Articles

Third-Party Risk Is Negotiated Before It Is Measured

Vendor-risk programmes often present the rating as if risk existed as a clean, objective fact before the assessment. In practice, technical, operational, procurement, legal and business teams first negotiate what the risk means, what evidence…

Research-informed articleDocument v3.12 min read

Vendor-risk programmes often present the rating as if risk existed as a clean, objective fact before the assessment. In practice, technical, operational, procurement, legal and business teams first negotiate what the risk means, what evidence matters and what disruption is tolerable.

That negotiation is not a flaw. Hiding it is.

What the research adds

Laura D. Osburn's 2025 ethnographic study of IT and Facilities professionals found that storytelling, sensemaking and sensegiving helped teams negotiate the cybersecurity and operational meaning of IoT vendor risk. Vendor stories did more than describe culture: they helped create shared interpretations and shape decisions.

The study is context-specific and qualitative. It does not establish a universal causal model or a scoring formula. It does reveal something conventional questionnaires miss: different functions can use the same word, risk, while describing different consequences.

The accepted method

C2M2 v2.1 includes Third-Party Risk Management as a domain. NIST CSF 2.0 places cybersecurity supply-chain risk inside Govern. ISO/IEC 27001 includes supplier relationship controls within its broader management system. These sources support governance, due diligence, monitoring and response; they do not remove the need for organisational judgement.

The IO addition: preserve the decision trail

For each material vendor condition, IO should preserve:

  • the observed signal and source;
  • the technical, operational and business consequences proposed;
  • who advanced or challenged each interpretation;
  • the versioned rule or threshold ultimately applied;
  • the accountable owner and treatment decision;
  • the intervention and its declared verification measure; and
  • what changed after treatment.

The narrative is evidence of how the organisation reached a decision. It is not evidence that the vendor is safe. That distinction protects both culture and measurement.

Against the standard industry shortcut

The common shortcut is a questionnaire score that compresses control claims, criticality, relationship history and judgement into one number. IO's position is not that questionnaires are useless. They are assertions that require corroboration proportional to exposure.

Where direct telemetry is unavailable, IO records the source as attestation, reduces confidence and names the next evidence needed. It never converts a completed questionnaire into verified operating effectiveness.

A better vendor review question

Instead of asking only, “Did the vendor pass?”, ask:

What condition would cause us to change this decision, who could observe it, and what would we do next?

That turns a negotiated judgement into an operational control.

References

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.