Every global (or globally-aspiring) company now carries a stack of overlapping obligations: security and resilience standards, privacy law, regulator-driven resilience rules, finance-specific third-party mandates, and a fast-growing layer of AI governance. The list never stops growing, and sharp local requirements like the EU's MiCA enforcement cliff or China's AI rules can land on a company that never moved.
Most third-party risk programs respond in one of two ways. They multiply questionnaires, one per regulation, or they lean on criticality tiers that tell you how deep to assess but never what actually applies. Both break down as vendor catalogs and regulations expand.
This session offers a different model: a single global baseline built on common standards (NIST CSF, Privacy Framework, AI RMF or ISO 27001, 42001, 27701), with jurisdictional supplements layered on top, connected by a “crosswalk: that maps one control to many standards and regulations. The key is “materiality”, meaning what a vendor does and where it operates, which decides exactly which requirements activate. The result is one questionnaire that answers your audits and your obligations, and absorbs the next new regulation without a rebuild.