© 2016 Provi Inc. An Equal Opportunity Employer M/F/Disability/Veterans. © 2016 The Santa Fe Group, Shared Assessments Program. All rights reserved. To learn more, visit sharedassessments.org and provi.com/vendor-risk. 61 % 65 % Organizaons that have an incident response plan in place to respond to events at vendors or third pares Organizaons with an incident response plan in place that test the plan with vendors or third pares 2016 Vendor Risk Management Benchmark Study The Shared Assessments Program and Provi Examine the Maturity of Vendor Risk Management Companies appear to have reached a posive turning point with regard to managing their vendor risks. The results of the latest Vendor Risk Management Benchmark Study from the Shared Assessments Program and Provi indicate that: • Organizaons in all industries are increasing their focus on managing vendor and third party risks. • Levels of maturity in different vendor risk management components have noceably improved. • Organizaons with high levels of board engagement with regard to vendor cybersecurity risks report higher maturity levels for all aspects of vendor risk management. About the Survey The Vendor Risk Management Benchmark Study was conducted online in the second and third quarters of 2016, with 391 execuves and managers parcipang in the study. For each vendor risk component, respondents were asked to rate the maturity level as that component applies to their organizaon, based on the following scale: 5 = Connuous improvement – benchmarking, moving to best pracces 4 = Fully implemented and operaonal 3 = Fully defined and established 2 = Determine roadmap to achieve goals 1 = Inial visioning 0 = Do not perform Program Governance Policies, Standards and Procedures Contracts Vendor Risk Idenficaon and Analysis Skills and Experse Communicaon and Informaon Sharing Tools, Measurement and Analysis Monitoring and Review Vendor Risk Management Maturity Levels 2016 Companies with high board engagement in vendor cybersecurity 2016 Overall index 2015 Overall index 4 3.5 2.5 3 2 CATEGORY