Third Party Threat Hunters
A dialogue with leaders in Cybersecurity and Third-Party Risk Management led a leader in the field: Gregory Rasner (author of three books in TPRM and one in PAM)
Third Party Threat Hunters
Sanctions Ready Third-Party Risk with Michael Volkov
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Sanctions enforcement is starting to feel like the new FCPA, and that is not just a catchy line, it is a warning. When more and more OFAC and export controls violations trace back to distributors, agents, and vendors, “third-party risk” stops being an onboarding task and becomes a real legal and operational threat. We talk through how strict liability changes the stakes, why diversion risk through transshipment points can catch even well-meaning companies, and what happens when regulators decide your controls were never built to see the end user in the first place.
We also dig into the enforcement trend line: DOJ’s National Security Division is leaning in, and sanctions cases can now resemble classic FCPA outcomes with coordinated settlements, criminal exposure, and painful fines. The practical question is simple: if the government asks why you did business with a third party, can you pull a complete, auditable due diligence file that shows your screening, your OSINT research, your beneficial ownership checks, and your documented compliance sign-off? If your evidence lives in emailed questionnaires and scattered attachments, we explain why that approach breaks the moment there is a subpoena, an investigation, or a breach.
Then we widen the lens to today’s vendor ecosystem, where cybersecurity and AI governance are inseparable from third-party due diligence. Vendors can become the pathway into your systems, and AI tools can create liability when they act on your behalf, especially in HR hiring decisions. We share a clear next-step mindset: automate onboarding workflows, build cross-functional partnerships with procurement and IT, and put AI guardrails and a framework in place so the program can evolve without chaos. If this helps, subscribe, share the episode with a colleague, and leave a review with the biggest third-party risk you are tackling right now.
Sanctions Become The New FCPA
SPEAKER_00Listen, let me get into the hook start. The big the the first the first question, which is uh just a a five minute, we should just touch on the question, which is sanctions, uh I'm quoting here, sanctions are the new FCPA, operationalizing sanctions and export controls and third party risk management. The scenario I'm providing you here with is n over 90% of foreign corrupt uh foreign corrupt uh practices act, sorry, uh FCPA enforcement actions and a growing surge of O5 sanction violations trace directly back to third-party intermediaries, distributors, and vendors. Kind of what you've been you've been you've been talking about already. Yet most security and compliance programs still treat vendor risk as a low priority aesthetic onboard checkbox. What happens when your vendors breach or legal act triggers personal liability or a DOJ subpoena? I don't think a lot of folks in this space think about that.
SPEAKER_01Well, here's Okay, so this is this is a big issue right now. And you know, your hook is, I mean, it's a right hook that can knock you out. And the point is here that your third-party risks are absolutely just significant in the sanctions space and export controls.
Distributors And Hidden End Users
SPEAKER_01So let's talk about first on the distribution side. You have distributors, you have agents, but mainly you have distributors or or people that you have commercial arrangements with, and you may just simply provide them with goods. And you don't know where those goods are going necessarily. Well, that's not, you can't do that today. That's not you gotta know more. And this is where we get into our third party due diligence. You, Greg, are an expert in this area, and we rely on people like you with your expertise to bring us the transparency, the visibility into the third party to know whether or not goods or services, usually goods, obviously, to make sure they don't end up with a sanctioned party. Even Apple, even Amazon has been the subject of OFAC investigations when they started to provide goods and services to prohibited persons. Iran, for example, Amazon started to serve every Iranian embassy in the country with low, you know, low volume, but nonetheless, multiple deliveries of goods to the Iranian embassy in various locations. That's a no-no. They got on the hook and they were, they reached a civil settlement. Similarly, Apple did a screening and you know didn't figure out that Cuba is spelled with a C, not a K, or Crimea is not spelled with a K with a C, but a K, you know, they put in K and they got a negative re you know, there's no restriction on. Well, guess what? Apple ended up paying for that. Okay, so even the best tech companies can get in trouble here. So my concern is this that companies are not recognizing who they're selling to and where their goods might end up. And let me give you a scary scenario. I'm a medical distributor and I sell medical supplies, and I sell them to a third party in Turkey. That company intern, unbeknownst to me, I didn't even bother to ask them the question, sells those medical items to a military hospital in Russia. So now you're on the hook for selling milit uh military goods to a Russian entity through a third party in Turkey, which is a known transshipment point and high-risk area for selling into Russia, let alone Eastern Europe or any other location.
