Denis Oproescu - 24 Feb 2025
Working with external vendors: risk management and best practices
External vendor risk falls into six categories: limited visibility into the work, misalignment with business goals, cost and scope drift, security and compliance exposure, lock-in through undocumented systems and, since 2025, provenance risk in AI-assisted code. The first five are managed through contracts, defined KPIs, milestone-based payment and documented knowledge transfer. The sixth is newer and most buyers are not yet asking about it. Third-party involvement in breaches reached 48% of all breaches in the 2026 Verizon DBIR, up from 30% the year before, which makes vendor governance a board-level concern rather than a procurement detail.


