Your Vendors Are Your Risk Too: Why Third-Party Risk Management Can't Wait
When people think about a data breach or compliance failure, they usually picture something happening inside their own walls — an employee clicking a phishing link, a misconfigured server, a lost laptop. But a large and growing share of incidents now start somewhere else entirely: with a vendor. Roughly one in three breaches today involves a third party in some way, and for small and mid-size businesses juggling dozens of software tools, contractors, and service providers, that statistic should give you pause.
The Problem With "Set and Forget" Vendor Reviews
For most small and mid-size businesses, vendor risk management has historically meant sending a questionnaire when a new vendor is onboarded, filing it away, and moving on. That approach made sense when vendor relationships were simpler. It doesn't hold up well anymore, for a few reasons.
Vendors change faster than annual reviews can track. A vendor that was low-risk when you signed the contract can add new subprocessors, change its data handling practices, or get acquired — all without you knowing, unless you're checking.
AI has added a new, harder-to-see layer of exposure. Many of your vendors have quietly built AI features into their products over the past two years — sometimes using your data to train or fine-tune models, sometimes routing your data through additional third-party AI providers you've never heard of. If you haven't asked your vendors directly how they're using AI and what data it touches, you likely don't have a full picture of your own risk.
Fourth-party risk is real and mostly invisible. Your vendors have their own vendors. A cloud storage provider might rely on a subcontractor for backups; a billing platform might route payments through a processor you've never vetted. Most businesses have no visibility into this second layer at all, even though a failure there can affect you just as directly as a failure at your direct vendor.
Why This Is a Compliance Issue, Not Just an IT Issue
If you're subject to HIPAA, you're required to have business associate agreements and to reasonably vet the vendors who touch protected health information. If you're a public company or preparing for one, SOX expects documented controls over vendors that touch financial reporting systems. If you handle any regulated data, your obligations don't end at your own systems — regulators and auditors increasingly expect you to demonstrate that you understand and manage the risk your vendors introduce, not just the risk you create yourself. "We didn't know" is rarely an acceptable answer during an audit or after an incident.
Practical Takeaways for Getting Vendor Risk Under Control
Build a complete vendor inventory, including which vendors touch sensitive data (patient information, financial data, customer PII) and which don't. You can't manage what you haven't listed.
Tier your vendors by risk, and focus deeper scrutiny on the small percentage that are truly critical — the ones with access to sensitive data or systems — rather than spreading effort evenly across every vendor.
Move from annual questionnaires to periodic check-ins, even lightweight ones, for your highest-risk vendors. A quick quarterly email asking about material changes is far better than a static form from two years ago.
Ask vendors directly about AI usage — whether your data is used to train models, and whether it's shared with additional AI subprocessors.
Review your contracts for data handling, breach notification, and subcontractor disclosure clauses, and update older agreements that are silent on these points.
Document your vendor risk process, even if it's simple. Auditors and regulators care as much about evidence of a repeatable process as they do about the process being perfect.
The Bottom Line
You don't need an enterprise-grade third-party risk platform to manage this well. What you need is a clear inventory, a sense of which vendors actually matter, and a process — however lightweight — for checking in on them regularly instead of once and never again. The businesses that get burned by vendor risk are almost always the ones that never wrote any of this down in the first place.
If vendor risk feels like a blind spot in your compliance program, we'd be glad to help you build a practical, right-sized process. Reach out to The Compliance Labs for a consultation to get started.

Comments