CBA Improves Its Third-Party Risk Management Approach
We independently review everything we recommend. When you buy through our links, we may earn a commission which is paid directly to our Australia-based writers, editors, and support staff. Thank you for your support!
Brief Overview
- CBA is nearing the transition of 5000 suppliers to ServiceNow’s third-party risk management system.
- The CPS230 prudential standard demands improved vendor risk oversight.
- AI tools such as Now Assist AI will enhance compliance and risk evaluation workflows.
Consolidating Vendor Risk Management
The Commonwealth Bank of Australia (CBA) is in the concluding phases of shifting 5000 suppliers to a newly consolidated third-party risk management system facilitated by ServiceNow. This strategic initiative, discussed during the ServiceNow World Forum in Sydney, aims to unify vendor risk management processes and utilize AI capabilities for improved supervision and compliance.
ServiceNow and AI Synergy
CBA began the integration of ServiceNow into its procurement activities several years back with the rollout of the Sourcing and Procurement Operations (SPO) module. Greg Johnstone, executive product owner, stated that the module was launched to address the difficulties associated with supplier onboarding. Following the implementation of the CPS230 prudential standard, which requires solid vendor risk oversight, CBA broadened its adoption of ServiceNow to further encompass third-party risk management.
Emphasis on Non-Supplier Third-Parties
The primary focus of CBA’s move to ServiceNow was on non-supplier third-parties, such as professional service firms. Stephen Bombardiere, crew lead for business platforms, highlighted that, while the bank had a solid supplier-centric risk management system, managing non-supplier third-parties was disjointed among various teams. This consolidation through ServiceNow’s TPRM module last April enabled CBA to fulfil CPS230 requirements and bolster its organisational assurance in the third-party risk sector.
Supplier Migration Ahead
With the non-supplier migration finished, CBA is now deeply engaged in transferring its suppliers, with completion anticipated within five to six weeks. Once finalized, all risk management workflows for both suppliers and non-suppliers will be streamlined onto the unified ServiceNow platform.
The Role of AI in Risk Evaluation
After the migration, CBA intends to leverage AI, particularly Now Assist, to facilitate risk evaluation processes. AI will assist in reviewing compliance reports and provide insights during risk assessments. As Bombardiere mentioned, the integration of AI will reduce the manual workload involved in interpreting reports and formulating controls, equipping risk professionals with pre-analyzed data.
Conclusion
CBA’s transition to a centralised third-party risk management platform represents a crucial advancement in enhancing its vendor risk oversight in line with the CPS230 standard. The integration of AI tools is projected to further optimise processes, rendering risk assessments more efficient and thorough.











