Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

No high-risk third parties? That may be a warning sign

October 5, 2026
•
8 min read
Kristy Grant-Hart

Kristy Grant-Hart

Head of Compliance Advisory Services

“I’m pleased to report that we have an extremely low risk third-party population. In fact, 95% of our third parties are classified as low risk, and we have no high-risk third parties.”

On the surface, that sounds like good news. But a third-party population that is almost entirely low risk, with no high-risk relationships at all, may be a reason to look more closely rather than celebrate.

Third-party populations evolve. Organizations enter new markets, regulations change and suppliers take on new responsibilities. The services a third party provides, the data it handles and the access it has to your systems, customers, funds and decision-makers can all change over time.

A risk model that produced sensible results last year may no longer reflect the risks your organization faces today. That is why every third-party risk program needs a regular, deliberate review.  The goal is to make sure the program identifies risk credibly, consistently and defensibly.

How often should you review your third-party risk program?

An annual review is a useful target for many organizations. In some cases, a formal review every two years may be reasonable, depending on the organization’s size, complexity, regulatory exposure and third-party risk profile.

Whatever cadence you choose, the review should be documented and supported by evidence. It should not depend on an informal sense that the program appears to be working.

Mature programs and newly formalized ones alike benefit from a periodic review that confirms risk ratings, workflows and due diligence activities remain aligned with the risks the organization faces now.

How to conduct a practical program review

A refresh does not have to become a major transformation project. Start with a focused health check across the areas most likely to affect the credibility and performance of the program.

1. Revisit the risk model

Begin by asking whether the risk model still reflects how your organization operates and where it is exposed. The exercise tests whether its questions, weighting, thresholds and escalation rules still make sense — not whether it produces a more dramatic spread of high-, medium- and low-risk third parties.

Review the assumptions behind the model. Are the right factors being considered? Are they weighted appropriately? Do the thresholds distinguish meaningfully between relationships that require different levels of review? Do exceptions and overrides follow clear, documented rules?

Pay particular attention to factors such as:

  • Government touchpoints and interaction with public officials
  • Use of agents, intermediaries or subcontractors
  • Access to confidential information, personal data or critical systems
  • Handling of organizational or customer funds
  • Ownership, control and beneficial ownership
  • The nature and criticality of the services provided
  • The countries and locations in which work is performed

Then test the logic against real examples. What types of third parties enter the review process? What level of review do they receive? Are desktop reviews, enhanced due diligence or on-the-ground inquiries triggered when the facts warrant them?

If the answer is that no third party is ever classified as high risk and no relationship receives enhanced review, that is not necessarily evidence of an effective program. It may indicate that the model, thresholds or underlying information need attention.

2. Update the external inputs

Review the external data and reference points that inform the model. If you use sources such as Transparency International’s Corruption Perceptions Index, confirm that the program is using the most recent available edition rather than an older data set.

Country risk, sanctions exposure, regulatory scrutiny and other external indicators can change. The information used to assess third parties should change with them. Document which sources the program uses, when they were last updated and who is responsible for keeping them current.

3. Examine the risk distribution

A basic statistical review can reveal where to ask better questions. The numbers will not tell the whole story, but they can show whether the program’s output appears plausible in the context of the organization’s activities.

Consider asking:

  • How many third parties are in scope, and how has that population changed year over year?
  • How many are classified as high, medium and low risk?
  • Does the distribution make sense given the business model, geographic footprint and services involved?
  • Are there unexpected concentrations by country, business unit, service type or risk category?
  • Are there outliers or unusual results that warrant investigation?
  • How often are risk ratings overridden, by whom and for what reasons?
  • How many enhanced reviews are requested, completed, approved or declined?

The goal is to understand whether the distribution is credible, and whether a knowledgeable reviewer would recognize the results as consistent with the organization’s actual exposure.

4. Check what happens between assessments

Third-party risk is not static. A supplier’s ownership, sanctions exposure, financial condition, adverse media profile, cybersecurity posture or regulatory standing may change after onboarding.

Use the program review to assess whether ongoing monitoring is proportionate to the risks involved. Confirm what changes the organization monitors, how alerts are triaged, who owns follow-up and what triggers reassessment or escalation. A strong onboarding decision can quickly become outdated if meaningful changes are not identified and acted on.

5. Ask the people who use the program

Program owners do not always experience the process in the same way as the people who use it. A short survey, focus group or series of interviews can uncover delays, inconsistencies and workarounds that are not visible in central reporting.

