Site navigation

Is Bad Communication Behind the Rise of Third-party Risks?

Elizabeth Greenberg

,

third-party risks
As supply chains are continually destabilised, managing third party risks is of growing importance. 

Third-party risks are causing increasing issues for organisation security, but research from Gartner suggests that open communication could mitigate vendor risk.

Gartner found that third-party risk mangers are often not reliably communicating any red flags they find in their vendors to compliance teams, leading to an increase of risk.

These managers are most often midlevel managers, directors, and senior vice presidents who have a crucial and unique view into multiple third-parties that compliance leaders deem as high-risk.

“Organisations tend to be working with a lot more third-parties as they are key to accelerating business growth after the various disruptions of recent years,” said Chris Audet, vice president and chief of research in the Gartner Assurance Practice.

“In light of rising sustainability standards that pertain to the use of third-parties, this is an area that has the attention of compliance teams.”

A Gartner survey of about 900 third-party relationship managers in August 2024 revealed that while 95% saw a third-party red flag in the past 12 months, only around half of them escalate it to compliance teams.

“Relationship owners have a unique vantage point for identifying potential risks in third-party relationships,” said Audet. “By empowering them to share insights effectively, organizations can significantly enhance their risk management capabilities.”

The survey showed that three key factors significantly affect the likelihood of sharing: confidence in identifying red flags, objectivity in prioritising third-party issues, and then perceived return on investment (ROI) of sharing information.

“Helping relationship owners to be more confident in identifying third-party red flags should be seen as low-hanging fruit for compliance teams and can likely be addressed with some targeted training or communications,” said Audet.


Recommended reading


When relationship managers develop affinity for their third-parties, however, they are less likely to involve compliance out of fear that compliance may overreact and harm the relationship.

36% of these relationship managers say they feel obligated to protect third-party relationships from people in their own organisations, and a further 27% are reluctant to do anything which might bring harm to the third-parties they manage.

This is especially concerning considering the growing threat of third-party and supply chain risks. In 2024, third-party risks account for 31% of client insurance claims according to Resilience, and nearly a quarter (23%) of material losses over the year.

“Organisations must prioritise effective communication and collaboration with relationship owners to enhance third-party risk management,” said Audet. “By addressing the barriers to sharing and fostering a culture of transparency, businesses can mitigate risks more effectively and align with strategic goals.”

Elizabeth Greenberg

Staff Writer

Latest News

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far

Cybersecurity Security Skills

Report: Cyber Training Gaps Leave Public Sector Exposed

AI

Governance Challenges Derail UK AI Project Progress

AI Climate Energy

AI Net Climate Impact Could Be More Negative Than We Thought