Back to the module/Third-party risk, from a flat vendor list to a monitored portfolio
The point

A vendor list without tiering forces the same assessment on everyone, which in practice means it reaches almost no one.

A list is not a programme

A third-party inventory at a company of about three thousand people.

The third-party inventory

Every supplier with a contract, however small, and how much of the list has ever been reviewed

Vendors

1,412

Ever assessed

31%

at any depth, at any time

Unknown data access

614

no record of what they hold

Why it matters

Two-thirds of this list has never been reviewed, and for well over a third nobody can say what data they hold. That is not negligence — it is the arithmetic of applying one process to fourteen hundred suppliers.

Treating everyone the same

A uniform assessment is the fairest-sounding policy and the least effective one. The landscaping contractor receives the same ninety questions as the payments processor, the team drowns, and the questions that mattered arrive late or not at all.

Third-party risk, from a flat vendor list to a monitored portfolio | GeneSecure