Why traditional third-party risk management requires reform
In our recent survey of 500 cyber security and third-party risk management (TPRM) professionals across the UK, we found that 82% of organisations experienced at least one supply chain incident over the past 12 months…
In our recent survey of 500 cyber security and third-party risk management (TPRM) professionals across the UK, we found that 82% of organisations experienced at least one supply chain incident over the past 12 months, with 47% experiencing two or more. It is therefore no surprise that 86% of the respondents placed such incidents among their top three areas of concern for 2026.
The threat environment is further complicated by a volatile geopolitical situation, the rapid evolution and adoption of AI across global supply chains, and growing regulatory scrutiny. In this fast-changing context, the traditional approach to managing risks in organisations’ supply chains, TPRM, has reached its structural limits. A recent study from EY agrees, describing current TPRM as “fundamentally misaligned with this new risk environment.” Our survey supports this view, with only 28% of the respondents still considering TPRM highly effective at significantly reducing supply chain risks.
According to EY, TPRM “relies on slow and intermittent processes. In a world of interconnected risks, it is siloed and uncoordinated.”
Far too often, security, procurement, and operational resilience teams continue to operate in isolation. Cross-functional coordination is inconsistent, and meaningful information-sharing with external partners remains limited. Many organisations also rely on legacy tools that provide little real-time insight beyond their immediate suppliers. As a result, TPRM is anchored in static, compliance-led frameworks built to check boxes rather than surface emerging risks.
This fragmentation creates blind spots. Without coordinated teams, scalable platforms and continuous monitoring, risks arising from fourth parties and shared suppliers remain undetected. Effective TPRM therefore needs to become a more collaborative and intelligence-led capability. That means bringing people, processes and technology together to provide a more complete view of the supply chain and shifting TPRM from a largely reactive compliance exercise towards an active approach to supply chain cyber security.
Why people still matter in TPRM
Technology alone cannot solve the problems that TPRM is facing. Despite significant investment in tools and systems, many TPRM programmes do not adequately address the fundamental human dynamics at play. Historically, poor coordination between security, procurement, and operational resilience teams have resulted in delayed supplier onboarding, inconsistent due diligence and, ultimately, a heightened risk exposure. Relevant information may be held across these different teams, with no single team being able to see the complete picture. This internal disconnect leads to missed signals and allows vendors with inadequate controls to slip through.
The challenge also extends beyond the organisation. Limited collaboration with suppliers creates a reactive risk posture. Without access to the suppliers’ security teams and clear communication protocols, organisations struggle to obtain reliable information or coordinate an effective response when an incident occurs.
However, perhaps the greatest missed opportunity lies at the industry level. Organisations, especially within the same industry, often depend on the same suppliers, yet assess these relationships independently. While the relationship between a client and supplier can be unique, organisations can still adopt a collaborative approach to assessing suppliers to identify potential systemic risks across a sector.
To move forward, we must reframe how we think about risk, not just as a technology issue, but as a human challenge. The future of TPRM depends on giving security, procurement, and operational resilience teams shared visibility into supplier risk, rather than each holding a partial picture.
Building resilience in a real-time risk landscape
Many organisations still rely on spreadsheets or basic platforms that serve primarily as digital versions of static questionnaires. While these can help teams stay compliant, they offer little actionable intelligence and rarely enable information sharing between organisations.
One of the most significant limitations is the reliance on point-in-time assessments. An organisation’s supply chain is dynamic with new supplier relationships being created or eliminated as organisations go about business as usual. In addition, a supplier’s security posture can change after an assessment due to technology changes, acquisitions, or security incidents. In a rapidly evolving threat environment, this leaves organisations exposed to emerging risks that remain undetected.
Current tools also struggle to scale. Many platforms lack the flexibility and automation to cope with an increasingly complex and interconnected supply chain ecosystem. As suppliers and dependencies grow, so does the volume of work which results in time spent manually keeping up with changes, rather than identifying and reducing risk. A significant blind spot lies in the inability to map fourth parties and identify hidden concentration risks where multiple suppliers rely on the same underlying fourth-party provider. These dependencies can create systemic risks that could disrupt entire supply chains.
Keeping pace with an evolving threat landscape
Third-party risk management cannot continue to be a governance exercise designed merely to satisfy auditors and regulators. TPRM is a frontline security function and needs to operate at the same speed as the threats it is meant to defend against.
Organisations that rely on siloed teams, static assessments and limited visibility continue to face avoidable exposure. This is not because they lack tools; instead, it often comes down to a lack of coordination, context, and shared intelligence. Keeping pace with this environment requires a shift from reactive, compliance-led programmes towards continuous monitoring and shared intelligence across suppliers and industry peers. Assessments should provide a foundation — not the endpoint — of third-party risk management.
TPRM programmes that make this shift will be better equipped not only to meet regulatory expectations, but to understand their dependencies, respond more effectively to incidents and build operational resilience across their supply chains.