← University
Vendor and Third-Party Risk Management
0 of 4

A regional healthcare network operating 4 outpatient clinics across southern Ontario discovered during a routine audit that patient billing records processed by its external billing services provider contained errors affecting approximately 1,200 accounts over a 7-month period. The billing provider, engaged 3 years earlier to handle all patient invoicing, insurance claims processing, and collections, had undergone a change in ownership 14 months into the relationship. The new ownership had subsequently migrated the billing platform to a different cloud infrastructure provider and reduced staffing levels by roughly 30 percent, changes the healthcare network learned about only after the audit findings emerged.

The healthcare network had originally selected the billing provider following a competitive procurement process that evaluated 5 candidate firms. The selection committee, comprising the network's chief financial officer, its operations director, and an external consultant, had assessed each candidate's financial statements, client references, data security certifications, and proposed service delivery model. The successful vendor had demonstrated ISO 27001 certification, carried professional liability coverage of $5 million per occurrence, and provided audited financial statements showing 4 consecutive years of profitability. At the time of engagement, the vendor appeared to represent a low-risk, cost-effective solution for a function the healthcare network had struggled to perform efficiently in-house.

The master services agreement executed between the parties ran to 47 pages and included standard provisions addressing confidentiality, indemnification, and termination. The agreement required the vendor to maintain "commercially reasonable" data security practices and to provide 60 days' notice before any material change in service delivery. It did not define what constituted a material change, did not require notification of ownership transitions, and did not establish specific performance metrics against which the vendor's work could be measured. The healthcare network had not requested a right-to-audit clause during negotiations and had not conducted any formal review of the vendor's operations since the initial engagement.

The billing errors had resulted in delayed insurance reimbursements, patient complaints regarding incorrect balances, and at least 3 formal inquiries from the provincial health insurance plan regarding claims discrepancies. The healthcare network now faces questions about how to assess the full scope of the problem, what remedies exist under the current contract, whether to continue the vendor relationship or transition to an alternative provider, and what changes to its vendor management practices might prevent similar situations in future engagements.

Vendor Due Diligence: What to Assess Before Engaging a Critical Supplier

Vendor due diligence represents one of the most consequential yet frequently underestimated disciplines within operational risk management. When an organization engages a third-party supplier, particularly one that becomes critical to its operations, it does far more than execute a commercial transaction. It extends its operational perimeter, entrusts aspects of its reputation to another entity's competence and ethics, and creates interdependencies that can amplify or mitigate risk depending on the quality of the relationship established. The practice of systematically assessing potential vendors before engagement has evolved considerably over the past two decades, driven by regulatory expectations, high-profile supply chain failures, and a growing recognition that organizational resilience depends as much on the strength of external partnerships as on internal capabilities.

The conceptual foundation of vendor due diligence rests on a straightforward principle: organizations cannot outsource accountability. When a business contracts with a supplier to perform services, manufacture components, process data, or deliver any function that supports the organization's mission, the contracting organization retains responsibility for the outcomes of that relationship in the eyes of regulators, customers, and other stakeholders. This principle finds expression across multiple Canadian regulatory frameworks. The Personal Information Protection and Electronic Documents Act, as of the date of authorship, establishes that organizations remain accountable for personal information transferred to third parties for processing, requiring them to use contractual or other means to ensure comparable protection. Provincial private sector privacy statutes in British Columbia, Alberta, and Quebec contain analogous provisions, with Quebec's Act respecting the protection of personal information in the private sector imposing particularly stringent requirements around data processor oversight following amendments that came into force in September 2023.

That’s the free preview

You’ve reached the end of what’s open to read. The rest of this lesson is part of a $79 course — purchasing unlocks it, or sign in if you already have access.