The Lawxy Times

Author Image
Abhishek Mundra

Deloitte Shifts Third-Party Risk Management

Deloitte Touche Tohmatsu India LLP's announcement of a vacancy for a Consultant in Third-Party Risk Management on August 4, 2026, indicates a significant shift in the landscape of risk management in consulting firms. This development affects professionals in the risk management sector, creating a need for enhanced due diligence and risk assessment skills. The announcement highlights the importance of expertise in Third-Party Risk Management (TPRM) and vendor risk management. The core requirement for the position includes experience in TPRM, vendor risk management, due diligence, risk assessments, and issue management.

Full News Breakdown

The vacancy was triggered by the need for expertise in Third-Party Risk Management. The essential qualifications and experience required for the position include:

  • TPRM / vendor risk experience

  • Risk and compliance knowledge, including understanding of key risk domains such as information security, data privacy, business continuity, operational risk, regulatory compliance, financial risk, and outsourcing or third-party governance

  • Assessment and documentation skills, with the ability to review questionnaires, policies, procedures, control evidence, and third-party responses, and translate observations into clear risk narratives and actionable recommendations

  • Stakeholder management, with strong coordination skills and the ability to follow up with vendors, client teams, business owners, control owners, and risk stakeholders across regions

  • Tools and reporting, with working knowledge of Microsoft Excel, PowerPoint, and Word, and experience with GRC / TPRM platforms, workflow tools, or ticketing systems

  • Professional skills, including strong written and verbal communication, attention to detail, analytical thinking, ownership mindset, and the ability to manage multiple deliverables within a consulting environment

How Does This Affect You?

The announcement specifically resolved the need for expertise in this area. This shift means that professionals in the risk management sector must enhance their due diligence and risk assessment skills. The practical outcome of this shift will be explored in the sections below for lawyers, law students, and businesses.

For Lawyers & Advocates

The Indian Contract Act, 1872, and its provisions on indemnity and guarantee will be crucial in drafting and reviewing contracts for third-party services. Lawyers may find it useful to review the Information Technology Act, 2000, and its amendments to assess data privacy and security risks, and ensure compliance with regulatory requirements. The Companies Act, 2013, and its provisions on corporate governance will be relevant in ensuring compliance with regulatory requirements. Lawyers may want to consider the Reserve Bank of India's guidelines on outsourcing when advising clients on third-party risk management. The role of lawyers in drafting and reviewing contracts for third-party services will be critical, and they may want to review these contracts to ensure compliance with regulatory requirements and adequate address of third-party risk management.

For Law Students

The decision provides an opportunity to examine the doctrine of privity of contract and its application in third-party risk management. The core legal doctrine or distinction students should focus on is the doctrine of privity of contract. The decision is relevant for the study of Business Law, Contract Law, Regulatory Compliance, and Corporate Governance. Comparable cases to read alongside this decision are Bharat Aluminium Co. vs. Kaiser Aluminium Technical Services (2012) and World Sport Group (Mauritius) Ltd. vs. MSM Satellite (Singapore) Pte. Ltd. (2014), which highlight the importance of considering the doctrine of privity of contract in business transactions.

For Businesses

Companies in the consulting sector may want to review their third-party risk management policies and take into account regulatory requirements, including the Indian Contract Act, 1872, and the Information Technology Act, 2000. Businesses may consider enhancing their due diligence and risk assessment skills to manage third-party risks effectively, and review their contracts for third-party services to ensure compliance with regulatory requirements. The board of directors and CFOs may want to decide on the allocation of resources for third-party risk management and review internal documentation and filing processes to reflect the new requirements. Companies may find it useful to review their contracts for third-party services and ensure they are compliant with regulatory requirements, and that they adequately address third-party risk management.

Key Takeaways

The legal principle established is the importance of expertise in third-party risk management in consulting firms, and the need for enhanced due diligence and risk assessment skills. This ruling highlights the need for professionals in the risk management sector to enhance their due diligence and risk assessment skills. The practice consequence is that lawyers may find it useful to advise clients on the implications of third-party risk management for their business operations. The enforcement consequence is that regulatory bodies may expect companies to have robust third-party risk management policies in place, and non-compliance may have potential implications. CFOs may want to review their company's third-party risk management policies before the next audit, and take into account regulatory requirements and third-party risk management.

Source: Consultant Vacancy At Deloitte Touche Tohmatsu India LLP

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested