Getting Started

Why Third-Party Risk Is Now a Board-Level Problem

Third-party risk is the exposure an organization takes on through its vendors, suppliers, and service providers. As companies rely on more external tools and services, that exposure compounds quietly—until a breach, audit finding, or regulatory deadline makes it impossible to ignore.

Security teams have always known vendor risk is real. What’s changed is the scale. The average mid-market company now manages hundreds of vendor relationships, and every integration, subprocessor, or cloud dependency extends the organization’s attack surface beyond its direct control.

Most programs weren’t built for that reality. They were built for a world where a two-person GRC team could work through a stack of questionnaires and feel reasonably confident about the vendors they’d reviewed. That world is gone. According to Drata’s State of GRC in the Age of AI (2026), 75% of IT and security professionals say the speed of AI adoption is outpacing their ability to properly vet third parties. At the same time, the 2026 KPMG Global Third-Party Risk Management (TPRM) survey found that only 15% of organizations have high confidence in the quality of their TPRM data.

The result is a coverage gap. Security teams can typically conduct thorough reviews on just 10–20% of their vendor portfolio annually. The rest get a shallow assessment, an outdated questionnaire, or nothing at all. Boards and regulators are starting to ask questions that most programs can’t answer.

What Is Third-Party Risk, and Why Does It Keep Growing?

Third-party risk is the potential for harm arising from an organization’s relationships with external vendors, suppliers, alliances, and service providers. That harm can take several forms: a data breach through a vendor’s compromised system, a regulatory violation caused by a subprocessor’s inadequate data handling, or reputational damage when a partner’s security failure reflects on your organization.

The exposure compounds because third-party risk doesn’t stop at the vendor you contracted with directly. It extends to the vendors your vendors rely on—fourth-party and nth-party risk—and to the concentration risk that accumulates when too many critical processes depend on a single provider.

Companies scale their vendor portfolios much faster than their security team headcount. A new SaaS integration, an AI tool embedded in a business workflow, a payment processor added during a product expansion—each one adds a relationship that carries risk. Managing that risk at scale without automation isn’t a headcount problem. It’s a structural one.

Explore the Future of AI Agent Governance with Drata

Get hands-on with our limited availability platform, in development with select enterprises.

AI Agent Governance


What Regulations Now Require From Third-Party Risk Programs

Regulatory expectations have shifted considerably. TPRM is either explicitly required or strongly implied by a growing number of frameworks:

The Digital Operational Resilience Act (DORA) entered full application for European Union (EU) financial entities in January 2025. It requires a comprehensive register of contractual arrangements with information and communications technology (ICT) third-party providers, risk-based classification, contractual provisions such as audit and termination rights, exit planning, and management of ICT concentration risk.

HIPAA requires covered entities to execute Business Associate Agreements (BAAs) with vendors that handle protected health information (PHI). Covered entities should also apply risk-based due diligence when selecting and overseeing those vendors.

SOC 2’s Common Criteria (CC9.2) address vendor and business-partner risk management; auditors typically look for evidence of due diligence, contractual requirements, and ongoing monitoring.

ISO/IEC 27001:2022 includes five dedicated Annex A controls on supplier relationships (A.5.19–A.5.23), covering supplier agreements, information and communications technology (ICT) supply chain security, monitoring and review of supplier services, and the use of cloud services.

NIST Cybersecurity Framework 2.0 added Govern as a new, sixth function and elevated cybersecurity supply chain risk management to its own category (GV.SC) within it—a clear signal that vendor risk oversight is a governance responsibility, not an operational afterthought.

For organizations running multiple frameworks, those requirements overlap significantly. The underlying program needed to satisfy them is the same one; the documentation requirements simply vary by framework. That’s where a unified approach to TPRM pays off.

Why Point-in-Time Reviews Are No Longer Sufficient

Annual questionnaires were never a strong signal of vendor security. A vendor that checks “yes” to encryption questions while running unpatched infrastructure isn’t rare. What has changed is that regulators and enterprise customers increasingly know this—and they’re asking for evidence that goes deeper.