OFAC Excuses End And DOJ Steps In
SPEAKER_01So here's what DOJ is tired of. And DOJ, and it started with OFAC, when people would catch people with their third party doing something like that. They said to OFAC, OFAC, I didn't know that the third party was going to do that. So I thought it was legal if I sell it to a third party who's in a legal jurisdiction and I can't control where they sell my goods to. And OFAC said, We're getting tired of that excuse. If you look through the enforcement settlement actions of OLFAC, you will see third party after third party after third party. I had a client who said, I send it to a third party in Canada, and I didn't know they were sending it to Iran. Well, guess what? OFAC cared at that point. So now DOJ has come in and said, look, we are going to use criminal laws on national security issues. We may not do all the FCPA cases that you guys are used to dealing with, but we have beefed up and moved more prosecutors to the Justice Department in the National Security Division, which is responsible for export controls and responsible for uh sanctions, violations, and criminal prosecution. All right. So now what we're seeing, and we saw it last year, there were two cases. One was a merger case, the other was Cadence Design Systems, a Chinese company, in which the third party was basically moving items of intel uh software to a military organization of China, and believe me, Cadence paid for it. How did they pay for it? Why do we know that this is the new trend? Because they use the same structure as an FCPA case. There was a deferred process, there was a plea of guilty, there was a civil settlement, there was a criminal settlement with the guilty plea and a fine, and there was an old fact settlement, and it was just like analogous to DOJ and the SEC bringing in FCPA case. We had a merger, merger and acquisition case that occurred, and which this the company cooperated after acquiring the company and found out they were selling to Iran. And guess what? The CEO of the former, you know, the former CEO after the buyout was criminally prosecuted in the United States. So this is the new era of criminal prosecution of sanctions and export controls.
SPEAKER_00That's a great stuff. I'm glad I invited you. This has been an early learning experience for me as well already, wife, and we're only halfway into the uh end of the conversation.
Build An Auditable Due Diligence File
SPEAKER_00Let me get into big question number one. Operationalizing audit insights for threat hunting. You've noted that sanction enforcement has become sort of the new SCPA for third-party risks. How are the strict liability sanction exposures fundamentally changing how organizations must screen, monitor, and tier their vendor ecosystem?
SPEAKER_01Well, that's a great question. And how in other words, how do we build an effective compliance, a set of compliance controls here to make sure this doesn't happen in the future and we don't that we minimize our liability? And you there is such a danger of silos of operation here. If I'm managing third-party risk, my two best friends in the organization, the head of procurement and the head of marketing or third parties on the distribution side, they are my friends. We break bread together, I'm in touch with them constantly because any third party that's onboarded on either side has to be part of my ecosystem so that we coordinate together and make sure that nobody can engage this third party, be it a vendor side or distribution side, without compliance, signing off, and a due diligence documentation system that's in place and auditable, meaning you can audit it. And so, for example, Greg, you call me up and you say, Mike, you're head of compliance at my company. What did we do with regard to this third-party, you know, X on the distribution side? And I said, Okay, let me give you the entire record of what we did. I have emails, I have searches through third-party open and source intelligence databases. I have even, I use enhanced due diligence services from Greg Rasner, and I have that in the file. That's what we did. And I have a legal opinion which says this is okay. You have generally complied with all of the due diligence requirements and best practices. And here's my legal opinion, go forward with the person. If that person blows up, meaning if that person ends up being the target of some investigation or the subject, let's be technically correct, the subject of an investigation, and it turns into a target relationship, the government's going to come to me and say, Why are you doing business with this person? How did you know to do business with this person? Why did you do business? And I have my due diligence file with Greg Rasner's impermature on it, and with the Volkoff law legal opinion in it that says, here's why we went forward. This is everything we checked, these are all the due diligence activities that we did. Now, those are our audit insights that require coordination with procurement, procurement, legal, and you mentioned or you've also referred to cybersecurity. Now we have cybersecurity and AI to worry about. And why? The third party, and going back to 2012 in the Target case, when all those credit report credit information was there was a data breach in 2012 that Target paid for for years, was the result of a third-party air conditioner salesperson or service person who didn't encrypt their communications such that somebody was able to use the third party to breach all of that data at Target. So now sitting at the table with us for due diligence has to be your IT team to talk about cybersecurity and AI now. And when we get into AI, the risk that we're looking at there, it's mind-blowing in many respects. So we need our IT people to be our best friends. And we already are because we train on phishing, we train with them. The most significant relationship that's occurred, the new one in compliance, is the partnership of compliance with IT.
