Third Party Therapy

podcast artwork

Podcast by Mike Day

Third Party Therapy

A bi-weekly podcast about the world of third party risk. Many of us are in the same position, facing ever evolving challenges, trying to keep up with new regulations and laws and it often feels like we are struggling to keep up. I want to really open up the conversation on this topic by speaking with practitioners to discuss key topics, understand what worked well and what went wrong, what people struggle with and to bring in ideas from other industries too. I’ll be asking the questions that folks may feel silly or uncomfortable asking too. So, why not join me for a series of informal interviews and discussions to really open up the conversation for the third party risk community?

Latest episodes

episode artwork

31 August 2026

Third Party Therapy - David Warrick - From Xbox to Agentic AI: Building Supply Chains That Embrace Chaos

Mike Day is joined by David Warrick — a 23-year Microsoft veteran (including original Xbox project manager) and former Coca-Cola manufacturing engineer — for a wide-ranging conversation on what it actually takes to run a supply chain in a world where "normal" no longer exists.

David explains why the industry's decade-long obsession with "resilience" may be quietly limiting agility, why inventory buffering — once seen as a P&L sin — is back in fashion as a tariff hedge, and why 2020 was one of the most innovative years supply chain has ever had, simply because there was no other option. The conversation moves from the Ever Given's grounding in the Suez Canal (and the knock-on effects nobody was watching for) to the shift from static ERP snapshots to real-time, point-of-sale-driven planning, and on to the idea of agentic AI as a workforce in its own right — one that needs guardrails, not just guardrails around software.

Mike and David also dig into why these same principles apply well beyond physical goods — financial services, insurance, and any business built on supply and demand — and why hiring "industry insiders" can sometimes be the worst way to solve a problem.

Topics covered, in order:

  • David's background — Coca-Cola, the Hong Kong airport build, Accenture and 23 years at Microsoft (Xbox, Nokia, Surface)
  • How supply chain complexity has changed — from "simplify everything" to embracing volatility
  • Why buffering inventory is back as a tariff hedge, after a decade of trying to kill it
  • 2020 as one of supply chain's most innovative years — because there was no choice
  • Why "resilience" can actually limit a supply chain's ability to grow and adapt
  • Moving from "sense and respond" to "anticipate and act" using AI and predictive models
  • The Ever Given, the Suez Canal, and the downstream bottlenecks nobody was watching for
  • Multi-tier supply chain mapping vs understanding true industry-wide dependency risk
  • Real-time point-of-sale data and the shift away from static, "point in time" ERP systems
  • Federated inventory and dynamic order allocation
  • Applying supply chain principles to financial services and other non-physical industries
  • Agentic AI as a workforce, not just software — guardrails, accountability and trust
  • Why hiring "industry insiders" isn't always the right call
  • Common mistakes: sunk-cost thinking on legacy software, and "wait and see" paralysis on AI
  • David's advice for building a resilient, nimble supply chain from scratch

Key quotes from David Warrick:

  • "Never let a good crisis get in the way of innovation."
  • "What we experience now is our new normal... it's a constant stream of grey swan events."
  • "Supply chains are built to sense and respond, but the modern supply chain has to be able to anticipate and act."
  • "Not every suggestion is a rip and replace."
  • "This is not an if, it's a when conversation."

Guest: David Warrick, supply chain advisor and former Microsoft VP of Supply Chain (Europe, Middle East, Asia Pacific & Japan; original Xbox project manager; led Nokia integration and Surface manufacturing in China). Since retiring from Microsoft in 2022, he works with venture capital and private equity firms bringing startup technology into major corporate supply chains.

Third Party Therapy is a podcast about third-party risk, vendor management and supply chain resilience, produced in association with CeFPro. New episodes on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube.

🔔 Subscribe for more conversations on supply chain, AI and third-party risk management 🌐 Sign up to the newsletter: thirdpartytherapy.com

#SupplyChain #ThirdPartyRisk #TPRM #AgenticAI #ArtificialIntelligence #SupplyChainManagement #Microsoft #RiskManagement #VendorRisk #SupplyChainResilience

00:00

48:50

episode artwork

17 August 2026

Third Party Therapy - Donna Bowden & Laura Sellers - Career Coaching for Procurement & Third-Party Pros

Mike Day is joined by Donna Bowden and Laura Sellers, co-founders of Procurement Pivots — a coaching collaboration focused on the development of procurement and third-party risk professionals.

Laura spent almost 10 years in-house in public sector procurement before retraining as a coach and launching her practice in 2022. Donna has 25 years' experience supporting procurement and risk careers, including a background leading corporate governance recruitment, and set up her own coaching practice two years ago. Together they talk personal branding, burnout, imposter feelings and what actually helps a career move forward, whether you're aiming for CPO or planning your next step beyond it.

