Reports

The State of TPRM 2026

For most security teams, third-party risk isn't a checklist you clear once — it's a growing list of vendors, a shrinking amount of time to vet each one, and an incident rate that stays stubbornly high. Assessing every vendor thoroughly has become harder to do with the same headcount.

This report draws on a survey of 309 IT and security leaders and practitioners to show what third-party risk management (TPRM) teams actually do — where coverage falls short, how they're stretched, and where they're placing their bets for the next 12 months.

What’s Inside

  • Where the pressure is coming from. 78% of security teams say insufficient staff or tools are limiting how many third parties they can assess — or how thoroughly. And it isn't theoretical: 85% reported at least one third-party incident in the past year. See what's driving the squeeze and who's feeling it most.

  • How the gaps actually show up. 87% of organizations assess less than 100% of their third parties, and even the vendors they do assess often get a lighter review than they should — 93% fall short of a full assessment. Most full assessments are repeated once a year or less. Learn where coverage breaks down first.

  • Where programs are placing their bets. Staffing is the top obstacle (59%), but only 11% plan to hire — teams are automating instead: 48% are prioritizing automated data collection next year. Meanwhile, only 42% have a standard process for assessing AI risk in their vendors. See where the roadmap is headed, and where it still falls short.


See how your program compares, and where the biggest gaps are.

Programs Under Strain

77% of teams say they don't have enough people or tools to properly assess third parties

85% of organizations reported at least one third-party incident in the past 12 months

Only 42% have a standard process for assessing AI risk in their third-party ecosystem — most handle it case by case

48% are prioritizing more automation of third-party data collection over the next year

Where the Gaps Exist

Insufficient staffing is the #1 obstacle to managing third-party risk, cited by 59% of security leaders — yet only 11% plan to add headcount in the next 12 months. Most are betting on automation instead.

87% of organizations assess less than 100% of their third parties — and even among those they do assess, 93% fall short of a full, in-depth review.

The State of Third-Party Risk Management | Drata