SPEAKER_00Let
Break Silos With Procurement And IT
SPEAKER_00me let me build off of your previous uh answer. How can security and compliance teams break down internal function silos? Because that's kind of what we're talking about here. Both of us, how how do you find the best success when people are being able to break down silos?
SPEAKER_01Well, the best way is not to start complaining about it and become like a squeaky wheel and all that stuff. You know, the best compliance people have best have great interpersonal skills. And what you really find are situations, and I wish I could come up with this phrase, but it's a friend of mine, Dan Chapman, who's a great compliance person from Houston, and he used a you look for win-wins. In other words, what can I do for you on the procurement side? And what do I need from you that will make both of us look good? Well, procurement needs to avoid an embarrassing situation where they deal with a sanctioned entity and they onboard them. Or procurement needs to make sure that somebody can't uh send a fraudulent request to change your banking instructions without making a phone call to the new vendor to say, hey, are you really changing this banking account information? So procurement does not want to be embarrassed. And we so and we don't want to be embarrassed because what happens when there's a calamity in a company? They the CEO looks at compliance and says, Hey, what happened? I thought you were supposed to protect us from this. So we build relationships by helping each other out. I'll give you one unfortunate story. It took three years for the head of compliance at a major soda company, I'm not going to tell you which one, to get access to the HR data from HR. You know, and they it took three years. It went all the way up to the CEO to decide. That's ridiculous. Okay. We're all in this together. We're part of a team, and we all know where that we need each other to keep the company committed to an ethical culture of compliance. And so my thing is be a good person, treat people the way you want to be treated, use your mother's motto for that, and then talk to them and build a relationship. Now, some look, it took another company uh experience I had was it took somebody 18 months to negotiate five questions that they insisted the procurement needs to ask a new vendor to flag out, to to flood out, to bring out the issues of third-party risk on sanctions. It took them 18 months of negotiation. Because a lot of times there's resistance to change, but breaking down the silos is just it's it's so critical in compliance because there you're only as good as your partnerships are.
SPEAKER_00Yeah. Well, I and the most successful people at any level are are the ones that build relationships, right? And know how to play nice, right? Anyway, I like how you start stop complaining about it. Just you just get on with it.
SPEAKER_01Two things that I absolutely learned through all of my experience as an old man here. Number one, you need to you don't scare people into action. The worst thing a compliance person can do is say if we don't do this, everybody's gonna go to jail. That doesn't work. The second thing is to treat people with respect and offer to help and take your time and be patient and don't get emotionally upset about things. Take a step at a time. But you need to build relationships. And so your CEO is important, your chief legal officer is important, all of these people are important, but we're not there to make you look good. I mean, meaning the chief compliance officer. We already know what you do. And I this is why I admire the profession so much, because this is not like you win a case as a lawyer. This is where if you do a great job, all you're doing is creating more work for yourself. Once you've got to happens to some extent, you're right. It's a continual loop. We are like, you know, the gerbil or the hamster in the wheel. But those are critical functions to maintaining the most important and an invaluable asset that every company has, which is its reputation.
SPEAKER_00And you and I have lived long enough to know the number of companies that have died on their reputation.
SPEAKER_01Mm-hmm. He said, we can lose money, and when then we we can regain that money in a short period of time. But if you lose your reputation, that takes a lifetime to recover. Right.
Automated Workflows Beat Paper Questionnaires
SPEAKER_00Big question number two is the title is Beyond Paperwork Real-time diligence versus AI enforcement. Why do traditional annual paper pushing due diligence questionnaires fail to protect companies during actual regulatory investigations or cyberbreach incidents?
