EY US is recognized for its extensive risk and regulatory experience, system implementation and superior service delivery in SCRM services. It brought these capabilities to its engagement with a federal agency.
The EY approach helped the entity establish the processes and implement a C-SCRM program by driving innovation and leveraging two leading-edge technology platforms:
Supplier assessment platform
Utilizing commercial best practices honed from 15+ years of experience, EY teams developed tailored processes and implemented a supporting technology solution for this federal agency. The SCRM processes are risk-based so that the level of diligence conducted increases based on the risk the supplier presents to the organization. The established process is accompanied by the ServiceNow Vendor Risk Management application, which EY teams tailored to:
- Meet federal requirements while driving efficiency through an easy-to-use process
- Enable entity customization to meet the needs of a hyper-federated federal department made up of more than 50 independent entities
- Establish a centralized data set of supplier information providing enterprise visibility
The combination of best-in-class processes and a tailored technology solution set a new standard that government agencies are able to use to establish a leading-class C-SCRM program.
Business Relationship Economic and Threat Analysis
Business Relationship Economic and Threat Analysis (BRETA) is an automated tool that enables risk scoring by culling publicly and commercially available data sources from government and public sector resources to assess risks. It provides a multidimensional overview of threats in business relationships across six categories: financial, cybersecurity, geopolitical, technical, supply chain, and regulatory and compliance.
Working with the federal agency, EY teams used BRETA in combination with government data sources and analysts, conducting a detailed C-SCRM assessment to identify potential threats, monitor suppliers and offer actionable insights for risk mitigation.
A more resilient suppler ecosystem
From a risk perspective, the federal agency is now able to:
- Make informed, risk-based decisions. Prior to acquiring products and services, the agency can now assess suppliers against multiple risk levels while addressing the impact on the organization.
- Reduce risk and provide secure, quality services. By making risk-based decisions, ongoing supplier monitoring and risk remediation, the agency can negate working with suppliers that present an unacceptable risk to the enterprise. This helps improve supplier security and negate potential supplier breaches that could have a large-scale impact on the department.
- Meet federal compliance. Due to recent breaches in the supply chain, regulators step in and introduce new regulatory requirements. The C-SCRM program is helping this federal agency meet and exceed numerous SCRM federal laws, regulations and standards while promoting transparency and better decision-making in governance, risk and compliance.