Part 2 of a Two-Part Series on Third-Party Cyber Risk Management in the Age of Frontier AI
By: Chris Gordon/Senior Solutions Consultant
The traditional third-party cyber risk management model was built for a different operating environment.
Organizations identified vendors, classified them according to risk, distributed questionnaires, reviewed certifications, documented findings, and reassessed them periodically.
That process created structure and accountability. But it was never designed for an environment in which vulnerabilities can emerge continuously, AI can accelerate discovery and exploitation, vendors can introduce new AI capabilities between assessments, and critical exposures can develop long before the next questionnaire arrives.
The answer isn’t to abandon traditional TPCRM. It’s to evolve it.
The strongest programs are moving from questionnaire-led risk management toward intelligence-led risk management—using continuous visibility, business context, and prioritization to determine where action matters most.
Before organizations can govern third-party AI risk, they need to understand what they’re actually exposed to. That sounds obvious. In practice, it can be difficult.
Modern enterprises depend on thousands of vendors, SaaS platforms, APIs, cloud services, open-source components, models, agents, and fourth-party relationships. AI adds another layer.
You can’t govern what you can’t see.
Building and maintaining an accurate inventory of AI usage and third-party exposure is becoming a foundational security capability.
Questionnaires and certifications remain useful components of third-party due diligence.
But they should not be mistaken for continuous visibility.
A questionnaire tells you what a vendor says about its security posture at a particular moment. Continuous intelligence helps you understand how that posture changes.
Modern TPCRM should bring those perspectives together.
Instead of repeatedly asking vendors to complete more assessments, organizations can use external intelligence and technical telemetry to identify meaningful changes in risk and engage vendors with something more useful:
Here is the exposure. Here is why it matters. Here is what needs to be addressed.
That changes the relationship from interrogation to collaboration. And in an environment where both enterprises and vendors face limited remediation capacity, that distinction matters.
AI creates another challenge: volume.
As vulnerability discovery accelerates, security teams will face an increasingly large universe of findings. But more findings don’t automatically produce better security.
Black Kite’s 2026 Supply Chain Vulnerability Report illustrates the problem. More than 48,000 CVEs were published in 2025, and roughly 800 were exploited in the wild. After applying additional context around discoverability, exploitability, and vendor susceptibility, Black Kite identified just 58 that represented genuine, targeted threats to enterprise supply chains.
That’s the difference between finding risk and understanding which risk matters.
Trying to treat every vulnerability labeled “critical” as equally urgent is not a sustainable strategy. Security leaders need context.
Effective prioritization therefore needs to consider more than a severity score. Organizations should evaluate factors such as:
The objective is not simply to identify more risk. It is to identify the risk that matters now.
The same principle applies to the vendor ecosystem.
Not every third party creates the same exposure. A vendor processing sensitive customer information, operating a critical business service, or connecting directly to enterprise infrastructure should not receive the same level of scrutiny as a low-impact supplier with no system access.
Effective TPCRM programs should establish clear risk tiers based on business dependency, data access, operational impact, connectivity, and contractual obligations. That allows organizations to concentrate resources where disruption or compromise would matter most.
In an environment of finite budgets and growing risk, prioritization isn’t a compromise. It’s a requirement.
Organizations are increasingly developing governance frameworks for the AI they build internally. But a significant portion of enterprise AI risk may come from technology they don’t build.
Third-party applications may embed AI capabilities. Vendors may deploy agents inside their own environments. Employees may connect external models to enterprise workflows. SaaS providers may change underlying AI components without materially changing the application the user sees.
This means AI governance and third-party risk management can no longer operate as separate disciplines.
Organizations need governance that addresses both: the AI they operate and the AI they’re exposed to. That includes understanding model provenance, data access, identity and permissions, third-party dependencies, monitoring requirements, and clear accountability when something goes wrong.
Visibility without action doesn’t create resilience. Organizations need processes that connect identification, prioritization, ownership, remediation, and verification.
That may require rethinking traditional change-management processes for genuinely urgent exposures, defining escalation paths before an incident occurs, and establishing clear authority for rapid response. It also means ensuring that security, risk, procurement, legal, and business owners understand their respective responsibilities.
The question shouldn’t be: “Who owns this when something happens?”
That should already be known.
Technology alone cannot manage third-party cyber risk. Contracts remain an important part of the organization’s defense.
Security, legal, procurement, and business teams should work together to establish clear expectations around issues such as:
The goal isn’t to create the longest possible security addendum. It is to establish clear accountability before an incident tests the relationship.
There is one final operating-model shift worth considering. Attackers collaborate extraordinarily well. Defenders often don’t.
Organizations identify the same vulnerabilities at the same vendors, conduct similar assessments, request similar evidence, and independently attempt to resolve the same problems.
There is an opportunity to change that dynamic.
When customers approach vendors with actionable intelligence rather than another questionnaire—and when organizations can share appropriate threat information across their ecosystems—third-party risk management becomes more collaborative and potentially more effective. That is especially important for smaller and mid-sized vendors that may not have the resources of their enterprise customers.
Strengthening the supply chain ultimately requires strengthening its weakest links.
Organizations don’t need to redesign their entire TPCRM program overnight. They can start with a few practical questions:
Frontier AI is accelerating cybersecurity on both sides. The organizations that navigate that shift successfully won’t be those that attempt to eliminate every risk.
They will be the ones that can see what matters, make defensible decisions, and act before risk becomes disruption.
Source