Topics covered:

📈 How procurement and third-party risk management have evolved as professions

⚖️ The "do more with less" pressure, and why comparing yourself to other organisations backfires

🧠 Confidence, overwhelm and decision paralysis — and why capability is rarely the real issue

🤝 Influencing without authority, company politics, and inheriting a predecessor's legacy

👀 Why procurement and TPRM go unnoticed when things run well, and the profession's "PR problem"

🔀 Whether procurement, supplier management and third-party risk are converging or splitting apart

🚪 How people actually enter procurement and TPRM careers

⚧ Diversity and gender balance in the profession — progress made and gaps remaining

✨ Why personal branding is now essential, not optional, for career progression

🧭 Life after CPO: portfolio careers, consultancy and avoiding burnout

🪜 Practical first steps for anyone feeling stuck at a career crossroads

Timestamps:

00:00 Intro

01:00 Donna and Laura's backgrounds and how Procurement Pivots started

05:30 How procurement and TPRM have evolved as professions

09:30 "Do more with less" and the comparison trap

12:00 Confidence, overwhelm and decision paralysis

16:00 Influencing without authority, politics and inherited legacy

20:30 Why the profession is invisible when it's working well

23:00 Converging or splitting: procurement, supplier management and TPRM

30:00 How people actually get into procurement and TPRM

34:30 Diversity and gender balance in the profession

39:00 Why personal branding is now essential

45:30 Life after CPO: portfolio careers and burnout

51:00 Advice for anyone at a career crossroads

54:30 Where to find Procurement Pivots

Procurement Pivots: procurementpivots.com/home

Subscribe to Third Party Therapy and join the mailing list at thirdpartytherapy.com.

#Procurement #ThirdPartyRisk #TPRM #CareerCoaching #ProcurementPivots #ThirdPartyTherapy #PersonalBranding #CareerDevelopment

00:00

51:43

episode artwork

03 August 2026

Third Party Therapy - Julie Gaiaschi - Inside the TPRA: Building a Community for Third Party Risk

In this episode, Mike Day is joined by Julie Gaiaschi, CEO and co-founder of the Third Party Risk Association (TPRA), a non-profit, vendor-agnostic professional association for the third party risk management (TPRM) industry.

Julie shares how her career as an IT auditor and healthcare security practitioner led her to co-found a roundtable that grew from 15 companies to 125 in four meetings — and eventually became TPRA. She and Mike discuss:

  • How TPRM evolved from a procurement and compliance "check the box" function into a proactive, strategic risk management discipline
  • Why finance and healthcare led on TPRM maturity, and how retail and manufacturing have caught up post-COVID (including the Target/HVAC vendor breach as a catalyst)
  • The crossover between physical supply chain risk (manufacturing, pharma, automotive) and digital/cyber risk (SBOMs, AI-BOMs)
  • How TPRM as a profession has evolved — from an accidental, side-of-desk role to a recognised career path, and the rise of Chief Risk Officer functions
  • Geographic differences in TPRM maturity: the US and Europe (GDPR, DORA) leading, with Australia, Brazil, South Africa and China at earlier stages
  • Fourth-party and supply chain discovery tools, including mentions of Interos, Black Kite and Prompt Armor
  • TPRA's new AI-focused Trust Portal guidance, developed with a Third Party Advisory Committee of major tool providers, open for public comment until 3 July
  • TPRA's upcoming events: a free virtual conference (9 September), quarterly tool "demo days," a new event for consultants (September), and in-person events in Dallas (14–15 October) and London (10–11 November) in partnership with CeFPro
  • Julie's advice for anyone new to TPRM: download the free TPRM 101 Guidebook, learn your business, get involved in the community, and build cross-functional relationships early

Guest: Julie Gaiaschi, CEO & Co-Founder, Third Party Risk Association (TPRA) Host: Mike Day

Third Party Therapy is produced in association with CeFPro Connect.

🔗 Sign up to the mailing list at thirdpartytherapy.com 🔔 Subscribe for future episodes and hit like if you enjoyed this one

Chapter markers / timestamps

  1. Introduction and welcome
  2. Julie's background: IT audit → healthcare security → founding the TPRA roundtable
  3. Why finance and healthcare led on TPRM, and how retail/manufacturing caught up post-COVID
  4. Supply chain crossover: physical goods vs. services, SBOMs and AI-BOMs
  5. The professionalisation of TPRM: from procurement side-of-desk to Chief Risk Officer functions
  6. Where TPRM people come from, and the skills that matter most
  7. Geographic differences: US, Europe, Australia, Brazil, South Africa, China
  8. Technology landscape and fourth-party discovery tools (Interos, Black Kite, Prompt Armor)
  9. AI, resourcing, and moving TPRM "up the value chain"
  10. TPRA's Trust Portal guidance and Third Party Advisory Committee
  11. Upcoming TPRA events (virtual conference, demo days, Dallas, London)
  12. Lessons learned: advice for anyone new to TPRM
  13. Close and sign-off

