| 7:30am - 8:30am CT | Breakfast Buffet | | Breakfast will be served ahead of opening remarks at 8:30am CT | Summit Ballroom ABC |
| 8:30am - 8:45am CT | Opening Remarks & Awards | Andrew Moyad, CEO, Shared Assessments | | Summit Ballroom D & E |
| 8:45am - 9:35am CT | Panel: Building the Agile Program: Adapting TPRM to Shifting U.S. and Global Regulatory Tides | Moderator: Andrew Moyad, CEO, Shared Assessments
Panel:
David O'Connor, Director Information Security Governance, Risk, and Compliance, Iron Mountain
Dave Stapleton, Chief Trust Officer, Process Unity
Munish Walther-Puri, Head of Critical Digital Infrastructure, TPO Group and IANS Research
Neema Wasira-Johnson, Founder & CISO, Asili Advisory Group | Regulatory expectations are changing faster than many programs can adapt and are sometimes rolled back just as quickly. This session focuses on how to design TPRM programs that remain effective amid ongoing regulatory uncertainty and emphasizes judgment, prioritization, and the distinction between compliance requirements and effective risk management. | Summit Ballroom D & E |
| 9:35am - 10:05am CT | Sponsored Keynote | Nick Geyer, Sr. Technical Product Marketing Manager, OneTrust | “Major League” Risk Management In An AI-enhanced Era
Third Party Risk Management has always been a team sport, balancing critical risk factors to maintain a strategic advantage for your business. But AI is a changing the game as a legal performance enhancer—for your vendors, for attackers, and potentially for your TPRM program.
In this session, we’ll power rank the top TPRM use cases for performance enhancing AI (PEAI): faster and more comprehensive due diligence, responsive triage and workflow management, etc. We’ll also scout the side effects: AI-specific risks, accelerating risk velocity, expanding regulatory risk exposure, and more.
Walk away with practical considerations to evolve TPRM to manage AI risk and use AI responsibly to drive performance gains.
| Summit Ballroom D & E |
| 10:05am CT | Day Two Orientation | Andrew Moyad, CEO, Shared Assessments | Announcements, Raffles & Explanation of the Day Ahead
Day Two offers a flexible, choose-your-own-path experience designed to meet attendees where they are. Following opening remarks from Shared Assessments CEO Andrew Moyad, the Summit will split into two concurrent tracks: a Thought Leadership Track, featuring strategic panels on emerging trends and industry direction, and a Practitioner Track, focused on interactive discussions and real-world program execution. Attendees are encouraged to self-select sessions based on their interests and priorities within the TPRM ecosystem. | Summit Ballroom D & E |
| 10:05am - 10:35am CT | Exhibitor Networking Break | | 30 Minute Exhibitor Networkig Break | |
10:35am - 11:25am CT
| Concurrent Sessions: The Thought Leadership Track & The Practitioner Track | Thought Leadership Moderator: Elizabeth Dunsmoor, TPRM Principal, Shared Assessments
Panel: Tom Garrubba, Chief Commercial & Partnership Officer | Co-Founder, FusionAIrre
Brian Katula, Director of Operational Resilience, Global Resilience Federation (GRF)
Courtney Turner, Enterprise Third Party Risk Manager, John Deere
Practitioner Moderator: Sheria Williams, TPRM Principal, Shared Assessments
Panel: Eylem Alper, President, BraunWeiss
Matthew Ridenhour, Senior Manager, Compliance Operations, UKG
Alexei Saba, Senior Manager, Third Party Risk, McKinsey & Company | The Thought Leadership Track: "Operational Resilience in Action: Aligning TPRM and Business Continuity for Third-Party Disruption"
Operational resilience depends as much on third parties as it does on internal preparedness, but most organizations still struggle to connect TPRM and Business Continuity efforts. This session explores the critical "two-step" required between third-party risk teams and resiliency leaders. This session explores how third-party risk teams partner with operational resilience and continuity leaders to align vendor criticality, validate recovery expectations (RTO/RPO), and strengthen response planning for real-world disruptions.
The Practitioner Track: "How to work with what you got, when all you got is you"
Most TPRM programs operate under ongoing resource constraints, from limited staff to tightening budgets. This practitioner-led session explores how teams define realistic success, prioritize effectively, and build credibility with internal stakeholders. Panelists will share practical strategies for expanding impact, advocating for resources, and sustaining momentum without expanding headcount. | Thought Leadership: Summit Ballroom ABC
Practitioner: Summit Ballroom D & E |
| 11:25am - 11:30am CT | Transition Between Track Sessions | | 5 Minute Transition Between Track Sessions | |
| 11:30am - 12:20pm CT | Concurrent Sessions: The Thought Leadership Track & The Practitioner Track | Thought Leadership Moderator: Elizabeth Dunsmoor, TPRM Principal, Shared Assessments
Panel: Philip Bennett, AVP Cyber Governance, Communications & Reporting, Navy Federal Credit Union
Trony Clifton, Director | Cyber Third Party Governance, Information Security Division
Scott McMichael, Deputy Chief Information Security Officer, Cyber Governance and Risk, Live Oak Bank
Practitioner Moderator: Nasser Fattah, Senior Advisor, Shared Assessments
Panel: Jill Henriques, GRC GTM Subject Matter Expert, Vanta
John Yeoh, Chief Scientific Officer, Cloud Security Alliance (CSA)
Zaid A. Zaid, Senior Advisor, Orange Court Strategies
| The Thought Leadership Track: "Supply Chain Resilience in Times of Uncertainty"
Global supply chains are increasingly shaped by geopolitical, economic, and policy forces that challenge traditional risk models. This session explores how these dynamics translate into real third-party risk impacts, from regional instability to regulatory and trade disruptions. Panelists will share how TPRM programs are adjusting assessments, monitoring, and supplier engagement to remain resilient amid ongoing uncertainty.
