Category: Operational Resilience Author: Cody Swidler Tags: third-party risk, TPRM, reassessment, vendor tiering, monitoring, due diligence
A TPRM program I reviewed a few years ago was, by its own metrics, a machine: 340 vendors, every one reassessed annually, 100% on-time completion, a wall of green. Then one of those vendors — a mid-tier data processor — had a breach that exposed client records. In the postmortem, we pulled their file. They'd been reassessed on schedule, seven months earlier, with a passing score. In the five months after that assessment, the vendor had been acquired, migrated infrastructure, churned most of its security team, and quietly subcontracted the very function we relied on. The annual assessment hadn't been wrong. It had simply been describing a company that no longer existed.
Annual-for-everyone is the default cadence at most organizations, and it fails in both directions at once. For your riskiest vendors, a year is an eternity — acquisitions, migrations, and layoffs happen inside it, invisibly. For your low-risk vendors, an annual questionnaire is pure waste — nobody reads the answers from the office-plant service, and the analysts drowning in those questionnaires are the same analysts who should be spending real hours on the vendors that could take you down. The uniform calendar treats assessment capacity as free. It isn't. It's the scarcest thing in the program.
Let the Risk Score Set the Clock
The fix is to make cadence a consequence of the risk score rather than a policy constant. Score each vendor on exposure — what data they hold, what processes they support — and posture, how well they control it. The combined score tiers the vendor, and the tier sets the clock: the critical tier gets reassessed every six months, the next tier annually, and the long tail every two or three years with a lightweight check. The riskiest vendors get looked at most often, which sounds too obvious to write down until you audit a program and find the opposite: every vendor on the same clock, meaning the payroll processor with two million records gets exactly the attention of the catering company.
Deriving cadence from score has a second, subtler benefit: it makes the cadence defensible. When an examiner asks why a vendor is on a 24-month cycle, the answer is a number and a methodology, not a tradition. And when a vendor's score changes — new data access granted, a posture domain degraded — the clock changes with it, automatically, because the cadence was never a separate decision. This is the same principle I keep coming back to across the whole program, from risk registers on down: derived numbers stay honest; asserted numbers drift.
Events Reset the Clock
A cadence, however well-derived, is still a schedule — and vendor risk doesn't respect schedules. So the second rule is that defined events trigger reassessment immediately, regardless of when the last one happened. Acquisition or merger. A disclosed breach or a serious incident in their stack. Loss of a certification they were tiered on. Material subcontracting of the service you buy — the fourth-party shift I wrote about in the vendor behind your vendor. A change in what you send them: the moment a vendor goes from marketing data to regulated data, their old assessment describes a relationship that no longer exists.
The trigger list only works if someone is watching for the triggers, which is where continuous monitoring earns its place — not as a replacement for assessment, as vendors of monitoring tools like to pitch it, but as the tripwire that tells you which assessment can't wait for its calendar date. Monitoring without a reassessment consequence is just news. The breach report, the ratings drop, the acquisition announcement — each should land as a dated event in the vendor's record that either resets the clock or documents the decision not to.
Make the Reassessment Smaller and Sharper
Risk-driven cadence also changes what a reassessment should be. If your critical vendors are on a six-month cycle, the full 300-question annual questionnaire is the wrong instrument — you'll burn out both sides and get copy-pasted answers by the second cycle. The six-month touch should be a delta review: what changed since last time, in your organization, in your subcontractors, in what we send you, plus fresh evidence for the handful of posture domains that actually drive the score. Save the deep assessment for onboarding, for trigger events, and for an annual anchor. The question count is not the assurance; the freshness of the answers is.
And overdue must mean something. A reassessment that slips past its due date should flag loudly, sit on the TPRM dashboard, and — past a grace window — escalate to the business owner who wants the vendor relationship, not just the analyst who administers it. A program where overdue reassessments accumulate silently has converted its cadence back into a fiction, just a better-documented one.
The Metric That Matters
Notice what this does to the program's headline metric. "Percent of vendors reassessed on time" — the number that made that 340-vendor program look like a machine — stops being the point. The metric that matters is coverage-weighted freshness: what fraction of your actual exposure is described by an assessment recent enough to still be true? A program that reassesses its twenty critical vendors twice a year and its long tail every three years scores worse on the old metric and dramatically better on the real one. That's the trade you want, stated out loud, in your governance forum — because it's the trade the incident will eventually grade you on, as I argued in integrating risk assessments: the point of assessment machinery is decisions, not completion percentages.
The processor that breached hadn't skipped its assessment. Its assessment had simply expired in every way except the date. Cadence earned by risk, reset by events, and enforced by escalation is how you keep the file describing the vendor that exists — rather than the one that signed the contract.
Cody Swidler is the founder of PivotRisk and a Principal Program Manager, Enterprise Resiliency at Apex Clearing. He has built and scaled GRC, resilience, and risk programs across Microsoft, Twilio, Box, Zayo, and Miro.
Cadence that derives itself
The Vendor Risk Assessment template scores exposure and posture, tiers each vendor, and computes the reassessment clock from the tier — with due dates and overdue flags that run automatically.
Get the Vendor Risk Template