Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

A risk score isn't a decision: What third-party risk programs are missing

September 28, 2026
•
3 min read
Daniel Zmak

Daniel Zmak

Senior Director, Product Marketing

Most compliance teams can already sort vendors into low, medium or high risk. The bigger challenge is knowing what to do with that rating once it appears.

A "High" rating creates urgency without direction, leaving reviewers to reconstruct the decision the system should have made: which factor drove the rating, whether it is unusual for a vendor like this and what the policy calls for next. The real breakdown is direction: a color-coded dashboard does not give the board a defensible answer to what you knew, when you knew it and what you did about it.

The score doesn't explain itself

A "High" rating rarely tells a reviewer what actually tipped the balance: the geography, ownership structure, relationship type or specific risk signal. Without that context, two reviewers can look at the same file and land in different places because each is filling in the reasoning themselves.

A score is only useful if it explains the next step. That means surfacing the specific factors behind it (geography, relationship type, vendor type and discovered risk signals) and tying the rating to a recommended action instead of a color. Once the driver is visible, a reviewer can act on a "High" rating instead of guessing at what caused it.

The evidence underneath is too self-reported

Too often, evidence still starts with a questionnaire: a form that asks vendors to confirm what they have in place, without proving whether those policies are current, complete or followed in practice. Questionnaires aren't the issue, and attestations still have a place for simple acknowledgments. The issue is treating a self-reported answer as proof.

A vendor confirming they have a data protection policy tells you it exists, not whether it is complete, accurate or followed in practice. A stronger process starts with the evidence itself: the policy, certification, audit report or control document a vendor provides. When that evidence is checked against the standard you require, follow-up becomes more targeted. Instead of asking for confirmation across the board, reviewers can focus on what is missing, unclear or out of line with policy.

Clean files still need an external reference point

A "Medium" rating can look reasonable in isolation, but that does not tell a reviewer whether the risk profile is normal for that supplier type, market or industry. A distributor in a high-corruption region, for example, may carry a level of risk that is expected for that category. The same rating for a low-touch technology vendor in a mature market may point to something that needs more scrutiny.

That is where benchmarking becomes useful. It gives compliance teams a reference point beyond their own program, helping them see whether a vendor's rating, required evidence or follow-up path is broadly consistent with similar reviews. Benchmarking tells a reviewer whether a file sits within the expected range for that vendor type, or stands out enough to warrant a closer look — not whether it beats everyone else's score.

Turn that gap into a decision your team can stand behind

A stronger process brings the rating, rationale, evidence and follow-up into one vendor profile. Gaps get flagged automatically, and the exceptions that need human judgement move straight to due diligence. The reviewer still makes the call, but they get there with less manual work and a clearer record of what informed the decision.

Diligent's Third-Party Risk Intelligence (TPRI) attaches the rating, the reasoning and the evidence to every vendor file, so reviewers can defend the decision instead of just reporting the score.

Learn more about Diligent TPRI 

Explore More

idc report

Blog

· Sep 17, 2026

· 4 min read

Diligent named Leader of 'Worldwide Third-Party Risk Management Software 2026 Vendor Assessment' (IDC MarketScape)

By Christopher Manfredi

Read for an independent view of the TPRM market and a clearer picture of why Diligent was named industry 'Leader'.

Podcast

· Apr 13, 2023

· 1 min read

Reprioritizing Your Third-Party Risk Management Program — Risk Mitigation

By Tom Fox

With the ever-changing landscape of regulations and laws, it is becoming increasingly difficult for companies to keep up and remain compliant. In this 5-part blog post series, sponsored by Diligent...

idc report

Research

· Sep 17, 2026

· 1 min read

IDC MarketScape Worldwide: Third-Party Risk Management Software 2026 Vendor Assessment 

Learn how IDC MarketScape evaluates the third-party risk management software market across capabilities, strategy and market presence.