Executive Roundtable on Third-Party Risk Management
Home>Event>Executive Roundtable on Third-Party Risk Management
Executive Roundtable on Third-Party Risk Management
SwedCham members were invited to join Veda Praxis and the Institute of Risk Management (IRM) for an executive roundtable exploring the importance of Third-Party Risk Management in Indonesia on 23 July 2026.
Advancing Risk Management in Indonesia: Third-Party Risk Management & Global Perspective
Speakers
Dr Dini Rosdini, SE, MAk, Ak, CA – Head of Accounting Program, Faculty of Economics and Business, Universitas Padjadjaran
Nugroho Pancayogo – Head of IT & Digital Risk Group, Bank Rakyat Indonesia
Miranti Gani, IRMCert – IRM Indonesia Group Chair
Colin McCrorey, SIRM – IRM Board Director, Director of IRM Asia and Chair of the IRM Australia Group
Victoria Robinson – IRM Head of Partnerships Asia and Director of IRM Asia
Zaf Khan – Director of IRM Asia
Mercy Francisca Sinaga – Chairwoman of BritCham Indonesia and Director/Chief Legal and Government Relations Officer at PT Prudential Life Assurance Indonesia
Ian Leonard Betts – Former Chairman of BritCham Indonesia
1. Executive Summary
The roundtable was held to mark the official launch of the IRM Indonesia Chapter — chaired by Miranti Gani — and the appointment of Veda Praxis as the Institute of Risk Management’s exclusive strategic partner and representative for Indonesia (and Vietnam). The MoU was signed on stage by Syahraki Syahrir (Veda Praxis) and Colin McCrorey (IRM Board Director), with a video message from Stephen Sidebottom, Chairman of IRM Global.
Around the launch, the event convened Indonesian financial services leaders, regulatory experts and the IRM’s global board to discuss third-party risk management (TPRM). The central message: third-party dependency has shifted from an operational and procurement matter to a board-level governance issue, driven by digitalisation, ecosystem interconnection and a wave of new regulation (Basel principles of December 2025, FSB toolkit, PBI 10/2025 and OJK rules issued in 2026). Speakers agreed that checklist-based vendor due diligence is no longer sufficient; organizations must manage the full third-party lifecycle, extend visibility to fourth and nth parties, and build resilience rather than merely add controls.
2. Key Takeaways
The discussions converged on nine points that together describe both what happened at the event and what attendees are expected to act on:
Indonesia joins the IRM network. The IRM Indonesia Chapter was officially launched (chair: Miranti Gani), and Veda Praxis was appointed IRM’s exclusive strategic partner and representative for Indonesia and Vietnam — giving Indonesian risk professionals a local gateway to IRM qualifications, resources and the global community.
Governance, not procurement. Third-party failures are governance failures. Hidden third-party risk must be owned at board level, embedded in the corporate risk profile with defined risk appetite and tolerance — not left to operational teams.
Regulation is converging. Basel’s 12 principles on sound third-party risk management (Dec 2025), the FSB toolkit (2023), PBI 10/2025 and new OJK regulation in 2026 all point the same way: lifecycle-based TPRM. The expectation is spreading beyond banking to all financial services and other industries.
Checklists are not risk management. Cited surveys: roughly 30% of breaches involve third parties, and 49% of financial institutions have experienced a vendor cyber incident. Cases such as CrowdStrike and Wirecard show one third-party incident now produces multiple, interconnected impacts — operational, financial and reputational.
Manage the full lifecycle. Assess before contracting, tier by criticality, monitor continuously, and run a formal exit/offboarding step (revoke access, clear residual risk). BRI applies this across 93 IT vendors and 1,281 digital partners; questionnaires are evidence-based and kept lean (~50 questions).
Look beyond the third party. Partners with system integration can be riskier than vendors. HSBC now speaks of “nth-party risk” and maps full supply chains for its most important services. Concentration on a single supplier used industry-wide is a systemic exposure that boards are actively probing.
From controls to resilience. Leading banks are shifting focus from layering on controls to resilience: recovery playbooks, mock role-plays (e.g. cyber ransom scenarios) and tested continuity plans for supplier failure.
Proportionality for SMEs. Compliance is non-negotiable regardless of vendor size, but requirements should be tiered by risk. SMEs should be coached to comply rather than excluded — leniency ultimately backfires on the buyer.
People and culture decide. Frameworks and tools fail without the right behaviours and risk culture. Tone from the top was named the single most important enabler; other 12-month priorities were financially quantifying top risks, establishing AI/cyber governance, and stress-testing strategy against interconnected risks.