Include stakeholders such as procurement, sales, finance, business sponsors, legal, compliance and internal audit. Ask practical questions:

  • Do they understand when a third-party review is required?
  • Are requests and responsibilities clear?
  • Are the questions relevant to the relationship being assessed?
  • Do users know what happens after they submit information?
  • Where do they experience delays, confusion or unnecessary duplication?
  • What causes the most frustration?
  • What would they change to make the process easier to follow without weakening oversight?

Stakeholder feedback may show that the program is sound in principle but difficult to navigate in practice. It may also reveal inconsistent treatment of similar third parties or business-led workarounds that create gaps in the program.

6. Measure how the program performs

An effective review should examine not only the risk decisions being made, but also how reliably and efficiently the program makes them. Consider reviewing:

  • Time from the due diligence request to receipt of completed information
  • Time from review initiation to approval, rejection or escalation
  • The number and age of open reviews
  • The number of mitigating actions, their owners and completion status
  • Recurring mitigating actions or themes that may point to a wider control issue
  • The frequency of incomplete submissions, rework and manual intervention
  • Whether the team has the capacity, expertise and support required to operate the program

Mitigating actions deserve particular attention. If the same actions recur across multiple relationships, they may indicate a trend in the third-party population or a weakness in the way the organization manages a common risk. If actions are assigned but not tracked to completion, the program may be identifying risk without actually managing it.

7. Document the review and decisions

Regulatory expectations are one reason to document the review. Program credibility is another. The organization should be able to show what it reviewed, which data it considered, what it found, what decisions it made and why.

That record does not need to be a 100-page report. A concise document covering the methodology, key statistics, stakeholder feedback, identified gaps, action plan, owners and target dates may be sufficient. The point is to show the program is being actively managed, not left to run itself.

Secure, approved AI tools may help reduce the administrative burden of this work. For example, they may be used to organize stakeholder feedback, summarize findings or produce a first draft of the review report. Appropriate human oversight remains essential: experienced professionals should validate the inputs, conclusions and recommended actions before anything is finalized.

8. Assess whether your technology still supports the program

A program refresh is also an opportunity to assess whether your technology continues to meet the organization’s needs. Screening, workflow, reporting, monitoring and case management capabilities continue to evolve, and the tools that supported the program at launch may not address its current scale or complexity.

Ask technology providers how their roadmap aligns with your future requirements. Explore where automation or AI-supported workflows could reduce administrative effort, improve consistency or surface issues earlier across the third-party lifecycle. Potential use cases may include gathering information, triaging cases, identifying patterns, supporting ongoing monitoring and drafting reports.

Automation should remove repetitive work and surface better information for compliance and risk teams. The professional judgment stays with humans, not the machine.

The bottom line

A third-party risk program is only as good as its underlying mechanics. That means whether its model is current, its risk ratings are credible, its escalation process works, its mitigating actions are completed and its users can operate it effectively. It does not mean judging the program on how reassuring its dashboard looks.

A program that reports no high-risk third parties may be accurately reflecting an unusually low-risk population. Or it may be telling you that the questions, data, thresholds or processes need another look. A regular refresh helps you know the difference. 

Ready to build a more credible, defensible third-party risk program?

Go beyond periodic assessments with risk-based screening, automated workflows and continuous monitoring. Diligent Third-Party Manager helps you identify changing risks, streamline due diligence and track mitigation across the third-party lifecycle. Explore Diligent Third-Party Manager and request a demo today.

Explore More

A CCO considering anti-bribery and corruption compliance.

Blog

· Apr 9, 2026

· 13 min read

What is anti-bribery and corruption compliance?

By Jessica Donohue

Explore the complexities of anti-bribery and anti-corruption compliance in our comprehensive guide. Learn about key laws, best practices for building an effective compliance program, and how AI can transform your approach to managing third-party risks and maintaining oversight in a global business environment.

Business people interested in 3rdRisk for third-party risk management

Blog

· Apr 2, 2026

· 8 min read

From policy to practice: Why KPMG chose 3rdRisk for third-party risk management

By Jay Cameron

Discover how KPMG's partnership with 3rdRisk revolutionizes third-party risk management by seamlessly integrating advisory expertise with a purpose-built TPRM platform, empowering organizations to transition from theoretical policies to actionable risk management in response to evolving regulations like DORA and NIS2.

Diligent was named a Leader in the 2026 Gartner® Magic Quadrant™ for Third‑Party Risk Management Tools

Blog

· Apr 9, 2026

· 4 min read

Diligent named a Leader in the 2026 Gartner® Magic Quadrant™ for Third‑Party Risk Management Tools

By Jay Cameron

Diligent named a Leader in the 2026 Gartner Magic Quadrant for Third-Party Risk Management Tools. See how our AI-driven platform helps you scale vendor oversight.