The more fundamental problem with annual reviews is the gap between them. A vendor that passed your assessment in January can experience a material breach, financial deterioration, or a significant operational change by March. DORA requires EU financial entities to maintain ongoing oversight and review of ICT third-party risk, particularly for critical providers. NIS2 imposes supply chain security obligations that assume ongoing oversight, not point-in-time snapshots.

Even outside regulated industries, the expectation is shifting. Continuous monitoring—watching for newly disclosed vulnerabilities, vendor security incidents, or material changes in ownership—is becoming a baseline rather than an advanced capability.

4%

Only 4% of organizations have high confidence that their third-party questionnaires accurately reflect actual vendor risk posture.

RiskRecon, State of TPRM 2024

How AI Is Changing the TPRM Problem and the Solution

Two things are happening simultaneously. First, AI adoption inside organizations is creating a new class of third-party risk. Every AI tool integrated into a business workflow is a vendor relationship requiring assessment—including the subprocessors and model training data practices behind that tool. According to Drata’s State of GRC in the Age of AI (2026), 75% of IT and security professionals say AI adoption is outpacing their ability to vet third parties.

Second, AI is also the mechanism that makes comprehensive TPRM coverage achievable. The KPMG 2026 survey found that 50–58% of TPRM programs claim some AI adoption, yet only 22% call it “very effective.” The gap reflects a real distinction between tools that automate the questionnaire request and tools that actually evaluate vendor evidence. Sending a questionnaire faster doesn’t close the coverage gap. Evaluating the vendor’s actual documentation—SOC 2 Type II reports, Data Processing Agreements (DPAs), penetration test results—against your own criteria, at scale, does.

Drata’s Agentic TPRM Assessment, part of the Drata Agentic Trust Management Platform, automatically gathers available vendor security documentation—including from published Trust Centers—and evaluates it against your organization’s own defined criteria, flagging gaps and surfacing follow-up questions. Each finding links to the supporting source documentation behind it. The residual risk rating that results is evidence-backed and defensible to an auditor—not assembled from self-reported questionnaire answers.

UiPath has used Drata’s Agentic TPRM Assessment to meaningfully cut the hands-on time required per vendor review, without sacrificing rigor.

The Coverage Gap Is the Problem Worth Solving

Thoroughness on a small slice of the vendor portfolio while leaving the rest unchecked isn’t a partial solution—it’s a false sense of security with paperwork. The board wants to know the organization’s third-party risk posture. An auditor or regulator following a vendor-related incident will review the full program, not just the top 30 vendors that received careful attention.

The programs that hold up are the ones built around coverage and defensibility at scale: a current vendor inventory, consistent risk tiering, evidence-cited assessments, and monitoring that keeps the risk picture current between formal reviews. Getting there without significant manual overhead is where agentic automation changes the equation.

Request a demo to see how Drata’s Agentic TPRM Assessment closes the coverage gap across your full vendor portfolio.

Frequently Asked Questions About Third-Party Risk Management

Third-party risk management is the process of identifying, assessing, monitoring, and mitigating risks introduced by an organization’s vendors, suppliers, alliances, and service providers. A TPRM program covers the full vendor lifecycle—from initial onboarding through contract termination.

Most security teams can conduct in-depth reviews on only 10–20% of their vendor portfolio annually using manual processes. The remaining vendors are triaged, assessed shallowly, or skipped entirely. The gap is structural: vendor portfolios scale faster than headcount, and manual evidence collection is the bottleneck.

A defensible assessment requires collected documentation—SOC 2 Type II reports, certifications, DPAs, penetration test results—evaluated against defined criteria, with each finding linked to the supporting documentation behind it. Self-reported questionnaire answers without corroborating evidence are not sufficient under regulatory scrutiny.

Inherent risk is the vendor’s risk level before their security controls are evaluated. Residual risk is their risk level after those controls are assessed against your criteria. A vendor with high inherent risk can have low residual risk if their independently verified controls are strong. The distinction matters because it determines what level of ongoing oversight is appropriate.


August 20, 2026
Third-Party Risk Management Collection

Get Started with Third-Party Risk Management

Navigate to new worlds of trust with Drata.