WG Third Party Risk Management & Sustainability
Working Group “Third Party Risk Management & Sustainability” (formerly: “Third Party Risk Management & ESG”)
Amid a lot of volatility and uncertainty, sustainability and ESG are terms on everyone’s lips, given the avalanche of regulations that are being enacted, changed, retracted and re-inforced to make companies more sustainable – or at least to make companies report on all such matters.
One currently discussed point of sustainability regulations is the inclusion of the entire value chain instead of “only” tier 1 suppliers. With that, even smaller companies who do not fall in the scope of regulations will be indirectly impacted as they will be assessed by their larger corporate customers who are in scope. Managing compliance risks related to third parties, or as our co-chair Michael prefers to call it, “external partner risk management” is top of mind for a lot of companies and consequently or the compliance community.
To respond to these developments, the Working Group “Third Party Risk Management & Sustainability ” (formerly “Third Party Risk Management & ESG”) , co-chaired by Annette Schüller and Michael Reh brings together all those interested in questions of the management of third party/external partner risk and other adjacent sustainability compliance matters to discuss, exchange and share best practice on how best to deal with these new and novel requirements.
Annette and Michael look forward to your active participation. We also welcome any speakers or ideas for future events.
09 June 2026 – Sanctions & Export Controls: Legal Challenges for International Swiss Companies amidst Geopolitical Realities
04 March 2026 – Managing Human Rights and Corruption Risks Across Life Sciences Third Parties
On March 4, 2026 in partnership with Ethixbase 360, ECS hosted an exclusive webinar exploring one of the most pressing challenges facing the life sciences industry today: how to effectively manage human rights and corruption risks across complex third-party networks.
From clinical trial sites and distributors to manufacturers and logistics partners, life sciences companies operate within vast, global ecosystems. With increasing regulatory scrutiny and the emergence of mandatory human rights due diligence frameworks, organisations are under growing pressure to ensure their third-party risk management (TPRM) programmes are both robust and scalable.
Bringing together industry expertise, the session featured Aditi Wanchoo, Director of Human Rights at Novartis, Patrick Wellens, Chairman of Ethics and Compliance Switzerland and James Swenson, Managing Director at Ethixbase360
The discussion focused on how organisations can evolve their due diligence and monitoring programmes to meet shifting regulatory expectations, while remaining practical, proportionate, and aligned with business realities.
Key Insights from the Discussion
1. Different maturity levels drive different approaches
There is no one-size-fits-all approach to human rights due diligence. Organisations are at varying stages of TPRM maturity, and this directly influences how they embed human rights considerations.
Some companies are integrating human rights into existing TPRM frameworks, leveraging established processes and infrastructure. Others are developing standalone workstreams depending on organisational structure and priorities. Ultimately, the approach depends on internal maturity, resources, and strategic priorities, but alignment and clarity are key to ensuring effectiveness.
2. Risk assessments are foundational
A strong risk assessment framework is critical to any human rights due diligence programme.
Companies must first understand their inherent risk exposure by evaluating:
- Their operations
- Geographic footprint
- Their third-party ecosystem
While baseline models such as those based on jurisdiction or company type provide a useful starting point, they are not sufficient on their own. Internal factors, business models, and sector-specific nuances play an equally important role.
A more tailored, holistic assessment enables organisations to prioritise efforts where they matter most.
However, efficiency is equally important. Asking third parties to complete extensive questionnaires at scale is neither practical nor effective. A more targeted approach, such as screening suppliers against relevant databases and deploying detailed questionnaires only for higher-risk entities can significantly improve both response rates and data quality.
Equally, organisations should aim for a holistic view of third-party risk. Fragmented approaches where separate tools, methodologies, and assessments are used for human rights, sanctions, anti-corruption, and IT security can create inefficiencies and fatigue for suppliers. An integrated framework helps streamline processes while improving overall risk visibility.
3. A risk-based approach is essential for scalability
For large organisations, reviewing every third party is neither practical nor efficient.
A clearly defined, risk-based approach allows companies to allocate resources strategically and scale their programmes effectively. This approach should be embedded in policy and applied consistently across the business.
Key risk indicators may include:
- Geography
- Industry
- Nature of the relationship
- Spend thresholds
By focusing on higher-risk areas, organisations can enhance both efficiency and impact, without compromising on compliance.