SPEAKER_01Well.
SPEAKER_00And actually, this is interesting because I know mine from a slavery perspective why I think they fail. But and and it does not that mine's wrong. It's just that yours from a legal perspective and compliance perspective is going to be different. I want to really want to hear what your view is doing.
SPEAKER_01Okay. When you're onboarding somebody, you have to ask questions. The way I say it is like this. If you're sending emails with attachments of questionnaires that have been completed to each other within a company, you're not in compliance. You failed because DOJ, the Justice Department, or OFAC, when they find out you didn't have an automated program to onboard people through procurement, through on the market, on the distribution side, the sales side, if you don't have an automated program, by definition, you are ineffective. Okay. And the reason is you can't walk into DOJ and say, you know what, it was going to cost us $60,000 to get this automated platform. And the best solutions are where you make it easy for the business to use the system. So for example, one of the platforms, there are six entries that a businessman, a businesswoman has to make in a platform online in the cloud to start the process. And it's all automated at that point. We have manageable, we have workflows that are management, managed, and we have efficient workloads. Questionnaires, the old questionnaire system is done. Okay. We have a workflow that may include questions in it, but there's more to it than that. There's documentation requirements, there's uploading this, uploading that, there's verification, there's UBO information. And one of the things that happens is sometimes we actually have to ask the third party questions and see what their answer is. And that's a start. But some this workflow has to be there. And the regulators know it. They know that it's either you're so cheap that you you don't highlight or you don't emphasize the importance of compliance in your company that you won't spend $40,000 to $100,000 to manage your third-party risk. Now, here's the thing that's complicating life. Once you start to bring vendors in, and I don't want to see people hyperventilate over this because I'm pretty tired of the AI hyperventilation. There are vendors, we bring them on board, and we need to know how and what they use their AI for. And the only way that we have liability for what they may do as vendors is if they act on our behalf. This is a critical third-party concept that started with the FCPA and really agency law, which is a third party creates legal risk for you when they act on your behalf. So, for example, if I say I'm bringing in a specialty shipment of specially made Pepsi sodas for you that are just for you, and I pay bribes to get that specialty shipment across the border and delivered to you, I am acting on your behalf. And therefore, when I pay bribes, I'm creating liability for you, the company. However, if I'm just bringing over a gigantic shipment of Pepsi and I'm serving 85 customers in your country and I pay bribes, I'm not creating liability for you because I'm not acting on your behalf. I'm acting on my behalf for all of my customers, not for a specific customer at that point. And I cannot be held liable for that. Okay? Now that's a big difference. Apply that same principle now to AI. So for example, I get a vendor, and on my behalf, I take that vendor service, plug it into HR, and make all my hiring decisions based upon that AI. That is AI acting on my behalf to make hiring decisions and creates liability. If I'm just using AI to I mean, can I pause you there, Michael?
SPEAKER_00So let's say the AI that you plug into your HR has the bias, right? It detects the model. What you're saying is you're gonna be held liable for that bias because even though you can't you can't point at the machine and say it's the machine's fault. You're supposed to have oversight on that machine and say, wait, I see bias happening here. I need to correct for that.
SPEAKER_01Exactly. You'd say you hit the nail right on the head. Now, when I hire that a that vendor and they use that AI for hiring decisions, I may put in the contract a compliance requirement that you have to make sure this is not you are representing and warranting to me and certifying to me that there's no bias in this. Or if I get held liable, that you're going to indemnify me for your faulty software. And I better know, though, I better ask them the question and I better understand the technology that they use in the service that I'm buying from them to make sure I include those provisions, but also to mitigate the risk. Well, tell me how you're stopping the risk and document it. So you hit the nail right on the head. That AI in the HR situation is critical, and people are just bringing AI into HR and saying, hey, we got this solution, everything's hunky dory. Well, no, let alone I haven't even gotten to the risks of data privacy, of data that this vendor brings to us, of cybersecurity, of leaks or unencrypted information that can be targeted or vulnerabilities within. Their system that can be targeted. Okay. But that's like every vendor. We have to make sure that our IT team knows what these guys are doing. So this is the complication of cybersecurity and AI with third parties. So I talk a lot about sanctions over here. I'm not even getting to the nuance of the issue of AI and your vendor population and what you're doing nowadays with AI. And then the last point I'm going to make on AI, and I'm doing a webinar on this in early September. If you look at my website, we're doing one on AI and internal investigations. Now you want to talk about risk and attorney client privilege and things like that. That's where it gets even more interesting. So you asked about paperwork, and we've launched into real-time due diligence. It's great info. It's a great question, though, because everybody has hopefully nobody's using SharePoint with questionnaires on it anymore. Right. Okay. Hopefully we're at this point where it's automated, and you just tell, you ask me, Mike, get me the due diligence file. Or you're auditing me and you say, What did you guys do on third party risk? And I want to take a sample of 10 of your third parties and see what you did. That's that's where we are right now, that we better have everything organized and easily accessible.
