
The proxy advisor reckoning: what the DOJ’s August 2026 move means for boards and CFOs Corporate
August 25, 2026Third-party risk management is not working: what the data says and what boards need to do
Third-Party Risk Management | 6 min read | Raayzel Business Consulting
Third-party risk management has been on every board and compliance agenda for years. Frameworks have been built. Teams have been hired. Vendor assessment processes have been designed and documented. And yet, according to KPMG’s 2026 Global Third-Party Risk Management Survey of 851 organisations across all major industries, true integration and effectiveness in TPRM remain elusive for most. The headline finding is precise: only 18 percent of organisations have fully integrated their TPRM programme with enterprise risk management. A further 53 percent describe their integration as mostly in place. That leaves the remaining 29 percent operating TPRM in effective isolation from the broader risk framework that governs how their organisation understands and manages exposure.
This is not a resourcing problem. Most organisations have invested significantly in TPRM over the past five years, driven by regulatory pressure, high-profile supply chain failures, and the expanding role of technology vendors in core business processes. The problem is structural. TPRM programmes are being built and operated as standalone compliance functions rather than as integrated components of enterprise risk governance. The consequence is a risk management architecture that looks comprehensive from the outside and operates with significant blind spots from the inside.
This article examines what the integration failure actually means for boards and CFOs, where the most dangerous gaps are forming, and what a genuinely board-grade TPRM programme looks like in 2026.
What the integration failure actually means
When TPRM is not integrated with enterprise risk management, the organisation is making two separate and inconsistent assessments of its risk landscape simultaneously. The ERM framework produces a view of the organisation’s material risks. The TPRM programme produces a view of vendor and supplier risk. The two are rarely reconciled, which means that third-party exposures are not being reflected in the board’s risk picture in a way that connects them to strategic decisions and risk appetite.
The practical consequence appears in three specific failure patterns that are consistently observed in organisations with fragmented TPRM programmes.
The first is concentration risk invisibility. An organisation may assess each vendor individually and conclude that each one poses an acceptable level of risk. What the fragmented assessment does not surface is the cumulative exposure created by dependencies on a small number of critical vendors or on a common underlying technology or geographic concentration across the vendor base. That aggregate exposure is a material risk that the ERM framework should be managing but cannot, because the TPRM programme has not been designed to feed into it.
The second is escalation failure. When a third-party issue emerges, the TPRM programme identifies it and the vendor management team manages it. Whether it reaches the board, the CFO, or the audit committee depends on informal judgments about severity rather than a defined escalation pathway that connects third-party risk to the governance structure. Issues that should be receiving board-level attention are resolved at the operational level or remain visible only within the TPRM function.
The third is regulatory exposure from incomplete programme scope. Regulatory requirements for third-party risk oversight have expanded significantly across financial services, critical infrastructure, and digital services. DORA in the EU, the FCA’s operational resilience requirements in the UK, and sector-specific guidance from the PRA and ICO all place obligations on how organisations manage and oversee third-party relationships. A TPRM programme that is not integrated with the organisation’s broader regulatory compliance framework is unlikely to satisfy these requirements comprehensively, because the requirements themselves are designed to be assessed at the enterprise level.
Where regulatory pressure is shaping the agenda
The KPMG survey identifies regulatory compliance as the primary driver reshaping TPRM strategy across the globe in 2026, with cyber risk as the second. That ordering matters. It means that most organisations are building and upgrading their TPRM programmes in response to regulatory demand rather than in response to their own assessment of where material risk exists. Regulatory compliance-driven TPRM tends to produce programmes that satisfy the letter of regulatory requirements without producing the operational risk intelligence that makes TPRM genuinely protective.
The Digital Operational Resilience Act, which has applied in full to EU financial services firms since January 2025, is the most demanding third-party risk framework currently in force. Its requirements for ICT third-party risk management, including mandatory contractual provisions, performance monitoring, and exit strategies, have set a standard that other regulators are watching and that UK regulators are likely to reference in the evolution of their own requirements. For organisations with EU operations, DORA compliance is a current obligation. For UK-headquartered organisations without EU operations, the trajectory of UK regulatory development makes the DORA framework a reasonable guide to where domestic requirements are heading.
The FCA’s operational resilience framework requires organisations to identify their important business services, map the third-party dependencies that support those services, and demonstrate that they could restore those services within defined impact tolerances following a disruption. This requirement makes third-party risk a board-level accountability in a way that most TPRM frameworks have not previously been designed to support.
