Would anyone be available to share best practices on how Key IT vendors risk management is implemented in large organizations? I'm looking for real-life approaches as the web is full of best practices however it would be great to get something more pragmatic (vendor onboarding/monitoring, how to get independent assurance over vendor controls, how to review/challenge SOC reports, what's beyond SOC reports? are 3rd party reports the only way?, etc.)