AI is changing third-party risk management from a periodic, manual process into continuous supplier risk monitoring. Learn how AI can automate due diligence, analyse contracts, detect emerging risks and support better-informed TPRM decisions—while keeping accountability with people.

A modern organisation is largely built with the services of other companies. The infrastructure runs in the cloud, payroll is handled by an external entity, customer support systems are provided by another one – and each of these providers has its own sub-suppliers. As a result, TPRM (third-party risk management) becomes very complicated.

Artificial intelligence in third-party risk management (TPRM) means using machine learning and language models to automate the processes of identifying, assessing and monitoring risks that suppliers and business partners bring to the organisation.

It is worth emphasising right away that AI will not replace the supplier risk management process. Instead, it removes the bottleneck of manual labour, through which the evaluation in practice covers a handful of suppliers, is superficial and happens once a year.

A growing network of suppliers: why has risk outgrown the teams that are supposed to manage it?

The complexity of third-party risk management is due to three phenomena.

First: scale. The number of supplier relationships has grown much faster in recent years than the teams that are supposed to oversee it. Large organisations often can’t even pinpoint how many entities they’re working with, because purchasing, marketing, and individual business units enter into contracts independently of each other. The scale of the phenomenon is well illustrated by EY data from 2025: TPRM programs that have been in operation for less than three years serve 275 providers (median), and those with more than ten years of experience serve 80, because they have learned to prioritise according to risk, instead of evaluating everyone one by one. The dark side of this coin, however, is that some subcontractors “fall out” of the risk assessment process.

At the same time, the internal scope of this process has also changed: in a bank where one or two divisions used to deal with third-party risk, today there may be more than twenty of them.

Second: limited visibility. Traditional supplier evaluation is based on an annual survey – and therefore self-assessment – completed by the party least interested in revealing weaknesses and describing the condition on one day of the year. Such an image quickly becomes obsolete. A supplier that was solvent and well-secured in March may be neither one nor the other in October – and the organisation will only find out about it at the next review.

Third: regulations. The NIS2 Directive and the DORA Regulation have transformed supplier supervision from good operational practice into a documented, accountable obligation. The matter is further complicated by the suppliers of the suppliers themselves. Their problems become the problems of the organisation, although it is not connected by any contract with them.

From a snapshot to a continuous signal: what is AI really changing in supplier risk management?

The change is best described on three axes. Periodic evaluation gives way to an evaluation conducted on a continuous basis. Analysing a sample of suppliers is inferior to analysing the entire population. And the data from formalised surveys are supplemented with unstructured material: contracts, reports, media reports, data from registers.

Equally important is what does not change. Risk appetite, supplier classification criteria, risk acceptance decisions and responsibility for them remain with people – analysts, relationship owners, and management.

TPRM AreaTraditional approachAI-powered approach
Due diligenceManual review of surveys and documentationAutomatic document analysis and detection of requirements gaps
Risk assessmentStatic classification assigned during onboardingDynamic segmentation by criticality and data access
MonitoringAnnual re-evaluationContinuous analysis of cyber, financial and sanctions signals
Contract AnalysisIndividual reading of each documentA database of contracts that is searchable as a data set
Risk scoringResult in a worksheet, rarely updatedResult calculated on an ongoing basis with the inflow of data
EscalationProblem detected at the next inspectionAlert within days of a material change

Segmentation that defends itself: How does AI help determine which suppliers really matter?

The most common mistake TPRM programs make is to evaluate the office supplies provider and central banking platform according to the same logic. Algorithms can classify the entire supplier population according to criticality, sensitivity of the data processed, level of access to systems, geography and substitutability. This ensures that the depth of the assessment is concentrated where the effects of the failure would be most severe.

Analyst’s working day: what can be recovered from it?

A typical onboarding package includes a completed survey, security policy, business continuity plan, audit report or ISO 27001 certification, financial statements, and a contract. A reliable review of such a set takes up most of the working day for an experienced analyst.

Reading and organising such documentation has been automated for a long time. The tools were able to extract dates, scope of certification, names of entities or the presence of required clauses – and they stopped there. What is new is different: the language model compares documents with each other and notices, for example, that the declaration made in the survey is not covered by the content of the security policy. This is the transition from search to inference.

The result is an orderly summary with links to the source material. The decision is still made by the analyst – but he makes it with a ready-made list of discrepancies in front of him, not a pile of documents to read. And it takes it against every supplier, not just the fifty largest ones.

However, the analysis of the documents itself is only the first stage: the evaluation of the supplier usually goes through many hands – the owner of the relationship, the security team, the legal department – and it is the transfer of the case between them, rather than reading the documents, that can be the longest part of the whole process. Automated workflow routes the case to the right person based on the vendor’s classification, keeps an eye on deadlines, and records each approval so that the evaluation doesn’t stop in someone’s inbox.

