Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI-driven third-party vetting: what it means for GRC teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: 75% of IT and security professionals believe AI adoption is outpacing their ability to vet third parties, while 87% expect to rely more on AI-driven capabilities and 82% think agentic AI will improve vetting speed and reliability, according to Drata. Point-in-time vendor review is becoming a weak control when vendor AI footprints change continuously.

NHIMG editorial — based on content published by Drata: the final post in its five-part series on the State of GRC in the Age of AI report

By the numbers:

Questions worth separating out

Q: How should organisations assess third-party AI risk in vendor contracts?

A: Organisations should assess third-party AI risk by combining standard vendor checks with AI-specific review of model lineage, training data provenance, autonomy, human oversight, and change control.

Q: Why does point-in-time vendor vetting fail in fast-changing environments?

A: Because it assumes the supplier remains materially unchanged after the last review.

Q: What are the warning signs that third-party assurance is too stale to trust?

A: Common signs include long gaps between reviews, heavy reliance on attestation without fresh evidence, and no trigger for material product changes.

Practitioner guidance

  • Replace annual vendor approval with trigger-based reassessment Create review triggers for AI feature launches, data-flow changes, new integrations, and material control changes so vendor risk is reassessed when posture changes, not when the calendar turns.
  • Bound AI agents used in TPRM workflows Assign each agent a narrow evidence-gathering scope, explicit source allowlists, and mandatory human review for final risk decisions and exceptions.
  • Treat trust centers as evidence, not assurance Require independent validation of trust center claims against questionnaires, attestations, and any contractual security obligations before accepting them as current.

What's in the full article

Drata's full post covers the operational detail this analysis intentionally leaves for the source:

  • How its trust center and third-party risk workflow are structured for continuous vendor review
  • The specific operational sequence for automating evidence collection and summarisation
  • Examples of how AI-assisted vetting is expected to fit into procurement and GRC workflows
  • The vendor's framing of trust center adoption and the workflow changes it claims to support

👉 Read Drata's analysis of AI-driven third-party vetting and trust centers →

AI-driven third-party vetting: what it means for GRC teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Point-in-time vendor assurance is becoming governance debt. Annual review models were always a compromise, but AI makes that compromise visible. When vendors can ship material capability changes between reviews, the last attestation stops describing the live service. For security and GRC teams, the problem is not more paperwork. It is the inability of snapshot governance to track a moving supplier risk surface.

A question worth separating out:

Q: Should trust centres replace independent third-party risk reviews?

A: No. Trust centres can improve visibility and speed by giving buyers a more current posture view, but they are still supplier-provided evidence. They should feed the review process, not replace validation, contractual checks, or the buyer's own risk judgement.

👉 Read our full editorial: AI-driven third-party vetting is replacing point-in-time reviews



   
ReplyQuote
Share: