Trust at Scale: Rethinking Third-Party Risk, Assurance and AI

By Michael Hiskey

As organizations become increasingly dependent on third-party technology providers, AI platforms, cloud services, and digital ecosystems, trust has evolved from an abstract concept into a measurable business asset. That was the central theme of discussion during the HITRUST CxO Security Forum at the 3M Open, where senior cybersecurity, technology, risk, compliance, and business leaders gathered for an open, peer-driven conversation about the future of third-party risk management.

 

Rather than focusing solely on compliance frameworks or security questionnaires, the discussion explored how organizations can make better business decisions by understanding operational dependencies, validating trust through credible assurance, and communicating cyber risk in language executives and boards can act upon.

 

The conversation also provided an early look at emerging HITRUST capabilities designed to help organizations translate existing assurance evidence into meaningful risk signals, financial impact estimates, and more practical governance decisions.

Trust Is More Than a Security Objective

 

One of the strongest themes throughout the discussion was that trust has become a competitive differentiator.

 

Organizations are increasingly judged not only by the products and services they provide, but by their ability to demonstrate resilience, safeguard information, and manage an increasingly complex ecosystem of partners and suppliers.

 

As one participant challenged the group:

 

     “If we truly viewed trust as one of our organization’s most valuable strategic assets, what would we do differently?”

 

That question shifted the conversation away from regulatory checklists toward business outcomes. Companies that can credibly demonstrate sound governance and validated security practices are often better positioned to win new business, strengthen customer confidence, and differentiate themselves in competitive markets.

Comments

I welcome your input on this article… please do that via the summary LinkedIn post on this same topic

Governance Must Lead Technology

 

Technology alone cannot solve third-party risk.

 

Forum participants consistently emphasized that effective programs begin with governance: clearly defined ownership, decision-making authority, acceptable risk thresholds, and escalation processes.

 

Organizations also need to recognize that not every vendor represents the same type of risk. A cloud infrastructure provider, professional services firm, AI platform, payment processor, and facilities contractor each create different operational and security challenges.

 

Without governance, even the most sophisticated assessment platform simply automates inconsistency.

 

Third-Party Risk Is Everyone’s Responsibility

 

The days when procurement and information security controlled every vendor relationship are largely over.

 

Today, business units, marketing teams, software developers, finance departments, and individual employees can introduce new technologies with little warning. Shadow IT has expanded into shadow AI, making vendor oversight even more complex.

 

Because of this reality, successful organizations design risk management programs that business leaders can actually use. Processes that are slow, overly complex, or difficult to navigate often encourage employees to bypass them altogether.

 

The most effective security teams position themselves as trusted business partners who help accelerate informed decisions rather than simply acting as gatekeepers.

 

Third-Party Risk Goes Far Beyond Sensitive Data

 

Historically, many organizations classified vendors primarily according to the volume or sensitivity of data they processed.

 

While data protection remains essential, today’s risk landscape is significantly broader.

 

A vendor may present substantial organizational risk because it:

  • Supports a mission-critical business process
  • Has privileged access to infrastructure or production systems
  • Enables significant revenue generation
  • Would be difficult or expensive to replace
  • Creates concentration risk across multiple business functions
  • Relies heavily on AI models, subcontractors, or fourth-party providers

Executives increasingly want to understand not simply whether a vendor could experience a cyber incident, but what business consequences would follow if that vendor became unavailable.

 

Resilience Has Become as Important as Prevention

 

Participants acknowledged a simple reality: no certification, assessment, or questionnaire can guarantee that a third party will never experience a breach or disruption.

 

The more important question becomes:  How resilient is the organization when that disruption occurs?

 

That means understanding operational dependencies, mapping data flows, identifying recovery alternatives, and evaluating the potential business impact if a critical supplier fails.

 

Organizations that plan for resilience—not just prevention—are far better positioned to maintain operations during inevitable disruptions.

 

Better Questions Create Better Decisions

 

Many participants expressed frustration with lengthy, one-size-fits-all vendor questionnaires that generate large volumes of information but relatively little insight.

 

Meaningful assurance should reflect the specific relationship being evaluated.

 

A software developer should not undergo the same assessment as a consulting firm. Likewise, an AI platform presents different governance considerations than a payroll processor or managed service provider.

 

The objective should be improving decision quality—not simply collecting more documentation.

 

Not All Evidence Deserves Equal Confidence

 

Another recurring theme involved the difference between claims and independently validated evidence.

