Michael Rasmussen on TPRM in 2025: Understaffed Programs, Rising Regulation and Cautious AI
Mitratech
0:00 / 0:00
Michael Rasmussen on TPRM in 2025: Understaffed Programs, Rising Regulation and Cautious AI
11 просмотров · 5 дней назад
Mitratech
824 подписчика
11 просмотров · 5 дней назад
Third-party risk management (TPRM) is under pressure from regulatory change and resource strain. In this OCEG session, Michael Rasmussen (The GRC Pundit and Analyst, GRC 20/20 Research) and Henry Umney (Managing Director, GRC Strategy, Mitratech) review the current state of TPRM using findings from Rebalancing the Risk Ecosystem: The 2025 Mitratech TPRM Study. They explain what resilient TPRM looks like in 2025 and how to start rebalancing your own program.
What you'll learn:
Why nearly 70% of TPRM programs are understaffed and assess only about 40% of their vendors
How regulatory scrutiny has raised compliance team involvement in TPRM from 42% in 2023 to 88% in 2025
Where manual tools and fragmented oversight hold teams back, including the 41% still using spreadsheets for assessments
Why cybersecurity is the top monitored risk (85%), and why more than 50% of firms have had a third-party issue while 65% lack confidence in their incident response readiness
How AI adoption is gaining cautious momentum: 65% of firms are exploring AI and 14% have implemented it
Five recommendations for a resilient TPRM program
Key facts from this video
TPRM has moved from a back-office task to a frontline business imperative.
Nearly 70% of organizations report being understaffed, and about 40% of their vendor population is assessed.
41% still use spreadsheets for assessments.
Top AI concerns are data security, trust in AI decision-making, and bias or hallucinations.
Technology enables efficiency and resilience but cannot fix a poor strategy or process.
FAQs
What is the state of TPRM in 2025? Programs are under pressure from regulation and limited resources. Nearly 70% of organizations report being understaffed, and only about 40% of vendors are assessed.
How is regulation changing TPRM? Compliance team involvement rose from 42% in 2023 to 88% in 2025 as regulatory scrutiny increased.
How many organizations use AI in TPRM? In the study, 65% of firms are exploring AI and 14% have implemented it. Top concerns are data security, trust in AI decisions, and bias or hallucinations.
How should teams start using AI in TPRM? Begin with small, low-risk use cases such as document classification or report summarization, with strong governance and human-in-the-loop oversight.
What are the recommendations for resilient TPRM?
Establish cross-functional governance across procurement, IT security, risk, and compliance, with a "conductor" to coordinate.
Operationalize AI thoughtfully.
Identify and automate bottlenecks to move away from spreadsheets.
Embed compliance requirements in daily risk workflows.
Tier assessments by risk level rather than contract size.
Who should watch this? TPRM, vendor risk, compliance, procurement, and security leaders who want benchmarks and a plan for 2025.
Speakers: Michael Rasmussen, The GRC Pundit and Analyst, GRC 20/20 Research. Henry Umney, Managing Director, GRC Strategy, Mitratech. Presented in partnership with OCEG.
AI Third-Party Risk Management Under Global AI Regulations in 2026: https://mitratech.com/resource-hub/bl...
Third-Party Risk Management Frameworks: The 2026 Guide: https://mitratech.com/resource-hub/bl...
#TPRM #ThirdPartyRisk #GRC #OCEG #VendorRisk #AIinRiskManagement