Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

Why CISOs are questioning the vendor risk assessment

September 2, 2026
8 min read
The Diligent team

The Diligent team

GRC trends and insights

At a Diligent CISO roundtable held during the Gartner Security & Risk Management Summit in June 2026, security leaders zeroed in on one part of third-party risk management (TPRM): the vendor assessment process itself.

Vendor questionnaires, due diligence reviews and contract controls remain a core part of most cyber risk programs. What came up again and again was whether that traditional approach still fits how quickly vendor risk actually changes.

CISOs still run vendor assessments. What's changed is how much confidence they place in what those assessments actually tell them.

The assessment burden keeps growing

Third-party ecosystems have grown far beyond what most TPRM programs were built for; vast networks of vendors, partners, service providers and their own downstream suppliers. Security teams are being asked to manage that complexity without a matching increase in headcount or budget.

One security leader put it bluntly: "for one vendor, it's like a 40 hour job."

Another pointed out that assessments can take weeks because teams are juggling multiple contracts and reviews at once. A third contrasted this with a large financial institution that maintained a dedicated 21-person TPRM function, noting that "most companies aren't going to have that type of resource."

For many organizations, that raises a hard question: when the assessment process takes that much time and effort, is it reducing risk, or just managing compliance?

AI speeds up the paperwork. Vendor engagement is still a people problem.

AI was a major topic of discussion, but participants were quick to separate accelerating the work from solving the underlying challenge.

As one CISO put it, voicing a frustration shared across the room: "We have a very big issue with collaborating with third party vendors in answering questionnaire and giving us the documents that we need. I don't see that getting solved with AI."

Several in the room described how AI can speed up elements of vendor due diligence — contract reviews, document analysis, questionnaire completion. One risk leader said their procurement team was already using AI to "speed up components of the TPRM process" and shorten review cycles.

But when suppliers fail to respond, refuse to share information or delay providing evidence, no technology fixes that. For high-risk vendors, one participant said flatly, "you're going to have to apply political pressure through the business."

Assessments freeze a moment. Risk keeps moving.

The strongest criticism of traditional vendor assessments was that they capture only a point-in-time view of risk.

A supplier may complete an assessment, provide documentation and satisfy due diligence requirements today. Tomorrow, they could introduce new technology, expand services, experience a breach or change their risk profile in ways the assessment never anticipated.

This wasn't a one-off concern — several participants raised it independently. One argued that vendors can add new functionality or capabilities that "completely change" the risk profile after onboarding. Another concluded that monitoring vendor risk can no longer be periodic because "the regular checklist... almost like it needs to be constant."

As a result, many CISOs are shifting their focus toward continuous monitoring and ongoing visibility instead of relying solely on annual reviews and questionnaires.

More questions don't necessarily create more security

Assessment fatigue was one of the loudest complaints in the room.

Participants described receiving questionnaires ranging from 25 questions to more than 1,500. Another recalled assessments that ran to "more than 400" questions, calling the process "really painful."

Volume is only part of the problem: many organizations also require slightly different versions of the same information, which creates real work for both risk teams and vendors without necessarily improving security outcomes.

Several participants suggested that assessments should be far more risk-based, weighing factors such as the type of service provided, data sensitivity, contract criticality and business impact. Instead of applying the same controls to every vendor, organizations can focus deeper scrutiny where risk is genuinely highest.

CISOs are looking beyond questionnaires

One of the most direct moments came when a participant questioned the value of questionnaires altogether.

"From the questionnaire standpoint, we do questionnaires because we have to... from a compliance standpoint," they said. "It's not going to protect" the organization. A different voice in the room pushed the point further: "You can ask them all the questions you want." Vendors will still provide the answers needed to secure the contract.

From there, the discussion turned to what security leaders believe matters more: preparedness, monitoring and response. Several participants pointed to the need for continuous vendor monitoring, automated alerts when a supplier experiences a cyber incident, and clear processes for disconnecting or limiting access when risks emerge — documenting a risk matters less than being able to act on it quickly.

Accountability doesn't move, even as the process does

Nobody at the roundtable suggested that third-party risk management matters less than it used to. Several made the case that it matters more.

What CISOs are questioning is whether traditional vendor assessments remain the best way to manage that risk. AI can help reduce administrative burden, automate reviews and support monitoring — but participants were clear that responsibility for vendor risk stays with the business, not the tooling.

