How to Define TPRM Requirements Before You Shortlist

Third-Party Risk Management Software: How to Define Your Requirements Before You Build a Shortlist

In short Most TPRM evaluations start with a feature comparison — the wrong starting point. Before contacting a vendor, assess your programme’s actual maturity, map every regulatory regime driving the purchase, identify the three teams who’ll use the platform daily, and answer five internal questions in writing. This piece covers all four, plus the data […]

Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029

Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029

In short A company operating in Europe can face up to four supply chain due diligence obligations at once — the French Loi de Vigilance, Germany’s LkSG, the EU’s CSDDD, and the CSRD — each with its own threshold and enforcement route. Omnibus I (March 2026) narrowed the two EU-level regimes but left the two […]

CSRD Supply Chain Compliance

CSRD Supply Chain Compliance After Omnibus I: What Auditors Will Actually Check

In short CSRD supply chain reporting now applies to a narrower set of companies after Omnibus I, but the evidentiary bar for those still in scope hasn’t dropped. This piece covers what changed, what ESRS actually requires from supply chain data, the four things a limited assurance auditor checks, and a 5-step roadmap for building […]

Decarbonising the supply chain: the four questions every procurement department should be asking its suppliers right now

Supply chain decarbonisation is no longer a future objective. It has become an operational priority for procurement teams worldwide. As Scope 3 emissions increasingly represent the largest share of corporate carbon footprints, organizations are under growing pressure to gain visibility across their supplier ecosystems. The challenge is particularly complex for large international industrial groups managing […]

Supplier onboarding: why the first few weeks set the tone for the entire relationship

The Moment That Defines Everything That Follows Every supplier relationship has a founding moment. It is not the signing of the contract, nor the first invoice, nor the first delivery. It is the onboarding process, those first few weeks during which a new supplier discovers how your organisation works, what it expects, and whether it […]

GRC: why ROI isn’t the right metric for measuring the value of your programme

Why ROI Is No Longer the Best Metric for Measuring GRC Programme Value When organizations evaluate Governance, Risk and Compliance (GRC) initiatives, the discussion almost always starts with ROI. How much time will be saved? How many manual tasks will disappear? How many operational costs will be reduced? These questions are legitimate — but they […]

TPRM by design: how to manage the extended enterprise with integrity, insight and accountability?

TPRM by design: how to manage the extended enterprise with integrity, insight and accountability? The concept of the “extended enterprise” has fundamentally transformed how organizations operate. Today, companies no longer create value alone. They increasingly depend on vast ecosystems of: In many industries, third parties now represent a critical extension of the enterprise itself. But […]

Supplier fatigue vs compliance: how to get more from your suppliers without putting extra pressure on them?

Over the last few years, supplier compliance requirements have expanded dramatically. Companies now expect suppliers to provide far more than legal documents. They increasingly request: At the same time, suppliers are already dealing with multiple customers, multiple portals, and increasingly complex reporting obligations. As compliance requirements continue to expand, many organizations are discovering an unexpected […]

Post-Merger GRC Integration: The Hidden Risks of Fragmented Compliance Tools

Introduction: The Illusion of Coverage Through Accumulation There is a phenomenon well known to Risk Management and Compliance teams in post-acquisition organisations: tool proliferation. Every absorbed entity brings its own systems — its ERP, its document management tool, its internal control platform, its supplier repository. With each acquisition, the application landscape grows another layer. Five […]