Monitoring for changes to drive third-party risk management

Brian K. Lee ( is a Managing Vice President and Dian Zhang ( is a Research Specialist at Gartner in Arlington, Virginia, USA.

When managing third-party risk, compliance teams often focus most of their efforts on initial due diligence and recertification. Although these are important activities, they don’t decrease the risks nearly as much as we think in today’s risk landscape.

According to the 2019 Gartner Third-Party Risk Management Survey, 83% of legal and compliance leaders admitted that they identified third-party risks after due diligence but before recertification, and almost a third of those risks resulted in a material impact. More important, 92% stated that these material risks could not have been identified through initial due diligence. This often occurs because business strategy has changed (54% of the time) or the scope of the relationship has changed (50% of the time).[1]

This document is only available to members. Please log in or become a member.

Would you like to read this entire article?

If you already subscribe to this publication, just log in. If not, let us send you an email with a link that will allow you to read the entire article for free. Just complete the following form.

* required field