Every large company has some version of a vendor risk program by now. Vendor inventories, risk tiers, questionnaires, certifications, insurance requirements, and exception workflows all play an important role in understanding and managing third-party risk. But as organizations accumulate more vendors and more assessment data, many still struggle to answer a fundamental question: how much residual risk do those third parties collectively represent? Evidence about individual vendors is not the same as a measure of portfolio exposure.
HITRUST founder and executive chairman Daniel Nutkis argues that this measurement gap has become one of the biggest challenges in third-party risk governance. The industry has built a lot of machinery for tracking vendor activity, but it hasn’t built a common way to measure what’s left over once all that tracking is done. Put simply, most programs can show what they did; few can show how much risk remains.
Plenty of Data, No Consistent Measure
Here is the first important distinction: two companies can hold the same type of report and still be accepting materially different risk. The document is evidence. The assurance it provides depends on its scope, rigor, timing, and the controls actually evaluated.
A review of more than 100 compliance reports illustrates the problem. Are these reports focused on the same controls? Is multifactor authentication, a key security control, included? The answer may surprise you. The report label alone does not tell a third-party risk management team which controls were tested, how rigorously they were evaluated, or what residual risk remains.
An insurance certificate creates a similar blind spot. It confirms that a policy exists, not that a particular loss is covered or that the stated limit is available to one customer. If the same vendor policy must respond to a systemic incident affecting dozens of customers, many organizations may be relying on the same dollars. The certificate is evidence of insurance; it is not a measure of risk transferred.
Limited resources create a second blind spot: coverage is not exposure. Teams understandably prioritize the largest, most critical, or most visible relationships. But reviewing 80 percent of vendors does not mean the organization has addressed 80 percent of its third-party risk. The unreviewed population may contain concentrated access, sensitive data, operational dependencies, or correlated risks that vendor counts do not reveal.
Why a Common Measure Is Necessary, and Hard
The obvious challenge is finding a consistent way to take all that scattered evidence and boil it down into a standardized comparison. Security teams already collect certifications, questionnaires, audit reports, and insurance information, but each offers only a partial view. Without a common framework for evaluating the remaining exposure, organizations often rely on subjective judgments that can vary from one assessor, or one company, to another. A useful measure must also preserve the evidence and assumptions behind the number. Otherwise, standardization merely replaces many opaque judgments with one opaque score.
Let’s compare today’s environment to the consumer credit industry before FICO became widely adopted. Different organizations evaluate risk using different criteria, making it difficult to compare vendors consistently or communicate risk in a way that executives, boards, insurers, and business partners can easily understand. While no single measurement will solve every problem, a more standardized approach could help organizations make more consistent, defensible risk decisions. That was the same situation facing banks before FICO. However, they were focused on consumer credit risk vs. third-party risk. The goal is not a universal verdict that one vendor is safe and another is not. It is a common yardstick that makes assumptions visible and decisions comparable.
What a Common Measure Would Change
With a common measure, risk teams could ask a better question: Does the vendor’s residual risk fall within the company’s tolerance? If it does not, the team could identify the control improvements, contractual protections, or risk-transfer mechanisms needed to proceed. That changes the conversation from pass-or-fail gatekeeping to an explicit decision about what must change, who will own it, and how much risk the organization will retain in the meantime.
The bigger change would happen at the portfolio level. Teams could compare vendors on a common scale, identify concentrations of access or dependency, and test whether aggregate exposure is within the organization’s risk appetite. That matters because risk can appear acceptable one vendor at a time and still become unacceptable when accumulated across hundreds or thousands of relationships. A common measure could also make peer benchmarking more meaningful; today, “high risk” can mean something entirely different from one company to another.
A common measure would not make third-party risk disappear. Vendors will still experience incidents, controls will still fail, and contracts will still contain gaps. What measurement can do is make those tradeoffs visible and governable. Instead of asking only whether a vendor was reviewed, leaders could ask the questions that matter: How much residual exposure are we carrying, is it within our risk appetite, and should we accept it?
- When the AI Breaks Its Own Rules - September 2, 2026
- What It Took to Film a Real-Life Lion King - August 28, 2026
- Your AI Agents Are Multiplying and Nobody’s Counting - August 26, 2026




