In this episode, Mike Day is joined by Julie Gaiaschi, CEO and co-founder of the Third Party Risk Association (TPRA), a non-profit, vendor-agnostic professional association for the third party risk management (TPRM) industry.
Julie shares how her career as an IT auditor and healthcare security practitioner led her to co-found a roundtable that grew from 15 companies to 125 in four meetings — and eventually became TPRA. She and Mike discuss:
- How TPRM evolved from a procurement and compliance "check the box" function into a proactive, strategic risk management discipline
- Why finance and healthcare led on TPRM maturity, and how retail and manufacturing have caught up post-COVID (including the Target/HVAC vendor breach as a catalyst)
- The crossover between physical supply chain risk (manufacturing, pharma, automotive) and digital/cyber risk (SBOMs, AI-BOMs)
- How TPRM as a profession has evolved — from an accidental, side-of-desk role to a recognised career path, and the rise of Chief Risk Officer functions
- Geographic differences in TPRM maturity: the US and Europe (GDPR, DORA) leading, with Australia, Brazil, South Africa and China at earlier stages
- Fourth-party and supply chain discovery tools, including mentions of Interos, Black Kite and Prompt Armor
- TPRA's new AI-focused Trust Portal guidance, developed with a Third Party Advisory Committee of major tool providers, open for public comment until 3 July
- TPRA's upcoming events: a free virtual conference (9 September), quarterly tool "demo days," a new event for consultants (September), and in-person events in Dallas (14–15 October) and London (10–11 November) in partnership with CeFPro
- Julie's advice for anyone new to TPRM: download the free TPRM 101 Guidebook, learn your business, get involved in the community, and build cross-functional relationships early
Guest: Julie Gaiaschi, CEO & Co-Founder, Third Party Risk Association (TPRA) Host: Mike Day
Third Party Therapy is produced in association with CeFPro Connect.
🔗 Sign up to the mailing list at thirdpartytherapy.com 🔔 Subscribe for future episodes and hit like if you enjoyed this one
Chapter markers / timestamps
- Introduction and welcome
- Julie's background: IT audit → healthcare security → founding the TPRA roundtable
- Why finance and healthcare led on TPRM, and how retail/manufacturing caught up post-COVID
- Supply chain crossover: physical goods vs. services, SBOMs and AI-BOMs
- The professionalisation of TPRM: from procurement side-of-desk to Chief Risk Officer functions
- Where TPRM people come from, and the skills that matter most
- Geographic differences: US, Europe, Australia, Brazil, South Africa, China
- Technology landscape and fourth-party discovery tools (Interos, Black Kite, Prompt Armor)
- AI, resourcing, and moving TPRM "up the value chain"
- TPRA's Trust Portal guidance and Third Party Advisory Committee
- Upcoming TPRA events (virtual conference, demo days, Dallas, London)
- Lessons learned: advice for anyone new to TPRM
- Close and sign-off