Third-party vendor risk strategies will split by 2028

6 min read
The Two-Year Vendor Risk Forecast
- The Core Thesis: Over the next eight fiscal quarters, the compliance market will split into two camps: continuous telemetry-driven automation and high-assurance human auditing.
- The High Stakes: Regulatory deadlines from DORA and NIS2 make static, once-a-year security questionnaires a major regulatory liability.
- The Strategic Decider: Your organization's integration velocity dictates your path; fast-moving API stacks require automated telemetry, while legacy cores require human-signed assurance.
The Illusion of Security in the Annual Questionnaire Ritual
Sending a 200-question spreadsheet to a software vendor is not security; it is a bureaucratic cover-up that leaves your network exposed. For a decade, security teams have treated third-party vendor risk assessment as a paper-pushing exercise designed to satisfy auditors rather than stop attackers. This comfortable routine is about to end as geopolitical tensions spill over into supply chains and regulators demand proof of actual operational resilience.
As we look toward 2028, organizations face a hostile threat landscape where a breach at a minor supplier can disable a global enterprise in minutes. The current model of asking a vendor to self-report their security posture once a year is fundamentally broken. Security teams spend up to 70% of their time chasing signatures and filing SOC 2 reports instead of identifying active vulnerabilities. The next eight quarters will force CISOs to choose between two distinct, incompatible paths for managing this risk.
This is not a simple story of technology replacing human effort. It is an operational trade-off between the noisy, real-time data of automated scanning and the slow, deep assurance of human-led reviews. Each approach has a real cost, and choosing the wrong one will waste budget while leaving critical systems exposed to supply-chain attacks.
Why the Push for Pure Automation Is a Dangerous Half-Truth
The security industry is currently infatuated with "agentic GRC" and automated pipelines designed to replace manual reviews. Startups and legacy platforms alike promise that AI agents can ingest vendor documentation, scan external IP addresses, and update risk scores automatically. They argue that automation is the only way to scale as enterprise vendor portfolios balloon into the thousands.
This view ignores how enterprise software is actually bought and run. Automated scanning tools excel at finding external vulnerabilities, like expired SSL certificates or open ports, but they cannot evaluate internal operational controls. An AI agent scanning an external network cannot tell you if a vendor has a reliable background-check process for its database administrators or if their disaster recovery plan has ever been tested.
The Telemetry Trap of Continuous Scanning
When you shift to continuous automated monitoring, you exchange a data deficit for alert fatigue. If an automated tool flags a minor configuration change at a critical vendor, your security team is forced to triage the alert. This creates friction with business units that rely on that vendor to keep operations running.
"A security questionnaire is a snapshot of a vendor's promises; an open API port is a live map of their failures."
Furthermore, banking groups like the Consumer Bankers Association are raising alarms about systemic concentration risk. Automated tools assess vendors individually, but they fail to track the structural dependence of the entire financial system on a tiny handful of hyperscale cloud providers and AI infrastructure engines. When a single cloud region goes dark, it does not matter how clean your individual vendor's security scorecard looked that morning.
The Hard Operational Choice: Telemetry Noise vs. Audit Blind Spots
To build a resilient program, you must weigh the friction of automated monitoring against the blind spots of traditional auditing. There is no middle ground that does both cheaply. The table below outlines the operational realities of these two approaches.
| Operational Dimension | Continuous Agentic Telemetry | High-Assurance Human Auditing |
|---|---|---|
| Primary Data Source | API feeds, external vulnerability scans, live GRC platform integrations | SOC 2 Type II reports, ISO 27001 certificates, custom onsite audits |
| Operational Friction | High alert volume; constant chasing of minor telemetry changes | Slow onboarding cycles; high labor costs for GRC staff |
| Blind Spots | Internal policy enforcement, human-centric security controls | Changes in vendor security posture during the 364 days between audits |
| Regulatory Alignment | Meets DORA/NIS2 requirements for continuous monitoring | Meets traditional banking GRC and SOX control frameworks |
| Best Suited For | Dynamic SaaS providers and API-driven cloud integrations | Legacy core infrastructure, physical suppliers, and high-privilege vendors |
Choosing continuous monitoring means accepting a high volume of false positives and investing in engineering resources to maintain integrations. Choosing human-led auditing means accepting that you will be blind to vendor security changes for months at a time. The right choice depends entirely on your organization's digital architecture.
