<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is third-party risk still stuck in spreadsheets? in Welcome</title>
    <link>https://community.isc2.org/t5/Welcome/Is-third-party-risk-still-stuck-in-spreadsheets/m-p/89451#M3204</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I’ve been seeing that a common theme keeps coming up:&lt;/P&gt;&lt;P&gt;Third-party risk assessments are still largely handled through spreadsheets, email back-and-forth, and manual tracking—especially when it comes to remediation and continuous monitoring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the increasing expectations from regulations like DORA and the EU AI Act, this feels like a growing bottleneck.&lt;/P&gt;&lt;P&gt;Would love to hear your experience:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is this still the reality in your organization?&lt;/LI&gt;&lt;LI&gt;Have you found better ways to manage it?&lt;/LI&gt;&lt;LI&gt;What’s the hardest part to operationalize?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Looking to understand how widespread this is.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Apr 2026 07:34:22 GMT</pubDate>
    <dc:creator>AnilEmanueall</dc:creator>
    <dc:date>2026-04-29T07:34:22Z</dc:date>
    <item>
      <title>Is third-party risk still stuck in spreadsheets?</title>
      <link>https://community.isc2.org/t5/Welcome/Is-third-party-risk-still-stuck-in-spreadsheets/m-p/89451#M3204</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I’ve been seeing that a common theme keeps coming up:&lt;/P&gt;&lt;P&gt;Third-party risk assessments are still largely handled through spreadsheets, email back-and-forth, and manual tracking—especially when it comes to remediation and continuous monitoring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given the increasing expectations from regulations like DORA and the EU AI Act, this feels like a growing bottleneck.&lt;/P&gt;&lt;P&gt;Would love to hear your experience:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is this still the reality in your organization?&lt;/LI&gt;&lt;LI&gt;Have you found better ways to manage it?&lt;/LI&gt;&lt;LI&gt;What’s the hardest part to operationalize?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Looking to understand how widespread this is.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 07:34:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Welcome/Is-third-party-risk-still-stuck-in-spreadsheets/m-p/89451#M3204</guid>
      <dc:creator>AnilEmanueall</dc:creator>
      <dc:date>2026-04-29T07:34:22Z</dc:date>
    </item>
  </channel>
</rss>

