Vendor populations are expanding faster than TPRM teams can add staffing and review capacity, leaving parts of the vendor portfolio under-reviewed.
Third-party ecosystems now include cloud providers, software companies, data processors, managed service providers, consultants, and other external parties. Each relationship can extend cybersecurity, privacy, compliance, and resilience risk beyond the organization’s direct control. Yet the teams responsible for reviewing those relationships remain comparatively small.
The result is a capacity problem with direct business consequences. When assessment demand exceeds available resources, TPRM programs must choose which vendors receive a thorough review, which receive limited scrutiny, and which wait in a growing queue. Procurement slows, onboarding becomes a bottleneck, and full-portfolio due diligence becomes increasingly difficult to sustain.
“You're not able to actually do due diligence on your full vendor portfolio because you don't have enough people." -- TPRM Leader commenting on their capacity concerns
New 3rd party research coming soon from HITRUST and CHIME* surveyed over 100 qualified TPRM leaders and found that:
Nearly 55% of surveyed organizations manage more than 1,000 vendors, and almost 25% manage more than 2,500.
Only 9.8% reported more than 20 dedicated TPRM personnel.
Almost 62% agreed that their programs would not scale if vendor counts increased by more than 30%.
External research also reinforces these findings:
While all vendors should be known and risk-tiered, the goal is not to review every vendor in exactly the same way. It is to preserve meaningful coverage as the vendor population grows, without allowing speed to replace rigor or backlogs to define the risk strategy.
*CHIME Digital Health Analytics. Third-Party Risk Management Assurance: Strategic Market Validation Survey. Commissioned by HITRUST. Ann Arbor, MI: College of Healthcare Information Management Executives, Digital Health Analytics 2026. In July 2026, HITRUST commissioned CHIME Digital Health Analytics to conduct a blinded market-validation survey of 102 qualified respondents from separate healthcare provider organizations with more than $1 billion in annual revenue. Respondents represented security and GRC leadership, TPRM ownership, procurement and vendor management, legal and contracting, and executive leadership. Every participating organization actively managed at least 200 third-party vendors, and 87% managed more than 500.