- Risk, Technology
Share
Supplier risk does not wait for the next annual review. Vendors change, subcontractors enter the picture, cyber and financial signals move, and risk teams are left trying to decide which alerts deserve attention.
For Spencer Funke, head of third-party risk management at Edward Jones, earlier visibility buys something every risk team needs: time. “One of the most valuable assets that we have is time,” he said in a recent ProSight webinar. The earlier a team can identify a meaningful supplier risk signal, the more room it has to assess the issue, engage the supplier, develop a mitigation plan, and potentially limit the impact on the business.
That value depends on how the program is built. Panelists pointed to a practical sequence: understand where point-in-time reviews fall short, clean up fragmented data, reduce alert noise, use AI to help with first-pass triage, and keep analysts responsible for judgment.
Start with the limits of point-in-time review. Clarence Chio, cofounder and CEO of webinar sponsor Coverbase, said many companies are shifting from periodic assessments to a more continuous picture of vendor risk because software and service providers are changing faster than annual or biannual reviews can capture. The idea that those reviews can provide a useful picture for an entire year or two, he said, is “gradually fading away.”
Fix fragmented data before adding more feeds. In the webinar’s opening poll, fragmented data across third-party risk management, resilience, procurement, and security teams was cited as the top challenge. Chio said a survey of more than 200 financial institutions showed a similar pattern, with about 40% listing data fragmentation as one of their top three problems. His summary: “data is always the limiting factor.” Better monitoring starts by bringing cyber, financial, operational, compliance, and external intelligence into a view that teams can actually use.
Turn down the noise. More alerts can make monitoring harder. Chio said many risk-intelligence feeds become so noisy that more than 70% of users tune them out or stop operationalizing them after three months. The work is to decide which signals matter for which suppliers, especially where the institution has critical operational reliance.
Use AI as a first pass. AI can help correlate data, identify patterns, and flag which alerts are worth review. Funke said Edward Jones is exploring AI in intake, inherent risk questionnaires, assessment review, and continuous monitoring. For example, AI can extract information such as subprocessor lists or whether an application uses AI, then put that information in front of the business and analysts for review and challenge.
Keep humans in control. “AI is not replacing human judgment,” Funke said. Analysts still make the decisions. AI can help them spend less time scanning documents and more time assessing supplier risk.
The takeaway: Start small. Focus first on critical vendors, one or two useful data feeds, and the signals most likely to drive action. Continuous monitoring should extend the assessment process and help teams identify supplier issues sooner, with clearer context and better judgment.
Become a member to unlock exclusive content, connect with industry experts, and gain access to valuable resources. If your employer is an institutional member, activate your ProSight membership benefits with a simple email address.