Go back

The Invisible Risk Chain and Why Your Vendor's Vendor Impacts Growth with Girish Redekar

25m 22s

The Invisible Risk Chain and Why Your Vendor's Vendor Impacts Growth with Girish Redekar

The discussion emphasizes the critical role of Third-Party Risk Management (TPRM) in today's fast-paced, AI-driven business environment. Traditional vendor risk management is often outdated, relying on static assessments during procurement that fail to provide ongoing visibility into vendor activities, leading to significant blind spots. This issue is compounded by fourth-party risks, where companies are accountable for failures in their vendors' supply chains, even without direct control. The advent of AI further complicates risk mapping by introducing non-deterministic, dynamic dependencies that can change autonomously, making governance more challenging. Poor TPRM directly impacts business outcomes, as enterprise buyers increasingly demand continuous risk monitoring, and inadequate visibility can stall sales and revenue growth. Looking ahead, the future of TPRM requires autonomous, technology-driven solutions to provide real-time oversight of both known and shadow vendors, enabling companies to manage expanding risk chains effectively while maintaining trust and accelerating growth.

Transcription

4336 Words, 24274 Characters

English
Increasingly, there is more and more pressure for companies to go faster. The advent of AI, companies are expected to be able to become more productive and they have to basically be able to go faster and faster. So, if you think of your company as a faster ASCA, you can only go as fast as you can if you can trust the breaks. And your TPRM program is fundamentally that. It's basically giving you the confidence that you have the right breaks. That if you, that's so that gives you the confidence to go as fast as you want to go. Because that's what you will need if something were to go wrong. And you want to know basically if something were to go wrong before it goes wrong. So, I think of it like that. So, you know, it's like you want a fast car, you better trust the breaks. And your TPRM program is simply that. So, that's my one takeaway from this. Hello, ladies and gentlemen. And welcome to our Risk Management Show Podcast where we explore critical trends and strategies shaping risk, security and leadership today. I'm your host Boris Agaranovich, founder and CEO at Global Risk Community. And our guest today is Girish Redicar. Girish is a co-founder of Sprinter, which is an AI native GRC platform. So, Girish, welcome to our Risk Management Show Podcast today. Thank you for having me, Boris. I'm really excited to be here. Absolutely. It's my pleasure. And I believe we will have a very thoughtful conversation on the topic of the invisible risk chain and why your vendors impact growth. So, it's very hard topic in about third party, even fourth party risk. But before that, Girish, could you tell us a short story about yourself, your career path and what brought you to where you are right now and what you guys at Sprinter are up to these days? Sure. I think quickest way to describe myself is, I'm an engineer first. I'm happiest when I'm writing code and building product. At Sprinter, we are an autonomous GRC platform. We try and help our customers to maintain and build a trust program around governance risk and compliance. I had a rather incidental journey to where I am today. I think a few lucky things happened in a certain way for me to land in the place that I am at today. I did a startup before Sprinter. And that was in a completely undrated area. But one of the things that happened while we were growing that startup is that we started getting asked for security and privacy complices, like SOC 2 and ISO 201 and GDPR and HIPAA and those kind of things. And as an engineer, I got a front row seat to what these complices mean because it was my job to try and get the company compliant with these things. So I learned these things on the job. Long story short, I hate in the way it worked, not in terms of what happens because of compliance. We actually became a lot more secure and a better product as a result of it. But I didn't like the way we actually went about it. It was extremely manual. There was a lot of paper pushing, document-based process, etc. And in part, Sprinter was born out of that pain. You know, when we were thinking about what to do next, this was one of the experiences that stayed with us. And we thought that it should be a better way for companies to be able to build trust with their customers, their partners, their auditors, their board of directors. And that was the germination point of Sprinter. So yeah, that's a little bit about me. I have a rather, you know, while I have built and grown two startups as businesses, my lens to most problems is an engineer's lens. That's how I tend to look at these things. But yeah, that's a little bit about me. No, fantastic. So let's go deep into our topic. So what does a vendor risk management actually look like inside the most companies? And where do you do blinds spots typically form? You know, funnily, in most organizations, vendor risk management is still built like it was, you know, 20 or 30 years ago. It's extremely, you know, questionnaire driven, it's pointing time. So fundamentally, what happens is during when you're onboarding a new vendor as a company, you send over a spreadsheet or a questionnaire during procurement, the vendor responds to that with policies and documentations and certifications. And you sort of go over them and, you know, you file them away as due diligence. And while that process creates a, you know, a comforting illusion of the fact that you've had some oversight, what really happens in practice is that the moment that contractors sign, you know, the system sort of stops observing the reality. And what starts happening since then is that, you know, blinds spots start appearing almost be immediately like, you know, what you as a team have no visibility into what the vendors are really deploying after they get onboarded inside of your company. If they are changing their infrastructure or, you know, increasingly now vendors use AI models. If they change any dependencies on those AI models, if they started introducing new subcontractors and they didn't disclose it to you as a