Continuous supplier monitoring: how do you know that things are wrong between inspections?

Today, a vendor’s risk profile can be maintained as an image that is updated on an ongoing basis, built from sources that no team would be able to track manually. On the cybersecurity side, these are exposed breaches, leaks of credentials and the state of the external attack surface, i.e. what the provider exposes to the public network – open services, outdated software, expired certificates, forgotten test environments.

On the compliance side, sanctions lists, supervisory proceedings, litigation and negative media reports. On the financial side – deterioration of the rating, delays in filing reports or bankruptcy filings.

Language models have solved a problem that has made such monitoring unfeasible for years, namely, reading huge amounts of unstructured text in multiple languages and deciding whether a message is about a specific provider or just a company with a similar name. Now, when a supplier’s situation changes significantly, the organisation learns about it within days, not on the occasion of the next audit.

However, the signal itself is only half the job. Monitoring starts to pay off when alerts fall into an orderly process – with assigned owners, escalation thresholds, and an audit trail. This is how the supplier monitoring module in AdaptiveGRC connects external data to the internal workflow in the organisation.

Supplier Cyber Risk Monitoring: Which Alert Is the Urgent One?

Data about a provider’s security posture only becomes important when compared to what that provider actually has access to. An entity with weak security that doesn’t process anything sensitive is irrelevant. An entity with average security that has administrative privileges over a key system is an incident waiting to happen. Without this correlation, both glow the same orange colour on the desktop. This is all the more important because third-party breaches have become one of the main routes for attackers to enter the organisation.

The scale of the problem is shown in the Verizon Data Breach Investigations Report. In the 2026 edition, a third party was involved in 48% of all violations – 60% more than the year before. Two editions back, it was 15%. The reasons are rarely sophisticated: most often it is the lack or misconfiguration of MFA on the part of the provider and redundant access permissions.

Live news or a monument: what does dynamic supplier risk scoring give?

The risk score given during onboarding loses its connection with reality within a few months. The rating, which is updated on an ongoing basis, changes with each new batch of data and weighs the criticality of the supplier. What is crucial for organisational governance, it can be accounted for: you can always see which signals changed the result.

And predictive analytics goes a step further: based on patterns from previous supplier problems, it indicates relationships that are at risk of deterioration. However, a caveat is necessary here: the maturity of these methods is extremely uneven. Forecasting financial troubles is based on decades of data on bankruptcies, payment delays and rating changes – a relatively solid basis. Forecasting security breaches does not have such a backend: incidents at suppliers are sometimes disclosed selectively, with a delay or not at all, so historical data are fragmented. Prediction in TPRM therefore remains a tool that suggests where to direct attention – not a judgment.

The management and those responsible for risk can only rely on scoring if they can explain its results. That’s why the scoring model in AdaptiveGRC maintains a full history of changes and transparency of criteria – so that it is always possible to indicate where each result came from.

Which contracts include the right to audit, or what does the analysis of contracts and policies by AI give?

Many organisations cannot answer basic questions about their own contracts. Which provide for the obligation to notify a breach and within what period? Which allow subcontracting without consent? Which include the provisions currently required by DORA? Language models comb through the entire pool of contracts and give answers that can be checked in the source text – they turn a cabinet with binders into a searchable data set.

AI Agents at TPRM: What Happens When the System Not Only Responds, But Works?

An AI agent, unlike a regular model, does not answer a single question, but conducts a multi-stage task using various tools. In practice, it can look like this: an agent detects a disturbing signal about a supplier, reaches for their contract and rating history, determines which internal systems this supplier has access to, prepares a summary, creates a targeted follow-up survey, opens a corrective task, and notifies the relationship manager. The work, which today takes the team several days, goes on non-stop.

However, you have to draw a line: where the role of the agent ends. The sequence of his actions ends with a recommendation for a person or the creation of a task to be carried out – never by self-execution. Suspension of cooperation, acceptance of residual risk or termination of the contract are decisions with legal and financial consequences, and the responsibility for them rests with specific people in the organisation and cannot be transferred to an AI agent. This is not so much due to an explicit prohibition in the regulations, but to two things at once: the requirement for effective human oversight of high-risk systems, and the fact that both NIS2 and DORA assign responsibility for supplier oversight to management. System autonomy without clearly assigned responsibility is a risk, not a saving. For this reason, agent flows in AdaptiveGRC are designed with human approval points.

Subcontractors and concentration risk: who else is in the supply chain?

The picture would not be complete without a broader perspective. The risk does not end with the direct supplier – it reaches its sub-suppliers and their sub-suppliers. A separate phenomenon is the risk of concentration: dozens of seemingly independent vendors can rely on the same several cloud regions.

