Breaking News

AI Is Pushing Third-Party Risk Beyond the Annual Review

Written by Maria-Diandra Opre | Oct 1, 2026, 11:59:59 AM

Suppliers change faster than the paperwork used to assess them. Plenty of that paperwork is out there: EY’s 2025 survey found that companies using multiple control assessments sent suppliers an average of 55 questionnaires, most with more than 100 questions. The difficulty comes afterwards, when a supplier introduces an AI tool or changes how it handles customer data, and the answers on file no longer describe the service being delivered (EY, 2025).

Operational risk is now the most common factor companies consider when monitoring subcontractors, cited by 57% of respondents, up from 40% in 2023. Business continuity and resilience also rose to identify critical suppliers, from 14% to 23% over the same period. Companies are responding more aggressively when something looks wrong. Some 87% now escalate internal processes when suppliers fail to respond to assessments on time, compared with 70% two years earlier, while 29% say they may stop doing business with the supplier altogether, up from 17%.

The pressure comes partly from how far supplier networks now extend. A cloud provider relies on infrastructure vendors, software libraries and data processors; a manufacturer may depend on suppliers whose own production rests on another network of contractors. EY notes that what companies still call “third-party risk” increasingly includes fourth-, fifth- and nth-party exposure. Among the organizations surveyed, 64% said their due diligence now includes checking third parties' risk-management programs and their subcontractors’.

A favourable review in January offers little reassurance if a critical supplier is struggling to pay its bills by June. Trouble at one of its subcontractors may be harder still to spot, especially when the next scheduled assessment is months away. This is where AI could make a practical difference: following what happens between reviews. It can help sift financial data, regulatory filings, news and operational figures for developments worth investigating. A credit downgrade alone may tell a risk team relatively little. Put it alongside repeated delivery delays and the knowledge that the supplier would take six months to replace, and there is a much clearer reason to pick up the phone.

Besides, gap between ambition and actual deployment is still quite wide. Only 13% of companies in EY’s survey had reached the highest level of technology and automation maturity in third-party risk management. Yet AI and machine learning for due diligence and contract monitoring ranked as the top future investment priority, cited by 31% of respondents, ahead of data-driven supplier monitoring at 28% and automated due diligence at 27% (EY, 2025).

AI could also help teams notice problems that fall between their responsibilities. Procurement may be tracking missed deliveries while security has just approved the supplier’s controls, with neither team seeing a reason to compare notes. Reading contracts, performance data and external news together could reveal a connection worth investigating. EY gives the example of a supplier whose cybersecurity remains strong while its finances deteriorate. The assessment may be accurate today, but financial pressure raises a question it cannot answer: can the supplier afford to keep those controls working?

That helps explain the move towards centralized oversight. EY found that 57% of organizations now run an enterprise-wide third-party risk program, and these organizations report greater maturity in supplier inventories, risk models and governance. A shared view matters because a supplier that looks replaceable to one department may support several others, making the company’s overall dependence much greater than any single contract suggests.

At some point, AI could make that dependence easier to recognize and changes in the supplier’s condition harder to overlook. But companies will still face uncomfortable decisions about how much business to entrust to a supplier, when to fund an alternative, and whether a cheaper contract justifies the exposure. Better monitoring earns its keep when those decisions change.