SEPTEMBER 22, 2026 • 6 MIN READ

The State of Third-Party Risk Management: Why Teams Aren't Closing the Gap

State of TPRM Report

New Drata research: 309 security leaders on why bigger TPRM teams still can't close the third-party risk gap.


Security teams do what the moment asked of them. In recent years, they increased headcount, bought new tools, and automated more of the work. Our new report on the State of TPRM in 2026 shows that 69% of organizations grew their third-party risk management (TPRM) teams, and 75% increased automation across their programs.

The gap stayed open anyway.

In a new survey of 309 IT and security leaders and practitioners across the U.S., U.K., and Canada, 78% told us that insufficient people or tool capabilities still limit how many third parties they can assess and how thoroughly they can assess them. The most-cited obstacle is staffing. The plan almost nobody is choosing is hiring. Only 11% list adding headcount as a top priority for the year ahead.

That is the story of TPRM right now. Teams have concluded that more of the same will not move the needle, and they are looking for a different model.

Teams Grew, Workloads Grew Faster

The last 24 months pushed nearly every input in the same direction. Organizations reported working with more third parties (71% saw an increase), assessing more of them (74%), and worrying more about the risk they carry (75%). Team size rose too, for 69% of respondents.

The trouble is proportion. Only 10% reported a significant increase in team size, while roughly three times as many saw significant jumps in concern and in the number of vendors they assess. Capacity crept up. Demand sprinted.


So the resourcing question keeps resurfacing as the top obstacle. Insufficient staffing led the list at 59%, followed by the limited capabilities of current tools at 54%, and budget at 48%. These are all constraints on the same thing: how much assessment work a program can actually get done.

Coverage Is Wide, Depth Is Thin, Data Is Stale

Three gaps show up clearly in the data, and they compound one another.


The first is coverage. Only 13% of organizations assess all their third parties. Every vendor that goes unassessed can still introduce operational risk into the environment, so the 87% who cover less than everything are carrying unmeasured exposure by default.

The second is depth. Among the vendors that do get assessed, 93% receive a less-than-thorough review. For most programs, that means little more than confirming a partner holds a SOC 2 report, rather than evaluating the vendor against defined risk criteria.

The third is freshness. Most programs reassess critical vendors once a year at most, which describes 76% of respondents. A lot changes in twelve months. A single vendor turning on an agentic workflow can shift its security posture in an afternoon, long before the next annual review comes due.

Underneath all three sits a math problem. A full assessment of a critical vendor typically takes three to four weeks, and Drata's own data puts each one at roughly 16 hours of an analyst's hands-on labor. At that rate, one analyst can complete fewer than 100 thorough assessments a year. An enterprise with a few hundred critical vendors needs several full-time analysts just to keep pace, and most enterprises work with thousands of vendors. The arithmetic explains why coverage, depth, and cadence all give way at once.

Incidents Are Routine Now

This capacity gap is not academic. In the past 12 months, 85% of organizations reported at least one third-party-related security incident, and roughly two-thirds reported two or more.

The organizations getting hit hardest are the ones most likely to name capacity as the problem. Among those that experienced six or more incidents, 90% agreed that people or tool limits are constraining their assessments, compared with 60% of those that had no incidents at all. The more real-world risk a program faces, the less its current approach can keep up.

AI Is the New Blind Spot

Then there is the risk category that barely existed a few years ago. AI is now embedded in the products and services vendors sell, and most programs have no consistent way to evaluate it.

A majority of respondents, 58%, have no standardized process for assessing third-party AI risk. Only 37% are highly confident they can even identify where AI is being used inside a vendor's products and services. AI-specific governance ranks among the weakest capabilities teams rate in themselves.

Teams know it. Increasing their ability to assess AI governance ranked as the second-highest improvement priority for the year, nearly tied with automating data collection. The demand signal is loud. The tooling has not caught up.

What Teams Are Actually Buying

Look at where programs plan to invest and a clear pattern emerges. The top priorities are automating data collection (48%), assessing AI governance (47%), automating data analysis (44%), and continuous monitoring (42%). Every one of these is a technology investment. Adding staff sits at the bottom of the list.

The drivers behind these plans are operational resilience (69%) and regulatory requirements (53%), with regimes like DORA, NIS2, and the SEC cyber-disclosure rule raising the bar on third-party oversight. Board pressure barely registers at 6%. This is a practitioner mandate, driven by the people who own the work and answer to the regulations.

Achieving Depth at Scale

The counterintuitive finding at the heart of this research is that adding people to a manual process did not make it more effective. As long as each critical assessment consumes a fixed number of analyst hours, the number of vendors a team can cover will always be capped by its size, and vendor portfolios grow faster than any team can hire.

Closing the gap takes a different model, one where capacity scales with the portfolio instead of the headcount. That means covering every vendor rather than a critical few, keeping evidence current instead of letting it age, seeing where AI lives inside third-party products, and analyzing risk data without waiting on manual input.

This is why we built Drata's approach to third-party risk around criteria-based agentic assessment. Drata evaluates each vendor against defined risk criteria, gathers evidence that is traceable and consistently collected, and produces results that are defensible by design. Depth and breadth stop competing for the same scarce analyst hours, so programs can assess more vendors, more thoroughly, more often.

The organizations that keep pace with third-party risk will not be the ones that hired the most people. They will be the ones that changed the model.

Ready to close the gap? See how Drata's Third-Party Risk Management approach helps you achieve depth at scale with Drata. Book your demo now.


Chart Your Course

Navigate to new worlds of trust with Drata.