Mapping dependencies to such depth has always been possible – for single, key relationships, using the method of interviews and appropriate contractual provisions. It was unfeasible to carry it out for the entire supplier population and keep it up to date. AI does not remove the basic barrier: if a sub-supplier does not disclose its dependencies – and often does not disclose it, citing trade secrets – no model will fill this gap. The real change is different: it is faster to see which relationships deserve an in-depth interview.

NIS2, DORA, ISO 27001: Will AI generate evidence that the regulator will ask?

NIS2 requires supply chain security to be included in risk management measures and provides for the management’s personal responsibility. DORA goes further: it obliges financial entities to keep a register of information on all contracts with ICT service providers, assess concentration risk and demonstrate effective oversight of critical suppliers. It also requires operational resilience testing – a task that no automation can do for the organisation. AI will not perform the test, but it can collect evidence from the course of such a test, save subsequent versions of them and assign them to the supplier’s profile. ISO 27001 requires controlling and monitoring of relationships with suppliers, and the GDPR requires assessment and supervision of processors.

The common denominator of all these requirements is evidence. And evidence is a natural by-product of an automated process that is recorded on the fly – it is created during work, rather than being reconstructed in a hurry before an audit. AdaptiveGRC acts as a register and evidence layer in this system: from the DORA-required register of contracts to the history of assessments, alerts and decisions.

Benefits and business case

The supplier evaluation cycle is shortened because there is no need to wait for a manual review of documentation. The scope of the assessment is growing, because the unit cost is no longer limiting it to the narrow top suppliers. The deterioration of the supplier’s situation comes to light earlier, because between inspections the supplier is observed on an ongoing basis, and not only during the next audit. The amount of manual work with documents decreases, because the analyst receives a ready-made list of discrepancies for verification. And evidence of compliance is created continuously, because every step of the process is recorded.

It is worth keeping the proportions. Most organisations start with a process that generates unnecessary work in itself: according to an EY study, 43% of companies use separate surveys for different risk areas and send an average of 55 questionnaires, 45% of which have between 101 and 200 questions. At the same time, AI solutions supporting in-depth supplier analysis and contract monitoring are the most frequently indicated direction for future investments in TPRM (31% of responses), and only 13% of organisations have reached the highest level of maturity in their use. Therefore, the effect is determined not by the tool, but by the quality of the process into which it is introduced.

Confidence without coverage: where does AI fail in evaluating suppliers?

First, the quality of the data. An incomplete or duplicate supplier register will make the system produce the same erroneous conclusions – given with full conviction – only faster. Second, explainability: a risk assessment that cannot be justified before a regulator or board is useless – even if it is accurate, no one will base a decision on it. Thirdly, false positives – a system that generates more alerts than the team can handle will quickly start to be ignored. Fourth, the tendency to trust automation uncritically: analysts stop questioning results given in an authoritative tone.

Finally, there is a certain irony in this: the provider of third-party AI risk management tools is itself a third party that needs to be evaluated. In addition, the EU AI Act also covers organisations implementing such tools. Whoever automates the supervision of suppliers, ignoring the supervision of their own automation, has not solved the problem – they have only transferred it. A  separate article will be devoted to this issue.

Where to start: how to implement AI in TPRM without creating new risks?

Before anything is automated, you need to organise the register of suppliers and their classification. Next, it is worth choosing one area with a lot of manual work – most often continuous monitoring or document analysis – and measuring the real effect in this one area. Implementing everything at once can be postponed. Every decision that has consequences is approved by a person. Everything is subject to registration, because the audit trail is one of the main goals of the entire project. Escalation thresholds must be explicit and agreed upon in advance. Your own AI tools should be evaluated against the same framework that an organisation applies to other vendors. And you need to measure the right thing: the time it takes to detect a significant change in a provider’s risk, not the number of surveys processed.

Where is third-party risk management headed?

The direction is clear: from periodically reviewed lists of suppliers to ecosystems evaluated continuously. The second direction is to exchange credentials between organisations in a machine-readable format that will reduce the perpetual duplication of surveys. The third is agent systems that take over the routine so that expert attention is focused on assessing the situation, negotiating and really new risks.

Key takeaways

  • In an environment where a supplier’s risk profile can change overnight, scale, speed, and reach determine the outcome.
  • Artificial intelligence does not replace the TPRM process – it scales it. The gain is reach and speed, not a new judgment.
  • Continuous monitoring closes the gap between inspections where most supplier issues occur.
  • A risk assessment is only useful if it is up-to-date and can be explained.
  • Both NIS2 and DORA are awaiting evidence that supplier supervision actually works. In an automated and recorded process, this evidence is created automatically instead of being completed before the audit.
  • Responsibility for supplier decisions does not shift to the AI model.