company, you know, there are silent updates that keep happening under the hood, which may not be even apparent to you as a company and, you know, the data flows in the vendor that are evolving over time. So, you know, most companies believe that they are governing vendors, but in reality, they're just governing a snapshot of the vendor. And that snapshot was created at the procurement time. And you probably go back and, you know, look at those vendors once a year later. But it's not like, you know, you actually have an ongoing picture of how the vendors are behaving and what is it really like to use them. So, you know, like the simplest way to think about the analogy is that it's vendor due diligence in most companies works like, you know, you check somebody's driving license and they're driving record ones, but you give them the keys to your car forever. That's definitely the way you do vendor due diligence today. And I think, you know, blind spots come because of that and that's changing as we speak because companies are realizing that's that's not a tenable position anymore. And now we have a quick message to share. If you were listening to this podcast, it probably means you have a keen interest in risk and compliance. You're not alone as globalriskcommunity.com has already more than 100,000 active members. Together, we share knowledge, resources, and the latest events. On top of that, global risk community is a great and easy way to network and broaden your opportunities. Visit globalriskcommunity.com and sign up as a member. The link is in the description. Thank you for listening. Now back to the episode. All right, you gave a very nice analogy. So why is the fourth party risk so hard to see and why our company is still accountable for systems they don't control? And what party is harder because you at least know who your third-party vendors are. Like you signed a contract with them. You went through some process with them. But the fourth party by definition are your vendors, vendors. And, you know, for example, you signed a contract with vendor A. But vendor A internally, you know, is dependent on a bunch of other vendors. Like they have a cloud provider. They could have a machine learning infrastructure vendors. You know, they have third-party APIs that they're using. They have their own data suppliers. They embed their own AI models now increasingly. They have outsource development teams, etc. And each of those links is introducing new software, new data, new flows, new operational dependencies that your organization is going to inherit automatically, whether you know it or not. And the counter-pity problem is only you know sort of multiplying once you sort of peel that layer and look behind the curtain. Because increasingly your regulators, your customers, your auditors, you know, they don't care where the failure originated. They only care where the responsibility is. So, you know, you may not have visibility to your fourth parties and beyond. But the responsibility still with you is something wrong happens over there. So specifically, you know, if a subcontractor exposes your data, or if a model behaves unsafely, or if a vendor relies on unlicensed data sites or the liability lines with the company that is actually, you know, delivering the product of the service. So my simple example of again thinking about this, and I like to give simpler analogies is that, you know, when a car gets recalled because of some defect, it's rarely because the automaker made a bad car. It's often because they use some tier-2 supplier who shipped a 40-air bag or a defective chip or something like that. But whether recall happens is the automaker's name that's on the recall, right? Like it's the automaker who is actually paying the cost of it. The reputation of damage that happens because of it. Software works in the same way, you know, if something went wrong with your third party or your fourth party or somewhere else, it's still your name on the in the wrong places about, you know, how your software got hacked. And that's increasingly, you know, important for you as a company to recognize that this is a problem. And the web of third and fourth parties is just an ever-expanding and much larger web. So when you look at a vendor, the simplest way to think about it is you're looking at a tip of the iceberg. There's so much beneath the water there that you never get to see and that's much larger than what you can see. and that's a great analogy. So because we discussed now, we'll leave in AI age. So how has AI made the invisible risk chain even harder to map? And what are you guys doing in this kind of area? - That's a great question. Everything I mentioned until now was a problem in itself. But AI just takes that entire problem and makes it an order of magnitude larger. And it basically turns your traditional vendor stack into like a very layered dependency that is really, really hard to comprehend. And that dependency changes something that most companies can't fully see. And what happens as a result of that is that, before AI, most software companies, the dependencies were relatively predictable, infrastructure providers, SaaS tools, software libraries, et cetera, et cetera. But now what you're going to increasingly see is that there are agents who are going to do the work and these agents call other agents in order to do the work. And this thing becomes extremely intractable because they're not deterministic chains. So to be specific, like they're the foundational models that get embedded inside of a SaaS platform, there are APIs that change behavior without notice. There are datasets of unknown origin that are being used to train the models that are downstream or upstream in your lifecycle. There is prompt of registration layers, basically, which is where AI is fundamentally under-termistic. So you can't actually map out which vendor might get called or which other subsystem might get called in a deterministic way. So vector databases are running widely in the production. And vendors who's vendors are also using AI just multiplies this whole chain. So suddenly, the risk isn't just in the software that you deploy, but it's in the behavior of the systems that you didn't build yourself or you didn't control. So unlike traditional software, the problems are only much larger. AI systems behave