The Practitioner Track: "Shared Responsibility in the Cloud: Who Owns the Risk"
Cloud computing has blurred traditional lines of accountability between organizations and their third parties. This session examines how shared responsibility models work in practice, where they most often break down, and how teams can clarify responsibilities, strengthen oversight, and respond when providers push risk outside their scope. | Thought Leadership: Summit Ballroom D & E
Practitioner: Summit Ballroom ABC |
| 12:20pm - 12:25pm CT | Transition Between Track Sessions | | 5 Minute Transition Between Track Sessions | |
| 12:25pm - 1:15pm CT | Concurrent Sessions: The Thought Leadership Track & The Practitioner Track | Thought Leadership Moderator: Chris Johnson, Senior Advisor, Shared Assessments
Panel: Jonathan Dambrot, CEO & Co-Founder, Cranium AI
Konstantinos Karagiannis, Director Quantum Computing Services, Protiviti, Inc.
Brian Shaw, Vice President, Head of North America, Certa
Practitioner Moderator: Rhonda K.R. Cook, Senior Advisor, Shared Assessments
Panel: Michael Berman, Chief Executive Officer, Ncontracts
Susan Brindle, VP, Sourcing & Vendor Mgmt, F&G Annuities & Life
Debra Zoppy, Head of Third Party Risk, Guardian Life Insurance Company of America
| The Thought Leadership Track: "Emerging Technologies, Emerging Threats: How AI and Quantum Are Redefining Risk"
AI and quantum computing are accelerating change across third-party ecosystems, challenging assumptions about security, data protection, and control effectiveness. This session examines how these technologies are reshaping risk exposure and where traditional TPRM approaches may fall short.
The Practitioner Track: "These Boots Were Made for Walking: The Cost of a Messy Exit"
Vendor exits can create lasting risk if not managed effectively. This session explores the operational, reputational, and data impacts of poor offboarding and highlights practical lessons for strengthening contracts, transition plans, and governance. | Thought Leadership: Summit Ballroom D & E
Practitioner: Summit Ballroom ABC |
| 1:15pm - 2:30pm CT | Networking Lunch & The Risk Roundabout | | Networking Lunch
The Risk Roundabout: Your Hub for Expert Insights and Practical Solutions
The Risk Roundabout is Shared Assessments’ informal, committee-sponsored gathering space at Summit, designed for candid conversations, quick guidance, and real-world peer exchange. Drop in to connect with committee leaders, Senior Advisors, and SMEs who can help you pressure-test ideas, talk through challenges, and point you toward the right resources or community discussions. Some time slots may also be available for short, pre-scheduled 15–20 minute conversations, helping attendees connect with the right expert at the right time. | |
| 2:30pm - 4:00pm CT | Concurrent Interactive Sessions | TPRM Navigator Speakers:
Andrew D’Angelo, Director, Protiviti Inc.
Elizabeth Dunsmoor, TPRM Principal, Shared Assessments
Jennifer Hancock, Senior Vice President, Professional Development & Education, Shared Assessments
Paul Kooney, Managing Director, Protiviti Inc.
Incident Response Roleplay Speakers:
Christopher Denning, Chief Security Officer & Director of Business Resilience, Global Resilience Federation (GRF)
Brian Katula, Director of Operational Resilience, Global Resilience Federation (GRF)
Andrew Moyad, CEO, Shared Assessments
David O'Connor, Director Information Security Governance, Risk, and Compliance, Iron Mountain
SIG Evolution Speakers:
Mike Baker, Software Developer, Shared Assessments
Sheetal Chaudhari, Senior Software Engineer, Shared Assessments
Katie Dorkings, Director of Sales, Shared Assessments
Corinne Johnson, Sales Manager, Shared Assessments | Attendees will close out the Summit by selecting one of three concurrent working sessions:
- TPRM Navigator: Peer Benchmarking & Maturity Mapping (Guided Roundtable)
Participants will begin with an abbreviated TPRM maturity self assessment guided by the VRMMM’s 8 Domains using their laptop or tablet, followed by expert facilitated roundtables to compare results and explore shared challenges. The session will unpack how to evaluate and rate your program with greater consistency and confidence, supported by peer benchmarking and structured discussion. Attendees will leave with actionable insights and practical guidance to strengthen and advance their own TPRM program. Please bring a laptop or tablet to fully participate
- Incident Response Roleplay: Vendor Breach Edition
In this 90-minute interactive simulation, participants will navigate the first several phases of an incident affecting core services and external dependencies. Through timed injects and guided decision questions, attendees will work through incident identification, triage, and response prioritization. Participants will also navigate communications and legal constraints while weighing recovery vs. resilience tradeoffs under the added friction of vendor reliance. The session is designed to build shared understanding across functions and uncover at which points governance, response planning and dependency mapping break down under pressure. Please bring your laptop or notebook.
- SIG Evolution (SIG EV): Interactive Demo & Q&A Lab
This hands-on lab moves beyond slides and into the platform. Join the Shared Assessments Product team for a live walkthrough of SIG Evolution, the web-based delivery of the SIG methodology–and experience how assessments are created, distributed, reviewed, and scored in a secure, browser-based environment.
We’ll demonstrate how SIG EV preserves the trusted structure and content of the SIG while modernizing workflow efficiency, collaboration, and scoring visibility.
You’ll see what’s new, what remains consistent, and how SIG EV integrates into existing TPRM programs without replacing your GRC or workflow tools. Bring your questions.
This is an open Q&A session designed to surface real-world use cases, transition considerations, and practical insights from the team building the platform.
Whether you’re a long-time SIG workbook user or exploring SIG for the first time, this session is designed to give you clarity and confidence in what comes next. | |