Importantly, due diligence should not be viewed as a one-time exercise at onboarding. Ongoing monitoring across the lifecycle of the third-party relationship is essential to ensure risks are continuously identified and managed as circumstances evolve.
Leveraging data-driven insights across suppliers and extended value chains including N-1 and N-2 relationships can further strengthen programmes. This enables organisations to proactively identify emerging risks, rather than relying solely on reactive assessments.
12 February 2026 – Due Diligence Decoded
On February 12 Ethics & Compliance Switzerland co-organized with Baker & Mc Kenzie Switzerland an event on due diligence with Mr. Philippe Fleury (head of compliance Pictet Group), Samantha Miller (global head anti-bribery and anti-corruption Gunvor) and Simon Ntah (Partner Baker Mc Kenzie) as speakers. Patrick Wellens introduced the speakers and moderated the event.
Mr. Fleury elaborated on the current regulatory framework for banks and mentioned that regulatory expectations regarding anti-money laundering are increasing, there are more applicable legal and regulatory requirements (incl. upcoming new EU AML regulation) to be followed, there is a volatile geopolitical situation impacting client relationships,
there is a stronger focus of authorities on criminal prosecution and there is the personal responsibility of compliance officers.
Mr. Fleury mentioned that due diligence requirements must be applied at every step of the client lifecycle ( new prospect, client onboarding, changing circumstances of the client, transaction monitoring, sanctions /adverse media monitoring, periodic review, account closing).
Samantha Miller highlighted the evolving expectations on due diligence in the private sector. Given that there are limited resources, she stressed the risk-based approach for due diligence. How is risk appetite defined ( potential criminal or regulatory risk versus reputational risk) within the company, how is the responsibility for risk management best allocated and owned within the company. A challenge is to proof the value of due diligence to business stakeholders.
Simon Ntah presented the prosecutors’ view and stated that the question is always whether deviations from policies or violations of law are individual failures or systemic weaknesses? “Was the organization realistically able to prevent the offence”


8 May 2025 – Managing Third-Party Risks in Fintech: Insights and Best Practices
In a physical-only session hosted by eBay in Bern, the WG explored the evolving challenges and best practices in managing payment-related third-party risks in today’s fast-moving fintech landscape. In the first part, JB Helip, Global Head – Payment Third Party Risk & Governance at eBay Switzerland, provided key insights into emerging regulatory expectations, TPRM framework overview, uses cases & lessons learned from operating in a heavily outsourced model, with a particular focus on critical third-parties monitoring. His presentation was followed in a second part by an open exchange on the challenges of the present geopolitical situation, which continued over dinner.
13 February 2025 – Unlocking the Power of Open-Source Research: Best Practices for Third-Party Due Diligence
During an online workshop, ECS’s organizational partner Risk Advisory explored with the WG participants how best to approach conducting open-source research and details the benefits of incorporating source enquiries into an investigation. They shared best practice when undertaking open-source research, including top tips in the effective use of research tools, the benefits of gathering human intelligence, developing a sense for scope-building and research priorities, and how best to assess risks at a preliminary stage
21 November 2024 – How do European ESG and supply chain regulations impact foreign international enterprises that want to do business in Europe/Switzerland?
In snow-covered Zurich, Peter Faisst, board member of the Solar Stewardship Initiative, presented impacts of European ESG and supply chain regulations on foreign international enterprises wanting to do business in Europe/Switzerland? He described the challenges facing foreign enterprises using the example of the international solar power industry, an industry that is vital for sustainable future energy supply worldwide and that has long and complex supply chains. Mr. Faisst focussed on the difficulties of identifying and controlling large supply chains beyond tier 1 suppliers.
29 August 2024 – Launch event
Over 50 participants celebrated the launch event with us, some coming with us to the Novartis Campus in Basel, others attending remotely.
After a tour of the Novartis Campus, Stephan Geiger, Partner at EY and Head Advisory – Climate Change and Sustainability Services, Switzerland kicked the WG off with an overview of supply chain due diligence regulations existing and on the horizon (including CS3D). Thereafter Michael Reh, Global Head External Partner Risk Management at Novartis gave an introduction on how to translate the regulation into practice and how Novartis systematically manages risk related to external partner engagements.

