Summary
Overview
Work History
Education
Skills
Objective
Software and Platforms
Timeline
Generic

Nancy Agyapon

Buford,GA

Summary

Dedicated and detail-oriented professional with experience in third-party risk governance and vendor management. Proven ability to engage effectively with business partners and vendors, ensuring timely completion of risk management activities. Skilled in conducting quality assurance reviews, providing training and support, and managing communication regarding vendor-related issues.

Overview

23
23
years of professional experience

Work History

Third-Party Management Consultant

TruStage (contractor)
Madison, WI
10.2023 - Current
  • Initiate third-party risk governance efforts by engaging with business partners and vendors.
  • Ensure that vendor risk management activities are completed promptly through regular follow-ups.
  • Perform quality assurance reviews to confirm the accurate collection of necessary information and data.
  • Maintain and update the Third-Party Risk Management solution, including the uploading of relevant documents.
  • Offer support and training to vendors and business partners to promote compliance and understanding.
  • Provide updates on project status and escalate any issues to the Vendor Management Manager.
  • Involved in special projects and assignments to improve vendor management practices.

Consultant

Hancock Claims
Cumming, GA
11.2021 - 09.2023
  • Managed day-to-day communications with multiple vendors simultaneously.
  • Collaborated with cross-functional teams to ensure successful execution of vendor projects.
  • Assisted with centralizing all vendors into governance risk tool.
  • Made sure risk register is up-to-date
  • Ensured compliance with relevant regulations and laws governing vendor relationships.
  • Identified opportunities for process improvements within the vendor management program.

Third Party Risk Analyst

Bank of America (contractor)
Boston, MA
11.2009 - 07.2012
  • Performs third party identification, risk assessment and Tier classification based on their services and level of access to data.
  • Administer Inherent Risk Questionnaire to business unit and Security Questionnaire to vendors point of contact with set of instructions and timeline.
  • Utilization of GRC tool, Archer to conduct application assessment and track issues identified during the assessment with supporting mitigations measures.
  • Review and evaluate vulnerability scans, pen-test, and SOC 2 type 2 reports of third-party companies to assess their overall risk and impact level.
  • Develop third-party risk assessment reports of identified findings and recommend corrective actions for management consideration.
  • Prepare, evaluate, and review mitigation plans that keep residual risk within the organization minimal.
  • Conduct ongoing re-assessment and monitor vendors to ensure compliance after the offboarding process has been completed, change in ownership, scope of practice or breach in their database.
  • Identify and analyze conditions, with input from management and key stakeholders, for third parties requiring risk exceptions/acceptance and documents, escalates and retains approval, as needed.
  • Provide recommendations regarding qualitative and quantitative aspects of potential third parties to determine if a relationship would help achieve the organization's operational and financial goals.

Assess the effect of any changes in key third party personnel involved in the relationship with the organization.

  • Review the adequacy and adherence of the third party’s policies relating to internal controls and security issues.
  • Ensure integration with other relevant functions and processes, e.g., procurement.
  • Knowledge of controls and industry standard frameworks (COSO, COBIT, NIST SOC, ISO,).

Credit Card Fraud Analyst

Fleet Bank
Providence, RI
04.2002 - 08.2009
  • Conducted reviews of flagged transactions and reports that showed potential suspicious activity.
  • Documented investigative findings in reports.
  • Reported findings on risk exposures to senior executives and board of directors.
  • Managed and executed risk management projects to determine deficiencies and appropriate corrective actions.

Education

Bachelor of Arts - Business Management (expected 2026)

University of Alabama At Birmingham
Birmingham, AL

Skills

  • Decision-Making
  • Task Prioritization
  • Relationship Building
  • Attention to Detail
  • Vendor Relationship Management
  • Organizational Skills
  • Self Motivation
  • Adaptability and Flexibility

Objective

Seeking a Risk and Issues Management position in a growth-oriented organization with focus on Third-Party Risk Management.

Software and Platforms

RSA Archer, OneTrust, ServiceNow, BitSight. Security Scorecard, MS Office, Google Suite, MS Teams, Windows

Timeline

Third-Party Management Consultant

TruStage (contractor)
10.2023 - Current

Consultant

Hancock Claims
11.2021 - 09.2023

Third Party Risk Analyst

Bank of America (contractor)
11.2009 - 07.2012

Credit Card Fraud Analyst

Fleet Bank
04.2002 - 08.2009

Bachelor of Arts - Business Management (expected 2026)

University of Alabama At Birmingham
Nancy Agyapon