Join a community of professionals and get:
on all CeFPro events.
unlock speaker decks and audience polls.
Full library access the moment you sign up.
Digital Content

- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings

- Risk data alone doesn’t drive
action — executive decisions depend on judgment, confidence, and business
context.
- Translate risk into business
impact — ROI, severity, likelihood, and opportunity cost resonate most with
leadership.
- AI will enhance prediction, not
replace judgment — the real value lies in translating analytics into realistic
business scenarios.
- TPRM must become a strategic
advisor — understand the business, challenge the data, adapt to emerging risks,
and stay connected to business teams.
- The goal is action, not more data — turn risk intelligence into timely, informed business decisions.
Ahead of the Vendor & Third Party Risk
event in the USA this November, we spoke with Narahari Rao, Procurement Risk
Manager, SLB, about the evolving role of third-party and operational risk in
executive decision-making. He discusses why strong risk analysis does not
always translate into action, which risk metrics resonate most with senior
leadership, and how AI and predictive analytics can strengthen forward-looking
risk management. He also shares his perspective on how TPRM teams can move
beyond providing risk data to become strategic advisors who connect risk
intelligence with business priorities and timely action.
In your experience, what is the biggest
reason senior leaders fail to act on operational or third-party risk reports,
even when the underlying analysis is strong?
This gets to the real communication and
decision-making barriers organizations face today.
I believe the disconnect happens with the underlying analysis (confidence level) and the event actually materializing. After all, we all like to follow the path of least resistance. Pre-emptively acting on a risk that is yet to materialize takes more than just quantitative analysis; it relies on a generations-old, developed gut instinct. Acting on risk takes your eyes off revenue generation and possibly slowing down your approach. Hence, I think when senior leaders fail to act on third-party risk, it speaks at the very core of our human psychology.
What metrics or risk indicators have
proven most effective in helping executive teams quickly understand supply
chain and third-party risk exposure and make timely decisions?
This should reveal the measures and
visualizations that resonate most with leadership.
There are a few measures that
resonate.
ROI - I invest $x to better manage my
investment that is valued at $y ($y>>$x) and if I don't do anything then
I might incur a loss of $z ($z>>$x).
Severity and Likelihood - These measures
help to balance out the risk with how likely is it to happen and how severe
will it be.
Opportunity Cost - closely tied to ROI but it essentially is the cost of inaction.
As AI and predictive analytics become more embedded in risk management, how do you see executive decision-making changing over the next three to five years?
This explores how data-driven risk insights
may evolve from reporting to forecasting and scenario planning.
Indeed, AI can super-charge predictive
analytics by combining numerous data sources, plotting them over several years,
and calculating the likelihood/severity and the material impact to the
shareholders. Decision making however, reverts back to that human intuition. I
don't think we have paucity of data in our lives but we do have a deficit in
understanding how that data may translate to real-life scenarios. The ability
to synthesize AI generated predictive analytics and keep it grounded to reality
is what would differentiate a good from a great leader.
Looking ahead, what capabilities should TPRM and operational risk teams be building now to ensure they remain strategic advisors to leadership rather than simply providers of risk data?
TPRM practitioners should first and foremost understand the business that they are managing risk for. TPRM practitioners should rely on generating sound data from various data sources; building skillsets within the teams who are able to keep up with changing risk vectors' able to tailor and adapt to a changing business model; promote a federated approach where TPRM practitioners encourage both local and central governance models; a healthy combination of confidence and skepticism in data; and lastly, staying connected with business lines and divisions to understand ground realities.
As technology continues to evolve, what will distinguish a best-in-class ALM function over the next five years, and how will the roles of treasury, finance, and risk teams need to adapt?
Over the next five years, best-in-class ALM
functions will be distinguished by AI-driven capabilities, large use of
advanced analytics, and fully integrated decision-making across treasury,
finance, and risk. These teams will need to work more collaboratively, using
shared data and models to optimize balance sheet performance and respond
quickly to changing market conditions and geopolitical scenarios. The focus
will shift from producing reports to delivering strategic insights that drive
business value.
Global Supply Risk and Resiliency Director I build global procurement and risk frameworks that actually work — from policy design to automated execution. Over 20 years, I've led Third-Party Risk, Procurement, and Digital Transformation for a $500M+ supplier portfolio across 30 global business units at one of the world's largest energy companies. My latest experience has been designing global governance frameworks that bridge the gap between high level policy and automated execution. My career has traversed primarily within the energy space, where I have led diverse functions ranging from Third-Party Risk Management (TPRM) and Global Strategic Sourcing to Product Engineering, Manufacturing, Quality, and Digital Process Transformation. In my current job, I have orchestrated the end to end Third Party Risk Lifecycle for a $500M+ supplier portfolio. By integrating ISO 31000 and NIST-driven frameworks into regular business processes across 30+ global business units.