Rohan Kalyan · TPRM Portfolio Lead, Deloitte USI

Third-Party Risk
& Cybersecurity
Consultant

From assessment execution to risk-led portfolio ownership.

Owning the end-to-end TPRM lifecycle — onboarding, due diligence, continuous monitoring, exception tracking and third-party exit — across global technology, software and BFSI supplier portfolios, and validating GenAI-generated risk assessments as the domain subject-matter expert.

  • TPRM
  • Cybersecurity
  • Technology Risk
  • BFSI
  • GenAI Risk
Scope of ownership
3 workstreams owned
2020
2022
2023
2025
Now
5,500+ assessments in the first program

Assessor → QA → Team lead → Independent lead → Portfolio lead

  • 500+ TPRM engagements delivered End-to-end lifecycle across global technology, software and network supplier portfolios
  • 1,000+ Assessment reports QA-reviewed Reviewed for accuracy and control effectiveness across the portfolio
  • ~20% Year-on-year fall in high-risk findings Through proactive remediation tracking and governance
  • 15+ Analysts trained and mentored On TPRM process, assessment quality and risk-mindset principles

Career totals across the Deloitte USI tenure. Per-engagement figures — including 5,500+ assessments on a single program and a 57% turnaround reduction — are stated inside the case studies below, each scoped to its own engagement.

01 — Expertise

Six domains, evidenced by delivery

Each capability below is drawn from work actually performed on client engagements, not from framework familiarity.

Third-Party Risk Lifecycle

  • Onboarding, due diligence and continuous monitoring
  • Inherent risk assessment and tiering
  • Residual risk scoring and third-party exit
  • Risk exception tracking, approvals and escalation

Cybersecurity & Technology Risk

  • Security control assessments and technical walkthroughs
  • Evidence validation against ISO 27001 and NIST
  • Severity-rated findings and reporting
  • Assessment framework design and refinement

Risk & Control Governance

  • Vendor obligation mapping to ISO 27001, NIST, GDPR and PCI-DSS
  • Contractual and commercial arrangement oversight
  • KPI monitoring and supplier performance escalation
  • Root-cause analysis and remediation action plans

Privacy & Regulatory Risk

  • Regulation-to-requirement mapping
  • Regulatory gap identification
  • Privacy assessment walkthroughs
  • Support for regulatory requests and examinations

Senior Stakeholder Management

  • Chief Control Office, Compliance, Legal and Risk
  • Control Assurance and Procurement partnering
  • Risk communication at senior executive level
  • Managing objectives, service expectations and priorities

GenAI-Enabled Risk

  • TPRM subject-matter validation of AI output
  • Evidence grounding and traceability
  • Failure-mode identification
  • QA refinement loops and tooling UAT

02 — Career progression

Six stages of increasing ownership

Responsibility moved from executing assessments, to assuring their quality, to leading teams, to owning a supplier portfolio answerable directly to the client.

AssessNov 2020 – 2021 · Consultant 1

Delivering third-party assessments at volume

Executed reputational and contractual compliance assessments of business partners as third parties entered the client's ecosystem week over week.

  • 5,500+ assessments
  • 1,200+ third parties in scope

Optimise2021 · Consultant 1

Rebuilding the throughput, then the regulatory baseline

Automated weekly intake and redesigned the assessment workflow, more than halving turnaround on that program. In parallel, mapped the privacy regulatory baseline into an assessable requirement framework with direct client stakeholders.

  • 7h → 3h turnaround
  • 8 regulations mapped
  • Weekly intake automated

Assure2022 · Consultant 2

From performing assessments to assuring them

Ran privacy and cybersecurity walkthroughs for third-party developers, then moved into QA review and PMO coordination — accountable for the quality of other people's assessments as well as my own.

  • 100+ assessed and QA-reviewed
  • 4h → 2h assessment call
  • Assessor → QA → PMO

Lead2023 – Mar 2025 · Senior Consultant

Depth over volume, and a team to lead through it

Led deep-dive control assessments of ads measurement partners at roughly sixteen hours per third party, directing a three-person assessment team from evidence validation through severity reporting, remediation and SLA monitoring.

