The Rise of Fourth-Party Threats
Description
The Institute of Internal Auditors Presents: All Things Internal Audit Tech
In this episode, Mike Levy and Shontelle Mixon discuss the growing risks tied to fourth-party relationships. They discuss how internal auditors can leverage technology, enhanced contracts, and cross-functional collaboration to pinpoint, track, and reduce those downstream risks. They break down how internal audit's role is evolving in a world shaped by cybersecurity, AI, and shifting regulations.
HOST:
Mike Levy, CIA, CRMA, CISSP
CEO, Cherry Hill Advisory
GUEST:
Shontelle Mixon, CPA
Divisional SVP, Internal Audit and Special Investigations, Healthcare Service Corporation
KEY POINTS:
- Introduction [00:00 –00:00:38 ]
- What Is Fourth-Party Risk? [00:00:38 –00:01:52 ]
- Evolution of Risk and Offshoring Trends [00:01:52 –00:02:32 ]
- Mitigating Fourth-Party Risks [00:02:32 –00:03:47 ]
- Steps for Maturing a Vendor Risk Program [00:03:47 –00:04:50 ]
- The Challenge of Shadow IT [00:04:50 –00:05:54 ]
- Data Mining and Continuous Monitoring [00:05:54 –00:06:59 ]
- Beyond the SOC Report [00:06:59 –00:08:27 ]
- Getting Started Without Tech [00:08:27 –00:09:32 ]
- Cybersecurity as a Starting Point [00:09:32 –00:10:44 ]
- Educating the Audit Committee [00:10:44 –00:12:00 ]
- Real-Time Monitoring and Vendor Audits [00:12:00 –00:13:09 ]
- Misconceptions About Outsourcing Risk [00:13:09 –00:13:56 ]
- Preparing for the Future [00:13:56 –00:15:32 ]
- Pitfalls in Contracting [00:15:32 –00:16:38 ]
- First Step for New Audit Functions [00:16:38 –00:17:12 ]
- Aligning with Organizational Risk Priorities [00:17:12 –00:18:36 ]
- Getting Executive Buy-In [00:18:36 –00:20:06 ]
- Supporting Smaller Audit Shops [00:20:06 –00:21:14 ]
- Final Advice [00:21:14 –00:21:58 ]
THE IIA RELATED CONTENT:
Interested in this topic? Visit the links below for more resources:
- 2025 International Conference
- Learning Solutions: Navigating Third and Fourth Party Risks
- Learning Solutions: Auditing Third-Party Risks
Visit The IIA's website or YouTube channel for related topics and more.
Follow All Things Internal Audit:
Apple Podcasts
Spotify
Libsyn
Deezer