# Third-Party Risk Management: When to Accept or Reject Vendor Documentation Page: https://stenobird.com/podcast/grc-uncensored-7039393/third-party-risk-management-when-to-accept-or-reject-vendor-documentation Text version: https://stenobird.com/podcast/grc-uncensored-7039393/third-party-risk-management-when-to-accept-or-reject-vendor-documentation.md Podcast: [GRC Uncensored](https://stenobird.com/podcast/grc-uncensored-7039393) Published: 2025-03-27T10:30:00+00:00 Episode link: https://grcpod.substack.com/ Audio file: https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67e4a41cd6912226b5d693e9/media.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/third-party-risk-management-when-to-accept-or-reject-vendor-documentation Duration seconds: 3223 ## Resource On a recent episode of GRC Uncensored, host Troy Fine and producer Elliot Volkman were joined by guest Stanley Krochik , a now seasoned GRC professional and former city security program manager, to discuss the realities of third-party risk Management (TPRM). The conversation focused on the growing issue of low-quality audits, the challenge of assessing vendor security postures, and the dilemma risk managers face when reviewing third-party documentation. 04:43 The Importance of Third Party Risk Management 05:45 Challenges with Low Quality Audits 07:45 Evaluating SOC 2 Reports 12:55 Issues with Sales-Focused GRC Tools 14:44 The Need for Better Compliance Programs 27:50 High-Risk Vendor Architecture Review 29:07 SOC 2 Reports and Vendor Risk Management 31:50 Challenges with SOC 2 and Auditor Quality 36:49 Financial Impact of Data Breaches 38:10 Differences in Security Between Old and New Systems 47:43 Proactive vs. Reactive Security Measures Hosted on Acast. See acast.com/privacy for more information. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/third-party-risk-management-when-to-accept-or-reject-vendor-documentation/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/grc-uncensored-7039393/third-party-risk-management-when-to-accept-or-reject-vendor-documentation.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.