3. Session Summaries
3.1 Opening remarks
Mercy Francisca Sinaga (Chairwoman, BritCham Indonesia; Chief Legal & Government Relations Officer, PT Prudential Life Assurance Indonesia) framed the theme: cloud platforms, fintech partnerships and outsourcing are no longer back-office decisions — interconnectedness has turned third-party dependency into a governance matter touching capital resilience, customer trust, regulatory standing and systemic stability. She welcomed the launch of the IRM Indonesia Chapter as a milestone for the profession, with BritCham proud to be associated from day one.
Syahraki Syahrir (CEO & Partner, Veda Praxis) noted that recent incidents in Indonesia and globally (including CrowdStrike) trace back to third-party risk. Organisations have relied on compliance checklists — due diligence done, box ticked — without truly managing the risk. He highlighted the December 2025 Basel principles and 2026 OJK regulation, stressing the issue applies to all industries, not only banks.
3.2 Keynote 1 — Dr Dini Rosdini (Universitas Padjadjaran): TPRM overview and regulatory toolkit
Dr Dini Rosdini set out the conceptual and regulatory foundations of TPRM, arguing that it belongs at board level as an integral part of a company’s GRC. Her main points:
Digitalisation has fused previously separate business functions into one interconnected organisation; a single incident now cascades across operations, finance and reputation.
Third parties include vendors, suppliers, IT/cloud providers, outsourcers, asset managers, agents, brokers and JV partners. Main risk categories: financial (counterparty insolvency, concentration), cyber/IT, compliance and legal, operational, and reputational.
Common root causes across failure cases: verification assumed rather than performed, unclear risk ownership, and ignored warning signs.
TPRM lifecycle: identify & assess → due diligence (before contracting) → contract & onboard → continuous monitoring → exit. TPRM is part of vendor management and an enabler of GRC, supporting sustainable growth, operational resilience and stakeholder trust.
3.3 Keynote 2 — Nugroho Pancayogo (Bank Rakyat Indonesia): TPRM strategy in the digital banking era
Nugroho Pancayogo gave the practitioner’s view, describing how Indonesia’s largest bank has built and continues to evolve its TPRM function:
Context: BRI operates 7,385 outlets, 18 regional offices, 8 overseas channels, ~84,000 employees and 160+ million customers, with 93 IT vendors and 1,281 digital partners.
TPRM began in 2021 with vendors, extended to partners in 2024, and became a dedicated department in 2023; working papers deliberately kept “evolving” as the threat landscape changes.
Vendors and partners are treated differently: vendors sit in an employer relationship (screening at tender, during the engagement, and at offboarding); partners are peers connected by system integration — which makes them potentially the greater exposure.
Three-lines model: first line owns risk and reviews vendor questionnaires; second line (IT & Digital Risk) sets policy, templates, risk registers and a risk control library.
Tiering by criticality drives reassessment frequency (annually for high criticality; 2–3 years otherwise). Contract end triggers reassessment to revoke access and clear residual risk.
Assessment domains: resilience (SLAs, BCP), compliance/licensing, data privacy (a dedicated Third-Party Privacy Assessment under the PDP law), exit strategy, HR practices, fourth-party management, AI/automation governance and information security. Assessments are evidence-based, not audits.
3.4 Panel discussion (moderator: Dadan Gunawan, Veda Praxis)
Panelists: Dr Dini Rosdini, Nugroho Pancayogo, Miranti Gani (IRM Indonesia Group Chair) and Yong Han, Risk Management Director of HSBC Indonesia. Key exchanges:
Pre-contract assessment is workable in practice: BRI gives bidders 1–2 weeks to complete evidence-backed questionnaires; missing evidence raises the residual risk score. Legacy contracts are caught at renewal (max 5-year terms).
For non-financial industries and SMEs, the same four-step pattern applies — identify, assess/due diligence, mitigate, monitor — scaled to the organization’s size and budget. Even when the vendor is larger than you (e.g. global platforms), accountability cannot be outsourced.
HSBC has moved from “fourth-party” to “n’th-party” risk, mapping full supply chains for important business services; assessments for high-tier vendors can run to hundreds of questions, but the strategic focus has shifted to resilience — playbooks, mock role-plays and concentration-risk scenarios (including an industry-wide provider failure).
Internal audit’s role: HSBC’s third line surfaced the over-control thematic that triggered its resilience pivot; BRI’s TPPA privacy assessment originated from internal audit input — the functions matured together.
On timing: assessment should occur before contract signing; BRI is moving it even earlier, to vendor registration. Where a needed vendor is high-risk and unavoidable, the risk must be explicitly accepted, treated and monitored rather than ignored.
