blog icon

Vendor populations are expanding faster than TPRM teams can add staffing and review capacity, leaving parts of the vendor portfolio under-reviewed.

Why It Matters

Third-party ecosystems now include cloud providers, software companies, data processors, managed service providers, consultants, and other external parties. Each relationship can extend cybersecurity, privacy, compliance, and resilience risk beyond the organization’s direct control. Yet the teams responsible for reviewing those relationships remain comparatively small.

The result is a capacity problem with direct business consequences. When assessment demand exceeds available resources, TPRM programs must choose which vendors receive a thorough review, which receive limited scrutiny, and which wait in a growing queue. Procurement slows, onboarding becomes a bottleneck, and full-portfolio due diligence becomes increasingly difficult to sustain.

“You're not able to actually do due diligence on your full vendor portfolio because you don't have enough people." -- TPRM Leader commenting on their capacity concerns

What the Evidence Shows

New 3rd party research coming soon from HITRUST and CHIME* surveyed over 100 qualified TPRM leaders and found that:

  • Nearly 55% of surveyed organizations manage more than 1,000 vendors, and almost 25% manage more than 2,500.


  • Only 9.8% reported more than 20 dedicated TPRM personnel.


  • Almost 62% agreed that their programs would not scale if vendor counts increased by more than 30%.

  • 48% of TPRM leaders agreed they can’t keep pace with assessment volume, while 39% indicated they already have backlogs which have delayed vendor onboarding. 


External research also reinforces these findings:

  • The Venminder State of Third-Party Risk Management 2025 paper reports, “Despite managing more vendors, TPRM staffing has not increased proportionally. Programs with 1-2 full-time employees rose from 43% to 48%, while those with 6-10 FTEs dropped significantly (from 10% to 4%).”
  • The Ncontracts State of Third-Party Risk Management 2026 report states, “Most TPRM programs operate with minimal staffing while managing substantial vendor portfolios. Nearly two-thirds (63%) run on just 1-2 dedicated employees, and another 13% have no dedicated staff at all. At the same time, over half (53%) manage 300+ vendors, creating ratios where individual professionals oversee 100+ vendor relationships.”

What TPRM Leaders Can Do

  • Apply risk-tiered assurance so the most rigorous reviews are reserved for the relationships capable of causing the greatest harm.
  • Use standardized, independently validated assurance to reduce repetitive review work and reliance on one-off evidence requests.
  • Automate evidence collection, control mapping, reminders, and routine reassessment activity where human judgment is not required.

While all vendors should be known and risk-tiered, the goal is not to review every vendor in exactly the same way. It is to preserve meaningful coverage as the vendor population grows, without allowing speed to replace rigor or backlogs to define the risk strategy.

Coming Up in the Next Blog in the Series

If you missed the first blog in the series, please check out it here. Be sure to follow HITRUST on Linkedin and X to know when the next blog in the TPRM Top 10 series, Critical Vendors Become Too Important to Fail, is posted.  


*CHIME Digital Health Analytics. Third-Party Risk Management Assurance: Strategic Market Validation Survey. Commissioned by HITRUST. Ann Arbor, MI: College of Healthcare Information Management Executives, Digital Health Analytics 2026. In July 2026, HITRUST commissioned CHIME Digital Health Analytics to conduct a blinded market-validation survey of 102 qualified respondents from separate healthcare provider organizations with more than $1 billion in annual revenue. Respondents represented security and GRC leadership, TPRM ownership, procurement and vendor management, legal and contracting, and executive leadership. Every participating organization actively managed at least 200 third-party vendors, and 87% managed more than 500.

<< Back to all Blog Posts Next Blog Post >>

Subscribe to get updates,
news, and industry information.

The Only Certification Proven to Work

With a 99.62% breach-free rate among HITRUST-certified environments, HITRUST stands alone in cybersecurity assurance. From third-party risk to internal controls, trust the solution that reduces risk — and proves it.

Engage with HITRUST

Chat Now

This is where you can start a live chat with a member of our team