Vendor risk, five generations

Every generation of vendor assessment solved the last one's problem

Third-party risk has been rebuilt roughly every five years, and each rebuild was a reasonable answer to how the previous method failed. Questionnaires answered the need for a record. Ratings answered staleness. Detection answered speed. Subprocessor mapping answered depth.

Each also carried an assumption that eventually stopped holding. This is a walk through the five generations, what each one solved, what broke it, and what the AI era asks for that none of them deliver.

Five generations of vendor risk assessment plotted over time Questionnaires from 2005, ratings from 2013, detection and response from 2020, subprocessor mapping from 2023, and the AI era from 2024. Each is shown solid during the period it was built and faded through to the present, because all five are still running. Questionnaires a record that we asked Ratings an answer to staleness Detection time to know Subprocessors depth beneath the vendor The AI era pace and configuration now 2005 2010 2015 2020 2025 Solid: built. Faded: still running.

Nothing here ended. Every method is still running, which is why programs feel heavy — most teams operate five instruments at once, having been resourced for one. Note also that the interval between generations is shortening: ten years to the second, seven to the third, then three, then one.

·