"There is a risk. It will stay with us no matter how many people or AI we have on our staff," one CISO said, closing out the discussion.

That's shaping a real shift in mindset. Rather than more questionnaires and more paperwork, CISOs are pointing toward continuous visibility, risk-based decision making, and the ability to act quickly when vendor risk changes.

For CISOs, the test now is simple: can today's assessment model account for how quickly vendor risk actually changes?

What some risk teams are doing differently

If vendor risk can change the day after an assessment is completed, the challenge is no longer simply collecting more information. It's maintaining a current understanding of which supplier risks matter, what has changed, and where action is needed. That's prompting some organizations to rethink the role assessments play within their third-party risk programs.

  • They start with the supplier's business context. Rather than applying the same review process to every vendor, they first consider the service being provided, its criticality, the data involved, and the potential business impact if something goes wrong. This helps focus effort where risk is highest.
  • They use assessments as an input, not the entire program. Questionnaires and due diligence reviews still provide valuable information, but they are treated as one source of evidence rather than the primary mechanism for maintaining visibility into risk.
  • They look for signals of change between reviews. Supplier services, technology environments, ownership structures and risk exposures can evolve long before the next annual assessment. Continuous visibility helps identify those changes when they happen, rather than months later.
  • They triggeradditional assurance when riskwarrants it. Instead of reassessing suppliers on a fixed schedule, they usenew information, changing circumstances or emerging concerns to determine when deeper investigation or evidence collection is needed.
  • They focus on response as much as assessment. The goal is not simply to document risk but to understand what has changed, decide what action is required and maintain a clear record of how risks were managed over time.

This shift does not eliminate assessments. It changes their role: from the foundation of third-party risk management to one component of a more continuous, risk-based approach.

How Diligent helps

The CISOs at the roundtable weren't wrong to question the traditional assessment model, but the answer isn't fewer questions, it's a different operating model altogether.

Diligent's Third-Party Risk Management solution is built around the shift these security leaders are already describing: From static, point-in-time questionnaires to continuous, risk-based oversight of the vendors that matter most.

  • Move beyond the point-in-time snapshot. 3rdRisk replaces annual reviews with a risk profile, continually updated with real-time monitoring data and aligned to your business context and vendor relationships. That means you know when a vendor's risk profile changes, not just when the next assessment cycle rolls around.
  • Apply scrutiny where it counts. Configurable risk tiering and segmentation let you match the depth of due diligence to actual risk, rather than sending every vendor the same 400-question survey regardless of criticality.
  • Cut the administrative burden without losing the human judgment. AI-assisted questionnaires, document review and automated workflows speed up the parts of the process that don't require expert judgment, while keeping accountability, escalation and remediation decisions with your team.
  • Get a defensible, board-ready record. Centralized data, audit-ready workflows and integrated reporting give you a single source of truth you can stand behind when regulators or the board ask what you knew and when.
  • Move fast. Most organizations are fully live on 3rdRisk in as few as 10 days, with continuous optimization as your vendor population and regulatory requirements evolve.

Diligent was named a Leader in the 2026 Gartner® Magic Quadrant™ for Third-Party Risk Management Tools, recognizing exactly the kind of holistic, continuous approach to vendor risk that CISOs are now asking for.

Ready to see what continuous, risk-based vendor oversight looks like in practice? Request a demo of Diligent Third-Party Risk Management.

Explore More

CISO-GC-boardroom-meeting

Blog

· Feb 7, 2025

· 7 min read

CISOs and GCs Unite: Collaborating for stronger cyber risk management and compliance

How CISO-GC collaboration supports effective cyber risk management and strategic business initiatives

Podcast

· Jul 24, 2024

· 1 min read

Cybersecurity governance and the CISO's dilemma

By Dottie Schindlinger

How can boards and CEOs support their CISOs in the face of increasing cyber risks and personal liability? In this episode, Jim Alkove, co-founder and CEO of cybersecurity company Oleria, shares ins...

Guide

· Feb 7, 2025

· 1 min read

The Cyber Leadership Playbook

Discover how CISOs, GCs & board leaders can align priorities, communicate risk clearly & use GRC tech to lead smarter, more resilient cyber governance.