blog icon

Some vendors are so critical to business functions that organizations have little practical ability to reject or replace them, even when assessments identify material concerns. 

Why It Matters

Some vendors are embedded so deeply in business environments that the organization has few alternatives. Migration costs, delivery deadlines, service dependencies, and a lack of credible replacements weaken the influence of the TPRM program precisely when the potential impact is greatest.

In these cases, approval can become the expected outcome rather than the result of an open risk decision. TPRM teams may be asked to document a path forward even when the available evidence is incomplete or worse, the identified risk exceeds policy. The organization still carries the exposure, but accountability for accepting it may remain unclear.

What the Evidence Shows

New 3rd party research coming soon from HITRUST and CHIME* surveyed over 100 qualified TPRM leaders and found that:

  • Approximately 29% of CHIME survey respondents agreed or strongly agreed that their organizations had approved vendors beyond stated risk tolerance.

  • The other CHIME response by TPRM leaders demonstrates the potential impact of these approvals: About 22.6% reported that a vendor incident had caused clinical or operational disruption.

  • Creation and executive agreement on a decision rights and accountability model, to be able to assign explicit ownership for any approval beyond stated risk tolerance.

  • Document the rationale, material exposure, mitigating controls, and conditions of approval.

  • Set time-bound remediation requirements and enhanced monitoring for unresolved risk.

  • Test continuity arrangements and define an exit or substitution plan, even when replacement is not immediately practical.

What TPRM Leaders Can Do

Criticality does not reduce vendor risk. It raises the cost of failure and narrows the organization’s options, making transparent governance and accountable risk acceptance more important.

Coming Up in the Next Blog in the Series

If you missed the first blog in the series, please check out it here. Be sure to follow HITRUST on Linkedin and X to know when the next blog in the TPRM Top 10 series, Lack of Assurance Comparability, is posted.  


*CHIME Digital Health Analytics. Third-Party Risk Management Assurance: Strategic Market Validation Survey. Commissioned by HITRUST. Ann Arbor, MI: College of Healthcare Information Management Executives, Digital Health Analytics 2026. In July 2026, HITRUST commissioned CHIME Digital Health Analytics to conduct a blinded market-validation survey of 102 qualified respondents from separate healthcare provider organizations with more than $1 billion in annual revenue. Respondents represented security and GRC leadership, TPRM ownership, procurement and vendor management, legal and contracting, and executive leadership. Every participating organization actively managed at least 200 third-party vendors, and 87% managed more than 500.

<< Back to all Blog Posts Next Blog Post >>

Subscribe to get updates,
news, and industry information.

The Only Certification Proven to Work

With a 99.62% breach-free rate among HITRUST-certified environments, HITRUST stands alone in cybersecurity assurance. From third-party risk to internal controls, trust the solution that reduces risk — and proves it.

Engage with HITRUST

Chat Now

This is where you can start a live chat with a member of our team