Third Party Threat Hunters

Beyond The Vendor Questionnaire with Mike Day

Gregory Rasner Season 2

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 23:33

Send us Fan Mail

Your vendor questionnaire might be perfect and you can still be exposed. The real failures increasingly live three or four tiers deep, where you do not have a contract, do not have direct oversight, and often do not even know the dependency exists. I’m joined by Mike Day, Financial Services TPRM lead at Deloitte and host of Third Party Therapy, to get practical about what third-party risk management looks like when regulators, outages, and AI-era supply chains collide.

We unpack why DORA is widely misunderstood as a documentation exercise, and why the intent is operational resilience: knowing which third parties support critical services, de-risking them, and proving you can absorb disruption. We also get specific about fourth-party and nth party risk, including how teams are combining questionnaires with monitoring tools and external data to map hidden relationships and systemic concentration risk.

AI raises the stakes on concentration: many “AI-enabled” products depend on a small set of frontier model providers, which can amplify sector-wide impact and geopolitical sensitivity. From there we move into the future of TPRM: how generative AI can accelerate SOC 2 and vendor documentation reviews, why adoption varies by maturity and governance constraints, and how to break down procurement and security silos by rethinking intake from first principles. Mike closes with a simple quick win: collect data efficiently, ask each question once, and avoid the “data buffet” that slows everything down.

Subscribe, share this with a TPRM or procurement leader, and leave a review. What part of your third-party risk program feels most “stuck” right now?

Support the show