Guardians at the Gate: An Integrated Audit Approach for Evaluating and Maturing Third-Party Risks and Institutional Resilience
August 27, 2026 | 1:00 PM - 2:00 PM
August 27 @ 1:00 pm – 2:00 pm EDT
Universities increasingly rely on third parties to deliver critical academic, research, administrative, clinical, technology, and student-facing services. As institutional operating models become more interconnected, the risk perimeter now extends well beyond the organization’s walls — creating new exposure across cybersecurity, privacy, compliance, financial performance, operational resilience, reputation, and patient trust. Third-party risk is no longer a narrow vendor management review. It requires an integrated approach that incorporates governance, risk management, and controls across the full third-party life cycle — from selection and contracting to onboarding, ongoing monitoring, issue management, and offboarding.
As a trusted advisor and in accordance with the IIA Third Party Topical Requirements, it is important that the Audit Plan include an evaluation of third-party governance, risk management, and control processes across the third-party life cycle. This requires an integrated approach for assessing the risks and controls.
This webinar will provide ACUA members with a practical, risk-based approach to evaluating and maturing third-party risk management programs, aligned with The IIA’s Third-Party Topical Requirement and its intersection with the Cybersecurity Topical Requirements.
Participants will leave with practical considerations for building effective integrated audits, improving stakeholder conversations, and positioning internal audit as a strategic advisor in strengthening institutional resilience.
After attending this webinar, participants will be able to…
- Describe third-party types and common risks to the organization
- Identify assessment practices and standards for third-party governance, risk management, and controls
- Discuss the intersection of Third Party and Cybersecurity Topical Requirements for assessing third-party life cycle risks and controls
- Share integrated audit practices for evaluating third-party life cycle stages (Selecting, Contracting, Onboarding, Monitoring, and Off-boarding)
- Discuss practices for effectively translating emerging third-party risks into board and leadership insights
Delivery Method: Group Internet
Field of Study: Specialized Knowledge
Advance Preparation: None
Prerequisites are required: No
Cost: $25 for non-members
Recommended CPEs: 1
Resources
Host Information

Johan Lidros (CISA, CISM, CGEIT, CRISC, CDPSE, ITIL-F, HITRUST CCSFP)
President
Eminere Group
Johan Lidros is President of Eminere Group and an experienced IT risk, cybersecurity, privacy and governance advisor to higher education, healthcare and regulated organizations. He helps internal audit, compliance, privacy, IT, and executive teams assess mature technology risks management, cybersecurity governance, third-party risk, identity and access management, cloud controls, and privacy programs. Johan is known for translating complex technology risks into practical audit strategies, actionable recommendations, and leadership-ready insights.

Valla Wilson, CIA, CRMA, CHIAP™
Business Risk Assurance and Advisory Services Practice Director
Eminere Group
Valla Wilson is Eminere Group’s Business Risk Assurance and Advisory Services Practice Director. Valla has over 30 years of Internal Audit and Compliance, Enterprise Risk Management, Privacy, Healthcare Operations, and Executive Leadership experience. She previously worked for Anderson, LLP providing Audit and Consulting services and has held previous Chief Audit Executive, Chief Compliance Officer, Chief Privacy Officer, and Board leadership roles in healthcare and higher education industries. Valla helps organizations strengthen governance and risk management; conduct quality internal audit and consulting engagements; improve compliance program effectiveness; and enhance leadership reporting.
