AI is changing third-party risk management from a periodic, manual process into continuous supplier risk monitoring. Learn how AI can automate due diligence, analyse contracts, detect emerging risks and support better-informed TPRM decisions—while keeping accountability with people.
A modern organisation is largely built with the services of other companies. The infrastructure runs in the cloud, payroll is handled by an external entity, customer support systems are provided by another one – and each of these providers has its own sub-suppliers. As a result, TPRM (third-party risk management) becomes very complicated.
Artificial intelligence in third-party risk management (TPRM) means using machine learning and language models to automate the processes of identifying, assessing and monitoring risks that suppliers and business partners bring to the organisation.
It is worth emphasising right away that AI will not replace the supplier risk management process. Instead, it removes the bottleneck of manual labour, through which the evaluation in practice covers a handful of suppliers, is superficial and happens once a year.
A growing network of suppliers: why has risk outgrown the teams that are supposed to manage it?
The complexity of third-party risk management is due to three phenomena.
First: scale. The number of supplier relationships has grown much faster in recent years than the teams that are supposed to oversee it. Large organisations often can’t even pinpoint how many entities they’re working with, because purchasing, marketing, and individual business units enter into contracts independently of each other. The scale of the phenomenon is well illustrated by EY data from 2025: TPRM programs that have been in operation for less than three years serve 275 providers (median), and those with more than ten years of experience serve 80, because they have learned to prioritise according to risk, instead of evaluating everyone one by one. The dark side of this coin, however, is that some subcontractors “fall out” of the risk assessment process.
At the same time, the internal scope of this process has also changed: in a bank where one or two divisions used to deal with third-party risk, today there may be more than twenty of them.
Second: limited visibility. Traditional supplier evaluation is based on an annual survey – and therefore self-assessment – completed by the party least interested in revealing weaknesses and describing the condition on one day of the year. Such an image quickly becomes obsolete. A supplier that was solvent and well-secured in March may be neither one nor the other in October – and the organisation will only find out about it at the next review.
Third: regulations. The NIS2 Directive and the DORA Regulation have transformed supplier supervision from good operational practice into a documented, accountable obligation. The matter is further complicated by the suppliers of the suppliers themselves. Their problems become the problems of the organisation, although it is not connected by any contract with them.

From a snapshot to a continuous signal: what is AI really changing in supplier risk management?
The change is best described on three axes. Periodic evaluation gives way to an evaluation conducted on a continuous basis. Analysing a sample of suppliers is inferior to analysing the entire population. And the data from formalised surveys are supplemented with unstructured material: contracts, reports, media reports, data from registers.
Equally important is what does not change. Risk appetite, supplier classification criteria, risk acceptance decisions and responsibility for them remain with people – analysts, relationship owners, and management.
| TPRM Area | Traditional approach | AI-powered approach |
| Due diligence | Manual review of surveys and documentation | Automatic document analysis and detection of requirements gaps |
| Risk assessment | Static classification assigned during onboarding | Dynamic segmentation by criticality and data access |
| Monitoring | Annual re-evaluation | Continuous analysis of cyber, financial and sanctions signals |
| Contract Analysis | Individual reading of each document | A database of contracts that is searchable as a data set |
| Risk scoring | Result in a worksheet, rarely updated | Result calculated on an ongoing basis with the inflow of data |
| Escalation | Problem detected at the next inspection | Alert within days of a material change |
Segmentation that defends itself: How does AI help determine which suppliers really matter?
The most common mistake TPRM programs make is to evaluate the office supplies provider and central banking platform according to the same logic. Algorithms can classify the entire supplier population according to criticality, sensitivity of the data processed, level of access to systems, geography and substitutability. This ensures that the depth of the assessment is concentrated where the effects of the failure would be most severe.
Analyst’s working day: what can be recovered from it?
A typical onboarding package includes a completed survey, security policy, business continuity plan, audit report or ISO 27001 certification, financial statements, and a contract. A reliable review of such a set takes up most of the working day for an experienced analyst.
Reading and organising such documentation has been automated for a long time. The tools were able to extract dates, scope of certification, names of entities or the presence of required clauses – and they stopped there. What is new is different: the language model compares documents with each other and notices, for example, that the declaration made in the survey is not covered by the content of the security policy. This is the transition from search to inference.
The result is an orderly summary with links to the source material. The decision is still made by the analyst – but he makes it with a ready-made list of discrepancies in front of him, not a pile of documents to read. And it takes it against every supplier, not just the fifty largest ones.
However, the analysis of the documents itself is only the first stage: the evaluation of the supplier usually goes through many hands – the owner of the relationship, the security team, the legal department – and it is the transfer of the case between them, rather than reading the documents, that can be the longest part of the whole process. Automated workflow routes the case to the right person based on the vendor’s classification, keeps an eye on deadlines, and records each approval so that the evaluation doesn’t stop in someone’s inbox.
