{"id":2645,"date":"2022-07-07T14:26:00","date_gmt":"2022-07-07T20:26:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2645"},"modified":"2025-10-30T09:15:54","modified_gmt":"2025-10-30T14:15:54","slug":"vendor-risk-management-program","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/","title":{"rendered":"Why Do You Need a Vendor Risk Management Program?"},"content":{"rendered":"\t\t<section id=\"block_4053003e7082d81c23b999d8f14c17d1\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Why Do You Need a Vendor Risk Management Program?<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_144ffedb606875d1cf1134e23c3e1a2e\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>Don\u2019t gamble with vendor risk management<\/h2>\n<p><b>Picture this:<\/b>\u00a0You caught wind that the Marketing Department just onboarded a third-party application that shares sensitive organizational data without including your privacy team in the validation process.<\/p>\n<p>Data shared includes employee contact information, customer data, and financial information. Your organization signed with an external vendor without due diligence of privacy risks.<\/p>\n<p><strong>Vendor risk management can feel uncomfortable for an organization. <\/strong>It\u2019s certainly easier to assume that\u00a0<em>this vendor has done its due diligence, and I do not have to worry about it.<\/em><\/p>\n<p>This can bite you, as it has for many other organizations.<\/p>\n<p>And governments are cracking down on these partnerships.\u00a0Demanding that the sharing of data of their citizens be protected and used according to their respective laws and regulations (GDPR, CCPA, <a href=\"\/regulations\/china-pipl\/\">PIPL<\/a>, etc.).<\/p>\n<p>Security breaches are all too common in the headlines today, and it seems to be a matter of\u00a0<em>when it will occur<\/em>\u00a0rather than\u00a0<em>if.<\/em>\u00a0<strong>After all,\u00a0<a href=\"https:\/\/www.ibm.com\/security\/data-breach\" target=\"_blank\" rel=\"noopener\">25% of all global security breaches<\/a>\u00a0resulted from \u201cthird-party attacks or incidents.\u201d<\/strong><\/p>\n<p>Resulting in an average international cost per data breach\u00a0<a href=\"https:\/\/www.forrester.com\/report\/the-state-of-privacy-and-data-protection-2021\/RES164716\" target=\"_blank\" rel=\"noopener\">reaching $4.24M<\/a>\u00a0\u2013 which isn\u2019t pocket change.<\/p>\n<p><strong>Overall, breaches can result in high financial penalties, a loss in company brand perception, a loss of trust, and potential lawsuits.<\/strong><\/p>\n<p>So, to sum up, crossing your fingers and hoping your third-party vendors have put controls in place to mitigate privacy risk is a gamble that could result in disastrous consequences.<\/p>\n<p>Your organization needs a solid framework to build a foundational <a href=\"https:\/\/trustarc.com\/resource\/does-your-company-manage-third-party-vendor-privacy-risk\/\" target=\"_blank\" rel=\"noopener\">vendor risk management program<\/a>.<\/p>\n<h2>Where is the best place to start?<\/h2>\n<p>Deciding what roles to outsource, of course!<\/p>\n<p>That\u2019s right, it all begins with understanding what business activities are best handled by third-party vendors. When writing up request for proposal (RFPs) for prospective vendors, a section should be dedicated entirely to privacy.<\/p>\n<p>Construct this section to make it easy for direct comparison with other vendors.<\/p>\n<p><strong>Lastly, it should cover the following topics:<\/strong><b><\/b><\/p>\n<h3>Defining the vendor risk landscape<\/h3>\n<p>Each country and jurisdiction use their own laws and regulations regarding data privacy. It\u2019s the role of your vendor risk management program to decide how much risk your organization is willing to take.<\/p>\n<p>Once outlined, determine the minimum standards your organization needs to meet.<\/p>\n<p>Risk is a part of doing business,\u00a0<strong>you need to establish guidelines on where that limit exists<\/strong>. Use this to facilitate discussions with potential vendors to see if their appetite is the same.<b><\/b><\/p>\n<h3>Creating a data flow inventory map across all of your vendors<\/h3>\n<p>No organization is an island and they all operate with multiple external vendors.<\/p>\n<p><a href=\"https:\/\/blog.trustarc.com\/2022\/07\/05\/data-inventory-mapping-compliance\/\" target=\"_blank\" rel=\"noopener\">Mapping out exactly where all the data flows<\/a>\u00a0across your entire vendor network will identify possible overlaps and show opportunities for streamlining &amp; reducing costs.<\/p>\n<p>Merging data flow duplication areas and deleting unnecessary data flows ensures that your organization reduces their exposure to third-party risk.<b><\/b><\/p>\n<h3>Data transfer risk assessment<\/h3>\n<p>In addition to determining how data flows for all of your vendors within your organization, assess any data transfer risk based on where your vendors\u2019 systems are hosted and the location of individuals whose data is being processed to ensure appropriate safeguards for international data transfers.<\/p>\n<h3>Ongoing monitoring of vendors<\/h3>\n<p>As always, nothing stays static for very long, and your organization may need to actively monitor vendor partners for any changes in data risk to the company. Some\u00a0<strong>vendors may even need in-person reviews annually.<\/strong><\/p>\n<p>Leverage and include departments from across the organization to assess all aspects of data risk.<b><\/b><\/p>\n<h3>Policies and procedures<\/h3>\n<p>To ensure that your company has oversight, be prepared to share your determined data policies and procedures with your third-party vendors as it pertains both to your customers and vendors.<\/p>\n<p>Develop straightforward policies, meeting controls, and have a set of proprietary implementation strategies.<b><\/b><\/p>\n<h3>Vendor contracts<\/h3>\n<p>Work with your leaders, procurement, and legal teams to ensure that your contract management system tracks what you need to know from a privacy perspective.<\/p>\n<p>Free vendors, or inexpensive ones, generally don\u2019t hit thresholds for procurement or legal review \u2013\u00a0<strong>make sure this is controlled!<\/strong><b><\/b><\/p>\n<h3>Termination of vendor relationship<\/h3>\n<p>Lastly, all good things must come to an end. Have processes put in place that covers both natural terminations along with terminations for cause.