Reality, Not Snapshots: Rethinking Third-Party Risk

Reality, Not Snapshots: Rethinking Third-Party Risk

By

Key Takeaways

  • The questions still matter; the self-attested questionnaire is what breaks. Third-party risk programs ask the right security questions. The problem is how they get answered: a vendor fills out a form, and the program takes the claim on faith.

  • Trust is not truth. A questionnaire captures what a vendor says its controls do, not what they actually do. Without evidence behind the answers, there is no way to verify at scale.

  • Point-in-time review can't hold in a real-time world. Annual assessments go blind between cycles while the risk surface keeps expanding, and regulators now expect more than a periodic snapshot.

  • The method has run out of capacity. As vendor portfolios grow into the hundreds and thousands, skilled analysts spend their days chasing responses and reading reports instead of analyzing risk. The backlog only grows.

  • The shift is from periodic review to continuous, evidence-based assessment. Verizon's 2025 DBIR found third-party involvement in breaches doubled to 30 percent. Purpose-built agents that answer security questions from real evidence are what make that shift workable at enterprise scale.

Deep Dive

Every risk discipline carries a habit that outlives its usefulness. In third-party risk management, that habit is the self-attested questionnaire. It is the artifact the whole practice is organized around. A relationship begins, a security questionnaire goes out, the vendor returns a few hundred answers, an analyst reviews them, and the file is closed until next year's cycle. The ritual is so established that it is easy to forget it was built for a smaller, slower, more stable world than the one we operate in now.

It’s important to recognize what has actually failed, because the questions themselves aren’t the problem. The security questions a mature program asks are the right ones. What breaks is the mechanism used to answer them. A questionnaire records what a vendor claims about its controls. But it doesn’t show what those controls actually do. The answers are self-reported and rarely checked against anything, so the exercise ends up measuring trust rather than truth. In an environment where a single vendor compromise can become your incident, taking a supplier's word for it is a strange place to rest a risk decision.

The timing is just as strained as the trust. Risk is continuous; periodic review is not. A vendor's posture on the day of onboarding tells you little about their posture eight months later, after they have migrated infrastructure, changed sub-processors, or silently fallen behind on patching. The document is accurate and stale at the same time because it describes a moment that has already passed. This is where exposure accumulates. Verizon's 2025 Data Breach Investigations Report found that the share of breaches involving a third party doubled to roughly 30 percent. Attackers understood the structural weakness some time ago: the fastest route into a hardened organization often runs through a softer partner.

Then there is the sheer arithmetic. Organizations that once managed dozens of vendor relationships now manage hundreds or thousands, each with its own downstream providers. Reviewing that terrain by hand, through forms, does not scale. Skilled analysts spend their days on data entry, chasing responses for months and reading hundred-page reports, while the backlog grows and the long tail of smaller vendors goes unassessed entirely. It is all manual effort and no capacity, and adding headcount has never closed the gap.

The more useful frame is to separate two ideas the questionnaire quietly conflates. Attestation is a claim: the vendor states that a control exists. Assurance is a demonstration: current evidence shows the control operating as intended. What third-party risk needs is assurance, and the evidence to support it already exists. SOC 2 reports, ISO certificates, trust centers, security and privacy documentation, and DPAs describe what a vendor actually does. The question worth asking about a critical vendor is not whether they claimed to encrypt data at rest last spring, but whether current evidence shows they still do, and whether anyone would know if that changed. Proof, not promises.

Answering that continuously, across hundreds of relationships, has simply been too labor-intensive to attempt by hand. That is what changes when the work moves to dedicated agents. The security questions stay; the manual, self-attested questionnaire as the default way of answering them goes away. Agents answer each question from source evidence, trace every answer back to the document behind it, surface each gap as a finding, and reassess when documents expire or change. The program becomes a living view of vendor risk rather than a stack of completed forms: reality, not snapshots. When the board or a regulator asks about a vendor, the posture you report reflects the current state.

That evidence trail also changes what a risk score is worth. A score generated from a fixed, one-size-fits-all formula is hard to defend when someone asks why a vendor landed where it did. A score built from a specific vendor's evidence and your program's own priorities can carry a written rationale and the full assessment behind it. Every decision becomes explainable to an auditor, to leadership, and to the business, which is exactly the standard rising regulatory scrutiny is starting to demand.

None of this removes people from the loop, and it shouldn’t. It changes where their attention goes. In a questionnaire-driven program, skilled people spend most of their time chasing, formatting, and filing. When agents handle that groundwork, a single queue surfaces only the decisions that genuinely need judgment: tier confirmations, assessment calls, exceptions. Human-in-the-loop becomes a design choice rather than a fallback for when automation falls short. You set the rules; the agents do the work.

None of this means the questionnaire disappears tomorrow. Contracts, regulators, and long-standing process will keep it in circulation for years. But it’s worth recognizing it’s limitations. A form completed once describes a vendor at one instant. True third-party risk lives in the interval between those instants, and closing that interval is the work now in front of the discipline.

What continuous, evidence-based, agent-driven assurance looks like in practice is one of the sessions on the agenda at Anecdotes' GRC Data & AI Summit on August 12, alongside a broader look at how agents are reshaping GRC work. Third-party risk was never really about the questionnaire. It was about knowing, at any given moment, whether the organizations you depend on can be trusted, and having the evidence to prove it.

Oops! Something went wrong
No items found.