When SOC 2 was drafted, its authors did not expect it to apply to companies under 100 employees. Today roughly 90 percent of the organizations going through a SOC 2 are under that threshold.
Part one of this series put the industry data on the table. Part two brings in the other side of the conversation. Nick Norton, co-founder of Geels-Norton (now a Smith & Howard firm) and now leading the cyber risk practice at Smith & Howard, has spent his career issuing SOC 2 reports for high-growth and public SaaS companies. He joins Ryan Patrick of HITRUST and AJ Yawn of Rippling and the GRC Engineering Club for a live, unscripted conversation about where SOC 2 breaks down in third-party risk management, what HITRUST is actually building, and what a workable path forward looks like for the TPRM teams stuck in the middle.
You will leave with a clear read on what a SOC 2 report gives a TPRM team and what it leaves out, how HITRUST positions itself as a third-party risk company, why one audit feeding many reports may be closer than you think, and what still has to change in contracts and procurement before any of it matters.
If you liked this webinar, you may also be interested in:
Third-party Risk Management (TPRM) was built to help organizations understand and govern risk beyond their walls, but the operating model is being overtaken by the ecosystem it is meant to control. Vendor populations are expanding, critical dependencies are deepening, and the evidence used to make decisions is often incomplete, inconsistent, or already out of date.
The uncomfortable truth is that many programs are still organized to process assessments while the business needs them to manage an ecosystem and the associated risks. The result is a widening gap between the volume and speed of third-party risk and the capacity of TPRM programs to respond. Teams spend scarce expertise chasing documents, interpreting incomparable reports, and revisiting basic facts instead of identifying the exposures most capable of disrupting critical operations or compromising sensitive data.
Why This Is Needed Now
Third-party dependence has crossed from a procurement concern into a material source of enterprise exposure. Organizations are adding vendors, concentrating critical operations in a smaller number of providers, inheriting deeper supply-chain dependencies, and relying on point-in-time reviews while risk changes continuously.
The evidence shows that the operating environment is accelerating faster than the traditional review cycle:
- Nearly half of breaches now reach the enterprise through the ecosystem: the 2026 Verizon Data Breach Investigations Report found that 48% of breaches involved a third party, a 60% year-over-year increase.
- The World Economic Forum reported that 54% of large organizations identify supply-chain interdependencies as the greatest barrier to achieving cyber resilience.
- KPMG found that only 15% of TPRM leaders have high confidence in the data underpinning their programs, while just 18% report that TPRM is fully integrated with enterprise risk management.
New research coming soon from HITRUST and CHIME* surveyed over 100 qualified TPRM leaders and found that:
- Nearly 55% of surveyed organizations manage more than 1,000 vendors, yet only 9.8% reported more than 20 dedicated TPRM personnel.
- 62% said their programs would not scale if vendor counts increased by more than 30%
- 48% said they cannot keep pace with assessment volume
- 39% reported onboarding delays caused by backlogs
- Every surveyed organization reported discovering at least one vendor gap or vulnerability after approval
- 23% said a vendor incident had caused clinical or operational disruption
The constraints are not on how much organizations spend. Although 81.4% of respondents reported annual TPRM program costs of at least $1 million, cost ranked last among the challenges presented. TPRM leaders placed greater emphasis that their operating model produces timely, trustworthy decisions at scale.
Together, the issues describe an interconnected operating problem: How can TPRM programs scale without sacrificing the rigor, timeliness, and confidence required to protect critical operations and data?
Introducing the TPRM Top 10
The operating problem facing TPRM leaders is no longer whether third-party risk matters. It is where to focus limited resources, expertise, and investment when vendor ecosystems are expanding faster than traditional review models can keep up. Answering that question requires moving beyond general concern and identifying the operational challenges most likely to determine whether TPRM can scale with the business, sustain confidence in risk decisions, and protect critical operations and data.
The TPRM Top 10 is a new perspective on the most pressing issues confronting modern third-party risk programs. These issues are the ones shaping board discussions, slowing vendor decisions, and consuming scarce expertise. Developed from HITRUST’s ongoing work with TPRM leaders and practitioners responsible for complex third-party ecosystems, it reflects what programs are seeing in the field and where they believe change is most urgently needed.
