small logo tdpg retina - The Data Privacy Group
global media cs header - The Data Privacy Group
Published On: 4 March 26

Third-Party Risk Transformed, Governance Maturity Proven

How a Global Media Organisation Built a Credible, Automated TPRM Programme on OneTrust — and Achieved a 0.6-Point Maturity Uplift in Independent Audit

global media cs 01 - The Data Privacy Group
0
Backlog Tasks Delivered Across TPRM Programme
0
Days Managed Service Effort Deployed
0/5
Client Satisfaction Rating

Client Overview

The client is a globally recognised media and publishing organisation, operating across print, digital, and events platforms. With a substantial international readership and a significant volume of commercial relationships with third-party vendors, the organisation handles a wide range of personal and sensitive data flows across its supply chain. In the media sector, third-party vendor risk is not a peripheral compliance concern: it sits at the intersection of data protection law, editorial independence, and commercial reputation. Regulatory scrutiny under UK GDPR is material, and the reputational consequences of a third-party data breach or a failing in due diligence are acute for a brand whose credibility is its primary commercial asset. The organisation had invested in OneTrust as its risk management platform and was committed to professionalising its Third-Party Risk Management (TPRM) programme.

global media cs 02 - The Data Privacy Group

The Challenge

The organisation had built the foundations of a TPRM programme within OneTrust but faced a critical execution gap: a backlog of 16 tasks across the platform that the internal team lacked the capacity, specialist skills, and available time to deliver. These tasks were not cosmetic. They included broken assessment workflows with logic errors that prevented completion, reporting configurations that had never been built, and automation capabilities for vendor off-boarding, re-assessment, and re-certification that remained entirely manual.

The consequences were operational and strategic in equal measure. Without accurate vendor status reporting, the team could not filter archived vendors from active risk views, creating noise in a risk register that decision-makers needed to rely on. Without KPI and executive reporting from OneTrust, senior leadership and legal teams had no visibility to active or emerging third-party risks except through manually compiled flat files. Internal stakeholder and vendor assessment questionnaires contained duplicate questions, missing AI-related questions, and technical errors including a broken SOC flow that blocked submission. A sustainability reporting capability required by the ESG function did not exist at all.

The internal team had spent significant time attempting to develop dashboards and reporting outputs independently, without success. With all 16 tasks carrying a target delivery date of 31 July 2025 and multiple rated as High priority, the risk of continued inaction was clear: compliance exposure, reporting gaps, and an inability to demonstrate TPRM maturity to auditors, the legal team, or the board.

Objectives of the Engagement

The engagement set out to achieve three outcomes, in order of business priority:

  • Resolve all 16 outstanding OneTrust TPRM configuration tasks by 31 July 2025, including broken assessment workflows, vendor status reporting, and automation gaps for off-boarding, re-assessment, and re-certification.
  • Build and activate executive, legal, and operational reporting within OneTrust, giving leadership and stakeholders direct visibility to vendor risk profiles, treatment plans, and KPIs without manual intervention.
  • Advance the maturity and auditability of the TPRM programme to a standard that could withstand independent external scrutiny.
global media cs 03 - The Data Privacy Group

Our Approach

DPG structured the engagement as a managed service, with a DPG consultant working on-site at the client’s offices for full delivery days. This approach was deliberate: the task backlog required deep platform configuration work that benefited from direct access to the environment, the internal team, and the stakeholders whose requirements had shaped the outstanding items.

Delivery was guided by a prioritisation framework agreed at the outset. Tasks rated High priority, including the broken assessment workflows, the legal notification mechanism for high and very high risks, and the executive and KPI reporting capability, were addressed first. Medium-priority tasks, including vendor status attribute configuration, off-boarding automation, and sustainability reporting, followed in sequence.

For the assessment workflow remediation, DPG worked directly with the internal programme lead to understand and implement the approved changes across the Internal Stakeholder, Tier 1, and Non-Tier 1 assessment templates. This included removing duplicate questions, incorporating AI-related questions as required, correcting the broken SOC flow, and resolving the contract value field error. Each change was reviewed and signed off before implementation.

The reporting workstream required DPG to design and build from scratch: KPI reports for key stakeholders, an executive monthly view of active and new risks, a post-assessment risk activities dashboard covering risks and treatment plans, and a risk process compliance report. DPG also created a sustainability-focused report to support the client’s ESG team.

For the automation workstreams, DPG followed a two-phase approach: first educating the internal team on how the processes could work within OneTrust, then scoping and implementing automation for off-boarding, re-assessment, and re-certification workflows. Legal notification for completed assessments surfacing High and Very High risks was configured to provide the legal team with direct access to risk and treatment plan information without requiring them to work natively in OneTrust.

Throughout the engagement, DPG maintained active communication with the client’s programme lead, ensuring that all configuration changes were aligned to the organisation’s evolving requirements and that outstanding dependencies were surfaced and resolved promptly.

Technology and Tools Used

The engagement was delivered entirely within the OneTrust platform, across its Vendor Risk Management and Reporting modules.

OneTrust Vendor Risk Management was used to configure and remediate all assessment templates, implement the new vendor follow-up workflow stage, build vendor status custom attributes, and deliver the automation workflows for off-boarding, re-assessment, and re-certification. The platform’s configuration capabilities required specialist knowledge to implement correctly: incorrectly structured workflows actively block assessment completion, and improperly configured attribute logic can corrupt vendor status reporting across the entire risk register.