  • 16 third parties
  • 16 hrs per assessment
  • 3-person team led
  • End-to-end remediation

OwnOct 2023 – Present · Senior Consultant, TPRM Portfolio Lead

Direct accountability for a supplier portfolio

Progressed inside the enterprise TPRM program from assessor to QA to lead for three client-facing workstreams, and took portfolio-level ownership of the end-to-end lifecycle — inherent risk through due diligence, continuous monitoring, exception tracking and third-party exit. Advises Chief Control Office, Compliance, Legal and Risk stakeholders, and concurrently led a separate client's assessments independently.

  • 3 client-facing workstreams
  • 500+ engagements to date
  • Inherent → control → residual
  • Senior stakeholder ownership

Transform2025 – Present · Senior Consultant

Domain expertise applied to AI-generated risk output

Acting as TPRM subject-matter expert on an internal GenAI assessment accelerator: validating AI-generated assessment responses against source evidence, identifying the failure modes that undermine them, and feeding QA refinements back into the tool. AI-driven automation raised vendor onboarding efficiency by a quarter.

  • TPRM SME
  • AI output QA
  • 25% onboarding efficiency
  • Failure-mode identification

Also supported cost, revenue and recovery data analysis for a separate client in 2022 — high-volume dataset work, listed here as supporting experience rather than a flagship engagement.

03 — Selected work

Seven engagements, weighted by what they prove

Client identities are anonymised. Every figure is scoped to the engagement it belongs to. Where a detail was not documented it has been left out rather than estimated.

Client B · 2022

Third-Party Developer Assessments

Privacy and cybersecurity walkthroughs of third-party developers, moving from assessor into QA review and PMO coordination.

  • 100+assessed and QA-reviewed
  • 4h → 2hassessment call
Context
Assessment of third-party developers building against the client's platform, covering both privacy and cybersecurity requirements.
My role
Assessor, then QA reviewer, then PMO — responsible for assessment quality and program coordination as well as delivery.
Scope
Over one hundred assessments assessed and QA-reviewed.
Approach
Privacy and cybersecurity walkthroughs with the developer, followed by questionnaire and process redesign to remove time that was not producing risk signal.
Outcome
Assessment call time halved, from four hours to two, without reducing assessment scope.
Career significance
First move into quality ownership — being answerable for what other assessors produced.

Client A · Technology / Media · 2021

Business Partner Risk & Contractual Compliance

High-volume reputational and contractual compliance assessment of business partners, rebuilt into a faster, automated intake process.

  • 5,500+assessments
  • 57%turnaround reduction
Context
Reputational and contractual compliance assessment of business partners entering the client's third-party ecosystem.
Why it mattered
Third parties were entering the program continuously; assessment capacity, not assessment method, was the constraint.
Scope
More than 5,500 assessments delivered on this program, against an intake of over 1,200 third parties.
Approach
Sustained high-volume assessment execution, with weekly intake automated and the assessment workflow redesigned around it.
Outcome
Turnaround per assessment reduced from seven hours to three — a 57% reduction on this program — at unchanged volume.
Career significance
Established delivery scale, and the habit of treating a slow process as a problem to redesign rather than absorb.

Client A · Technology / Media · 2021

Privacy Regulatory Framework Mapping

Translated privacy regulation into an assessable requirement framework, built with client stakeholders to survive future regulatory change.

  • 8regulations mapped
  • Reusablegap-identification framework
Context
The client needed privacy regulation expressed as requirements that could actually be assessed against, not cited.
Scope
Eight regulations mapped in the initial scope.
Approach
Regulatory research, then regulation-to-requirement mapping, developed through direct interaction with client stakeholders.
Outcome
A framework the client used for gap identification and designed to absorb future regulatory updates rather than be rebuilt for them.
Career significance
Earliest regulatory translation work and earliest direct client stakeholder ownership.

Client D · Jan – Oct 2025

Independent Assessment Leadership

Led third-party assessments for a separate client without senior oversight, and designed the pointed assessment framework used to run them.

  • Independentcall leadership
  • 16 hrsper assessment
Context
Third-party assessments for a separate client, run over ten months alongside the enterprise TPRM program.
My role
Independently led the assessment calls, refined and designed the pointed assessment framework, and mentored and QA-reviewed other assessors.
Scope
Three third parties, at approximately sixteen hours of assessment each.
Career significance
Independence rather than volume: leading client-facing assessment calls unsupervised, and shaping the assessment approach itself rather than applying one.

Included as evidence of independent ownership and framework design. The engagement was deliberately small and is not presented as a volume achievement.

