Third Party Therapy

podcast artwork

Podcast by Mike Day

Third Party Therapy

A bi-weekly podcast about the world of third party risk. Many of us are in the same position, facing ever evolving challenges, trying to keep up with new regulations and laws and it often feels like we are struggling to keep up. I want to really open up the conversation on this topic by speaking with practitioners to discuss key topics, understand what worked well and what went wrong, what people struggle with and to bring in ideas from other industries too. I’ll be asking the questions that folks may feel silly or uncomfortable asking too. So, why not join me for a series of informal interviews and discussions to really open up the conversation for the third party risk community?

Latest episodes

episode artwork

23 February 2026

Third Party Therapy - Layla White - Beyond Third Parties: Mapping Fourth-Party Risk and Early-Stage Suppliers

Beyond Third Parties: Mapping Fourth-Party Risk and Early-Stage Suppliers – with Layla White (TechPassport)

Episode overview

Season 2 opens with a practical deep dive into one of the hardest problems in modern third-party risk management: understanding what sits beyond your immediate suppliers. Mike is joined by Layla White, founder of TechPassport, to unpack why fourth- and fifth-party dependencies remain opaque, how early-stage suppliers change the risk profile, and why traditional questionnaires and web-scraping approaches struggle to keep up with today’s supply chains.

The conversation blends lived experience from financial services procurement and vendor management with a grounded look at how supply chain mapping actually works in the wild, where outages, cloud concentration, geopolitics, and cyber incidents collide.

What you’ll hear in this episode

  • Why fourth- and fifth-party risk is still a blind spot for many organisations
  • The limits of questionnaires and AI/web-scraped data for mapping supply chains
  • How to identify critical dependencies deeper in the supply chain
  • The problem of hidden concentration risk (especially with cloud and shared infrastructure)
  • Why small suppliers and early-stage tech firms introduce different resilience risks
  • The importance of validating supplier-provided data rather than guessing from public sources
  • How outages propagate through unseen dependencies
  • Why supply chain risk now stretches beyond cyber into resilience, data, ESG, and modern slavery
  • Where regulation is pushing firms to understand and evidence extended dependencies

Key takeaways

  • Supply chain risk is no longer a third-party problem. The real fragility often sits further down the chain.
  • Public signals and scraped data are useful clues, not ground truth. Critical dependencies usually only emerge when suppliers confirm them directly.
  • Concentration risk is rarely obvious until something breaks. Mapping dependencies before an incident is the difference between response and surprise.
  • Early-stage suppliers need structure and support to meet enterprise expectations, not just scrutiny.
  • Effective TPRM is a system of approaches, not a single tool. Questionnaires, live data, mapping, and supplier engagement all have different strengths.

Guest bio

Layla White is the founder of TechPassport, a platform focused on improving how organisations gather and manage supplier information, map extended supply chains, and engage early-stage technology providers. Layla previously worked in financial services procurement and vendor management, where she experienced first-hand the friction, delays, and blind spots that exist in traditional third-party onboarding and supply chain visibility.

Who this episode is for

  • Third-Party Risk and Operational Resilience leaders
  • Procurement and Vendor Management teams
  • Cyber and Cloud risk practitioners
  • Risk, Compliance, and Resilience professionals
  • Anyone grappling with fourth-party visibility, concentration risk, or supplier onboarding in complex ecosystems

Listen to the episode

🎧 Full episode: https://thirdpartytherapy.com

Tags / themes

TPRM, Fourth-Party Risk, Supply Chain Mapping, Concentration Risk, Operational Resilience, Early-Stage Suppliers, Cloud Dependencies, Cyber Resilience

00:00

48:10

episode artwork

15 December 2025

Third Party Therapy - Robert Hannigan - Cybercrime-as-a-Service, Data Poisoning and the future of Cyber Crime.

Great conversation with Robert Hannigan from Blue Voyant, former Director of GCHQ and author of "Counter Intelligence - What The Secret World Can Teach Us About Problem Solving & Creativity". Talking about the business model of cyber crime, how companies can protect themselves and the role of the human in combatting the cyber criminal.

00:00

59:06

episode artwork

01 December 2025

Third Party Therapy - Charlie Lewis - Beyond the Third: Navigating 4th Parties and Cyber Risk in TPRM

A great conversation with Charlie Lewis from McKinsey exploring the cyber risk that develops from a complex supply chain and how companies can take a business focussed approach to risk management

Read Charlie's article on Taking a business-critical approach to supplier nth-party IT risk management

Distributed in conjunction with CEFPRO Connect

00:00

57:02

episode artwork

16 November 2025

Third Party Therapy - Natalie Druckmann - AI Unleashed: Transforming Third-Party Risk

Third Party Therapy – Episode 13

AI Unleashed: Transforming Third-Party Risk

Guest: Natalie Druckmann, Head of EMEA at Certa

Host: Mike Day

Episode Summary

How is artificial intelligence reshaping third-party risk management? In this episode, Mike Day speaks with Natalie Druckmann from Certa, exploring how AI can transform due diligence, regulatory compliance, and supplier oversight. Natalie shares her journey from delivery and procurement into technology leadership, before unpacking the real-world use cases that are redefining TPRM—from automating document review to interpreting complex regulations like DORA. Together, they discuss how organisations can move from spreadsheet chaos to continuous monitoring, and from compliance overhead to strategic insight.

Key Topics

  • Natalie's path from practitioner to tech leader
  • The evolution of TPRM tech: from Excel → platforms → modular AI solutions
  • Industry maturity: financial services vs pharma, retail, and defence
  • Using AI to analyse supplier evidence, interpret new regulations, and enable 'risk management by exception'
  • Why 'process → people → platform' is the right order for success
  • Common pitfalls in adopting technology
  • The future of TPRM: faster onboarding, smarter risk insight, and human + AI collaboration

Memorable Quotes

“We fixed the problem of not knowing—and created the problem of knowing too much.”

“AI in TPRM isn’t about replacing people; it’s about freeing them to focus where it matters.”

“Process first, people second, platform third.”

Takeaways

✅ Start with why and who, before deciding what or how.

✅ Design your process first—technology won’t fix a broken one.

✅ Use AI for transparency, not black-box decisions.

✅ Adopt a base-plate approach: start simple, build as you mature.

✅ Aim for risk management by exception, not exhaustion.

Links & Resources

🌐 thirdpartytherapy.com – show archive

🤖 certa.ai – learn more about Certa’s AI-driven risk solutions

💬 Connect with Mike Day on LinkedIn for future episodes

00:00

01:09:09

episode artwork

06 October 2025

Third Party Therapy - Dharminder Mehmi - Bridging the Gap: from regulation to implementation in TPRM.

Join me in a conversation with Dharminder Mehmi from Legal & General as we explore regulation in the UK Finance sector, the experience of moving from the regulator to the regulated and how regulation may develop in the future.

Distributed with support from CEFPRO Connect

00:00

54:34

episode artwork

15 September 2025

Third Party Therapy - Harj Mattu - Established players and new entrants into the TPRM Technology market

I get to explore my TPRM nerdy side with Harj Mattu from Deloitte as we explore the world of TPRM technology. Who are the big players, who are the new entrants bringing something difference and our favourite topic of AI in TPRM.

Published in partnership with CEFPRO Connect

00:00

58:18

Copyright © Third Party Therapy. All rights reserved.

Powered by