The Next Eight Quarters of Regulatory and Operational Reckoning
Between now and 2028, regulatory pressure will make passive risk management impossible. Organizations that fail to choose a clear strategy will find themselves out of compliance and exposed to severe liability.
- DORA and NIS2 Enforcement: European regulators will begin imposing heavy fines on financial entities and critical infrastructure operators that cannot demonstrate active, continuous oversight of their ICT third-party providers.
- The End of the Questionnaire: Enterprise vendors will increasingly refuse to fill out custom security spreadsheets, directing customers to automated trust portals instead.
- Systemic Concentration Audits: Federal banking agencies in the US will require financial institutions to map their dependencies down to the fourth-party level, exposing hidden reliance on shared infrastructure.
If your business relies on rapid deployment of cloud services and third-party APIs, you must build automated telemetry pipelines to survive the regulatory wave. If your business runs on a stable, highly regulated core with a fixed set of partners, trying to automate your GRC program will only introduce useless noise and distract your team from deep, meaningful audits.
The era of the checklist is over.
Frequently Asked Questions
What happens to our compliance audit trail when a vendor's automated GRC API goes dark?
When an automated integration fails, your GRC platform must immediately flag the connection loss and fall back to the last verified state. From an audit perspective, you must have an automated exception-handling workflow that logs the outage, alerts the vendor owner, and initiates a manual review if the connection is not restored within 72 hours. Without this fallback, your compliance trail has a gap that regulatory auditors will flag during your next review.
How do we handle the liability shift when an AI agent automatically approves a vendor that later suffers a major breach?
An AI agent cannot sign a contract or accept risk on behalf of an enterprise. Legally, the liability remains with the human officers of your organization. AI-driven GRC platforms should only be used to collect, organize, and score risk data; the final sign-off and risk acceptance must always be executed by a designated human risk owner within an established GRC approval matrix.
Will European regulators enforcing DORA accept continuous AI-driven risk scores in place of a signed SOC 2 Type II report?
No. Regulators enforcing DORA and NIS2 do not view these methodologies as mutually exclusive. DORA requires organizations to perform initial due diligence, which typically relies on high-assurance reports like SOC 2 or ISO 27001, and continuous monitoring of the service delivery. You cannot use an automated external scan to bypass the requirement to verify a vendor's internal organizational controls.
How do we prevent our security team from drowning in alert noise if we implement continuous automated assessments?
You must establish strict thresholds for what triggers an alert. If an automated tool detects a minor vulnerability on a non-critical vendor's marketing website, it should be logged automatically without alerting a human analyst. Alerts should only escalate to your security team if they affect a critical system, involve a high-severity CVE, or persist beyond an agreed-upon remediation window, typically 14 to 30 days depending on the vendor's service-level agreement.
The Final Verdict: Stop trying to build a hybrid risk program that satisfies everyone while securing nothing. If your production environment is dynamic and API-driven, invest heavily in continuous automated telemetry; if it is static and highly regulated, double down on rigorous human audits. The worst decision you can make over the next two years is to hide behind a stack of paper questionnaires and hope the regulators do not look too closely.
Related from this blog
- GDPR Data Privacy APIs: Gateways vs Continuous Discovery
- How ERM Software Buyers Choose Between Risk and Category Views
- Is SOC 2 compliance automation SaaS a security trap?
- Continuous compliance monitoring drains 5000-employee banks
- Does Enterprise Risk Management Software Reduce Real Risk?
Sources
- Global Third-Party Cyber Risk Regulatory Trends to Know: US and Europe - Bitsight — Bitsight
- Anecdotes Extends Agentic GRC to Third-Party Risk Management - PR Newswire — PR Newswire
- Financial Services Industry Outlines Proposed Third-Party Risk Management Reforms to Federal Banking Agencies - consumerbankers.com — consumerbankers.com
- Commugen Launches AI Agents to Automate Third-Party Risk Management (TPRM) - The National Law Review — The National Law Review
- What DORA and NIS2 mean for third-party cyber risk management - Wolters Kluwer — Wolters Kluwer