Services Experience Case Studies AI Readiness Assessment Contact About
← All case studies
Global SaaS Platform (Fortune 500)

Third-Party Risk Program Turnaround

When I took on the third-party risk program, assessments were taking as long as 120 days against a 30-day SLA, with no framework for deciding which assessments to prioritize first. At the same time, the team’s ServiceNow automation work was being planned through standard agile sprints — user stories written and queued without regard for whether the team had the bandwidth to build them alongside their actual risk assessment workload. There was no SDLC governing that automation work, so enhancements were built ad hoc, competing directly with the assessments they were meant to support.

I closed 100% of the risk items that had aged past 90 days, eliminating the most severe SLA breaches first. I introduced a proper SDLC for ServiceNow enhancement work, giving the automation backlog the same rigor as the risk assessments it was meant to accelerate. And I restructured what reached the Jira board in the first place — narrowing the backlog to only the work that materially moved the program forward, so the team stopped splitting time between low-value stories and their primary risk assessment responsibilities.

Have a similar problem?

Let's talk about what's actually going on in your operations and where a fractional CTO or GRC lead could move the needle fastest.

Book an introductory call