Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu

Rebuild Your Vendor Risk Program From Scratch

Third Party Podcast: When Questionnaires Have Not Worked

YouTube video thumbnail

Stop Perfecting the Questionnaire

Most TPRM programs don't have a tooling problem. They have a religion problem. In the latest episode of the Third Party podcast, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik make a case that will annoy anyone who has spent a career perfecting a vendor questionnaire: Stop perfecting it. Retire it.

Humans build mental models, then get quietly married to them. A TPRM program is just a mental model that's been institutionalized. Once a team commits to "assess with a 500-question form," that model calcifies into habit, then into identity, then into the thing nobody in the org is allowed to question. Breaking it isn't a software upgrade. It's a demolition.

There's a useful, decades-old military framework for this: Air Force strategist John Boyd's theory of creation and destruction. The idea is that stale mental models eventually have to be destroyed, not patched, before something better gets built from the pieces worth keeping. TPRM has been overdue for its destruction phase for a while now.

Why Compliance Keeps TPRM Programs Stuck on Questionnaires

Here's an inconvenient truth: most programs are questionnaire-first not because questionnaires work, but because compliance frameworks and regulators reward evidence of effort over evidence of security. A completed 500-question form proves activity. It proves nothing else.

Ask why a team sends a questionnaire and the honest answer is usually "to collect information about controls." That's the tell. The controls are the point. The questionnaire is just the least imaginative way to get there, kept alive by an entire industry of certifications, associations, and consultants built to defend it.

Deloitte's Global TPRM Survey found that as programs mature, they shift from administering questionnaires toward genuinely collaborative vendor conversations. That's directionally right, but don't get comfortable. Highly regulated industries like banking are moving the opposite way, piling on more questions rather than fewer, and AI has already added another fifty questions to everyone's existing three hundred.

What Replaces the Vendor Questionnaire in a Modern TPRM Program

If a questionnaire's whole job is collecting evidence about controls, the fix isn't a shorter questionnaire. It's skipping the form and going straight to the evidence. Security policies, patch cadence, DNS configuration, and independently verified control data already exist somewhere. None of it requires asking a vendor to self-report and hoping they're not grading their own homework.

The same logic applies to the AI wave currently flooding every vendor review with new questions. Instead of sending 250 AI-specific questions to a vendor, ask for the AI model card, the document a properly governed AI vendor should already maintain. Black Kite AI is built around that same premise: pull the signal directly instead of trusting a vendor's paperwork about the signal.

The catch is that reading a model card takes real expertise, while assigning a percentage score off a checklist does not. That trade-off, actual interpretation instead of comfortable theater, is exactly why so many teams still default to the form.

Can You Outsource Third-Party Risk Management?

Can you outsource the whole mess? Sort of, but be honest about what you're outsourcing. Questionnaire management, sure, hand it off. Third-party cyber risk management itself is a different animal: strategic and deeply relationship-intensive. Handing a vendor relationship to a script-reading intermediary doesn't produce the same outcome as calling your account rep directly.

That's part of why The Bridge™ exists as a vendor engagement layer rather than a vendor-management proxy: the goal is closer contact with vendors, not more distance. And the accountability problem never disappears. If an outsourced provider drops the ball, firing them doesn't retroactively fix the decision that got made on their watch.

Smaller and midsize programs will lean harder into outsourcing pieces of this work as agentic tools mature. Large enterprises will keep more in-house, because the bigger the spend, the more leverage a direct relationship buys with a vendor who might otherwise ignore your fifth follow-up email.

Monitor Every Vendor, Assess Only the Ones That Matter

Here's the reframe that should end the assess-everyone habit for good: one GRC team was running full assessments on every one of the roughly 100 vendors it onboarded monthly. Once it applied real data instead of a blanket process, only three to five of those vendors actually carried meaningful risk. Everyone else was getting the same expensive scrutiny for no reason.

Flip the model. Monitor the entire ecosystem continuously, then reserve deep assessment for the vendors the data flags, not the vendors whose turn it happens to be in the rotation. That includes looking past direct vendors into the fourth- and fifth-party dependencies most programs never map, an area Nth-party visibility exists specifically to cover. A standards-based, quantified approach to risk makes that prioritization defensible instead of just vibes-based.

The payoff isn't subtle. Faster onboarding, tighter alignment with actual business risk, lower cost, and a team that finally spends most of its time on the handful of vendors that could really hurt it instead of spreading itself across a hundred that can't.

Don't Miss an Episode!

Subscribe to Third Party on YouTube, the podcast for people who don't need to ask ChatGPT what TPCRM means. New episodes every other week.

Next time on Third Party:

Next time we get into cascading and concentrated risk. The vendors you depend on, the vendors they depend on — and what happens when the same provider goes down across half your ecosystem at once.

Subscribe below.

Real Talk on Third-Party Risk.

Check out our new podcast, Third Party, where we unpack what actually works (and what doesn't) in TPRM.

Apple Podcasts
Follow Third Party on Apple Podcasts
Follow
Spotify
Follow Third Party on Spotify
Follow

Ready to get started?

Integrate risk intelligence into every part of your workflow so you can make more informed decisions with confidence.