Back to Blog

Program Planning

Scoping Your Third-Party Risk Program for the Year Ahead

7 min read
Circular planning cycle with vendor coverage nodes, year-end review concept

Year-end is when most vendor risk programs get reviewed, and usually not in a structured way. The review is often prompted by a budget cycle, an upcoming audit, or a close call with a vendor incident that made leadership ask questions. The result is a conversation about what the program covers, what it misses, and whether the current investment level is right. Without a clear framework for answering those questions, the conversation tends to produce either "add more vendors to the questionnaire queue" or "we need a new tool," neither of which necessarily addresses the actual gap.

What follows is a structured approach to the year-end scoping exercise: how to look at what your program actually covered in the past year, where the gaps are, and how to translate that assessment into a concrete plan for the year ahead. It is written for security managers and GRC leads who own the third-party risk function, typically on teams of two to five people.

Start with the Inventory, Not the Risk Ratings

The first question to answer is not "how risky are our vendors" but "what does our actual vendor inventory look like." Most programs have a gap between the vendors in the formal risk register and the vendors that are actually active in the environment. Shadow IT purchases, departmental SaaS subscriptions approved outside the procurement process, API integrations built by engineering teams without formal vendor onboarding: these are common. A year-end review that only looks at the formal risk register misses the exposure that is not in the register.

A practical inventory check involves pulling three sources and comparing them. First, the formal vendor risk register: the vendors your program has assessed, with their current tier assignments and last review dates. Second, the accounts payable or purchasing system: every vendor who received a payment in the past 12 months. Third, a query of your identity provider's application catalog or SSO integrations: every third-party application that employees authenticated to this year. The delta between these three lists is your shadow inventory.

Some items in the shadow inventory will be trivial: a vendor who received a one-time payment for office supplies, a productivity application with no meaningful data access. Others will be significant: a vendor who was paid $200,000 over the year for data processing services who has never been assessed. The year-end review should include a pass through the delta list with a brief triage to identify which items need to enter the formal program.

Audit Your Tier Assignments Against Actual Access

Tier assignments made at onboarding are based on the intended scope of the vendor relationship. Over the course of a year, actual access often diverges from intended access. A vendor whose tier was set based on read-only reporting access may now have write credentials granted to support a specific project. A vendor who was Tier 3 at onboarding may have been integrated into a production workflow in a way that makes them operationally critical.

Check each Tier 1 vendor against two questions. First, is the access they currently have consistent with what was assessed at their last review? If the answer requires more than a single phone call to confirm, the access record is already degraded. Second, if this vendor's service went down for 72 hours starting today, what would the impact be on your operations and your customers? If the honest answer is "significant disruption" and the vendor is not currently in Tier 1, that needs to change.

Tier migration in both directions is normal and healthy. A vendor who was Tier 1 because of extensive integration with a legacy system you have since migrated away from can reasonably be reclassified. Documenting those migrations makes the overall tier distribution more accurate and prevents the list from becoming inflated with historical placements that no longer reflect current risk.

Review Your Coverage Against Your Questionnaire Cycle

Look at which vendors were actually assessed in the past year versus which ones were due for assessment. In programs running manual questionnaire processes, it is common for 20 to 30 percent of scheduled reviews to slip past their due dates, usually because the questionnaire process is expensive and the team's capacity is finite. The slippage is rarely evenly distributed: low-priority vendors tend to slip, but occasionally a higher-priority vendor slips because of scheduling coordination problems.

For each vendor whose review is more than three months overdue, ask whether the delay creates an actual risk exposure or just a documentation gap. A Tier 3 vendor who processes no sensitive data and whose last assessment was clean is a documentation gap. A Tier 2 vendor who handles internal financial reporting data and whose last assessment was 18 months ago may be an actual gap.

The year-end review is also a good time to look at the vendors whose questionnaire responses were completed but whose answers raised questions that were not followed up on. Most programs have a handful of these: a vendor who answered "partially" to a critical control question, a vendor whose questionnaire noted a pending SOC 2 audit that was supposed to be complete six months ago. These represent latent risk items that the questionnaire process surfaced but did not resolve.

Identify the Monitoring Gaps

For programs that are using some form of continuous monitoring, year-end is the time to look at what the monitoring actually caught versus what it should have caught. Did any vendors in your monitored portfolio experience incidents that your monitoring did not flag ahead of formal disclosure? Were there signals that appeared in the monitoring feeds that were dismissed at triage but in retrospect warranted follow-up?

This retrospective is valuable because monitoring programs accumulate calibration data over time. Alert thresholds that produced too much noise in month one are often still set at the original level. Vendors that were added to the monitoring roster in high-priority tiers may have proven to be quiet, while others added as lower priority may have shown more signal activity than expected. The year-end review is the right moment to adjust those configurations based on what the past year actually looked like.

For programs that have not yet added continuous monitoring to their Tier 1 coverage, the year-end review is a natural decision point. The question to answer is whether there were any situations in the past year where you learned about a vendor risk issue after you would have wanted to know about it. If the answer is yes, and especially if the delay created any compliance, operational, or customer-facing consequence, that is the case for investing in monitoring coverage for the vendors involved.

Set the Scope and Priority for the Year Ahead

With the inventory review, tier audit, coverage assessment, and monitoring review in hand, you can make concrete decisions about next year's program scope. The decisions fall into three categories.

The first category is the vendor register: which new vendors need to be formally onboarded into the program, which existing vendors need tier changes, and which can be removed because the relationship has ended. A clean register is operationally important because it determines your questionnaire workload for the year.

The second category is review cadence: are you running annual reviews for all Tier 1 vendors, and is the schedule realistic given your team's capacity? If the answer to the second part is no, the choice is either to increase resources or to adjust the scope of what each review covers. A lighter-weight attestation review combined with continuous monitoring coverage can provide adequate assurance for some Tier 1 vendors, freeing capacity for full questionnaire reviews on the highest-consequence relationships.

The third category is monitoring coverage decisions: which vendors will be added to or removed from continuous monitoring feeds, and whether the current monitoring investment is appropriately targeted at the vendors that warrant it. This is not just a budget question. It is a judgment about where your program's detection coverage needs to improve and where it is already adequate.

The Document Is Not the Output

The year-end scoping review produces documents: an updated vendor register, a revised tier distribution, a plan for the monitoring program. But the real output is a shared understanding among the security team, the GRC function, and leadership about what the vendor risk program actually covers and where its limits are. That shared understanding is what enables the right escalation decisions when a vendor incident occurs during the year and the team needs to quickly assess whether the program has the information needed to respond.

A scoping exercise that produces a clean document but leaves the team without a clear sense of which vendors they are most worried about has missed the point. The document should be a record of decisions that the team has already made, not a planning artifact that gets filed and forgotten until the following year.

See continuous vendor monitoring in action

Magnitude monitors your vendor portfolio around the clock for security, regulatory, financial, and operational signals. Request early access and your roster is live within one business week.

Request Access

More from the blog