<\/p>\n<p>Your business must be prepared to end the relationship if the vendor is non-compliant with data protection and where the risk is high.<\/p>\n<p>So there you have it.<\/p>\n<p><strong>Following these 7-steps will set you with stable foundations to build your vendor management program and avoid any non-compliance fines.<\/strong><\/p>\n<p>Of course, there is much more involved when it comes to vendor risk management.<\/p>\n\t\t\t\t\t\t\t\t\t<div class=\"question-box-multiple\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Framework_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>How to Build a Vendor Risk Management Program<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>Our panel of experts will guide you through the indispensable steps to establish an effective vendor risk management strategy.<\/p>\n<a href=\"https:\/\/trustarc.com\/resource\/webinar-how-to-build-a-vendor-risk-management-program\/\" class=\"cta\">Watch now<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Insight_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Data Mapping &amp; Risk Manager<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>Save time and reduce risk with automated data flow mapping and risk identification.<\/p>\n<a href=\"https:\/\/trustarc.com\/solutions\/data-mapping-vendor-risk-management\/\" class=\"cta\">Learn more<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/risk-management\/\" class=\"badge\">Risk Management<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/vendor-management\/\" class=\"badge\">Vendor Management<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t\n\n\t\t<section id=\"block_f65a8c66da0c4dc6c3a3816a454ab8af\" class=\"resource-section\">\n\t\t\t<div class=\"container\">\n\t\t\t<div class=\"resource-head\">\n\t\t\t\t\t\t\t<h2>Related resources<\/h2>\n\t\t\t\t<a href=\"\/resources\/\" class=\"cta block\">View all resources<\/a>\t\t<\/div>\n\t\t\t\t\t\t<ul class=\"resource-lists \">\n\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/ai-supply-chain-risk-vendor-due-diligence\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-rect-purple-test-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>AI Supply Chain Risk: The New Frontier of Vendor Due Diligence<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/centralized-privacy-office-operating-model-ai-risk-governance-teams\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-rect-blue-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Articles<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>The Centralized Privacy Office: A New Operating Model For AI, Risk, and Governance Teams<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li>\n\t\t\t\t\t<a href=\"https:\/\/trustarc.com\/resource\/ai-governance-practice-privacy-hero-starter-kit\/\" class=\"resource-single\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"120\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/res-feat-rect-pink-380x120.png\" class=\"attachment-380x120 size-380x120 wp-post-image\" alt=\"\" \/>\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"resource-label uppercase\">Templates<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Put AI Governance into Practice: Privacy Hero Starter Kit<\/h4>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\t\t<\/section>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Don&#8217;t gamble with third-party vendor risk. Your organization needs a framework to build a foundational vendor risk management program.<\/p>\n","protected":false},"featured_media":1248,"template":"","topic-resource":[68,74],"type-resource":[6],"class_list":["post-2645","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-risk-management","topic-resource-vendor-management","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Why Do You Need a Vendor Risk Management Program? | TrustArc<\/title>\n<meta name=\"description\" content=\"Don&#039;t gamble with third-party vendor risk. Your organization needs a framework to build a foundational vendor risk management program.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/vendor-risk-management-program\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/vendor-risk-management-program\\\/\",\"name\":\"Why Do You Need a Vendor Risk Management Program? | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/vendor-risk-management-program\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/vendor-risk-management-program\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-blue-test.png\",\"datePublished\":\"2022-07-07T20:26:00+00:00\",\"dateModified\":\"2025-10-30T14:15:54+00:00\",\"description\":\"Don't gamble with third-party vendor risk. Your organization needs a framework to build a foundational vendor risk management program.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/vendor-risk-management-program\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/vendor-risk-management-program\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-blue-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-blue-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Why Do You Need a Vendor Risk Management Program? | TrustArc","description":"Don't gamble with third-party vendor risk. Your organization needs a framework to build a foundational vendor risk management program.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/","url":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/","name":"Why Do You Need a Vendor Risk Management Program? | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-blue-test.png","datePublished":"2022-07-07T20:26:00+00:00","dateModified":"2025-10-30T14:15:54+00:00","description":"Don't gamble with third-party vendor risk. Your organization needs a framework to build a foundational vendor risk management program.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/vendor-risk-management-program\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-blue-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-blue-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2645","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1248"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2645"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2645"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2645"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}