No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Research

ProcessUnity Research Finds Third-Party Risk Management Confidence Outpaces Breach Reality

Research Conducted with the Ponemon Institute Reveals High Confidence in TPRM Program Maturity Despite Large Numbers of Breaches and Lengthy Assessment Processes

by Corporate Compliance Insights
February 26, 2026
in Research
ProcessUnity Research Finds Third-Party Risk Management Confidence Outpaces Breach Reality

Third-party risk management company ProcessUnity today released its State of Third-Party Risk Assessments 2026 report in partnership with the Ponemon Institute. Based on responses from 1,465 third-party risk leaders and practitioners worldwide, the study reveals a widening gap between confidence in third-party risk management (TPRM) program effectiveness and real-world results.

While respondents claim a high degree of confidence in their assessment processes to reduce breach risk, they reported their organizations average of 12 third-party breaches or security incidents per year highlighting third-party risk as a persistent and material operational challenge.

Although many respondents report established assessment processes, policies, and frameworks, the data suggests that many equate the presence of a program with effective assessments. Despite this belief, most surveyed organizations apply no metrics to evaluate whether those programs actually reduce risk. Frequent breaches, prolonged assessment timelines, slow vendor responses, incomplete remediation, and limited visibility highlighted in this study indicate that effective TPRM maturity remains elusive. The disconnect is particularly pronounced in the financial services and technology/software sectors, where organizations report strong confidence in their TPRM programs while experiencing some of the longest assessment timelines and highest breach exposure (90% of financial services organizations and 85% of technology and software companies reported third-party breaches in 2025).

CCI Publisher Sarah Hadden interviews Scott West at ProcessUnity regarding the research study’s findings. Watch the full interview here.

The findings expose systemic weaknesses that continue to undermine third-party risk programs across organizations worldwide. The following highlights illustrate where programs break down in practice, with the full set of findings detailed in the complete report.

  • Manual program execution remains the norm, slowing assessment cycles and requiring human resources. Nearly two-thirds of organizations still utilize spreadsheets and homegrown or IT-built tools as part of their assessment management and tracking.
  • Delayed vendor responses slow down risk decisions. 60% of organizations report vendor response timelines range from four months to more than 12 months.
  • Non-response remains a persistent barrier. 27% of vendors fail to respond to assessments at all, leaving critical gaps in portfolio visibility.
  • AI adoption emerges as a major accelerator. 50% of organizations reported adopting AI to support third-party risk assessments, and 21% plan to adopt AI in the near future.

“This research shows that many third-party risk programs still lack maturity and fall short on outcomes. Organizations of all sizes invest in TPRM, but that effort doesn’t always translate into efficient, effective assessments or consistent risk reduction,” said Scott West, Vice President of Product Marketing at ProcessUnity. “We invite TPRM leaders and practitioners to use this research to benchmark their programs and build plans to improve measurement, speed, scalability, and visibility to manage third-party risk more effectively.”

The research translates these findings into a blueprint for scaling third-party risk assessments. Organizations can improve outcomes by evolving from periodic reviews to continuous oversight, applying inherent risk to prioritize vendors that introduce the greatest exposure, enforcing accountability for response and remediation, and extending visibility beyond direct vendors to include downstream dependencies and concentration risk. In addition, accelerating AI adoption now enables resource-constrained TPRM teams to reduce manual effort while increasing speed, consistency, and insight across the assessment lifecycle.

“Our research is dedicated to helping organizations improve oversight as third-party ecosystems expand,” said Dr. Larry Ponemon, Chairman and Founder of the Ponemon Institute. “These findings show why scalable execution and measurable outcomes are essential. We surveyed third-party risk leaders and practitioners globally to examine how organizations assess vendors in practice and where modernization is most needed.”

Detailed findings in the report explore assessment timelines, tooling reliance, budget ownership, fourth-party risk, industry and company-size breakouts, and more.

 

Previous Post

Reimagining KYC

Next Post

California’s Prescription for Healthcare Investors: New Restrictions, New Reporting

Corporate Compliance Insights

Corporate Compliance Insights

Corporate Compliance Insights

Related Posts

capitol building

So You’ve Been Subpoenaed by Congress? How to Prepare for Lawmakers’ Grilling

by Robert S. Hoff and Julie A. Edelstein
August 18, 2026

A congressional investigation is a high-stakes event where the response matters as much as the underlying facts

ways and means meeting room

As Midterms Approach, Specter of Transcribed Interviews Rises for Non-Governmental Actors

by Jason McCullough, Diana Shaw and Peter Rechter
August 18, 2026

TIs are informal, but records are kept and they are increasingly being videotaped

federal trade commission building front

You Settled With the FTC; Now Comes a 20-Year Consent Decree

by Tyler Bridegan and Audrey Karman
August 17, 2026

Third-party assessments generally considered costliest part of FTC decrees

double helix of lego

Illinois Genetic Information Protection Act Comes of Age

by Michael C. McCutcheon and Ruby Borja
August 17, 2026

Illinois’ experience with biometric privacy offers a cautionary tale for companies that keep genetic information in the AI era

Next Post
person putting on surgical latex gloves

California’s Prescription for Healthcare Investors: New Restrictions, New Reporting

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights