I once heard someone say, with genuine excitement: “I’m pleased to note that we have an extremely low-risk third-party population. In fact, 95% of our third parties have been ranked as low risk, and we have absolutely no high-risk third parties. Congratulations to us!”

Wait, what? To some, it will sound like good news. It sounds like the kind of result that should make a compliance team feel confident. But, in my experience, a third-party population that is almost entirely low risk—with no high-risk third parties at all—may be telling you something very different.
That’s why every year, it’s time for a refresh.
Your Risk Changes Year-to-Year, so should Your Review
Your third-party population changes. Your business changes. Your geographic footprint changes. Your regulatory environment changes. The services your third parties provide can change. Not to mention the access third parties have to your people, systems, customers, funds, and decision-makers. A risk model that was sensible last year may no longer be giving you the right answer today.
That is why every third-party program should be refreshed or, at a minimum, formally reviewed on a regular basis. Annually is ideal. Every two years may be reasonable in some organizations, depending on the size, complexity, and risk profile of the program. The important point is that the review should be deliberate, documented, and based on evidence – not simply an informal sense that everything seems to be working.
How to Do a Quick Review
If this all sounds like too much work, fear not! It doesn’t have to be a massive exercise.
Start with the risk model
The first question is whether or not your risk model still reflects the risks your organization faces. This is not about changing the model simply to produce a more dramatic distribution of high-, medium-, and low-risk third parties. It is about testing whether the questions, weighting, thresholds, and escalation rules still make sense.
Update the external inputs
Review the external information that informs your model. For example, if you use Transparency International’s Corruption Perceptions Index, make sure you are using the most recent available edition rather than relying on a prior year’s data. Country risk can move, and the information used to assess it should move with it.
Test the logic against the business
Ask whether the risk factors in your model reflect the way your business actually operates. Are you appropriately considering factors such as government touchpoints, use of intermediaries, access to confidential information, handling of funds, ownership and control, the nature of the services provided, and the locations in which work is performed?
Then look at the output. What types of third parties are entering your review process? What kinds of reviews are they receiving? Does the escalation path still make sense? Are desktop reviews and enhanced, on-the-ground due diligence reports being ordered when the facts call for them?
If the answer is that you have no high-risk third parties and therefore no enhanced reviews, that is not necessarily a success story.
Look at the numbers
A refresh should include a basic statistical review of the program. The numbers will not tell the whole story, but they can show you where to ask better questions.
- How many third parties are in scope, and how has that number changed year over year?
- How many are classified as high, medium, and low risk?
- Does the distribution make sense given your business model, geography, and third-party activities?
- Are there unexpected concentrations by country, business unit, service type, or risk category?
- Are there outliers or results that look unusual enough to investigate?
- How often are risk ratings overridden, and why?
- How many enhanced reviews are being ordered, completed, approved, or declined?
The goal is not to manufacture a particular spread between high, medium, and low risk. The goal is to determine whether the spread is credible—and whether the program is producing results that a knowledgeable reviewer would recognize as plausible.
Ask the people using the program

Program owners do not always experience the program in the same way as the people who use it. Consider conducting a short survey, focus group, or interviews with key stakeholders in your program. That might include people in procurement, sales, finance, business sponsors, legal, internal audit, and other people who initiate or manage third-party reviews.
Ask practical questions.
- Do they understand when a review is required?
- Are the requests clear?
- Are the questions relevant?
- Do they know what happens after they submit information?
- Where do they experience delays, confusion, or unnecessary duplication?
- What makes them crazy about the process?
- What would they change?
These conversations may reveal that the program is working well in principle but is difficult to navigate in practice. They may also reveal that certain types of third parties are being handled inconsistently, or that business teams have developed workarounds that are invisible in the central data.
Measure how the program performs
A good refresh should examine not only the risk decisions being made, but also how effectively the program makes them. Consider reviewing:
- Time from the request for due diligence to the receipt of the completed information.
- Time from review initiation to approval, rejection, or escalation.
- The number and age of open reviews.
- The number of mitigating actions assigned, their owners, and whether they are completed on time.
- Recurring mitigating actions or themes that may point to a broader control issue.
- The frequency of incomplete submissions, rework, and manual intervention.
- Whether the team has the capacity, expertise, and support needed to operate the program effectively.
Mitigating actions deserve particular attention. If the same actions appear repeatedly, that may indicate a trend in the third-party population or a weakness in the way the organization manages a recurring risk. If actions are being assigned but not tracked to completion, the program may be identifying risk without actually managing it.
Document the review
Regulatory expectations are one reason to conduct this work. Program credibility is another. You should be able to show what you reviewed, what data you considered, what you found, what decisions you made, and why.
That documentation does not need to be a 100-page report. A clear record of the methodology, key statistics, stakeholder feedback, identified gaps, action plan, owners, and deadlines may be enough. What matters is that the organization can demonstrate that the program is being actively managed rather than allowed to run on autopilot.
Want to make the review documentation easy? Speak it into a ringfenced AI and ask it to create your report. It’ll be done in minutes.
Ask your technology providers what is coming next
Finally, call your technology providers and ask to see their product roadmap. Your providers may be developing capabilities that could improve screening, workflow, reporting, monitoring, case management, or the user experience. Understanding what is coming can help you plan improvements rather than discovering them after your next renewal or implementation decision.
It is also worth asking what they are building or considering around agentic AI. There are exciting developments underway that may help compliance teams perform parts of the third-party lifecycle faster and more consistently, from gathering information and triaging cases to identifying patterns and supporting ongoing monitoring.
That does not mean handing judgment over to a machine. It means understanding where technology may be able to reduce administrative effort, surface issues earlier, and give experienced professionals better information on which to base their decisions.
The bottom line
A third-party program should not be judged by how reassuring its dashboard looks. It should be judged by whether its risk model is current, its outcomes are credible, its escalation process is functioning, its mitigating actions are tracked, and its users can operate it effectively.
Everybody needs a refresh now and then. Your third-party program is no different.
(By the way – if you are interested in hearing more about how emerging technology and agentic AI may support the future of third-party risk management, please contact me at kgranthart@diligent.com)