IT Brief India - Technology news for CIOs & IT decision-makers
India
Most firms still cannot keep up with third-party risk

Most firms still cannot keep up with third-party risk

Wed, 7th Oct 2026 (Today)
Raphael Veloso
RAPHAEL VELOSO News Editor

Drata has released a report on third-party risk management based on a survey of 309 security and risk leaders and practitioners. It found that 78% still cannot carry out as many third-party assessments as they want or at the level of detail they need.

The findings point to a persistent gap between growing third-party risk management workloads and the resources available to handle them. While 69% of respondents said their teams had grown and 75% reported more automation in their programmes, many still lacked the people or tools to keep up.

Across the US, UK and Canada, 71% of organisations said the number of third parties they work with had increased over the past two years. Over the same period, 74% said they were assessing more vendors and 75% reported greater concern about the risks those vendors carry.

The report suggests team growth has not kept pace. Only 10% of respondents reported a significant increase in team size, compared with much larger rises in concern levels and the number of vendors under assessment.

Staffing was the most commonly cited constraint, named by 59% of respondents. Limited tool effectiveness followed at 54%, while 48% pointed to budget pressures.

Three gaps

The survey identified three main weaknesses in current third-party risk management programmes: coverage, depth and freshness.

On coverage, only 13% of organisations said they assess all their third parties. That means most review only part of their external supplier base, even though unassessed suppliers can still create operational and security risks.

Depth was another issue. Among vendors that do undergo assessment, 93% receive what the report described as a less-than-thorough review. In many cases, that means checking whether a supplier has a SOC 2 report rather than measuring it against defined risk criteria.

The third gap was the age of assessment data. Some 76% of respondents said they reassess critical vendors no more than once a year, despite the speed at which a supplier's security posture can change.

The report linked those gaps to the analyst time required for a full assessment. A thorough review of a critical vendor typically takes three to four weeks and involves about 16 hours of hands-on analyst work. On that basis, one analyst would complete fewer than 100 thorough assessments in a year.

That creates a capacity problem for larger businesses with hundreds or thousands of suppliers. As vendor numbers rise, teams face pressure to compromise on the number of assessments they perform, the depth of each review, or the frequency of reassessment.

Incident rates

The survey also found that third-party-related security incidents are common. In the past 12 months, 85% of organisations reported at least one such incident, while about two-thirds said they had experienced two or more.

Respondents reporting the highest number of incidents were also more likely to say their teams were constrained by staff or tool limits. Among those with six or more incidents, 90% agreed that people or tool limitations were restricting their assessment work, compared with 60% of respondents reporting no incidents.

The findings suggest that organisations under the greatest strain are often those least able to expand the scope or detail of their third-party reviews.

AI risk

The report highlighted artificial intelligence as an emerging blind spot. It found that 58% of respondents do not have a standardised process for assessing AI-related risk in third-party products and services.

Only 37% said they were highly confident they could identify where AI is used within a vendor's products and services. At the same time, improving the ability to assess AI governance ranked as the second-highest priority for the year ahead, narrowly behind automating data collection.

Planned investment priorities were dominated by technology. Some 48% of respondents cited automating data collection, 47% named assessing AI governance, 44% pointed to automating data analysis and 42% selected continuous monitoring. Just 11% listed adding headcount as a leading priority.

Operational resilience was the main driver behind those plans, identified by 69% of respondents. Regulatory requirements came next at 53%, reflecting pressure from rules such as DORA, NIS2 and the US Securities and Exchange Commission's cyber-disclosure requirements. Only 6% cited board pressure.

The report argues that organisations increasingly see manual processes as unable to keep pace with expanding third-party ecosystems. Rather than relying mainly on larger teams, many appear to be looking for tools that can widen supplier coverage, improve review consistency and keep assessment data current.

The study's central finding is that staff growth alone has not resolved the issue for most programmes, even as external dependencies and regulatory demands continue to rise. As a result, many security and risk teams are trying to manage a larger, more complex supplier landscape with methods that still struggle to scale.