Common Third-Party Risk Mistakes
Most vendor risk programs don't fail because nobody cared. They fail because the process was built for the wrong number of vendors, or the wrong moment in the company's growth, and nobody went back to fix it. We've reviewed enough of these programs to notice the same handful of mistakes showing up again and again. Here they are, along with what we'd do instead.
Treating every vendor the same
The payroll processor that touches every employee's SIN and the scheduling app nobody logs into anymore do not deserve the same level of scrutiny. But a lot of programs run every vendor through one identical checklist, which means the checklist ends up too heavy for low-risk tools and not thorough enough for the ones that actually matter.
Tiering fixes this. Sort vendors by what they can actually touch, critical systems, customer data, or nothing at all, and let the depth of review match the tier. It's less work overall, not more.
Skipping reassessment after onboarding
A vendor gets vetted once, at signup, and then nobody looks at them again until the contract renews three years later. In the meantime, they've had a breach, changed subprocessors twice, or quietly let their SOC 2 report lapse. The onboarding review was the easy part. The ongoing part is where the actual risk management happens.
Set a cadence, even a light one, and stick to it. Annual for your critical vendors is a reasonable default.
Relying only on a signed questionnaire
A completed questionnaire tells you what a vendor says about themselves. It doesn't tell you whether any of it is true. We've seen questionnaires marked 'yes' to controls that, three questions later in the same document, get contradicted.
Cross-check the answers against something independent where you can: their SOC 2 report, a recent pen test summary, or just a follow-up call when something looks off. A questionnaire is a starting point, not proof.
No clear owner
Vendor risk tends to be everyone's job a little bit, which in practice means it's nobody's job most of the time. Reviews slip, renewals get missed, and the whole process quietly stalls until a customer's security team asks how you vet your vendors and nobody has a clean answer.
This doesn't require a full-time hire. It requires one named person who's accountable for the process running, even if they're doing a dozen other things too.
Ignoring subprocessors
Your vendor's vendors are still your risk. A company can pass every question you ask them and still hand your data to a subprocessor you've never heard of and never evaluated. This is one of the most commonly overlooked gaps we see, mostly because it requires asking one extra question that most questionnaires skip.
Waiting until a deal is at risk to start
The most common trigger for building a real vendor risk process is a deal stalling because a customer's security team asked a question nobody could answer well. That's a rough way to learn the lesson, and it usually means building the process under deadline pressure instead of doing it properly.
If you're reading this before that's happened to you, that's the ideal time to start.
None of this requires a big program on day one. Start with a vendor list, a simple tiering system, and one person who owns keeping it current. The rest can build from there.