The State of Third-Party Risk Management in the Age of AI
TPRM was built for a slower world. Most programs still rely on fixed review cycles and retrospective compliance evidence.
Meanwhile, vendors ship code weekly, introduce AI capabilities without clear disclosure, and operate within layered dependencies that traditional workflows rarely surface.

Where Third-Party Risk Programs Break Down
Survey data from Fortune 500 security and procurement leaders on what's broken and what comes next.


Everything leaders need to modernize TPRM
Teams are not struggling because they lack diligence. They are struggling because manual evidence collection and calendar-based reassessments cannot scale with modern vendor ecosystems. This report captures what practitioners are seeing, where friction concentrates, and what changes when programs become trigger-based and dependency-aware.
What changed and why the old model is failing
Traditional TPRM assumed vendors were stable. Today, risk shifts when vendors launch new products, add subprocessors, expand data access, change infrastructure, or add AI features. Those changes rarely trigger a reassessment, even when exposure increases.
The data behind the bottlenecks
Survey results show the operational consequences: 96% take more than two weeks to approve a vendor, half cite evidence collection as the primary bottleneck, and only 40% say they learn about vendor incidents before impact. Two-thirds review six or more vendors per month.
The operating model for modern TPRM
High-maturity programs shift from calendar cycles to triggers, from static documents to living evidence, and from isolated vendor reviews to dependency-aware oversight. The report outlines the principles and workflow shifts that reduce admin work while improving risk visibility.