Jan Anisimowicz

Head of Efficiency & Innovation | C&F

He has 25 years of experience in data warehousing, Business Intelligence, data analysis, risk, audit and compliance management. His skills include System Architecture and Design, Issue Management, and efficient team management. He currently holds the following certificates: PMP, Prince2, CISM, and CRISC.

View all articles by this author

Fill in the form

    The Controller of your personal data is C&F S.A. with its headquarters in Warsaw, Poland. Your data will be processed in accordance with C&F S.A. Privacy Policy

    Other posts:

    Solutions

    The AdaptiveGRC platform offers a range of modules designed to help organisations manage GRC activities in line with the latest regulations, including DORA and NIS2.

    In order to meet your company's specific needs, our team of experienced developers can tailor the required functionalities to deliver exactly what your company needs. If your company requires a customized module to effectively meet its needs, we can help.

    Let us fit the best solution for your company. Fill out the form below.
    GET CONSULTATION

    Streamline Your GRC Activities with AdaptiveGRC.
    Get Results Faster.

    • Fill out the form.
    • Our consultant will work with you to determine what your company needs.
    • We will schedule a product demo to show you the required features.
    • We will gain your feedback and tailor a tool to your needs.
    Fill in the form

      The Controller of your personal data is C&F S.A. with its headquarters in Warsaw, Poland. Your data will be processed in accordance with C&F S.A. Privacy Policy

      OUR TESTIMONIALS

      Read Gartner reviews to find out what users think about our solutions

      One of the best GRC software with very good price

      Adaptive GRC offers a great deal of flexibility in supporting GRC&AUDIT processes. The product is continuously developed and the customer receives new possibilities and functionalities. In addition, the price is very attractive in comparison to competitive products. The support team takes a flexible approach to the customer's needs.

      Sebastian B. CEO | Computer & Network Security Employees: 2–10

      Comprehensive platform for managing risk and compliance

      I used AdaptiveGRC Compliance and Risk Management modules for more than a year. Implementation went smooth, and the support team was always very helpful. I especially value the functionality AdaptiveGRC offers - all GRC processes can be managed in one tool, and there is a single database. The tool helped my organization lower operating costs and gain a better understanding of risks in the organization.

      Marcin K. Chief Information Security Officer | Financial Services Employees: 51–200

      Perfect program for compliance control

      It is amazing that thanks to AdaptiveGRC individual assessment management can be shortened from days to minutes. The tool can generate reports for different stakeholders containing only their desired assessment outcome data. I appreciate much the possibility of generating compliance specification lists for supplier contracts or internal departments.

      Jasween K. Compliance Pharmaceuticals Employees: 10 000+

      AdaptiveGRC supports insurance companies in their risk and compliance management processes

      I used AdaptiveGRC to 1. support insurance companies' compliance management processes following a complex industry-specific regulation. 2. I also used AdaptiveGRC to support the process of managing and monitoring data processors as GDPR came into effect. I experienced a significant increase in efficiency in both cases.

      Verified Reviewer Insurance | Self-employed

      What's in a name...

      As the name is representative, AdaptiveGRC is a complete, interconnected GRC solution that can be adapted to organizations across industries and size. The AGRC team did a superb job designing and building a best-in-class GRC solution that addresses the challenges faced in today's uncertain and ever-changing global business climate. Working with the AGRC team has been a pleasure and the support they have provided is exceptional.

      D Scott C. Business Development | Biotechnology Employees: 2–10

      Financial institutions could benefit greatly from AdaptiveGRC

      I am happy to be able to use AdaptiveGRC in my work. This dedicated solution is very helpful for anyone that has to fill out the SREP questionnaire. The extra time I gained was priceless. The platform's design was also very appealing to me. The fact that it was so simple to use was a major plus for me. Due to its comparison capabilities with past years' forms, I was able to cut down on the amount of time it took to complete the new questionnaire. What is more, I was able to monitor the progress of the people assigned to the process.

      Anna C. Head of Fin Crimes Team | Banking Employees: 10 000+

      Great support for insurance company

      My overall experience has been great. I also liked the layout of the platform. The time and control I gained is invaluable. I like the fact that it was very easy to use. It definitely allowed me to shorten the time I had to spend on filling out the SREP questionnaire. I also could easily control the status of work of my team members, check their progress, and monitor on daily basis.

      Verified Reviewer Insurance Employees: 201-500

      AdaptiveGRC - Big Player in GRC

      Easy to install and easy to configure. Out of the box solution. Cloud based or Server. AdaptiveGRC is an enterprise governance, risk management and compliance (eGRC) solution set with unique and unequalled capabilities. AdaptiveGRC can be deployed as one fully interconnected solution suite, or you can choose one or more modules.

      Leigh M. National Accounts | Consumer Goods