04 — Method

How I govern and assess risk

Two sequences run at once. The lifecycle governs the relationship from onboarding to exit; the assessment sequence governs what happens inside any single risk review.

The relationship — third-party lifecycle

  1. 01 Onboarding & inherent risk
  2. 02 Due diligence
  3. 03 Continuous monitoring
  4. 04 Exception tracking & approvals
  5. 05 Third-party exit

The review — inside a single assessment

  1. 01

    Business context

    What the third party does, what data and systems it touches, and how the business depends on it.

  2. 02

    Inherent risk

    Exposure before any control is credited — data sensitivity, criticality, access and regulatory reach.

  3. 03

    Control evaluation

    The controls actually claimed, assessed against ISO 27001, NIST, GDPR and PCI-DSS expectations.

  4. 04

    Evidence validation

    Whether the artefacts support the claim. A policy is not a control; a control without evidence is not assurance.

  5. 05

    Residual risk

    What exposure remains once validated controls are applied to the inherent rating.

  6. 06

    Remediation & escalation

    Severity rated, owners agreed, progress monitored against SLA, and what stays open escalated.

05 — GenAI & TPRM

Domain expertise applied to AI-generated risk assessment

Deloitte internal · GenAI TPRM Accelerator · 2025 – Present

My role TPRM subject-matter expert, evidence validation and output QA. Not model engineering — the contribution is the domain judgment that tells you when an AI-generated risk assessment is wrong.

Input

Third-party evidence and documentation

Model

GenAI analysis of the submitted evidence

Output

AI-generated TPRM assessment response

SME validation

Every response tested back against the source evidence

Failure modes identified and fed back

  • Evidence misunderstanding
  • Hallucinated controls
  • Incorrect ISO / SOC interpretation
  • Missed exceptions
  • False compliance signals
  • Ambiguous-document handling
  • Weak evidence grounding
QA loop

Refinements returned to the tool and re-tested

Result

Assessment output that is evidence-backed and defensible

The value is not that a model can draft a risk assessment. It is that someone who has run several thousand of them can tell when the draft is wrong, name why, and make the next one defensible.

06 — About

Background

I am a Senior Consultant and TPRM Portfolio Lead at Deloitte USI, working across third-party risk, cybersecurity and technology risk. Based in Gurgaon, India.

My work started in high-volume assessment delivery — several thousand third-party assessments and the process redesign that made them faster — then moved into quality assurance and PMO responsibility, then into deep-dive control assessments leading a three-person team through remediation. I now own the end-to-end TPRM lifecycle across a global portfolio of technology, software and network suppliers for Fortune 500 and BFSI clients: onboarding, due diligence, continuous monitoring, exception tracking and third-party exit.

That means maintaining complete risk profiles rather than issuing point-in-time reports, and working directly with Chief Control Office, Compliance, Legal, Risk and Control Assurance stakeholders — including support for global regulatory requests and examinations.

Alongside that I am the TPRM subject-matter expert on an internal GenAI assessment accelerator, validating AI-generated assessment output against source evidence and identifying the failure modes that make it unreliable.

Download résumé

Certifications held

  • ISO 27001 Lead ImplementerTÜV SÜD
  • Certified in Cybersecurity (CC)(ISC)²

In progress

  • CRISCExam scheduled
  • CISSPTraining completed
  • ISO 42001 AI Governance Lead AuditorTraining completed
  • AI Strategist — Prompt Engineering & Applied AITraining completed

Frameworks & standards

  • ISO 27001 / 27002
  • NIST
  • SOC 2
  • GDPR
  • PCI-DSS
  • COBIT

Platforms

  • ServiceNow
  • Risk management applications
  • AI assessment tooling (UAT)

Recognition

  • 3 Applause Awards · 4 Spot AwardsDeloitte, for TPRM portfolio delivery and client value creation
  • RFP development & TPRM solution designFor technology and BFSI clients globally

Education

  • PGDM, IT & MarketingBalaji Institute of Modern Management, Pune · 2018–2020
  • B.Tech, Mechanical EngineeringSUSCET, Mohali · 2014–2018

Languages

  • English (professional)
  • Hindi
  • Punjabi
  • German (foundational)

07 — Contact

Open to conversations

Third-party and vendor risk, technology risk, cybersecurity GRC, financial-services risk and AI-enabled risk programs.