Some vendors are so critical to business functions that organizations have little practical ability to reject or replace them, even when assessments identify material concerns.
Some vendors are embedded so deeply in business environments that the organization has few alternatives. Migration costs, delivery deadlines, service dependencies, and a lack of credible replacements weaken the influence of the TPRM program precisely when the potential impact is greatest.
In these cases, approval can become the expected outcome rather than the result of an open risk decision. TPRM teams may be asked to document a path forward even when the available evidence is incomplete or worse, the identified risk exceeds policy. The organization still carries the exposure, but accountability for accepting it may remain unclear.
New 3rd party research coming soon from HITRUST and CHIME* surveyed over 100 qualified TPRM leaders and found that:
Approximately 29% of CHIME survey respondents agreed or strongly agreed that their organizations had approved vendors beyond stated risk tolerance.
The other CHIME response by TPRM leaders demonstrates the potential impact of these approvals: About 22.6% reported that a vendor incident had caused clinical or operational disruption.
Creation and executive agreement on a decision rights and accountability model, to be able to assign explicit ownership for any approval beyond stated risk tolerance.
Document the rationale, material exposure, mitigating controls, and conditions of approval.
Set time-bound remediation requirements and enhanced monitoring for unresolved risk.
Test continuity arrangements and define an exit or substitution plan, even when replacement is not immediately practical.
Criticality does not reduce vendor risk. It raises the cost of failure and narrows the organization’s options, making transparent governance and accountable risk acceptance more important.
*CHIME Digital Health Analytics. Third-Party Risk Management Assurance: Strategic Market Validation Survey. Commissioned by HITRUST. Ann Arbor, MI: College of Healthcare Information Management Executives, Digital Health Analytics 2026. In July 2026, HITRUST commissioned CHIME Digital Health Analytics to conduct a blinded market-validation survey of 102 qualified respondents from separate healthcare provider organizations with more than $1 billion in annual revenue. Respondents represented security and GRC leadership, TPRM ownership, procurement and vendor management, legal and contracting, and executive leadership. Every participating organization actively managed at least 200 third-party vendors, and 87% managed more than 500.