00:00

45:04

episode artwork

13 July 2026

Third Party Therapy - Jeffrey Wheatman - Questionnaires, Scores and Shadow AI: Rethinking Third‑Party Cyber Risk

Mike Day is joined by Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite, for a wide-ranging conversation on third-party cyber risk management (TPRM). They cover why questionnaires alone are no longer enough, how dynamic monitoring and cyber risk quantification are changing vendor oversight, why storytelling is the key to getting business buy-in, and how AI — both as a business tool and an attacker's weapon — is reshaping the third-party risk landscape.

Guest

Jeffrey Wheatman, Senior Vice President, Cyber Risk Strategist at Black Kite. Previously spent 15 years as a research analyst at Gartner, built a security programme at Martha Stewart Omnimedia, and ran his own consulting practice. Joined Black Kite four years ago.

In this episode

  • [01:02] Jeffrey's route into cybersecurity — from managing a New York hardware store to Novell NetWare training, consulting, Martha Stewart Omnimedia, 15 years at Gartner, and now Black Kite.
  • [04:42] How third-party risk management has evolved: from contract/legal sign-off, to security questionnaires, to outside-in vendor scores, to today's risk-based, intelligence-led approach.
  • [07:11] Why not all vendors matter equally — tiering vendors so effort is focused on the ones that actually pose material risk.
  • [09:45] Two UK-rooted supply chain incidents: the KNP Logistics ransomware attack that put the firm out of business, and the Jaguar Land Rover cyberattack that reportedly affected UK GDP.
  • [11:17] Has the market moved beyond questionnaires? Financial services and insurance are further ahead; small niche vendors and giant vendors (e.g. Google) both present unique challenges.
  • [13:47] The case for cyber risk quantification — Black Kite's OpenFAIR-based model and the three risk scenarios it prioritises: data loss, ransomware, and vendor non-delivery.
  • [15:30] Translating cyber risk into business language: business impact analysis, stakeholder relationships, and a real anecdote about an aerospace manufacturer that stockpiled a critical component ahead of a supplier's ransomware attack.
  • [23:04] Jeffrey's simplified framing for engaging executives: money coming in, money going out, and who's accountable if something goes wrong.
  • [24:05] Scepticism around third-party risk scores, the case for methodology transparency ("open the raincoat"), and a credit-score analogy for contextualising vendor risk.
  • [28:00] The shift from "assess everyone, monitor a few" to "monitor everyone, assess dynamically" — including examples from a large retail customer monitoring 100,000 vendors and an insurer streamlining onboarding.
  • [30:00] Why questionnaires won't disappear entirely (audit and compliance still require them), and caution around AI-generated questionnaire responses and compliance reports.
  • [33:08] Discovering AI in the supply chain — shadow AI, the idea of an "AI Bill of Materials," and why AI adoption often bypasses IT-led vendor review (e.g. HR or marketing tools).
  • [40:01] A discussion of emerging agentic AI security research tools referenced in the episode, and concerns about a rising volume of reported vulnerabilities outpacing organisations' ability to triage them.
  • [43:47] Attack chaining — how several medium-severity vulnerabilities can be combined for privilege escalation, changing how vulnerabilities should be prioritised.
  • [46:47] A cautionary anecdote about a casino network reportedly compromised via an internet-connected aquarium thermostat.
  • [47:54] Where CISOs should prioritise investment: governance and clear ownership, business impact analysis, a defined vendor onboarding process, and continuous monitoring — illustrated with the Change Healthcare/UnitedHealthcare ransomware case.
  • [52:17] Regulatory pressure shaping third-party risk: DORA (EU/UK financial services), NIST, ISO, and HIPAA/NHS-equivalent requirements.
  • [53:28] Closing thoughts on AI and human-in-the-loop working, including a quote Jeffrey attributes to Nvidia CEO Jensen Huang about AI and jobs.

Notable quotes

  • "All vendors are equal. Some vendors are more equal than others." — Jeffrey Wheatman, paraphrasing Animal Farm
  • "Your business executives care about three things: money coming in, money going out, and if something goes wrong, who's in trouble." — Jeffrey Wheatman
  • "The biggest risk in communication is assuming it has taken place." — quoted by Jeffrey Wheatman, attributed to George Bernard Shaw
  • "Don't ask your vendors if they're using AI. They are. It's a matter of understanding what they're using it for." — Jeffrey Wheatman

00:00

55:38

episode artwork

29 June 2026

Third Party Therapy - Chloe Dellow - Walk Before You Run: AI, TPRM Maturity and the Build vs Buy Decision

What does a successful TPRM transformation actually look like — and why do so many organisations get it wrong?

