
At a recent CISO roundtable hosted by Diligent during the Gartner Cybersecurity & Risk Management Summit in June 2026, one comment landed hard with the room:
"For one vendor risk assessment, it's like a 40-hour job."
Nobody pushed back. The conversation that followed made the actual problem clear: security and risk teams aren't short on questionnaires, frameworks or controls. What's overwhelming them is the sheer effort of administering all three.
Reviewing contracts, analysing SOC reports, chasing vendors for evidence, moving information between systems and coordinating stakeholders can eat up hours of work before a single risk decision gets made.
So can AI actually shrink the 40-hour vendor assessment? The honest answer has two parts: one about the paperwork, and one about the risk underneath it.
When people talk about AI in third-party risk management (TPRM), they usually mean automating the questionnaire. That tracks. Teams are dealing with hundreds of questions from customers, regulators and vendors, with some organizations reporting assessments ranging from 25 questions to more than 1,500.
CISOs at the roundtable pointed to several places AI is already earning its keep:
Most CISOs at the roundtable treated this as the easy win, not the finish line. As one security leader described it, teams today are mainly trying to "speed up components of the TPRM process," not replace the process itself.
Everyone at the roundtable accepted that AI can speed up the existing process. It can extract responses from existing evidence, review contracts and assurance documents, identify gaps in vendor answers and pre-populate questionnaires before a person ever opens them.
That's a real reduction in manual burden, but not a complete one. Evidence still needs validating, gaps still need chasing, and someone still has to sign off on the answer.
Several CISOs pushed further, questioning whether the process itself, one built around questionnaires, actually manages risk, or simply gets completed faster. The consensus was that questionnaires satisfy compliance requirements but do little to prevent what happens next.
A vendor can complete an assessment, provide all the right answers, and still suffer a breach six months later (because a vendor assessment is a snapshot, and risk doesn't hold still for the picture).
Vendors add new services. Products gain new AI features. Business relationships evolve. Cyber postures change. Financial conditions deteriorate. New dependencies show up after the contract is already signed. As one CISO put it, tracking that kind of change "is almost like it needs to be constant."
That gap between a point-in-time assessment and continuously shifting risk is where AI's bigger, unrealised opportunity sits: not in making the same questionnaire-driven process faster, but in enabling a different kind of process altogether, one that starts with context and uses questionnaires only where they're actually needed.
The model several CISOs described starts with context instead of questionnaires.
Before engaging a vendor, teams need to understand what data is being shared, how critical the vendor is to operations, the nature of the relationship, and the potential impact of disruption, failure or compromise.
From there, AI can help assemble a tailored risk profile from available evidence, vendor documentation, public information and prior assessments. It flag gaps, surfaces material risks, and watches continuously for changes that need attention.
Questionnaires become one input into that profile, not the centerpiece of the program.
That changes what risk teams spend their time on, too. Instead of gathering evidence and chasing documentation, they can focus on the job they were actually hired to do: understand risk, make decisions, prioritize remediation and improve resilience.
Nobody at the roundtable argued for removing human judgment from the process. Participants were clear that AI's role is to take work off risk teams' plates, not to take the accountability that comes with it. Organizations still need to understand their exposure, set controls and be ready to respond when something goes wrong.
Vendor risk never fully transfers away, even with a contract in place. Liability terms can shift some financial exposure, but the operational, reputational and regulatory fallout stays with the business that hired the vendor.
As one CISO closed the discussion: "There is a risk. It will stay with us no matter how many people, or AIs, we have on our staff."
For the manual work (the document chasing, the contract review, the questionnaire slog), yes, substantially. For the underlying risk decision, AI is a tool that gives risk teams better information faster, while the judgment call still belongs to them.
What follows from that matters more: TPRM shifting from a periodic compliance exercise built around questionnaires into a continuous, evidence-based way of tracking risk, with fewer hours spent finishing the same assessments and more spent acting on what they find.
With Diligent, CISOs managing a growing vendor base with a flat headcount can scope every relationship before committing time to it, weighing the vendor's criticality, the data being shared, and the potential business impact. From there, they can tailor each assessment to that profile instead of applying the same process to every vendor.
With AI handling the gathering and organizing of evidence, the review of contracts and assurance documents, and the surfacing of gaps, CISOs can go straight to the decisions that need their judgment, instead of the paperwork that leads up to them.
With Diligent's continuous model of third-party risk, CISOs aren't limited to point-in-time reviews. They can track changes in a vendor's risk posture, follow emerging issues, and direct their attention to where risk is rising, spending less time on administrative work and more time managing risk proactively.
AI won't do a CISO's job for them, and it won't take their judgment away, either. What it can do is clear enough of the manual work off their plate that they have the time to use that judgment where it counts.
Don't let your team burn hours chasing documents, reviewing spreadsheets and managing administrative tasks. See how Diligent helps CISOs and risk leaders cut the manual work out of vendor assessments and build a continuous view of third-party risk.