Hi everyone,
I’ve been seeing that a common theme keeps coming up:
Third-party risk assessments are still largely handled through spreadsheets, email back-and-forth, and manual tracking—especially when it comes to remediation and continuous monitoring.
Given the increasing expectations from regulations like DORA and the EU AI Act, this feels like a growing bottleneck.
Would love to hear your experience:
- Is this still the reality in your organization?
- Have you found better ways to manage it?
- What’s the hardest part to operationalize?
Looking to understand how widespread this is.