differently than traditional software. They can drift, they can hallucinate, they can change outputs without any changes at your end or without any core changes. Or they can evolve in the upstream models or tensiles are updated. So the fundamental problem when you're using, and I shouldn't say if you're using, you are always using some AI system or the other now, is that your system can change behavior even when you didn't deploy anything new. And that's not the bug, that's just the way of AI supply chains. It's kind of like you rented out your house, but the tenant is keeping on subletting it to other people. And you don't know these people, and they're new people every time, et cetera. So that's the way you have to look at this. So the supply chain becomes simultaneous, the more opaque, as well as more dynamic. And it's extremely hard for even really good organizations today to map even the top 10% of the AI components that are influencing their operations. And that's why there's a real governance problem. And the governance problem is beyond just shadow AI. Shadow AI is at least security teams knowing what they don't know, but there's a far bigger issue with the AI supply chain. And there's a risk that organizations inherit automatically through the vendors, through the models that the vendors are using, and the data pipelines that they can barely understand. So it's a much, much deeper and larger problem that way. - So let's discuss the following. Maybe without solving the name, can you share some in your experience? What have you seen kind of vendor or fourth party risk directly, how they directly impact enterprise deals or revenue growth, maybe on some examples? - Yeah, this is, you know, you hit the nail on the head, like while all of these things are happening, you know, this directly impacts, this is not a theoretical risk, or it's not a risk that only risk managers and security engineers understand. It actually impacts business and it actually impacts top line revenue numbers. And the reason that is happening is because, you know, we are seeing this in the market that enterprise buyers are now becoming far more cautious about the operational dependencies that they have as compared to what they were maybe three to five years ago. And, you know, procurement teams, you know, beginning to ask questions like, you know, what other sub-processors and what are the vendors power your platform? Do you really monitor your supplier risk continuously? What happens if one of your dependencies starts failing? Does it affect your own availability or does it affect your own ability to provide your services? How do you govern the AI models that are used inside of your product and so and so forth? And as soon as the answers to those questions are unclear, then you start to see that your deals slow down at the stall entirely. And we've seen situations where companies lose momentum in enterprise sales and not because their product is weak, but simply, you know, struggling to demonstrate the kind of supply chain visibility and this kind of supply chain strength that they have. So the trust has shifted. It's no longer too enough to say we are compliant. Buyers want to see how risk is monitored on a continuous basis. Are do you have the infrastructure in place so you can actually look at all your vendors and their third parties on a more continuous basis? So the companies that can demonstrate this, they actually see shorter sales cycles, which means that they earn revenue faster and they can move more faster through the procurement cycle. So I think again, just since we talk of analogies and just it makes it very simple to understand. You know, enterprise buyers, they used to treat software purchases like you're just auditing a house at move-in and you never walk through that house again. You know, maybe once in a year, you tour the apartment to check if all the locks are in place, etc. But you know, increasingly enterprise buyers now understand that they are basically buying a house that they're going to live in. So even as, you know, they don't want the scenario where the vendors are bolting on new rooms, knocking out walls and installing doors that you didn't approve, etc, etc. They actually are careful about everything that's happening at the vendor's end. So it's important that you have a very, very solid third party and fourth party risk management program because that fundamentally affects your ability to actually grow your business. It is not something that's, you know, like a back office function. It is something that actually affects your top line. It is something that your customers, your partners, your auditors, your cyber security insurers and so on. So more and more people are going to ask about and it will affect your top line so that we have clearly seen everywhere in the market now. So, Girish, I would like to ask you a personal point of view. What are the major misconceptions in this field of when the risk management that you kind of strongly disagree with? Ah, you know, they're not done of that. Like, for example, I think the simplest one is that vendor risk management is something that just to process it's one end and then you look at a vendor at a time and then you're okay, it's done. I think that's the biggest misconception in the industry. Like the fact that you need to keep looking at a vendor on an ongoing basis is something that people find hard to grow. And it's kind of like this, right? Like, I think the biggest misconception is that people still treat vendor management as something where, you know, would you bank, put your money in the bank which turns on its security camera only every Thursday for this one hour? If you would not feel very comfortable doing that but that's how we treat vendors still. And I think that's the largest misconception here. Like we have to basically have like a CCTV kind of image of your vendor. Like we have to know what's happening over there in a closed circuit all the time. And that's the only way to make sure that you're safe. So looking ahead, how can, what do you see in, will be developed in the few years from now in this field? What is your opinion? - I think there are a couple of trends that's happening and you know, at Springtov we are, this is something that we are also betting on. And this is what Springtov is trying to bring into the