The cyber risk dimension that most TPRM programmes underweight
Cyber risk and third-party risk have converged in ways that most TPRM programmes were not designed to address. The assumption embedded in most vendor assessment processes is that the organisation can evaluate a third party’s cyber posture at the point of onboarding and at periodic reassessment intervals, typically annually. That assumption is no longer adequate.
The threat landscape facing third parties changes continuously. A vendor that passed a security assessment twelve months ago may be operating with known vulnerabilities today, may have experienced an unreported breach, or may have made technology changes that have altered its risk profile materially. The organisations that suffered the most significant third-party cyber incidents in 2025 and 2026 were not organisations that had skipped vendor assessments. They were organisations whose assessment processes did not maintain continuous visibility of their vendors’ security posture between formal review cycles.
Continuous monitoring of third-party cyber risk, using automated tools that provide real-time signals rather than periodic assessments, is the direction TPRM programmes need to move. It is also the capability that most programmes currently lack. Building it requires a deliberate decision to treat TPRM as an operational discipline rather than a compliance activity, which in turn requires integration with the security function, the technology function, and the enterprise risk framework.
What board-grade TPRM looks like
A TPRM programme that operates at board grade has four distinguishing characteristics that separate it from the compliance-driven programmes that represent the current market norm.
First, it produces a consolidated view of third-party exposure that is designed to inform the board’s risk picture rather than satisfy a regulatory checklist. This means that the output of TPRM is expressed in terms that connect to the organisation’s strategic objectives and risk appetite, not in terms of vendor assessment scores and due diligence completion rates.
Third, it is integrated with the enterprise risk framework such that third-party exposures are reflected in the organisation’s overall risk profile, concentration risks are visible at the aggregate level, and the TPRM programme is calibrated against the same risk appetite that governs the rest of the organisation’s risk management activity.
Second, it has defined escalation pathways that connect third-party risk events to the governance structure. When a critical vendor experiences a significant issue, the programme specifies who is informed, at what threshold, and within what timeframe. That pathway is designed before the issue occurs and is tested periodically to confirm it functions.
Fourth, it is maintained dynamically. Third-party relationships change. The criticality of specific vendors shifts as the business evolves. New regulatory requirements impose new obligations. A programme that is designed once and reviewed annually is not adequate for the pace at which the third-party risk landscape is currently moving.
The CFO’s stake in third-party risk governance
CFOs carry direct exposure to third-party risk failures through three channels that are often underestimated. The first is financial: supply chain disruption, vendor failure, and third-party cyber incidents all have direct financial consequences that can materialise rapidly and at scale. The second is regulatory: CFOs who sign off on financial statements and internal control assessments are certifying the adequacy of processes that often depend significantly on third-party services. If those services are not adequately governed, the certification is made on incomplete information. The third is reputational: third-party failures that affect customers, data, or operational continuity carry reputational consequences that the CFO’s financial narrative cannot insulate the organisation from.
The CFO who treats TPRM as a procurement or compliance matter rather than a financial risk governance matter is operating with a blind spot that the organisation’s actual exposure does not afford. The connection between third-party risk and financial risk is direct, material, and in most organisations, systematically underreported to the people who carry accountability for managing it.
The question boards should be asking
The KPMG survey finding that only 18 percent of organisations have fully integrated TPRM with ERM is not primarily a data point about programme maturity. It is a data point about governance architecture. It tells you that in 82 percent of organisations, the board is receiving a view of enterprise risk that does not fully incorporate the exposure created by the organisation’s third-party relationships.
The governance question boards should be asking directly, with the expectation of a specific and evidence-based answer, is not whether a TPRM programme exists. It is whether the programme produces a complete and integrated view of third-party exposure that informs the board’s risk picture and connects to the organisation’s risk appetite and strategic decisions. The distinction between those two questions is the difference between governance that demonstrates TPRM exists and governance that ensures TPRM is working.
Raayzel works with CFOs, Chief Risk Officers, and boards to assess TPRM programme effectiveness, design integration frameworks that connect third-party risk to enterprise risk governance, and build the escalation and monitoring structures that regulators and institutional investors are increasingly expecting to see in place. The work is advisory and execution-oriented, calibrated to the specific third-party landscape and regulatory exposure of each organisation.
Stay ahead of the governance, risk, and compliance agenda.
Sign up for free insights and resources from Raayzel Business Consulting: https://lp.constantcontactpages.com/sl/sBV4psC/insights
Book a free 30-minute consultation wiith us: https://calendly.com/raayzelconsulting/30min




