Third Party Threat Hunters

Treat Vendors As Part Of The Enterprise with Julie Giaischi

Gregory Rasner Season 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 26:51

Send us Fan Mail

Vendor risk feels like it’s turning into paperwork at scale: endless security questionnaires, overwhelmed vendors, and yet third-party breaches keep climbing. We sit down with Julie Giaischi, CEO and co-founder of the Third Party Risk Association, to challenge the habits that quietly keep programs stuck in compliance theater and to map a path toward measurable risk reduction.

We dig into a core myth that still drives bad decisions: scaling third-party risk management based on the number of vendors. Julie explains why mature TPRM scales by risk and strategic impact, not raw volume, and why soft skills like communication and relationship building become even more critical as AI changes what “doing the work” looks like. We also unpack why standardized questionnaires can create assessment fatigue when they’re treated as a checkbox, and how evidence-based testing and continuous monitoring better reflect the real control environment.

From there, we get practical about the future: AI-powered vendor risk tools, trust portals, and the move toward near real-time assurance that can become predictive, not just reactive. We also address the governance side of AI, including the risk of feeding vendor data into frontier AI when contracts and confidentiality rules say you cannot. Finally, we break down nth-party and fourth-party supply chain risk, including a simple set of questions to identify which sub-tier providers are truly material, plus how to translate benchmarks and risk metrics into board-level messaging that supports budget and action.

If you found this useful, subscribe, share it with a risk leader who is drowning in questionnaires, and leave a review with your biggest TPRM challenge.

Support the show