Enhancing Vendor Risk Management: Best Practices for Security Oversight
- In an era of accelerating digital transformation and increasing regulatory scrutiny, third-party risk management (TPRM) has become a strategic imperative for financial institutions. This thesis examines the TPRM framework of Deutsche Börse Group (DBG), a critical financial market infrastructure provider, with the aim of evaluating its current maturity, identifying internal control gaps, andIn an era of accelerating digital transformation and increasing regulatory scrutiny, third-party risk management (TPRM) has become a strategic imperative for financial institutions. This thesis examines the TPRM framework of Deutsche Börse Group (DBG), a critical financial market infrastructure provider, with the aim of evaluating its current maturity, identifying internal control gaps, and proposing targeted improvements aligned with international regulatory expectations. The research adopts a qualitative case study methodology, leveraging internal documents,stakeholder feedback, and benchmarking against established standards such as DORA, the ECB SSM guidelines, ISO 27001, and COBIT. A detailed internal insight analysis reveals gaps in areas such as automation, fourth-party risk visibility, performance monitoring, and escalation protocols. These are further mapped against best practices to quantify maturity levels and assess risk exposure. Based on the findings, a set of strategic recommendations is proposed across five dimensions: governance, process, technology, compliance, and culture. These are structured into a phased implementation roadmap to support DBG’s efforts in achieving operational resilience and regulatory alignment. The thesis contributes both to academic understanding of TPRM in highly regulated environments and to practical enhancements for financial institutions operating under European supervision.…
Document Type: | Master's Thesis |
---|---|
Zitierlink: | https://opus.hs-offenburg.de/10577 | Bibliografische Angaben |
Title (English): | Enhancing Vendor Risk Management: Best Practices for Security Oversight |
Author: | Abhishek Wasnikar |
Advisor: | Jörg Pfeffer, Daniel Hammer |
Year of Publication: | 2025 |
Publishing Institution: | Hochschule Offenburg |
Granting Institution: | Hochschule Offenburg |
Place of publication: | Offenburg |
Publisher: | Hochschule Offenburg |
Page Number: | 78 |
Language: | English | Inhaltliche Informationen |
Institutes: | Fakultät Medien (M) (ab 22.04.2021) |
Collections of the Offenburg University: | Abschlussarbeiten / Master-Studiengänge / ENITS |
DDC classes: | 000 Allgemeines, Informatik, Informationswissenschaft |
Tag: | Digital Operational Resilience Act (DORA); Third-Party Risk Management (TPRM); Vendor Risk | Formale Angaben |
Open Access: | Closed |
Licence (German): | ![]() |