SEPTEMBER 14, 2026 • 7 MIN READ

The Third-Party Problem: The Next Automation Frontier

State of GRC - Third Party Risk Management

75% say AI adoption is outpacing their ability to vet vendors. Why AI third-party risk management is the next frontier for automation.

This is the final post in our five-part series on the State of GRC in the Age of AI report. Our previous post in the series covered the debt that builds when AI adoption outruns our governance efforts. In this post, we're looking externally: at the web of third parties we rely on who are also adopting AI just as quickly as we are.

Vetting a third party has usually been a point-in-time snapshot: we assess a vendor as part of initial purchase, allow or reject the addition of the vendor, file the result, and carry that "approval" forward for a year (or two!) as if nothing about them changed. Often, the level and frequency of vetting is dependent on the commensurate criticality and impact of the vendor on our organization’s data, systems, people, or operations. AI is here to stay, like a welcomed (now expected) “camel’s nose in the tent” that started when LLMs became readily usable, to now in a thrash of expansion of new AI capabilities found throughout our vendors’ services, platforms, and offerings. AI didn't create the gap in the original model; AI made the exponentially widening gap impossible to ignore. 

Every third party in our supply chains is wiring AI models into its platforms on a rolling basis, and each new capability is one more thing last year's review never saw. In the report, 75% of IT and security professionals say AI adoption is outpacing their ability to vet third parties. The problem isn't the review itself, the problem is we still treat it as a once-a-year event in a world that changes every week, and in some cases, every day! The traditional vetting process was built for a prior era, and the pace of AI adoptions in our vendor ecosystem has left it behind. The strain has purpose though, we do these to identify and assess the risk(s) the vendor adds to our own organization’s risk posture.

A Process Already Under Strain

Third-party risk management was a bottleneck for sales deals long before the AI era started. 66% of professionals agree their TPRM process is time-consuming and creates procurement bottlenecks. Long questionnaires, manual evidence chasing, and back-and-forth reviews slow deals down, frustrating buyer and seller alike. In all cases, the volume and efficacy of questions posed largely depends on the intentionality put forth by the buyer, and the accuracy of the answers depends on the integrity, credibility, and accuracy of the vendor. Many exchanges now include and rely on point-in-time third party attestations that provide reasonable assurance of design and operating effectiveness of controls for a time period and scope before AI was introduced into their platforms.

Now add AI to both sides of that exchange. Vendors ship AI capabilities faster than a questionnaire can ask about them, so a process that was merely slow now can't keep up at all. The backlog grows faster than we can work it, and every vendor becomes a moving target. 

Interestingly, many of the AI-related questions that are being asked between companies aren't answered by the traditional respondents on our security, GRC, or sales engineer teams. While our security, GRC, and sales engineering team members may house these answers for customers, the true source of the actual answers usually comes from our AI engineering team members, making them a critical stage gate in the process of responding back to customer questions. Many of these newly added team members aren’t used to the timeliness pressure our sales and CS organizations demand from them to ultimately service our external customers, but that’s here to stay.

Deploying AI to Fix Vendor AI

Our report doesn’t hedge on the source of the fix. 87% of professionals say they will have to rely more on AI-driven capabilities to vet third parties, and 82% believe agentic AI will improve the speed and reliability of that vetting. When a manual process can't scale to the problem, teams reach for an automated tool that can.

The logic mirrors the shift happening across GRC. A purpose-build AI agent built to vet a vendor owns that outcome end-to-end. When trained and instructed in a reliable way, these agents review the criteria, collect the documents, assess the vendor against expectations, summarize assessment results for our security and GRC team members, and produce a record of these actions. As a result, we can measure and build trust in the actions of these agents, which is exactly what a general-purpose assistant bolted onto a procurement workflow struggles to offer with the same level of reliability. The demand is hardening into the new baseline we expect for what AI capabilities our vendors offer us.

Trust Centers Change the Exchange

Automating our side of the review solves half the problem. The other half is how vendors share their posture, and the market is converging on trust centers to fix it. Trust centers give us a living, verifiable way to demonstrate our security posture continuously.

Adoption is already broad. 99% of organizations are familiar with the concept, 78% have implemented a trust center or are actively building one, and 92% report that a vendor or partner has shared one with them. The payoff shows up in the parts of the process that hurt most:

  • Greater transparency into vendor security: 47%
  • Faster vendor reviews: 44%
  • More consistent vendor information: 42%
  • Increased trust in vendors: 42%

Combine automated vetting and trust centers together and the exchange changes shape. Instead of two teams reconstructing trust from scratch for every review, both sides work from continuously maintained, verifiable posture to actively build and maintain trust between organizations.

From Point-in-Time to Continuous

We’re also seeing a deeper shift from vetting as a snapshot to vetting as a continuous state. A lot can change between the times we vet our vendors, especially as vendors ship AI features on a rolling basis. Point-in-time assessment was already a weak proxy for real vendor risk identification and assessment, and AI has widened that gap between the last time we vetted the vendor and what the vendor is actually doing now.

In practice, the vendor we approved in January may have a completely different risk profile due to AI capabilities, making it not the same vendor risk assessment we vet in June of the same year. I've watched a tool we'd already cleared quietly ship an AI feature that changed the risk profile where the original review didn’t have these newly added capabilities available.

Continuous assessment closes that gap. It means monitoring vendor posture on an ongoing basis, backing assessments with real evidence rather than attestation, and treating a material change in a vendor's AI footprint as a trigger for review rather than waiting for the calendar. With purpose-built AI agents to aid us in these on-going third party risk assessments, we’re now armed with the ability to achieve that continuous trust that's visible by default or have frequent enough point-in-time checks to rebuild trust on demand.

Automate Third-Party Risk Management With Drata

Drata unifies Trust Center and Third-Party Risk Management, replacing the questionnaire grind with continuous, evidence-backed vendor assessment. Your own trust center shares your posture the moment a partner asks. Vetting keeps pace with the AI your vendors keep shipping, and reviews that used to take weeks compress into a process that runs on its own. See how to automate third-party risk management: schedule your demo today.

That closes out the series! Across five posts we've traced the same AI gap from the inside out—from the AI you can't see, to who answers when it doesn’t do what we expect, to tools that don’t survive our stringent audits, to the risks from AI adoption without governance leaves behind and, finally, to the vendors extending that risk beyond your walls.

Missed the previous posts? Catch up to get the full picture.

Chart Your Course

Navigate to new worlds of trust with Drata.