Third-Party Risk Is Moving Too Fast for Humans to Go It Alone
Sponsored by Riskonnect
Quin Rodriguez explores why third-party risk management can’t rely on manual processes anymore, and where AI delivers the highest returns in TPRM programs.
Third-party risk management still runs on manual labor. Risk teams spend hours parsing vendor questionnaires, chasing follow-ups, and updating spreadsheets. The same vendors are then rescored on an annual cycle that reveals little about what they are doing right now. Meanwhile, the vendor ecosystem – and the risks – keeps growing.
Verizon's 2025 Data Breach Investigations Report found that third-party involvement in breaches jumped to nearly 30%, double the rate from the prior year. Whistic's 2025 TPRM Impact Report puts the average vendor count at 286 per organization, up 21% from the year before. More vendors, more complexity, more exposure – and most risk teams are still using the same manual processes as they did a decade ago.
Something has to give. And that’s where AI comes in.
A Cautionary Tale About a Single Point of Failure
The Change Healthcare breach remains the clearest case study for why third-party risk management needs to evolve. Change Healthcare is the subsidiary of UnitedHealth Group that processes claims and manages pharmacy benefits across the U.S. healthcare system. When its systems went down in 2024, pharmacies couldn't fill prescriptions, hospitals couldn't process claims, and medical practices scrambled to keep their doors open with no money flowing in.
UnitedHealth ultimately confirmed that close to 190 million Americans had personal and healthcare data exposed, making it the largest healthcare data breach in U.S. history. The financial toll was also severe. UnitedHealth's direct costs for responding to the breach topped $3 billion. That’s on top of the disruption costs that rippled through the broader healthcare industry.
The failure wasn't just technical. It was a failure of risk visibility. This is what happens when organizations depend on a single vendor and have little real-time insight into that vendor's security posture. Annual questionnaires and point-in-time assessments couldn’t catch what continuous monitoring would have flagged.
Where AI Delivers the Highest Returns
Many organizations chase AI as a headline rather than a tool. They ask broad, theoretical questions like how AI should be used AI in the security program. The more useful question narrows that to asking where, specifically, AI removes manual work and creates measurable value in the TPRM program.
Look at where analyst time actually goes, and the answer becomes clear. Much of a typical TPRM analyst's week isn't spent assessing risk. It's spent finding the information needed to assess it: pulling vendor documentation from trust centers and public filings, reading through SOC 2 reports and security questionnaires, and manually transferring details into an internal system.
AI can do all that in a flash. High-volume, rules-based work (rather than judgment-heavy analysis) is where AI delivers the clearest return.
Here are other places where AI-powered third-party risk management creates measurable value:
Vendor data collection and questionnaire processing. AI can read, extract, and normalize vendor responses at scale. It can flag patterns that point to risks that used to stay buried in unread PDFs. With the help of AI, Risk teams can stop copying data and start interpreting what it means.
Continuous monitoring. A static, point-in-time questionnaire can't tell you what's happening with a vendor today. AI-driven monitoring can scan financial news, security disclosures, regulatory filings, and public sentiment across an entire vendor portfolio all at once. It will immediately flag emerging issues so you can act before they escalate.
Risk-based prioritization. Not every vendor deserves equal attention. AI scoring models help teams direct limited time toward the vendors whose failure would hurt the business the most.
AI Is Not the Decision-Maker
One guardrail matters most: AI should not make the final call. A model can accelerate the work to flag a vendor's deteriorating financial health or an unpatched vulnerability, but deciding whether that risk is acceptable, what compensating controls to require, or whether to end a relationship still belongs to a human who understands the business context.
Done well, this trade-off is straightforward. Analysts spend less time on data entry and more time on judgment calls that require their expertise. Meantime, the organization keeps a clear record of who made which decision and why.
The Regulatory Pressure Is Already Here
The regulatory backdrop adds urgency. AI oversight must be consistent across the extended enterprise. TPRM frameworks increasingly need to look beyond the organization’s own internal AI use to account for AI risk introduced by vendors and partners. In the EU, DORA has raised resilience requirements for the financial services industry, and NIS2 has made supply-chain security a core part of cybersecurity practice.
Boards and regulators are no longer simply asking whether you assessed a vendor. They want to know whether you understood the magnitude of the dependency and prepared for its failure.
Getting Started
Most TPRM teams don't need a full overhaul to get started. They just need to map out a clear sequence of priorities.
Begin with the analyst work that delivers the fastest return: data collection, questionnaire review, and initial risk scoring. Once that's automated, layer in continuous monitoring. Keep the human decisions where they belong, with governance, escalation, and accountability.
Your vendors are an extension of your business. Using yesterday's tools to manage them is a huge risk in and of itself.
See how Riskonnect's Third-Party Risk Management software helps identify vendor threats and immediately let every dependent function know about it. Please visit the Riskonnect Resource Library for guides, research, and tools to strengthen your TPRM program.
Featured in: Third Party Management