3.5 IRM Indonesia Chapter launch and partnership signing
The centerpiece of the event: the formal establishment of the IRM’s presence in Indonesia and the appointment of Veda Praxis as its exclusive local representative.
Victoria Robinson (IRM Head of Partnerships Asia), Miranti Gani and Zaf Khan (Director, IRM Asia) presented the IRM: 40+ years old, present in 106 countries, offering modular awards, 60+ courses, free toolkits and guidance, special interest groups, and a Senior Executive Route (SCR) for practitioners with 8+ years’ experience. The Indonesia chapter follows Malaysia (first in Asia) and Singapore.
In a video message, Stephen Sidebottom (Chairman, IRM Global) announced Veda Praxis as IRM’s official strategic partner for Indonesia and Vietnam, with exclusive reseller rights to IRM’s new suite of awards and plans for locally relevant qualifications (a third-party risk management award was floated).
The MoU was signed on stage by Syahraki Syahrir (Veda Praxis) and Colin McCrorey (IRM Board Director), formally launching both the partnership and the IRM Indonesia Chapter chaired by Miranti Gani.
3.6 Closing panel — beyond compliance (moderator: Ian Leonard Betts, CastleAsia)
The closing panel widened the lens from third-party risk to enterprise risk management as a whole — what separates organizations that merely comply from those that excel:
Colin McCrorey: frameworks are necessary, but people make the difference — risk maturity must match organizational objectives, and culture and behaviors determine whether tools deliver value. His 12-month recommendation: stress-test strategy against interconnected risks and fix what fails.
Zaf Khan: risks are now interconnected — geopolitics, tariffs, supply chains, AI. He cited a recent incident of an AI model escaping its test sandbox as a live warning. His 12-month priorities: financially quantify top risks, empower the risk function, establish active cyber/AI governance, benchmark internationally.
Miranti Gani: tone from the top is decisive — convince leadership that risk management is a brake that enables safe speed, not a show-stopper; the goal is continuous profit, not one-time profit.
The IRM’s RASP framework (Risk Architecture, Strategy and Protocols), built around the ISO 31000 process, was recommended as a freely available starting point.
Satya Rinaldi (Managing Partner, Veda Praxis) closed the event, reflecting that continuous change keeps shifting the risk landscape, and that a strong ecosystem — now anchored by the IRM partnership — is what Indonesia’s risk profession has lacked.
4. The Milestone
The meeting was also the official launch of the Institute of Risk Management Chapter Indonesia, where
Miranti Gani is Group Chair. At the same ceremony, a strategic partnership was signed appointing Veda
Praxis as IRM’s exclusive partner and reseller for Indonesia and Vietnam. Both parties expressed the
intent to develop locally relevant IRM qualifications.
5. Suggested Follow-ups for Attendees
Drawing on the speakers’ recommendations, the following actions are suggested for organizations represented at the event:
Benchmark your TPRM against the Basel 12 principles and the five-stage lifecycle (identify/assess, due diligence, contract/onboard, monitor, exit).
Confirm board-level ownership: put third-party risk in the corporate risk profile with defined appetite and tolerance.
Map concentration and nth-party exposure for your most important business services; run at least one supplier-failure scenario exercise.
Review contracts for audit rights, termination rights and exit plans; capture legacy vendors at renewal.
Explore IRM membership, toolkits and the new modular awards via the Indonesia chapter.
Follow up – More information from Veda Praxis
Key takeaways:
Adopting global risk best practices gives us the foresight to stay resilient in a fast-changing world.
A strong TPRM strategy protects the entire ecosystem from hidden vulnerabilities.
Skilled risk professionals turn potential threats into sustainable business opportunities.
The event also marked the launch of the strategic partnership between Veda Praxis and the Institute of Risk Management (IRM), opening new opportunities for network building and capability development across Indonesia, Vietnam, Southeast Asia, and globally.
Continue the learning.
Presentation materials from the forum: https://vedapraxis.com/materials-tprm (Please note that the presentation by Nugroho Pancayogo is not included in the shared materials, as it contains information intended for a limited audience.)
The forum was a starting point; the real work is strengthening your organisation’s risk posture every day. Our experts partner with organisations across Indonesia and the region to:
Assess, design, and elevate your TPRM and overall risk management approach
Deliver practical, globally benchmarked risk training and capability-building programmes for your teams
Build long-term resilience, backed by internationally recognised practices through our IRM partnership
To join IRM and have your administrative fee waived, or to express interest in becoming a committee member of the IRM Indonesia Chapter, contact Victoria Robinson at [email protected].
We look forward to continuing the dialogue and growing together as part of a global network of risk professionals committed to building stronger, more resilient organisations.