This list is not presented as a universal ranking or approach for all organizations. Instead, it is intended as a practical guidance for TPRM leaders to modernize their programs. Together, these issues define the work required to move from process-centered vendor review to a more scalable, evidence-driven, and enterprise-relevant model for managing third-party risk.
|
# |
Issue |
What it means |
|
1 |
Vendor Growth Is Outrunning TPRM Capacity |
Vendor populations are expanding faster than TPRM teams can add staffing and review capacity, leaving parts of the vendor portfolio under-reviewed. |
|
2 |
Critical Vendors Become Too Important to Fail |
Some vendors are so critical to business functions that organizations have little practical ability to reject or replace them, even when assessments identify material concerns. |
|
3 |
Lack of Assurance Comparability |
Inconsistent scoring and reporting methods make it difficult to compare assurance reports and results across vendors. |
|
4 |
Manual Work is Consuming TPRM Capacity |
Spreadsheets, questionnaires, and disconnected tools consume capacity that should be spent evaluating and reducing risk. |
|
5 |
Hidden Vendor Risks |
Vague scopes, inconsistent assurance methods, and limited exception reporting can obscure material control gaps until a vendor has already been approved. |
|
6 |
Incorrect or Incomplete Risk Tiering Is Directing Attention to the Wrong Places |
Incorrect or incomplete tiering makes it harder to identify which vendors pose the greatest exposure, spreading scarce resources too thin. |
|
7 |
Limited Visibility Into the Deep Supply Chain |
Organizations often lack a clear view of the subcontractors and other downstream parties supporting their most critical vendors. |
|
8 |
Concentration Risk Turns Vendor Failures Into Enterprise Events |
Heavy dependence on a small number of providers can turn one vendor incident into a broader enterprise disruption. |
|
9 |
Unreliable Vendor Data Undermines Risk Decisions |
Incomplete or unreliable information weakens risk decisions and delays action. |
|
10 |
Vendor Risk Changing Faster Than Reassessment Cycles |
Without timely reassessment, material changes in a vendor’s security posture can go undetected between formal reviews |
Addressing the Top 10 in Practice
This blog launches a series of posts that will explore each of the ten issues in greater detail including why it matters, what the evidence shows, and what TPRM leaders can do to respond. Be sure to follow HITRUST on LinkedIn and X to know when the next blog in the series is posted.
* CHIME Digital Health Analytics. Third-Party Risk Management Assurance: Strategic Market Validation Survey. Commissioned by HITRUST. Ann Arbor, MI: College of Healthcare Information Management Executives, Digital Health Analytics 2026. In July 2026, HITRUST commissioned CHIME Digital Health Analytics to conduct a blinded market-validation survey of 102 qualified respondents from separate healthcare provider organizations with more than $1 billion in annual revenue. Respondents represented security and GRC leadership, TPRM ownership, procurement and vendor management, legal and contracting, and executive leadership. Every participating organization actively managed at least 200 third-party vendors, and 87% managed more than 500.
Traditional Third-Party Risk Management Has Reached Its Operating Limit Traditional Third-Party Risk Management Has Reached Its Operating Limit
Welcome to October, and to Cybersecurity Awareness Month. At HITRUST, we’re using the month to spotlight modern third-party risk management with new research, insights and expert perspectives, and preview product updates designed to help organizations work more efficiently and confidently. Here’s a look at what’s ahead.
Moving From Traditional to Modern TPRM
We’re going to be focusing on third-party risk management (TPRM) over the course of the entire month. Traditional TPRM programs are failing to keep up with the growth and complexity of an organization's vendor and supply chain ecosystem. Vendor populations are expanding, critical dependencies are deepening, and the assurance evidence used to make decisions is often incomplete, inconsistent, or already out of date. We know there is a better way, but the first step in the journey to a modern TPRM program is to recognize the issues on the path and know how to react.
More Product Innovation Ahead
Following the recent releases of Report Center and CSF v11.9.0, we’re announcing an exciting new AI-powered capability in MyCSF designed to help HITRUST certified organizations address a persistent, time-consuming challenge. We can’t share all the details yet, but we can say this: copying and pasting will soon be a thing of the past.
Hear From the Experts
October will offer several opportunities to hear practical perspectives from industry practitioners and security leaders addressing assurance, cyber risk, and vendor oversight challenges.
The second installment of our Assurance Gap webinar series, SOC 2 vs. HITRUST: A Practitioner Debate on What Third-Party Risk Actually Needs, takes place on October 8. Join TPRM and GRC experts Nick Norton, Ryan Patrick, and AJ Yawn as they discuss the strengths, limitations, and real-world applications of today's most common assurance approaches.
Looking for broader industry perspectives? HITRUST experts will also be participating in several industry events where the conversation will extend beyond compliance checklists to the future of cyber resilience and vendor risk. At the CHIME State of Cybersecurity event, we’ll join a panel of industry leaders to discuss the top priorities for CISOs over the next 90 days and how organizations are navigating an increasingly complex threat landscape.
Later in the month, our team will be speaking and exhibiting at Vendor & Third Party Risk USA, in Ft. Worth, TX. If you’re going, be sure to block time to head to Ryan Patrick’s breakout session, Rethinking Vendor Due Diligence: When Cyber Threats Outpace Traditional Assurance.
HITRUST will cap off a busy few weeks with a keynote at GRF Summit on Security & Third-Party Risk, where attendees will gain insights into emerging risks, evolving assurance expectations, and practical approaches for building greater trust across the vendor ecosystem.