Continuous supplier monitoring: how do you know that things are wrong between inspections?
Today, a vendor’s risk profile can be maintained as an image that is updated on an ongoing basis, built from sources that no team would be able to track manually. On the cybersecurity side, these are exposed breaches, leaks of credentials and the state of the external attack surface, i.e. what the provider exposes to the public network – open services, outdated software, expired certificates, forgotten test environments.
On the compliance side, sanctions lists, supervisory proceedings, litigation and negative media reports. On the financial side – deterioration of the rating, delays in filing reports or bankruptcy filings.
Language models have solved a problem that has made such monitoring unfeasible for years, namely, reading huge amounts of unstructured text in multiple languages and deciding whether a message is about a specific provider or just a company with a similar name. Now, when a supplier’s situation changes significantly, the organisation learns about it within days, not on the occasion of the next audit.
However, the signal itself is only half the job. Monitoring starts to pay off when alerts fall into an orderly process – with assigned owners, escalation thresholds, and an audit trail. This is how the supplier monitoring module in AdaptiveGRC connects external data to the internal workflow in the organisation.
Supplier Cyber Risk Monitoring: Which Alert Is the Urgent One?
Data about a provider’s security posture only becomes important when compared to what that provider actually has access to. An entity with weak security that doesn’t process anything sensitive is irrelevant. An entity with average security that has administrative privileges over a key system is an incident waiting to happen. Without this correlation, both glow the same orange colour on the desktop. This is all the more important because third-party breaches have become one of the main routes for attackers to enter the organisation.
The scale of the problem is shown in the Verizon Data Breach Investigations Report. In the 2026 edition, a third party was involved in 48% of all violations – 60% more than the year before. Two editions back, it was 15%. The reasons are rarely sophisticated: most often it is the lack or misconfiguration of MFA on the part of the provider and redundant access permissions.
Live news or a monument: what does dynamic supplier risk scoring give?
The risk score given during onboarding loses its connection with reality within a few months. The rating, which is updated on an ongoing basis, changes with each new batch of data and weighs the criticality of the supplier. What is crucial for organisational governance, it can be accounted for: you can always see which signals changed the result.
And predictive analytics goes a step further: based on patterns from previous supplier problems, it indicates relationships that are at risk of deterioration. However, a caveat is necessary here: the maturity of these methods is extremely uneven. Forecasting financial troubles is based on decades of data on bankruptcies, payment delays and rating changes – a relatively solid basis. Forecasting security breaches does not have such a backend: incidents at suppliers are sometimes disclosed selectively, with a delay or not at all, so historical data are fragmented. Prediction in TPRM therefore remains a tool that suggests where to direct attention – not a judgment.
The management and those responsible for risk can only rely on scoring if they can explain its results. That’s why the scoring model in AdaptiveGRC maintains a full history of changes and transparency of criteria – so that it is always possible to indicate where each result came from.
Which contracts include the right to audit, or what does the analysis of contracts and policies by AI give?
Many organisations cannot answer basic questions about their own contracts. Which provide for the obligation to notify a breach and within what period? Which allow subcontracting without consent? Which include the provisions currently required by DORA? Language models comb through the entire pool of contracts and give answers that can be checked in the source text – they turn a cabinet with binders into a searchable data set.
AI Agents at TPRM: What Happens When the System Not Only Responds, But Works?
An AI agent, unlike a regular model, does not answer a single question, but conducts a multi-stage task using various tools. In practice, it can look like this: an agent detects a disturbing signal about a supplier, reaches for their contract and rating history, determines which internal systems this supplier has access to, prepares a summary, creates a targeted follow-up survey, opens a corrective task, and notifies the relationship manager. The work, which today takes the team several days, goes on non-stop.
However, you have to draw a line: where the role of the agent ends. The sequence of his actions ends with a recommendation for a person or the creation of a task to be carried out – never by self-execution. Suspension of cooperation, acceptance of residual risk or termination of the contract are decisions with legal and financial consequences, and the responsibility for them rests with specific people in the organisation and cannot be transferred to an AI agent. This is not so much due to an explicit prohibition in the regulations, but to two things at once: the requirement for effective human oversight of high-risk systems, and the fact that both NIS2 and DORA assign responsibility for supplier oversight to management. System autonomy without clearly assigned responsibility is a risk, not a saving. For this reason, agent flows in AdaptiveGRC are designed with human approval points.

Subcontractors and concentration risk: who else is in the supply chain?
The picture would not be complete without a broader perspective. The risk does not end with the direct supplier – it reaches its sub-suppliers and their sub-suppliers. A separate phenomenon is the risk of concentration: dozens of seemingly independent vendors can rely on the same several cloud regions.
