Third Party Threat Hunters

Sanctions Ready Third-Party Risk with Michael Volkov

Gregory Rasner Season 2 Episode 9

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 27:32

Send us Fan Mail

Sanctions enforcement is starting to feel like the new FCPA, and that is not just a catchy line, it is a warning. When more and more OFAC and export controls violations trace back to distributors, agents, and vendors, “third-party risk” stops being an onboarding task and becomes a real legal and operational threat. We talk through how strict liability changes the stakes, why diversion risk through transshipment points can catch even well-meaning companies, and what happens when regulators decide your controls were never built to see the end user in the first place. 

We also dig into the enforcement trend line: DOJ’s National Security Division is leaning in, and sanctions cases can now resemble classic FCPA outcomes with coordinated settlements, criminal exposure, and painful fines. The practical question is simple: if the government asks why you did business with a third party, can you pull a complete, auditable due diligence file that shows your screening, your OSINT research, your beneficial ownership checks, and your documented compliance sign-off? If your evidence lives in emailed questionnaires and scattered attachments, we explain why that approach breaks the moment there is a subpoena, an investigation, or a breach. 

Then we widen the lens to today’s vendor ecosystem, where cybersecurity and AI governance are inseparable from third-party due diligence. Vendors can become the pathway into your systems, and AI tools can create liability when they act on your behalf, especially in HR hiring decisions. We share a clear next-step mindset: automate onboarding workflows, build cross-functional partnerships with procurement and IT, and put AI guardrails and a framework in place so the program can evolve without chaos. If this helps, subscribe, share the episode with a colleague, and leave a review with the biggest third-party risk you are tackling right now.

Support the show