
“I’m pleased to report that we have an extremely low risk third-party population. In fact, 95% of our third parties are classified as low risk, and we have no high-risk third parties.”
On the surface, that sounds like good news. But a third-party population that is almost entirely low risk, with no high-risk relationships at all, may be a reason to look more closely rather than celebrate.
Third-party populations evolve. Organizations enter new markets, regulations change and suppliers take on new responsibilities. The services a third party provides, the data it handles and the access it has to your systems, customers, funds and decision-makers can all change over time.
A risk model that produced sensible results last year may no longer reflect the risks your organization faces today. That is why every third-party risk program needs a regular, deliberate review. The goal is to make sure the program identifies risk credibly, consistently and defensibly.
An annual review is a useful target for many organizations. In some cases, a formal review every two years may be reasonable, depending on the organization’s size, complexity, regulatory exposure and third-party risk profile.
Whatever cadence you choose, the review should be documented and supported by evidence. It should not depend on an informal sense that the program appears to be working.
Mature programs and newly formalized ones alike benefit from a periodic review that confirms risk ratings, workflows and due diligence activities remain aligned with the risks the organization faces now.
A refresh does not have to become a major transformation project. Start with a focused health check across the areas most likely to affect the credibility and performance of the program.
Begin by asking whether the risk model still reflects how your organization operates and where it is exposed. The exercise tests whether its questions, weighting, thresholds and escalation rules still make sense — not whether it produces a more dramatic spread of high-, medium- and low-risk third parties.
Review the assumptions behind the model. Are the right factors being considered? Are they weighted appropriately? Do the thresholds distinguish meaningfully between relationships that require different levels of review? Do exceptions and overrides follow clear, documented rules?
Pay particular attention to factors such as:
Then test the logic against real examples. What types of third parties enter the review process? What level of review do they receive? Are desktop reviews, enhanced due diligence or on-the-ground inquiries triggered when the facts warrant them?
If the answer is that no third party is ever classified as high risk and no relationship receives enhanced review, that is not necessarily evidence of an effective program. It may indicate that the model, thresholds or underlying information need attention.
Review the external data and reference points that inform the model. If you use sources such as Transparency International’s Corruption Perceptions Index, confirm that the program is using the most recent available edition rather than an older data set.
Country risk, sanctions exposure, regulatory scrutiny and other external indicators can change. The information used to assess third parties should change with them. Document which sources the program uses, when they were last updated and who is responsible for keeping them current.
A basic statistical review can reveal where to ask better questions. The numbers will not tell the whole story, but they can show whether the program’s output appears plausible in the context of the organization’s activities.
Consider asking:
The goal is to understand whether the distribution is credible, and whether a knowledgeable reviewer would recognize the results as consistent with the organization’s actual exposure.
Third-party risk is not static. A supplier’s ownership, sanctions exposure, financial condition, adverse media profile, cybersecurity posture or regulatory standing may change after onboarding.
Use the program review to assess whether ongoing monitoring is proportionate to the risks involved. Confirm what changes the organization monitors, how alerts are triaged, who owns follow-up and what triggers reassessment or escalation. A strong onboarding decision can quickly become outdated if meaningful changes are not identified and acted on.
Program owners do not always experience the process in the same way as the people who use it. A short survey, focus group or series of interviews can uncover delays, inconsistencies and workarounds that are not visible in central reporting.
Include stakeholders such as procurement, sales, finance, business sponsors, legal, compliance and internal audit. Ask practical questions:
Stakeholder feedback may show that the program is sound in principle but difficult to navigate in practice. It may also reveal inconsistent treatment of similar third parties or business-led workarounds that create gaps in the program.
An effective review should examine not only the risk decisions being made, but also how reliably and efficiently the program makes them. Consider reviewing:
Mitigating actions deserve particular attention. If the same actions recur across multiple relationships, they may indicate a trend in the third-party population or a weakness in the way the organization manages a common risk. If actions are assigned but not tracked to completion, the program may be identifying risk without actually managing it.
Regulatory expectations are one reason to document the review. Program credibility is another. The organization should be able to show what it reviewed, which data it considered, what it found, what decisions it made and why.
That record does not need to be a 100-page report. A concise document covering the methodology, key statistics, stakeholder feedback, identified gaps, action plan, owners and target dates may be sufficient. The point is to show the program is being actively managed, not left to run itself.
Secure, approved AI tools may help reduce the administrative burden of this work. For example, they may be used to organize stakeholder feedback, summarize findings or produce a first draft of the review report. Appropriate human oversight remains essential: experienced professionals should validate the inputs, conclusions and recommended actions before anything is finalized.
A program refresh is also an opportunity to assess whether your technology continues to meet the organization’s needs. Screening, workflow, reporting, monitoring and case management capabilities continue to evolve, and the tools that supported the program at launch may not address its current scale or complexity.
Ask technology providers how their roadmap aligns with your future requirements. Explore where automation or AI-supported workflows could reduce administrative effort, improve consistency or surface issues earlier across the third-party lifecycle. Potential use cases may include gathering information, triaging cases, identifying patterns, supporting ongoing monitoring and drafting reports.
Automation should remove repetitive work and surface better information for compliance and risk teams. The professional judgment stays with humans, not the machine.
A third-party risk program is only as good as its underlying mechanics. That means whether its model is current, its risk ratings are credible, its escalation process works, its mitigating actions are completed and its users can operate it effectively. It does not mean judging the program on how reassuring its dashboard looks.
A program that reports no high-risk third parties may be accurately reflecting an unusually low-risk population. Or it may be telling you that the questions, data, thresholds or processes need another look. A regular refresh helps you know the difference.
Go beyond periodic assessments with risk-based screening, automated workflows and continuous monitoring. Diligent Third-Party Manager helps you identify changing risks, streamline due diligence and track mitigation across the third-party lifecycle. Explore Diligent Third-Party Manager and request a demo today.