An Interactive 5-Day Training Course

Third-Party Risk Management (TPRM) for Oil and Gas Industry

Governing Supplier Risk, Digital Dependencies & Supply Chain Resilience Across Oil and Gas Operations

Third-Party Risk Management (TPRM) for Oil and Gas Industry

Scheduled Dates

26 - 30 Oct 2026
London - UK
$7,500
21 - 25 Dec 2026
Paris - France
$7,500
19 - 23 Apr 2027
London - UK
$7,500
28 Jun - 02 Jul 2027
Dubai - UAE
$7,500
25 - 29 Oct 2027
London - UK
$7,500
20 - 24 Dec 2027
Paris - France
$7,500

Why Choose this Training Course?

This Third-Party Risk Management (TPRM) for Oil and Gas Industry training course provides a structured approach to identifying, assessing and governing the risks created by suppliers, contractors, technology providers and other external parties. Oil and gas organisations operate through extensive third-party ecosystems that support critical operations, engineering, maintenance, logistics, technology and specialist services. These relationships can create significant operational, financial, cyber, regulatory, ESG and geopolitical exposures that extend beyond traditional procurement and contract management.

The training course examines the complete third-party lifecycle, from governance, risk appetite and pre-contract due diligence through ongoing monitoring, assurance and eventual exit. Participants will explore supplier tiering, financial viability, contractual risk controls, cyber and cloud dependencies, fourth-party exposure and AI vendor risk. Particular attention is given to supply chain resilience, ESG, sanctions and geopolitical exposure. The training course concludes with continuous monitoring, assurance, executive reporting and the development of a practical roadmap for improving TPRM maturity.

This Third-Party Risk Management (TPRM) for Oil and Gas Industry training course will highlight:

  • Integrating third-party risk with enterprise risk management and organisational governance
  • Applying risk-based due diligence, onboarding and supplier segmentation
  • Managing cyber, cloud, SaaS, AI and fourth-party dependencies
  • Strengthening supply chain resilience and contingency preparedness
  • Assessing ESG, responsible sourcing, sanctions and geopolitical exposure
  • Establishing continuous monitoring, assurance and executive TPRM reporting

What are the Goals?

By the end of this training course, participants will be able to:

  • Establish effective governance, ownership and risk appetite for third-party relationships.
  • Apply risk-based due diligence and supplier tiering throughout the vendor lifecycle.
  • Evaluate cyber, technology, cloud, AI and fourth-party risks.
  • Assess supply chain resilience, ESG and geopolitical exposures across the supplier base.
  • Develop continuous monitoring, assurance and reporting mechanisms using appropriate risk indicators.
  • Strengthen organisational TPRM maturity through structured improvement and exit planning.

Who is this Training Course for?

This training course is suitable for professionals responsible for managing supplier, contractor, technology and extended-enterprise risks within oil and gas organisations. It will be particularly valuable for:

  • Third-Party and Vendor Risk Professionals
  • Enterprise Risk Management Professionals
  • Procurement and Supply Chain Managers
  • Contract and Commercial Managers
  • Vendor and Supplier Management Professionals
  • Cybersecurity and Technology Risk Professionals
  • Internal Audit and Assurance Professionals
  • Compliance and Governance Professionals
  • Business Continuity and Operational Resilience Professionals
  • ESG and Responsible Sourcing Professionals
  • Legal and Regulatory Affairs Professionals
  • Operations and Asset Management Professionals

How will this Training Course be Presented?

This training course combines expert-led presentations, facilitated discussions, oil and gas industry scenarios, supplier-risk assessments and practical TPRM exercises. Participants will evaluate third-party relationships using due diligence, tiering, cyber-risk, resilience and ESG perspectives. Case-based activities will address supplier failure, technology dependencies, geopolitical disruption and vendor incidents, enabling participants to translate TPRM principles into practical governance and risk decisions.

Organisational Impact

Organisations will benefit from:

  • Greater visibility of material risks across the extended enterprise
  • Stronger governance and accountability for third-party relationships
  • More consistent supplier due diligence and risk-based onboarding
  • Improved management of cyber, technology and concentration exposures
  • Greater resilience to supplier, geopolitical and supply chain disruption
  • Stronger monitoring, assurance and reporting of third-party risk

Personal Impact

Participants will develop:

  • Greater understanding of third-party risk across oil and gas operations
  • Improved capability to assess and tier suppliers according to risk
  • Stronger understanding of cyber and digital supply chain exposure
  • Greater confidence in evaluating resilience, ESG and geopolitical risks
  • Improved ability to interpret supplier risk indicators and assurance information
  • Practical capability to contribute to the development of mature TPRM frameworks

Daily Agenda

Day 1: Building the Foundations of Third-Party Governance
  • Outsourcing, cloud and SaaS are reshaping third-party risk
  • Embedding TPRM into ERM and the Three Lines Model
  • Governance structures with clear accountability and ownership
  • Setting risk appetite for supplier relationships
  • Board oversight of the extended enterprise
  • Navigating DORA and sector-specific regulations
Day 2: Due Diligence, Onboarding and Governing the Supplier Base

  • Screening and onboarding vendors before contract award
  • Risk-proportionate due diligence frameworks
  • Tiering suppliers by risk exposure
  • Operational risk across the vendor lifecycle
  • Evaluating supplier financial health and viability
  • Embedding risk clauses into contracts and SLAs
Day 3: Managing Cyber, Technology and Digital Supply Chain Risk

  • Cyber risk frameworks — ISO/IEC 27036, NIST SP 800-161
  • Cybersecurity due diligence questionnaires
  • Cloud and SaaS shared-responsibility risk models
  • ICT concentration and fourth-party exposure
  • AI vendor risk — data governance and model assurance
  • Coordinated incident response and resilience testing
Day 4: Supply Chain Resilience, ESG and Geopolitical Exposure

  • Mapping single points of failure and dependencies
  • Diversified sourcing and contingency planning
  • ESG risk frameworks across the supplier base
  • Modern slavery and responsible-sourcing due diligence
  • Geopolitical, sanctions and country-risk evaluation
  • Scenario planning for supply chain disruption
Day 5: Monitoring, Assurance, Reporting and Long-Term Maturity

  • Continuous monitoring built on Key Risk Indicators
  • Tracking vendor performance and SLA compliance
  • Third-party audits and independent assurance
  • Executive and board risk dashboards
  • Managing vendor offboarding and exit planning
  • Roadmap for continuous TPRM maturity

Certificate

  • Upon successful completion of this training course, delegates will be awarded an official PetroKnowledge Certificate of Completion, signed by the course facilitator. The certificate confirms successful participation and records the total learning hours completed.
  • Continuing Professional Education credits (CPE): In accordance with the standards of the National Registry of CPE Sponsors, one CPE credit is granted per 50 minutes of attendance.

Accreditation

NASBA Approved Training Courses

In Association With

Would an alternative date be more suitable?

We offer a variety of tailored training options, customized to meet your organisation's needs. Delivered anytime, anywhere, we make it easy to bring expert training directly to your team.

Related Categories

Other Training Courses You Might Be Interested In

Follow Us:

Subscribe To Our Newsletter