Mike sits down with Chloe Dellow, TPRM and GRC specialist at Diligent, who brings nearly eight years of experience helping organisations build, mature and optimise their third party risk programmes. Chloe offers a frank, experience-led perspective on why technology should enable a well-defined programme — not compensate for an absent one.

In this episode:

🔍 Why most organisations should sort their operating model before they even open an RFP ⚠️ The "magpie effect" — chasing features before understanding your own problem 🤖 How AI is entering TPRM in phases, from SOC 2 document review to continuous monitoring 🔨 Why the build vs buy debate is back — and the hidden risks of going DIY 🧩 Why AI risk isn't really "emerging", and what that reframing means for your framework ✈️ Which industries actually do supply chain visibility well (aerospace and automotive may surprise you) 🔄 The biggest mistake organisations make when switching platforms — and how to avoid rewriting history

Whether you're just starting out or looking to optimise a mature programme, this is a practical and honest conversation about what good looks like in TPRM today.

Timestamps 00:00 Introduction 02:15 Chloe's background — from JavaScript to TPRM advisory 06:30 How TPRM technology has evolved 11:00 Regulatory pressure and programme maturity 16:45 Helping clients through the "where do I start" problem 23:00 The magpie effect and the risk of over-configuration 29:30 AI adoption in TPRM — phased approaches and real use cases 38:00 Build vs buy — and the shadow AI risk 45:00 Is AI really an emerging risk? 51:30 Supply chain visibility — who gets it right? 58:00 What goes wrong in TPRM transformations 1:04:00 Where to start before you go to market

Guest: Chloe Dellow, Diligent Host: Mike Day

🔔 Subscribe for more episodes | 🌐 thirdpartytherapy.com | 📧 Sign up to the mailing list

#TPRM #ThirdPartyRisk #GRC #RiskManagement #AI #OperationalResilience #DORA #Compliance #Podcast

00:00

55:49

episode artwork

16 June 2026

Third Party Therapy - Dave Rusher - Is TPRM Actually Mature? AI, Cross-Sector Lessons & Getting Started Right

In this episode of Third Party Therapy, Mike Day is joined by Dave Rusher, Chief Customer Officer at Aravo, one of the longest-standing dedicated TPRM technology platforms. With 15 years at Aravo and decades of experience across the Americas, UK, Europe and Asia-Pacific, Dave brings a genuinely global perspective on how third party risk management has evolved — and where it still has growing up to do.

They cover the maturity landscape across financial services, pharma and manufacturing, the real-world AI use cases that are already delivering results, and the three most common mistakes organisations make when implementing TPRM technology. Whether you're just starting your TPRM journey or trying to evolve an existing programme, this episode is packed with practical insight.

Topics covered in this episode:

  • How TPRM maturity differs across financial services, pharma and manufacturing — and why FS and pharma led the way
  • The difference between a US "compliance-driven" approach and a more principles-based European one
  • Why manufacturing actually has a head start on Nth-party visibility and ESG — and what FS can learn from it
  • The cross-sector skills that are genuinely portable (anti-bribery/anti-corruption, cybersecurity) versus those that aren't
  • The consolidation vs. diversification tension in TPRM technology ecosystems
  • Where AI is delivering tangible results today — and why cyber/infosec assessment automation is the most mature use case
  • Why getting AI approved internally is often the biggest blocker to adoption in regulated industries
  • How shadow AI usage by employees is compressing organisations' due diligence timelines
  • Dave's three biggest TPRM implementation pitfalls: overestimating maturity, overcomplicating scope, and over-relying on technology
  • Why iterative, objectives-first implementation beats the traditional ERP-style "big bang" rollout
  • How Aravo is building AI capabilities along two parallel tracks — for customers who are ready and those who aren't yet

Timestamps: 00:00 — Introduction 02:00 — Dave's background and 15 years at Aravo 04:30 — How TPRM maturity varies by sector and region 10:00 — Manufacturing vs. financial services: who's ahead and where 15:30 — Cross-sector lessons: what's portable, what isn't 20:00 — Technology trends: consolidation vs. proliferation 25:00 — AI in TPRM: hype vs. reality 31:00 — The biggest AI use case delivering results today 37:00 — Why internal AI approval processes are the real bottleneck 43:00 — AI as a "tool not a transformation" — Mike's take 47:00 — Aravo's AI development roadmap 53:00 — The three TPRM implementation mistakes to avoid 58:00 — Where to start: outcomes-first, iterative delivery

00:00

54:42

Copyright © Third Party Therapy. All rights reserved.

Powered by