If you're responsible for risk management, compliance, or vendor oversight, these sessions offer a chance to hear how peers and industry experts are addressing the challenges shaping the future of assurance.
Don’t Miss Out
If you don’t want to miss out on our content, product news, and events, subscribe to be notified and be sure to follow HITRUST on Linkedin and X. In the meantime, check out our recent Navigating AI Security and Assurance paper and our recent blogs.
October at HITRUST: TPRM Insights, Expert Events, and Product Innovations October at HITRUST: TPRM Insights, Expert Events, and Product Innovations
Navigating AI Security and Assurance: AI Security Requires More than Governance
Artificial intelligence is rapidly moving from experimentation into business-critical operations. The next stage of adoption will increasingly depend on agentic AI systems that can access enterprise data, interact with other systems, and take actions with varying degrees of human oversight.
This transition can create significant business value, but it also expands the potential consequences of insecure AI across organizations and their extended vendor ecosystems.
Traditional information security and AI governance remain essential. Organizations also need reliable evidence that deployed AI systems are protected against AI-specific threats such as prompt injection, data poisoning, and the misuse of privileges granted to AI agents and applications.
Agentic AI Changes the Risk Equation
Organizations continue to expand their use of AI. According to McKinsey’s The State of AI: Global Survey 2025, 88% of organizations report using AI in at least one business function, while 62% of organizations using AI remain in the Experimenting or Piloting phase. Deloitte’s 2026 State of AI in the Enterprise report found that 74% of companies plan to deploy agentic AI within the next two years.
However, relatively few companies have the AI security programs necessary to align with their AI adoption. F5’s 2025 State of AI Application Strategy Report found that 96% of organizations are implementing AI models, but only 2% indicate they are “highly ready” for the challenges of their AI deployments.
The transition from generative AI tools to agentic AI systems represents a meaningful change in organizational risk. Generative AI systems primarily produce content or recommendations. Agentic AI systems may also access data, call APIs, use software tools, communicate with other agents, and take actions on behalf of users or organizations.
As organizations grant AI systems more authority, they can also increase the consequences of a security failure. Many organizations will adopt agentic capabilities through third-party applications and vendor-managed AI services. As a result, an organization’s AI security will increasingly depend on controls that companies throughout its technology and data supply chain implement.
Comprehensive AI Assurance Requires Four Domains
Comprehensive AI assurance requires visibility across four complementary domains:
-
Traditional information security governance
-
Traditional information security
-
AI governance
-
AI security
Together, these domains help organizations determine whether they appropriately govern an AI-enabled system, whether they secure its underlying IT environment, and whether they implement protections for threats that arise specifically from the use of AI.
Many organizations use NIST AI RMF to define AI governance controls and ISO 42001 to demonstrate AI compliance to stakeholders. ISO 42001 provides valuable guidance for establishing AI management systems, accountability structures, and risk management processes. However, this level of AI compliance does not demonstrate that organizations have addressed system-level AI threats within their environments.
ISO 42001 and HITRUST AI Security address different layers of assurance. ISO 42001 focuses primarily on governance, accountability, risk management, and continuous improvement. HITRUST AI Security focuses on security controls for deployed AI systems and their operational protection.
In simple terms, ISO 42001 answers the question, “Are you governing AI responsibly?” HITRUST AI Security Certification answers the question, “Is your AI system secure?”
AI Access Controls Become Critical as Agents Gain Authority
Agentic AI increases the importance of identity, access management, and least privilege because an agent may access enterprise data, interact with applications, invoke APIs, or take actions on behalf of a user. If an agent processes malicious instructions or operates with excessive permissions, an attacker may exploit that authority to access information or perform actions the attacker could not execute directly.
According to IBM’s Cost of a Data Breach Report 2026, 92% of organizations that experienced an AI-related breach lacked proper AI access controls.
Organizations therefore need to evaluate not only whether access controls exist, but also whether they appropriately restrict and monitor the permissions, tools, data, and actions available to an AI system.
Building Assurance for Deployed AI
As AI becomes more embedded in critical business processes, organizations will need more than evidence that they govern AI. They will need reliable evidence that they protect systems using AI against threats associated with their data, models, and actions.
For third-party risk management programs, that means identifying vendors with AI-enabled systems that can access sensitive information, support important operations, make consequential decisions, or take actions within the organization’s environment. TPRM programs should establish risk-based assurance expectations that address both foundational cybersecurity controls and AI-specific threats.
For organizations deploying AI, that means identifying the AI-enabled systems that customers and partners rely upon and demonstrating the security of those systems through a consistent, independently validated approach.
Read Navigating AI Security & Assurance to explore the complete AI assurance landscape and considerations for organizations deploying AI and managing third-party risk.