world as well. While the amount of continuous due diligence needs to happen on vendors has to keep on increasing and it has to happen in every company is going to only work with more and more vendors and each of those vendors are going to have more and more fourth parties. The volume of work is increasing. You're not necessarily going to have more and more people to throw at the problem. So our vision for the world is that this problem has to be solved in a manner that is autonomous in the sense that we have to use technology to solve the problem rather than throwing human circuit in the sense that you can't actually just start piring up much larger to say that, hey, I want to monitor my vendors more continuously. That's not the way to go about this. So the way I see the world going and where the future is going to be is that TPRM or third party risk management is going to become more and more autonomous. And that's something that we actively work on at Springtov. And that becoming more autonomous not only means that it is just going to take the model that existed today, which is you know, you have a white listed set of vendors and those need to be evaluated. There is a much larger group of vendors which is shadow AI in inside of your company, those need to be evaluated as well. So you need to have an active system which tells you what might be your vendors that you may not even know about. And you have to basically build a system that is allowing everybody in your company to be able to evaluate whether it's okay to work with the vendor or not, or one central team who is holding all the keys to this. So I'll give you an example. Imagine a company that's a couple of thousand people. The company has some approved set of vendors, but every day, every week, there is a new tool that's coming into the market that your leaf node employee might want to trial because it promises that, hey, this year's a great AI based way to build a presentation, to build a spreadsheet, to build a new agent that can actually make your life more productive, et cetera. So every single day new things are coming up. And if the leaf node employee now has to go back to the GRCT with the center or the TPR and T with the center and say, hey, is it okay for me to use this? And if that team is going to take two weeks to respond back to that request, I'll never going to do that as a leaf node employee. So there has to be like a way where people can actually look at a vendor and there's like a programmatic way, a technology based way that you immediately know whether it's okay to or not to okay to work with this vendor. In respect to whether you've previously done due diligence on this vendor or not, that's the place the world is going to go to. And that's the only way to make sense of the world that we are going to go into, right? Given any vendor, you should be able to know whether the media companies or departments and your policies and be able to work with that. That's it. That's the way we need to get into. - Okay. All right. Final. So if we summarize our interview for someone who's listening and would like to walk away with one or two major takeaways, what would that be? - Well, the one thing that I'd say is that, you know, think of your TPRM program as, you know, increasingly, there is more and more pressure for companies to go faster. The advent of AI companies are expected to be able to become more productive and they have to basically be able to go faster and faster. So if you think of your company as a faster ASCA, you can only go as fast as you can if you can trust the breaks. Like it's basically giving you the confidence that you have the right breaks, that if you, that, so that gives you the confidence to go as fast as you want to go, because that's what you will need if something were to go wrong. So I think of it like that. So, you know, it's like, you want the FAFSA, you better trust the breaks and your TPRM program is simply that. So that's my one takeaway from this. - Mm-hmm. Fantastic. So there's my questions. If I forgot to ask you something that you think is important to our audience, please go ahead. - No, great questions. I appreciate all the, you know, really good questions. It was great conversation. If there's anything the audience would like to know more about Sprinto or reach out to me, personally. So Vrart Sprinter.com, I'm specifically at GearyShirtSprinter.com. My first name is Sprinter.com. You know, happy to answer any questions that people might have based off what we said. - All right, fantastic. Thank you. Thank you again, Gaurich. And I wish you a great success. And to your company Sprinto, to, and maybe we have to continue our discussion within half a year or something like this. - Yeah, absolutely. Thanks for having me, Boris. I really enjoyed it here. - Thank you. Thank you. - If you like this episode, please give it five stars on your favorite podcast app. It will help us in spreading the word. Don't forget to subscribe to receive your notifications of future episodes straight to your phone. If you like to be connected with your peers, risk managers and compliance executives from all over the world, make sure to go to our main sign site at www.globalriskcommunity.com and click on the sign up button to join in. There are some incredible conversations happening inside the community. If you work in a fast growing company operating in the risk management space and your job is to acquire new customers, generate third leadership and awareness about your products and services, consider to become our partner. Here is a concept. Global risk community is looking to work with a limited number of innovative risk management companies interested in a new partnership model. What do I mean by that? We will put you in front of our engaged community of more than 100,000 subscribers by using our multi-channel approach, such as website, email, events, online business, social communities, video and podcast to name a few. You generate leads, awareness and advocacy. Everybody wins. Interested? Send your request to [email protected]. Last but not least, if you or someone you know will be an incredible guest on our show, email us at [email protected] and let us know. We love connecting with risk and compliance executives and we love sharing your perspectives and expertise. See you in the next episode.