OneTrust Reporting and Dashboards was used to build the full suite of KPI, executive, and operational reporting outputs. These reports required custom attribute creation, aggregation logic, and stakeholder-specific views that the client’s internal team had been unable to deliver despite significant effort invested. DPG’s status as the first OneTrust Certified Deployment Partner, with all implementation staff holding OneTrust Fellow certification, was directly material to the speed and quality of delivery.

What We Delivered

Across the 16-task scope, DPG delivered the following:

  • Vendor status custom attribute created to capture downgrade reasons, enabling risk trend reporting and governance accountability.
  • Assessments view updated to include vendor status, enabling accurate filtering of archived vendors from active risk registers.
  • Internal Stakeholder, Tier 1, and Non-Tier 1 assessment templates updated: duplicate questions removed, AI-related questions incorporated, SOC flow corrected, and contract value field error resolved.
  • New vendor follow-up workflow stage implemented, enabling SLA tracking and reporting on follow-up durations for the first time.
  • Legal notification mechanism configured to alert the legal team automatically on completion of assessments surfacing High or Very High risks, including associated treatment plans, without requiring legal team members to access OneTrust directly.
  • Full KPI reporting suite built and activated for key stakeholders as per the agreed stakeholder map.
  • Executive monthly report configured to display active and new risks for senior leadership visibility.
  • Post-assessment risk activities dashboard built, covering risks and treatment plans.
  • Risk process compliance report delivered.
  • Vendor holistic report built, covering portfolio, categories, and risk profiles.
  • Off-boarding, re-assessment, and re-certification automation processes scoped and implemented across two phases.
  • Sustainability-focused report created for the ESG function.
global media cs 04 - The Data Privacy Group

Value Delivered

The most concrete outcome of this engagement was independently verified: following the delivery of this programme, the client was subject to an external audit in September and achieved a 0.6-point increase in TPRM maturity score, compared to a baseline of 2.4 the previous year. This is a measurable, audited improvement in governance capability directly attributable to the work delivered.

Before the engagement, the legal team had no visibility to OneTrust risks outside of manually prepared flat files supplied by procurement on a per-vendor basis. Executive leadership had no direct access to active or emerging third-party risks within OneTrust at all. Both limitations were resolved: automated reporting now delivers structured, timely risk information to legal and senior leadership without manual compilation, reducing the operational burden on the TPRM team and closing a governance gap that had previously been identified as a programme risk.

The assessment workflow remediation delivered immediate operational value. Broken submission flows had been blocking assessment completions for vendors including those in the SOC compliance pathway. These were resolved, restoring programme throughput. The removal of duplicate and irrelevant questions from assessment templates reduced respondent burden and improved data quality, while the incorporation of AI-related questions brought the programme into alignment with current due diligence expectations.

The team had spent significant time prior to the engagement attempting to develop reporting dashboards independently, without success. DPG delivered the full reporting suite, freeing internal resource from a task that had been consuming days of effort without output.

Client satisfaction following the engagement was rated 5 out of 5. Across all assessed dimensions, the engagement was rated Excellent. The client highlighted the depth of technical knowledge, the quality of personal engagement, and the flexibility of the DPG team as defining characteristics of the delivery.

“The way every single person I engaged with at DPG from start to finish demonstrated a true customer-focused approach and delivered on what we wanted — it was a true breath of fresh air. I have worked with professional services organisations for 15+ years and at this level I have never seen it — well done all! Linked to this work, we were audited in September and achieved a 0.6 increase compared to a maturity of 2.4 last year. DPG helped us achieve this.”

Head of Third-Party Risk Management, Global Media Organisation

Why This Matters

Media organisations operate under a specific and underappreciated set of third-party risk pressures. The breadth of their vendor relationships, spanning technology providers, data processors, distribution partners, and commercial data suppliers, creates a complex supply chain exposure that UK GDPR and emerging AI governance frameworks are increasingly bringing into regulatory focus. For organisations whose brand depends on public trust and editorial credibility, a third-party data incident is not merely a compliance failure: it is a reputational event.

This engagement illustrates a pattern visible across the sector: a well-intentioned TPRM programme, backed by the right technology, that had stalled due to a combination of internal capacity constraints, specialist skills gaps, and the accumulated weight of an undelivered backlog. The risk was not that the organisation lacked commitment to compliance. The risk was that, without delivery capability, its compliance position could not be demonstrated to auditors, legal teams, or the board.

For organisations in similar positions, the cost of inaction is not theoretical. It shows up in audit findings, in leadership blind spots, and, ultimately, in maturity scores that do not reflect the investment already made.

Is Your TPRM Programme Delivering What It Promises?

If your organisation has invested in OneTrust or a comparable platform but cannot yet demonstrate automated reporting, auditable governance, or measurable maturity improvement, the problem is unlikely to resolve itself through internal effort alone. Backlogs grow, and the gap between what a programme should deliver and what it does deliver widens.

The Data Privacy Group works with organisations across sectors to configure, optimise, and operationalise their third-party risk programmes to a standard that withstands scrutiny. As the first OneTrust Certified Deployment Partner and the only certified partner for OneTrust data discovery, DPG brings implementation expertise that no generalist consultancy can replicate.

Contact DPG to discuss your TPRM programme and find out what a focused engagement could deliver.

Share this article

Go to Top