
At a Diligent CISO roundtable held during the Gartner Security & Risk Management Summit in June 2026, security leaders zeroed in on one part of third-party risk management (TPRM): the vendor assessment process itself.
Vendor questionnaires, due diligence reviews and contract controls remain a core part of most cyber risk programs. What came up again and again was whether that traditional approach still fits how quickly vendor risk actually changes.
CISOs still run vendor assessments. What's changed is how much confidence they place in what those assessments actually tell them.
Third-party ecosystems have grown far beyond what most TPRM programs were built for; vast networks of vendors, partners, service providers and their own downstream suppliers. Security teams are being asked to manage that complexity without a matching increase in headcount or budget.
One security leader put it bluntly: "for one vendor, it's like a 40 hour job."
Another pointed out that assessments can take weeks because teams are juggling multiple contracts and reviews at once. A third contrasted this with a large financial institution that maintained a dedicated 21-person TPRM function, noting that "most companies aren't going to have that type of resource."
For many organizations, that raises a hard question: when the assessment process takes that much time and effort, is it reducing risk, or just managing compliance?
AI was a major topic of discussion, but participants were quick to separate accelerating the work from solving the underlying challenge.
As one CISO put it, voicing a frustration shared across the room: "We have a very big issue with collaborating with third party vendors in answering questionnaire and giving us the documents that we need. I don't see that getting solved with AI."
Several in the room described how AI can speed up elements of vendor due diligence — contract reviews, document analysis, questionnaire completion. One risk leader said their procurement team was already using AI to "speed up components of the TPRM process" and shorten review cycles.
But when suppliers fail to respond, refuse to share information or delay providing evidence, no technology fixes that. For high-risk vendors, one participant said flatly, "you're going to have to apply political pressure through the business."
The strongest criticism of traditional vendor assessments was that they capture only a point-in-time view of risk.
A supplier may complete an assessment, provide documentation and satisfy due diligence requirements today. Tomorrow, they could introduce new technology, expand services, experience a breach or change their risk profile in ways the assessment never anticipated.
This wasn't a one-off concern — several participants raised it independently. One argued that vendors can add new functionality or capabilities that "completely change" the risk profile after onboarding. Another concluded that monitoring vendor risk can no longer be periodic because "the regular checklist... almost like it needs to be constant."
As a result, many CISOs are shifting their focus toward continuous monitoring and ongoing visibility instead of relying solely on annual reviews and questionnaires.
Assessment fatigue was one of the loudest complaints in the room.
Participants described receiving questionnaires ranging from 25 questions to more than 1,500. Another recalled assessments that ran to "more than 400" questions, calling the process "really painful."
Volume is only part of the problem: many organizations also require slightly different versions of the same information, which creates real work for both risk teams and vendors without necessarily improving security outcomes.
Several participants suggested that assessments should be far more risk-based, weighing factors such as the type of service provided, data sensitivity, contract criticality and business impact. Instead of applying the same controls to every vendor, organizations can focus deeper scrutiny where risk is genuinely highest.
One of the most direct moments came when a participant questioned the value of questionnaires altogether.
"From the questionnaire standpoint, we do questionnaires because we have to... from a compliance standpoint," they said. "It's not going to protect" the organization. A different voice in the room pushed the point further: "You can ask them all the questions you want." Vendors will still provide the answers needed to secure the contract.
From there, the discussion turned to what security leaders believe matters more: preparedness, monitoring and response. Several participants pointed to the need for continuous vendor monitoring, automated alerts when a supplier experiences a cyber incident, and clear processes for disconnecting or limiting access when risks emerge — documenting a risk matters less than being able to act on it quickly.
Nobody at the roundtable suggested that third-party risk management matters less than it used to. Several made the case that it matters more.
What CISOs are questioning is whether traditional vendor assessments remain the best way to manage that risk. AI can help reduce administrative burden, automate reviews and support monitoring — but participants were clear that responsibility for vendor risk stays with the business, not the tooling.
"There is a risk. It will stay with us no matter how many people or AI we have on our staff," one CISO said, closing out the discussion.
That's shaping a real shift in mindset. Rather than more questionnaires and more paperwork, CISOs are pointing toward continuous visibility, risk-based decision making, and the ability to act quickly when vendor risk changes.
For CISOs, the test now is simple: can today's assessment model account for how quickly vendor risk actually changes?
If vendor risk can change the day after an assessment is completed, the challenge is no longer simply collecting more information. It's maintaining a current understanding of which supplier risks matter, what has changed, and where action is needed. That's prompting some organizations to rethink the role assessments play within their third-party risk programs.
This shift does not eliminate assessments. It changes their role: from the foundation of third-party risk management to one component of a more continuous, risk-based approach.
The CISOs at the roundtable weren't wrong to question the traditional assessment model, but the answer isn't fewer questions, it's a different operating model altogether.
Diligent's Third-Party Risk Management solution is built around the shift these security leaders are already describing: From static, point-in-time questionnaires to continuous, risk-based oversight of the vendors that matter most.
Diligent was named a Leader in the 2026 Gartner® Magic Quadrant™ for Third-Party Risk Management Tools, recognizing exactly the kind of holistic, continuous approach to vendor risk that CISOs are now asking for.
Ready to see what continuous, risk-based vendor oversight looks like in practice? Request a demo of Diligent Third-Party Risk Management.