In a recent LinkedIn post, Francisco Gaffney discusses the critical need for a more tailored and efficient approach to managing third-party risk. Gaffney, a proponent of strategic risk mitigation, argues against generic solutions, emphasizing that effective third-party risk management (TPRM) requires a nuanced understanding of individual relationships and their associated risks.
Gaffney opens by stating the core principle of his approach: “Navigating third-party risk requires a nuanced approach, not a one-size-fits-all solution.” He draws an analogy to life jackets, suggesting that just as these safety devices must be appropriately sized based on the specific risks involved, so too must third-party relationships be managed with “tailored treatments, each requiring validation.” This highlights his belief that a uniform policy is insufficient and can lead to either inadequate protection or unnecessary burdens.
The Importance of Risk Tiers
Central to Gaffney’s argument is the concept of tiered risk assessment. He outlines a practical methodology for categorizing third-party relationships based on potential exposure. According to Gaffney, the process should commence with a comprehensive risk screen that considers factors such as:
- Country of operation
- Industry sector
- Governmental touchpoints
- Payment methods
- Referral sources
This initial screening, as Gaffney explains, is designed to “tier risk likelihood and impact.” By understanding these dimensions, organizations can then implement appropriate levels of oversight.
Proportionate Risk Mitigation Measures
Gaffney advocates for applying measures that are directly proportionate to the identified risk level. He suggests a clear framework:
- Low-risk relationships necessitate simple attestation processes.
- Medium-risk relationships require more involved training and monitoring.
- High-risk relationships demand stringent controls, including senior management approval and extensive documentation.
This tiered strategy, Gaffney points out, ensures that resources are allocated effectively, focusing the most intensive scrutiny on the areas that pose the greatest potential threat.
Streamlining the TPRM Process
Beyond the assessment and mitigation strategies, Gaffney also addresses the operational efficiency of TPRM. He introduces the idea of a centralized system that can provide continuous gap analysis. “All in one place. Continuous gap analysis. Clear view of what’s done, what’s missing, and who owns the fix before assurance or audit,” he writes, underscoring the benefits of a unified platform.
This integrated approach, in Gaffney’s view, simplifies the entire assurance and audit process. It allows organizations to maintain a constant awareness of their risk posture and proactively address any deficiencies. He concludes with a call for thoroughness and finality in the process: “Do it once. Do it properly. Move on.” This sentiment emphasizes his desire to move organizations beyond perpetual risk assessment cycles towards a state of sustained, well-managed compliance.
Gaffney’s insights offer a compelling case for a more dynamic, data-driven, and efficient approach to managing the complexities of third-party risk in today’s business environment.
📝 About This Content
This article is based on insights shared by Francisco Gaffney on LinkedIn.
📅 Originally posted on November 12, 2025 | View original post on LinkedIn →