← All posts

The 400-Hour Vendor Risk Problem

Most SMEs cannot justify a standalone TPRM team, and the risk itself touches so many parts of the business that some distribution of ownership makes sense on paper.

Risk Management Guru·

Ask an SME insurer or financial services organisation who owns third-party risk management, and the honest answer is usually nobody in particular. It is rarely a dedicated function with its own headcount and mandate. Instead, responsibility is spread across compliance, risk, IT, cybersecurity, operations, procurement and business management, with each person picking up a piece of the work alongside the job they were actually hired to do.

This arrangement is understandable. Most SMEs cannot justify a standalone TPRM team, and the risk itself touches so many parts of the business that some distribution of ownership makes sense on paper. Compliance understands regulatory obligations. IT understands technical architecture. Cybersecurity understands threat exposure. Operations understands service continuity. Procurement understands contractual leverage. Each brings something the assessment genuinely needs.

The problem is that none of them are specialists across every domain a vendor risk assessment actually requires. A compliance officer reviewing a penetration test report is doing their best with material outside their core expertise. An IT manager scoring a vendor's business continuity plan is applying judgement built for a different discipline. This is not a criticism of the people involved. It is simply what happens when specialist risk work is absorbed into generalist roles.

The Real Cost Rarely Shows Up on a Budget Line

Because this work is distributed rather than centralised, its true cost is easy to underestimate. When you add up the hours spent issuing questionnaires, chasing responses, reviewing evidence, interpreting technical documentation, scoring risk, escalating concerns and following up on remediation, the assessment and management of just ten vendors can consume between 350 and 450 internal working hours. That is not a typo. It is the accumulated effort of multiple people, each contributing a slice of their week over a period that often stretches across several months.

This fragmentation carries its own cost beyond the hours themselves. Work that is split across seven or eight people, each juggling it against their primary responsibilities, moves at the pace of the least available person. A vendor review that should take three weeks can drift into three months simply because everyone involved has other priorities that take precedence when deadlines collide.

Perhaps the harder truth is what happens at the end of all that effort. Even after months of work and hundreds of hours, many organisations still cannot say with confidence that vendor evidence was interpreted correctly, that risk scores reflect genuine exposure rather than a best guess, or that identified mitigation actions were actually resolved rather than quietly forgotten once the assessment cycle closed. The organisation has spent significant internal capacity and still carries residual uncertainty about the very risks it set out to understand.

A Different Model for the Same Problem

A managed third-party risk service does not ask an SME to solve this by hiring specialists it cannot afford or by asking existing staff to somehow become experts in five disciplines at once. Instead, it replaces fragmented internal effort with access to a multidisciplinary risk capability, delivered through a structured platform and a managed workflow designed specifically for this kind of assessment.

Rather than internal staff coordinating questionnaires, interpreting technical evidence, identifying risk and chasing mitigation actions between other commitments, that work is carried by people whose full-time focus is exactly this. For a typical ten-vendor cycle, the shift in operating model tends to produce results along these lines:

Internal operational involvement drops by approximately 75% to 80%, freeing between 260 and 380 working hours that would otherwise have been absorbed across compliance, risk, IT, cybersecurity, operations and procurement. In practical terms, that is somewhere between 33 and 48 working days returned to teams who can redirect that time toward the work they were actually hired to do.

Beyond the hours recovered, the organisation gains something harder to quantify but arguably more valuable: direct access to risk, compliance, cybersecurity, IT and operational resilience expertise applied consistently across every vendor, rather than whatever expertise happened to be available internally that quarter. Risk decisions become more consistent and more defensible, because they are being made by people whose core discipline is risk assessment rather than by generalists doing their best with unfamiliar material. And critically, identified risks are far more likely to be tracked through to actual resolution, rather than logged and gradually lost as internal attention moves elsewhere.

Under a base-case scenario, when you account for recovered internal hours, improved consistency and stronger risk resolution, the economic value generated by this shift can exceed R400,000 for every ten vendors assessed and managed. That figure represents real capacity returned to the business and real risk exposure that no longer sits unresolved.

Where This Leaves SME Risk Leaders

None of this suggests that internal compliance, risk, IT, cybersecurity, operations and procurement teams are doing anything wrong. They are doing exactly what most SME organisations ask of them. They are absorbing specialist work into already full roles because a dedicated function has never been part of the budget conversation. The issue is the model itself, not the people working within it.

If any part of this reflects how third-party risk currently gets done in your organisation, it may be worth understanding what a managed approach could look like against your own vendor population. We offer a complimentary Third Party Dependency Review for organisations wanting to see this scenario mapped against their actual vendor list rather than a hypothetical one, and to get a clearer picture of the hours, timeline and risk exposure currently tied up in the current way of working.