SPEAKER_00You raised some really great points, uh Mike, and we're right. I'm surprised that somebody on the compliance side is finally saying we don't need to do the questionnaires as much anymore because that always seemed to me like the go-to place that the compliance folks always skated to. But that makes it totally different. Yeah, yeah, totally.
SPEAKER_01Okay, well, if you got a document and you send me a questionnaire, I'm like, hello, McFly.
SPEAKER_02This is 2026. Okay. All right. Yeah, yeah. Totally agree.
SPEAKER_00I'm interviewing a lot of the service providers in this space who are making software in this space. Right. I think there's a lot of prize points, a lot of different providers, almost all of them have automated workflows because they know that's what you need.
SPEAKER_01Exactly.
Tomorrow’s Moves On AI Governance
SPEAKER_00Let's ask uh I want to ask you one one question here at the after action report. What is the one immediate legal or compliance audit step a taper leader or or risk compliance leaders should take tomorrow to shield the organization from third-party enforcement actions or sanctions with exposure?
SPEAKER_01Two things. And I'm sorry to, you know, spoken like a true lawyer, when asked one question, you ask two. You answer two. The first one is no doubt, no doubt, if you're not automated, you're out of compliance. Okay. That that one's easy. Number two, people are not focusing on third-party AI risks. We I'm okay, we're not seeing a governance structure that is being developed in the field right now on how do you manage AI risks. People are befuddled, people are scared or unwilling to dig into these issues. My advice is build a system of governance from the top down. You're gonna set some guardrails, you're gonna have an accept, you know, an authorized acceptable use policy, and you're gonna have to adjust as you go along, but start with the structure. And who knows how to do this best? Compliance professionals, third-party risk managers. This is what we do every day. We deal with risk. And so my thing is address the AI issue. We have shadow AI use out the wazoo right now of employees using it, and nobody even knows that they're using it. So that's my worry.
SPEAKER_00Yeah. Well, uh, uh, and Mike, I I think one of the points you bring up are really excellent. I would say uh uh just to add to that would be make sure that you pick a framework, an AI risk management framework that will help guide you for control points and decision points. If you're if you don't have a framework, you've got a bucket of best practices that best for your program. So framework make sure you hit all the points and those frameworks get updated, then you can update your program. So uh pick a framework and just stick to it.
SPEAKER_01Start somewhere. Like I mean, Greg, and I hate to say this in my age, but if you go back, we started in the FCPA arena, we started to really develop third-party risk management systems because we had to. And we did it and we started, and I look back on some of the things we did. I mean, thank God we uh evolved because we were doing some wacky things. But now that's the way the process works. It improves as time goes on. So, like you're saying, find a framework, dedicate yourself to it, and then you're going to adjust it as time goes on.
SPEAKER_00Totally agree.
Closing Thanks And Next Steps
SPEAKER_00All right, thanks uh again for uh thanks for being a guest, Mike. I really appreciate it. I definitely want to have you back on in some future.
SPEAKER_01I really enjoyed it, but really enjoyed it. Just a terrific podcast. Thank you for your work. Thank you for promoting third party risk management.
SPEAKER_00Thanks again for tuning in to third party threat hunters and tune in for tune in for more episodes and podcasts. We will make sure to put in Mike's uh information and his his links to all his podcasts and his information as well on on the site as well.