Third-party risk management (TPRM) processes designed for 30 vendors do not slowly weaken as portfolios double. They fail at a specific and predictable point, according to a new eBook from compliance automation firm Copla, aimed at vendor risk, compliance and procurement teams looking to move beyond spreadsheets.
The problem is coordination. Every vendor still requires sign-off from four roles: compliance, legal, IT and a business owner. As vendor numbers grow, those four calendars must align far more often. Hiring another analyst adds review capacity but not calendar availability, and availability runs out first.
The pressure is compounded by regulatory complexity. The World Economic Forum’s Global Cybersecurity Outlook 2025 found that 69% of organisations say cyber regulations are too complex or numerous to track, or that they cannot verify whether suppliers are complying.
Copla argues that automation decisions should be made at the level of individual questionnaire answers rather than per vendor. Tasks that are fixed, routine and verifiable, such as document collection, questionnaire distribution, risk scoring, approval routing, certification expiry tracking and breach monitoring, can be automated.
Judgement calls, including approval decisions, exceptions and explaining changes to regulators, must remain with a named person. The firm estimates this split means roughly 80% of a TPRM workflow can be automated.
One-size-fits-all questionnaires are another bottleneck. A payroll provider with access to salary data and a courier with access to a loading dock should not face identical scrutiny. In one example, a 45-vendor portfolio using a single questionnaire routinely took eight to ten weeks to clear approvals. After introducing three tiers based on data access and criticality, that timeline shrank by more than half.
Timing matters too. Calendar-based reviews leave dangerous blind spots, as a certification lapsing in March may go unnoticed until a December review, creating nine months of hidden exposure.
Copla also challenges the assumption that “The business unit owns monitoring”, arguing this fails by design because business units are built to catch operational issues, not risk signals. Trigger-based reassessment, prompted by events such as certification expiry, breach disclosures or contract changes, addresses this gap.
This has direct regulatory consequences. Under DORA, financial entities face annual register submissions, with 2026 national deadlines clustering around the end of March, while Article 28 requires the register to be available to supervisors on request at any time. NIS2 Article 21 makes supply chain security a baseline measure for other sectors.
The guide also highlights accountability gaps. A Thomson Reuters Institute 2025 survey found 68% of C-suite leaders see compliance work as a significant barrier to effectiveness. Copla recommends a RACI framework assigning one owner per stage.
Its advice for getting started is to define a single register with minimum fields, set risk tiers and reassessment triggers, assign ownership per stage, and evaluate platform needs against actual scale.
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





