Trust at Scale: What Security Leaders Are Rethinking About Third-Party Risk
Third-party risk is no longer a narrow cybersecurity or compliance issue. It is a business resilience issue, an operational issue, and increasingly, an AI governance issue.
HITRUST recently brought together nearly 30 executives and senior leaders at the 3M Open in Minnesota for a day of candid discussion, peer exchange, and relationship building. The group represented organizations of all sizes across a range of industries, bringing together leaders responsible for cybersecurity, privacy, technology, and risk. The morning began with a closed-door executive roundtable focused on how organizations can make third-party risk management more efficient, scalable, and defensible. The conversation continued throughout the afternoon with networking and time together at the tournament.
Executives quickly focused on a shared challenge: organizations are managing more vendors, technology dependencies, and AI-enabled services, yet many still rely on fragmented questionnaires and inconsistent evidence to make critical risk decisions.
Key Takeaways from the Discussion
Governance must come before technology
Effective third-party risk management begins with clear ownership, decision rights, risk tolerances, and escalation paths. Technology can support a well-designed process, but it cannot correct unclear accountability.
Organizations also need alignment across security, procurement, legal, compliance, risk, and business teams. When vendor reviews are too slow or disconnected from business priorities, stakeholders find ways around them. The goal should be to help the business make informed decisions faster, not add another barrier to progress.
Third-party risk extends beyond data exposure
Data sensitivity remains important, but it is only one part of the risk picture. A third party may create material exposure because it supports a critical business process, has privileged system access, enables revenue, is difficult to replace, or creates concentration risk across the enterprise.
Leaders therefore need to understand not only whether a vendor could be compromised, but what would happen if that vendor became unavailable or failed to perform. That requires visibility into business dependencies, recovery options, and the potential operational impact of disruption.
More evidence does not always create more confidence
Third-party risk teams are receiving more questionnaires, reports, ratings, certifications, and alerts than ever before. But more information has not necessarily produced better decisions.
The quality, relevance, and scope of the evidence matter. A self-reported questionnaire, readiness review, and independently validated certification do not provide the same level of assurance. An assessment may also be credible but still provide limited value if it does not cover the specific service or environment being used.
HITRUST helps Relying Parties use standardized, independently validated assurance to make more consistent and defensible decisions across their vendor ecosystems. By accepting appropriate HITRUST certifications from vendors, organizations can reduce redundant reviews and improve confidence in the evidence supporting their decisions.
Better signals are essential for scale
Large organizations may manage hundreds or thousands of third-party relationships. Applying the same intensive review process to every vendor is not sustainable.
A more mature approach uses risk tiering and validated assurance to determine where deeper review is needed and where existing evidence is sufficient. This improves the signal-to-noise ratio and allows teams to focus limited resources on the relationships that create the greatest risk.
The objective is straightforward: more vendors should not require more people.
AI is changing the third-party risk equation
AI can help organizations analyze evidence, identify inconsistencies, and manage larger vendor populations more efficiently. It also introduces new uncertainty.
Organizations may not know how vendors are using AI, what information is being exposed to models, how AI agents are governed, or which downstream providers are involved. AI capabilities may also change after a vendor has been approved, making traditional point-in-time reviews less effective.
AI governance cannot stop at the boundaries of the enterprise. It must extend into vendor onboarding, contracting, assurance, and ongoing oversight. AI at scale requires third-party risk management at scale.
Moving from Documentation to Decision-Making
The future of third-party risk management will not be defined by longer questionnaires or larger collections of reports. It will depend on whether organizations can establish strong governance, understand business dependencies, evaluate trustworthy evidence, and communicate risk in terms executives can act upon.
Trust must be earned, validated, and maintained.
HITRUST helps organizations move from fragmented third-party reviews to a more efficient, scalable, and defensible model of cybersecurity assurance.
This discussion is part of HITRUST’s continued commitment to bringing security, privacy, risk, and business leaders together for candid, peer-level conversations. HITRUST will host additional executive leadership discussions in cities across the country throughout the year, creating more opportunities to exchange perspectives and explore practical approaches to today’s most pressing trust and assurance challenges.