Major Medical Indemnity Insurer
Third Party Risk Management Managed ServiceAmstelveen is engaged by the client to establish and deliver an ongoing Third Party Risk Management (TPRM) managed service to support compliance with CPS 234 Information Security requirements. The engagement involves designing the end-to-end third-party risk assessment framework, including the development of assessment criteria, policies, procedures, and governance processes aligned with CPS 234 and information security obligations. As part of the managed service, Amstelveen conducts risk assessments for both new and existing service providers, evaluating information security controls and identifying areas requiring remediation or enhanced oversight. Amstelveen continues to manage the third-party risk assessment lifecycle on behalf of the client, providing ongoing assurance that material service providers are assessed consistently and in alignment with regulatory expectations and information security requirements.





