Year in Review: 10 Key Trends Shaping Third-Party Risk
Locktivity
Third-Party Risk
The ten trends shaping third-party risk management, from rising supply chain breaches and AI risk to continuous monitoring and new regulation.
Third-Party Risk Trends: 2025 Year in Review | Locktivity
Ten trends shaping third-party risk: rising vendor breaches, AI risk, waning trust in SOC 2, real-time monitoring, and DORA, NIS2 and SEC rules.
As we close out another transformative year, third-party risk management has evolved from a compliance checkbox to a strategic imperative. Here are the ten trends that we are following in third-party risk.
1. Breaches on the rise
Third-party breaches doubled in 2024, with 35.5% of all incidents involving third parties. High-profile cases like Salesloft, Ticketmaster (560M customers) and Change Healthcare (190M individuals) showed that even sophisticated organizations remain vulnerable through their supply chains. The financial toll: breaches now average $4.8 million to remediate. 65% of breached companies say they haven't been able to fully recover from breaches.
Not all "third-party-related breaches" have the same root cause, though. It's important to note that this steady rise in breaches reflects the dependency companies have on third-party tooling, but also that the impact of these breaches on companies is often manageable through the application of appropriate hardening standards, such as strong MFA, data minimization and proper management of OAuth tokens.
2. AI risk
According to some studies, one in six breaches in 2025 involved AI-driven attacks, while organizations struggle to assess AI risks in their vendor base. As most companies rely on third-party AI rather than building in-house, new vulnerabilities around bias, model drift, and data security have emerged. Social engineering and phishing are a leading attack vector, which only becomes more prominent with the use of AI.
Companies need to make informed decisions about how third parties are using their data, how business decisions are being made and AI outputs are created and used, and what access AI tools are being granted within company networks and systems.
Note: we like the HITRUST AI security requirements as a guideline for reviewing your use of third-party AI tools.
3. AI driving innovative solutions
The flip side: AI-powered solutions are changing the ROI of third-party risk management. From answering questionnaires to continuously scanning vendor attack surfaces, AI-powered solutions can correlate data efficiently to flag contract gaps and highlight contextualized business risks in a way that was previously incredibly expensive.
4. Waning confidence in SOC 2 and ISO certifications
Static certifications are losing their value as standalone assurance. Organizations now recognize that annual audit reports don't reflect real-time security posture—certified vendors still get breached. The shift: from "Do you have SOC 2?" to "Show me your current security posture across specific risk vectors," including continuous scoring, vulnerability assessments, and incident history. In a poll we ran, only 10% of respondents said SOC 2 is sufficient, while 74% replied that they need more evidence or that they just don't care about SOC 2.
Perhaps new TPRM models will emerge?
5. Real-time monitoring
Annual vendor reviews are dead. New regulations underscore this: DORA requires incident reporting within four hours, NIS2 within 24 hours. Continuous monitoring tools now track security ratings, breach alerts, expired certificates, and dark web exposure in real time, enabling organizations to detect and respond to vendor risks before they escalate.
6. Increased prominence
TPRM has moved from IT's back office to the boardroom. Companies are appointing dedicated third-party risk officers and establishing cross-functional committees. The SEC's cybersecurity disclosure rules now require public companies to report on third-party risk oversight, making vendor security a matter of public record and executive accountability.
Increased dependence on third parties, breaches rising in cost and frequency, and growing regulation mean third-party risk is becoming a greater priority for companies. Early results from a survey we are running on the State of Third Party Risk show third-party risk in the top 5 priorities for over 70% of security teams and nearly 70% of compliance, privacy and enterprise risk teams.
7. Move to self-hosted solutions
A counter-trend: the self-hosting market is projected to reach $85.2 billion by 2034, growing at 18.5% annually. Organizations are bringing critical systems in-house to reduce third-party dependencies. Roughly 70% cite data control as the primary driver, with security and customization close behind. Can't say I've verified these studies, but the trend makes sense. An interesting read on this, cited above: The rise of self-hosted applications.
8. Changing shape of technology solutions
The technology footprint of enterprises is fundamentally changing. Companies are moving away from monolithic, vendor-locked platforms toward composable architectures where internal teams use no-code/low-code tools and AI to build custom solutions. This shift spans all functions—finance teams building their own reporting dashboards, operations teams creating process automation, and yes, risk teams designing custom TPRM workflows. The democratization of software development means business units no longer wait for IT or pay for expensive custom development. Instead, they integrate best-of-breed APIs and SaaS tools, then connect them with internal builders to match their actual processes. The result: more agile, purpose-built systems that adapt as needs evolve.
9. Shift from risk reporting to risk reduction
The paradigm is flipping from documentation to action. Instead of "Vendor X has medium risk," programs have to identify actionable risk management strategies. The business wants to use Vendor X, and the fact that they don't have a SOC 2 isn't interesting; we need to identify the risk to the business and how we are going to reduce it. Tools are making risk reporting easier, so third-party risk teams can move to actionable risk reduction exercises, such as ensuring secure authentication is enabled, or that shifting use cases are identified and evaluated. Continuous monitoring surfaces specific, actionable issues that automated systems can track through remediation.
10. Increased regulation
The regulatory landscape exploded in 2024-2025. DORA (EU financial sector, effective January 2025) mandates incident reporting within four hours and oversight of critical ICT providers. NIS2 (EU critical sectors, effective October 2024) imposes penalties up to €10M or 2% of turnover. The SEC's rules require public disclosure of material incidents and annual TPRM reporting. Multinational organizations now navigate a complex patchwork, often adopting the strictest requirements across all jurisdictions.
With data flowing to and between third and fourth parties, companies have to consider increasing exposure and complexity in complying with privacy regulations. New laws take effect every year, with updates to the CCPA, and new laws in Rhode Island, Indiana and Kentucky taking effect in January 2026.
Track US privacy laws with the IAPP US State Privacy Legislation Tracker.
Need help with third-party risk?
Locktivity combines decades of experience with automation and AI to help you achieve greater confidence for your business efficiently. Contact us.