Third-party risk used to be something you managed at onboarding. You sent a questionnaire, collected a SOC 2 report if the vendor cooperated, filed it somewhere, and moved on. For a while, that was enough.
It is not enough anymore. Third-party-sourced breaches doubled from 15% to 30% of confirmed incidents between 2023 and 2024, according to Drata's State of GRC in the Age of AI report. Regulators across the EU and US have responded accordingly—DORA entered application for EU financial entities on January 17, 2025, NIS2 extends supply chain risk requirements across critical sectors, and HIPAA has long required evidence-backed business associate oversight. The message is consistent: showing that you have a vendor management policy is no longer sufficient. You need to prove it is actually working.
Most programs cannot prove that. A 2026 KPMG survey found only 15% of organizations have high confidence in the quality of their third-party risk data. That figure is not surprising when you consider how most vendor assessments are run—manually chasing documents, reviewing self-reported questionnaire answers, and completing thorough assessments for perhaps the top 10-20% of the vendor portfolio while the rest go largely unchecked.
The Real Problem: Coverage, Not Just Throughput
The instinct in most GRC programs is to treat vendor risk as a throughput problem. If the team could just move faster, they would get through more vendors. But faster movement through a broken process does not close the gap—it just produces more incomplete records more quickly.
The actual problem is coverage. A two- or three-person GRC team managing a portfolio of hundreds of vendors cannot conduct meaningful assessments across all of them with the time available. So they triage. Critical vendors get real scrutiny. Everyone else gets a completed checkbox and a risk that goes unmeasured.
This is the gap that regulators are pointing at when they ask for continuous vendor oversight. A point-in-time assessment of 30 vendors is not a third-party risk program. It is a selection of the vendors you had time to look at.
Explore the Future of AI Agent Governance with Drata
Get hands-on with our limited availability platform, in development with select enterprises.

Why Existing Approaches Fall Short
Questionnaire-based tools accelerated one part of the process—getting vendors to fill out forms—without solving the underlying evaluation problem. A completed questionnaire tells you what a vendor says about itself. It does not tell you whether those claims hold up against their actual documentation, whether the SOC 2 report they referenced has an unqualified opinion, or whether the observation period is still current.
Evidence collection has a similar gap. Security teams report spending days manually sourcing, downloading, and re-uploading vendor documentation before they can even begin evaluating it. The evaluation itself—mapping evidence against specific security criteria and reaching a defensible conclusion—takes additional time that most teams do not have to spare. When an auditor asks why a particular vendor was approved, "we reviewed their questionnaire" is not an answer that holds.
75% of GRC leaders say AI adoption is outpacing their ability to properly vet third parties, according to Drata's 2026 State of GRC research. That pressure will increase, not decrease. Every AI tool your vendors embed in their products introduces a new subprocessor, a new data handling question, and a new risk that most standard questionnaires were not designed to catch.
43%
Less than half — 43% — of TPRM programs are adequately staffed to handle current vendor volumes.
RiskRecon, State of TPRM 2024What Defensible Vendor Due Diligence Requires
Vendor due diligence is a lifecycle practice, not a one-time review. It begins at intake—before a vendor processes any of your data—and continues through every reassessment cycle, contract renewal, and material change in the relationship.
A defensible program has a few essential characteristics. It starts with vendor tiering based on actual risk factors: data sensitivity, system access, operational dependency, and regulatory classification. A payroll processor and a swag vendor do not warrant the same depth of assessment, and treating them identically burns team capacity without improving risk coverage.
Evidence collection needs to go beyond questionnaire answers. Current SOC 2 Type 2 reports, penetration test results with remediation documentation, executed data processing agreements, and subprocessor lists are the artifacts that demonstrate a vendor's security posture—not their self-reported answers to a standardized form. Collecting those documents, verifying that observation periods are current, and reviewing auditor opinions rather than just filing the reports is what separates a real assessment from a completed checkbox.
Every approval decision needs a traceable record. The vendor, the criteria evaluated, the evidence reviewed, and the conclusion reached should all link back to a specific record—one an auditor can examine, not a verbal conversation or a line item in a spreadsheet. When that record does not exist, organizations often discover the gap at the worst possible moment.
Ongoing monitoring closes the loop. Most third-party incidents involve long-standing vendor relationships where controls drifted after the initial assessment. Annual reassessments for critical and high-tier vendors are the minimum standard under DORA and most enterprise security programs; HIPAA requires risk-based business associate oversight but does not specify an annual reassessment cadence. Security news monitoring, breach disclosure tracking, and SOC 2 renewal calendars all feed a continuous picture of vendor posture between formal review cycles.
How Drata Approaches This Problem
Drata built Agentic TPRM Assessment, part of the Drata Agentic Trust Management Platform, to close the coverage gap at scale. Instead of walking a reviewer through a rigid, multi-step workflow, Drata's agent drives the full assessment—from vendor ingestion (including from procurement tools) through evidence collection and per-criterion evaluation—autonomously, surfacing to a human only at the decisions that require human judgment.
The distinction that matters most is how Drata evaluates vendors. Rather than scoring a vendor's self-reported answers, Drata assesses the vendor's actual documentation against your criteria. Every finding cites the exact passage—the specific line in the SOC 2 report, the relevant section of the DPA—that satisfies or fails to satisfy each requirement. That is what an auditable record looks like, and it is what regulators are asking for.
For security teams that previously completed perhaps 30 thorough vendor reviews per year, this changes the math. Reviews that took days now complete in under an hour. Coverage expands from a carefully selected subset to the full portfolio.
This post opens a series covering every phase of vendor due diligence: intake and tiering, evidence collection, contractual requirements, ongoing monitoring, and the documentation that supports regulatory and enterprise audits. Each piece is designed to give GRC and security teams what they need to build—or rebuild—a program that actually works.
Frequently Asked Questions
What is vendor due diligence, and who needs to do it?
Vendor due diligence is the structured process of evaluating a third-party vendor's security controls, compliance posture, financial stability, and operational practices before onboarding and throughout the relationship. Any organization that relies on vendors to process data, deliver products, or support critical operations needs a formal program—especially those operating under regulatory scrutiny from DORA, NIS2, HIPAA, or GDPR.
How is vendor due diligence different from vendor risk management?
Vendor risk management (VRM) is the broader ongoing program. Vendor due diligence is the assessment activity within that program—the structured evaluation conducted at intake and repeated at defined intervals. Due diligence produces the documentation and evidence record; the risk management program governs the full lifecycle.
How often should vendor assessments be repeated?
At minimum, annually for critical and high-tier vendors. Most enterprise security programs, and explicit regulatory requirements under DORA and HIPAA, treat annual reassessment as a floor, with additional triggered reviews after vendor security incidents, significant scope changes, or financial distress signals.