Mapping dependencies to such depth has always been possible – for single, key relationships, using the method of interviews and appropriate contractual provisions. It was unfeasible to carry it out for the entire supplier population and keep it up to date. AI does not remove the basic barrier: if a sub-supplier does not disclose its dependencies – and often does not disclose it, citing trade secrets – no model will fill this gap. The real change is different: it is faster to see which relationships deserve an in-depth interview.
NIS2, DORA, ISO 27001: Will AI generate evidence that the regulator will ask?
NIS2 requires supply chain security to be included in risk management measures and provides for the management’s personal responsibility. DORA goes further: it obliges financial entities to keep a register of information on all contracts with ICT service providers, assess concentration risk and demonstrate effective oversight of critical suppliers. It also requires operational resilience testing – a task that no automation can do for the organisation. AI will not perform the test, but it can collect evidence from the course of such a test, save subsequent versions of them and assign them to the supplier’s profile. ISO 27001 requires controlling and monitoring of relationships with suppliers, and the GDPR requires assessment and supervision of processors.
The common denominator of all these requirements is evidence. And evidence is a natural by-product of an automated process that is recorded on the fly – it is created during work, rather than being reconstructed in a hurry before an audit. AdaptiveGRC acts as a register and evidence layer in this system: from the DORA-required register of contracts to the history of assessments, alerts and decisions.
Benefits and business case
The supplier evaluation cycle is shortened because there is no need to wait for a manual review of documentation. The scope of the assessment is growing, because the unit cost is no longer limiting it to the narrow top suppliers. The deterioration of the supplier’s situation comes to light earlier, because between inspections the supplier is observed on an ongoing basis, and not only during the next audit. The amount of manual work with documents decreases, because the analyst receives a ready-made list of discrepancies for verification. And evidence of compliance is created continuously, because every step of the process is recorded.
It is worth keeping the proportions. Most organisations start with a process that generates unnecessary work in itself: according to an EY study, 43% of companies use separate surveys for different risk areas and send an average of 55 questionnaires, 45% of which have between 101 and 200 questions. At the same time, AI solutions supporting in-depth supplier analysis and contract monitoring are the most frequently indicated direction for future investments in TPRM (31% of responses), and only 13% of organisations have reached the highest level of maturity in their use. Therefore, the effect is determined not by the tool, but by the quality of the process into which it is introduced.
Confidence without coverage: where does AI fail in evaluating suppliers?
First, the quality of the data. An incomplete or duplicate supplier register will make the system produce the same erroneous conclusions – given with full conviction – only faster. Second, explainability: a risk assessment that cannot be justified before a regulator or board is useless – even if it is accurate, no one will base a decision on it. Thirdly, false positives – a system that generates more alerts than the team can handle will quickly start to be ignored. Fourth, the tendency to trust automation uncritically: analysts stop questioning results given in an authoritative tone.
Finally, there is a certain irony in this: the provider of third-party AI risk management tools is itself a third party that needs to be evaluated. In addition, the EU AI Act also covers organisations implementing such tools. Whoever automates the supervision of suppliers, ignoring the supervision of their own automation, has not solved the problem – they have only transferred it. A separate article will be devoted to this issue.
Where to start: how to implement AI in TPRM without creating new risks?
Before anything is automated, you need to organise the register of suppliers and their classification. Next, it is worth choosing one area with a lot of manual work – most often continuous monitoring or document analysis – and measuring the real effect in this one area. Implementing everything at once can be postponed. Every decision that has consequences is approved by a person. Everything is subject to registration, because the audit trail is one of the main goals of the entire project. Escalation thresholds must be explicit and agreed upon in advance. Your own AI tools should be evaluated against the same framework that an organisation applies to other vendors. And you need to measure the right thing: the time it takes to detect a significant change in a provider’s risk, not the number of surveys processed.
Where is third-party risk management headed?
The direction is clear: from periodically reviewed lists of suppliers to ecosystems evaluated continuously. The second direction is to exchange credentials between organisations in a machine-readable format that will reduce the perpetual duplication of surveys. The third is agent systems that take over the routine so that expert attention is focused on assessing the situation, negotiating and really new risks.
Key takeaways
- In an environment where a supplier’s risk profile can change overnight, scale, speed, and reach determine the outcome.
- Artificial intelligence does not replace the TPRM process – it scales it. The gain is reach and speed, not a new judgment.
- Continuous monitoring closes the gap between inspections where most supplier issues occur.
- A risk assessment is only useful if it is up-to-date and can be explained.
- Both NIS2 and DORA are awaiting evidence that supplier supervision actually works. In an automated and recorded process, this evidence is created automatically instead of being completed before the audit.
- Responsibility for supplier decisions does not shift to the AI model.