Podcast Summary

Key Points:

  1. Companies face increasing pressure to accelerate operations, especially with AI, making robust Third-Party Risk Management (TPRM) essential for maintaining trust and control, analogous to needing reliable brakes in a fast car.
  2. Traditional vendor risk management is outdated, relying on static, questionnaire-based snapshots during procurement, leading to blind spots as vendors evolve, use AI, or introduce subcontractors without ongoing visibility.
  3. Fourth-party risk (vendors' vendors) is particularly challenging because companies inherit risks from dependencies they don't control, yet remain accountable for failures, similar to automakers facing recalls due to defective parts from suppliers.
  4. AI intensifies these risks by creating non-deterministic, dynamic supply chains where systems can change behavior autonomously, making risk mapping extremely difficult and governance more critical than ever.
  5. Ineffective TPRM directly impacts business growth, as enterprise buyers now demand continuous risk monitoring, and poor visibility can stall deals, lengthen sales cycles, and damage revenue.
  6. The future of TPRM lies in autonomous, technology-driven solutions that provide real-time, continuous oversight of both known and shadow vendors, moving beyond manual processes to manage expanding risk chains efficiently.

Summary:

The discussion emphasizes the critical role of Third-Party Risk Management (TPRM) in today's fast-paced, AI-driven business environment. Traditional vendor risk management is often outdated, relying on static assessments during procurement that fail to provide ongoing visibility into vendor activities, leading to significant blind spots. This issue is compounded by fourth-party risks, where companies are accountable for failures in their vendors' supply chains, even without direct control.

The advent of AI further complicates risk mapping by introducing non-deterministic, dynamic dependencies that can change autonomously, making governance more challenging. Poor TPRM directly impacts business outcomes, as enterprise buyers increasingly demand continuous risk monitoring, and inadequate visibility can stall sales and revenue growth. Looking ahead, the future of TPRM requires autonomous, technology-driven solutions to provide real-time oversight of both known and shadow vendors, enabling companies to manage expanding risk chains effectively while maintaining trust and accelerating growth.

FAQs

A TPRM program provides confidence in your third-party risk management, acting like reliable brakes in a fast car, allowing you to accelerate safely by ensuring you can trust your vendors and respond if issues arise.

Traditional vendor risk management relies on a one-time snapshot during procurement, often using questionnaires, but fails to monitor ongoing changes like infrastructure updates, AI model dependencies, or new subcontractors, leading to immediate blind spots.

Fourth-party risk involves your vendors' vendors, which are often invisible, but companies remain accountable because regulators and customers hold them responsible for failures anywhere in the supply chain, similar to automakers facing recalls for supplier defects.

AI introduces non-deterministic, dynamic dependencies like foundational models, APIs, and data pipelines that can change behavior without notice, making the supply chain more opaque and harder to map, increasing governance challenges.

Enterprise buyers now demand continuous visibility into vendor risk and supply chain strength; unclear answers can slow or stall deals, while demonstrating robust risk management can shorten sales cycles and accelerate revenue.

A common misconception is that vendor risk management is a one-time process; instead, it requires ongoing, continuous monitoring, akin to having a CCTV system rather than periodic checks, to ensure safety and compliance.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.