Reality, Not Snapshots: Rethinking Third-Party Risk
Every risk discipline carries a habit that outlives its usefulness. In third-party risk management, that habit is the self-attested questionnaire. It is the artifact the whole practice is organized around. A relationship begins, a security questionnaire goes out, the vendor returns a few hundred answers, an analyst reviews them, and the file is closed until next year's cycle. The ritual is so established that it is easy to forget it was built for a smaller, slower, more stable world than the one we operate in now