 

Self-attestations, readiness assessments, security questionnaires, certifications, and independent audits all provide different levels of confidence.

 

Equally important is understanding scope.

 

An assessment covering one business division or public-facing website may provide very little assurance regarding the specific service a customer intends to purchase.

 

Organizations increasingly need to evaluate both the credibility of the evidence and whether it accurately reflects the product or environment on which they depend.

 

Reducing the Noise in Third-Party Risk

 

Security teams are drowning in information.

 

External ratings, continuous monitoring alerts, certifications, questionnaires, penetration test summaries, and audit reports continue to multiply. Unfortunately, more data has not necessarily produced greater clarity.

 

An emerging opportunity lies in transforming multiple forms of assurance into consistent, comparable residual-risk signals that account for the quality and credibility of each source.

 

Rather than performing exhaustive reviews on every vendor, organizations can focus resources where meaningful risk actually exists.

 

Boards Want Business Risk—Not Security Metrics

 

Executives and directors increasingly expect cybersecurity discussions to focus on business outcomes rather than technical controls.

 

Effective reporting should answer questions such as:

  • What is the financial impact if this vendor fails?
  • Which business operations depend on this provider?
  • How many customers or records could be affected?
  • Where are concentration risks emerging?
  • Should this risk be accepted, mitigated, transferred, or avoided?

When cyber risk is expressed in operational and financial terms, governance becomes significantly more effective.

 

Risk Transfer Continues to Evolve

 

The discussion also explored limitations within traditional cyber insurance.

 

Although vendors often maintain significant insurance coverage, those policies may ultimately be shared across hundreds or even thousands of affected customers following a widespread incident.

 

Emerging approaches could eventually provide more targeted coverage tied directly to individual vendor relationships, offering organizations additional options for transferring defined portions of third-party risk.

 

Assurance Can Become a Competitive Advantage

 

The conversation concluded with an important reminder for vendors themselves.

 

Strong assurance is not merely about satisfying customer requirements.

 

Organizations that invest in independently validated security programs can shorten procurement cycles, reduce repetitive assessments, strengthen customer confidence, and expand into highly regulated industries more efficiently.

 

In today’s marketplace, trust has become a genuine business differentiator.

 

AI Is Reshaping Third-Party Risk

 

Artificial intelligence appeared throughout nearly every discussion.

 

AI offers tremendous opportunities to streamline assessments, analyze documentation, identify inconsistencies, and help organizations manage increasingly complex vendor ecosystems.

 

At the same time, AI introduces new governance challenges. Organizations often have limited visibility into how vendors are using AI, what data may be exposed to models, how autonomous agents are authenticated, or which downstream providers are involved.

 

As AI adoption accelerates, vendor governance must evolve beyond annual questionnaires to become a continuous process supported by ongoing assurance and monitoring.

 

Five Practical Priorities for Security Leaders

 

Participants identified several immediate actions organizations can take to strengthen third-party risk programs:

 

  • Lead with governance. Define ownership, accountability, risk tolerances, and escalation procedures before investing in new technology.
  • Understand business dependencies. Map critical services, operational processes, data flows, and revenue impacts associated with key vendors.
  • Tailor assurance. Evaluate vendors based on the specific products and services they provide rather than relying on generic assessments.
  • Prioritize validated evidence. Give greater weight to independently verified assurance while considering scope, quality, and timeliness.
  • Communicate in business language. Help executives understand financial exposure, operational resilience, and available risk-management options.

Looking Ahead

 

The future of third-party risk management will not be defined by longer questionnaires or larger collections of documentation.

 

Instead, successful organizations will distinguish themselves through stronger governance, better evidence, greater visibility into operational dependencies, and the ability to translate cybersecurity into business decisions.

 

Trust is no longer simply a security objective—it is a strategic asset that must be earned, validated, and continuously maintained.

 

Organizations that can measure, communicate, and operationalize trust will be better equipped not only to reduce risk, but also to strengthen resilience, accelerate business growth, and compete with greater confidence.

 

Special thanks to the HITRUST leadership team—industry veteran CISO Myrna Soto, CIO Jeremy Huval, and CEO Gregory Webb—for moderating the executive roundtable and sharing their strategic perspectives on the future of trust, assurance, and third-party risk management.

 

We also thank A-LIGN for supporting the Forum, with guidance from Marc Solomon and Jessica Brown, CMP, whose contributions helped make this executive discussion possible.

Comments

I welcome your input on this article… please do that via the summary LinkedIn post on this same topic