Third-party risk programmes rarely fail for lack of ambition. They fail on arithmetic. A mid-sized company deals with hundreds of suppliers, distributors, agents and service providers. The team asked to review them has two or three people, who also do everything else. The predictable result is a programme that starts at the top of the list, covers the first sixty counterparties in depth, and quietly stops.
The pressure behind these programmes is real: due-diligence expectations along the supply chain, sanctions exposure, data protection, and customers pushing their own compliance terms down to you. What is usually missing is not motivation but a design that matches the scope to the capacity. Three decisions do most of the work.
Tier by exposure, not by alphabet
Not every counterparty deserves the same review, and pretending otherwise is how programmes die. Before collecting a single document, sort the third-party population by what could actually go wrong: what the counterparty does for you, what it can touch — funds, data, customers, your name in the market — where it operates, and how hard it would be to replace.
The output is a small number of tiers with genuinely different treatment. A handful of critical counterparties get a full review, including ownership and control. A middle tier gets a standard package. The long tail gets basic screening and contractual commitments, nothing more. The point of tiering is not to do less. It is to be able to explain, later and under scrutiny, why you did what you did — and to make the programme finishable at all.
Collect documents in a structure you can review
The slowest part of most programmes is not analysis; it is chasing paper. A defined request list per tier — registry extract, ownership information, relevant policies and certifications, the key terms of the contract you have with them — sent through a channel that tracks what has arrived and what is missing, changes the tempo entirely. An inbox full of unsorted PDF attachments is where reviews go to stall.
Structure pays twice. It disciplines the counterparty, because a specific request is harder to answer vaguely than a general one. And it makes next year's cycle a delta review instead of a restart, because you know exactly what you hold and what has changed.
Review at machine scale, escalate at lawyer depth
This is where the arithmetic finally changes. A system can read every questionnaire and every submitted document, check completeness and internal consistency, extract the facts the review actually turns on — ownership chains, jurisdictions, subcontracting, audit and termination rights — and flag deviations from your standards. What it produces is not a decision. It is a short list.
The lawyer's time then goes where it belongs: the files that show a real question. An ownership chain that ends somewhere unexpected. A refusal to accept anti-corruption terms. A contract that is silent where, for this counterparty, it must not be silent. Machines guarantee that everything was read; a named lawyer answers for what was concluded. That split is what lets a small team carry a large population honestly.
A finding is only useful if someone decides
Programmes also stall at the far end, where findings pile up in a register that no one owns. Every flagged issue needs a route to one of a few outcomes: accept the risk with reasons, fix it contractually, monitor it, or exit the relationship. Decide in advance who has authority to take each of those decisions at each tier, and record the decision in one place.
This is less bureaucratic than it sounds. Most findings resolve quickly once someone with authority looks at them. What erodes a programme is not hard decisions — it is unmade ones.
Keep it alive without starting over
Third-party risk is not an annual event, and a full annual re-run is exactly the exercise a small team cannot afford. The realistic alternative is trigger-based: re-check when something changes — new ownership, a new jurisdiction, a contract renewal, a sanctions development, an incident. A programme built on structured data can do that selectively; a programme built on a spreadsheet and memory cannot.
Whether your tiers, triggers and escalation lines are set correctly depends on your business, your markets and your contracts — there is no standard answer. But if your third-party list is longer than your team's year, the solution is design, not heroics. We build and run reviews on exactly this split of machine-scale reading and lawyer judgment, and we are happy to discuss what proportionate looks like for your supplier base.