessing the process, risks and controls through the TPRM program lifecycle. All of this work plays an important role in managing the risks that arise from third party relationships.