Annual Vendor Assessment Is Broken. What Should You Do Instead?
The SolarWinds attack happened in October 2019. Most affected organizations only discovered it in December 2020 — 14 months later. Throughout that period, SolarWinds likely passed annual vendor assessments at hundreds of client companies. All approved.
This is not a criticism of the assessment process itself. It is a criticism of frequency. The annual model was created when assessments were expensive, manual, and time-consuming. Today, a significant portion of a vendor's risk can be monitored continuously — and not monitoring is a choice with consequences.
What changes between one assessment and the next
In 12 months, a vendor can: suffer an undisclosed data breach, lose the CISO and half the security team, hire a data subprocessor in a country with no LGPD adequacy, leave ports exposed on the internet, have credentials leaked in underground forums, and undergo a merger that transfers your data processing to a third company you never assessed.
None of these events will appear in a questionnaire sent before they happen. And all of them materially alter the vendor's risk profile.
Regulatory pressure is increasing
The LGPD requires operators and controllers to demonstrate ongoing due diligence on partners who process personal data. Resolution CD/ANPD 02/2022 makes clear that responsibility does not end at contract signature. DORA (Digital Operational Resilience Act), for companies with European operations, goes further: it requires active monitoring and exit plans for critical vendors.
Regulators no longer accept 'we did the assessment last year' as an adequate response when an incident occurs through a vendor.
The continuous monitoring model in practice
Continuous monitoring does not mean reassessing 100% of the portfolio every month — that would be operationally unviable. It means stratifying the portfolio by criticality and defining different cadences: P1 vendors (critical, access to sensitive data or core systems) with quarterly reviews and continuous passive monitoring; P2 vendors with semi-annual reviews; P3 with a simplified annual cycle.
Passive monitoring covers what does not require interaction with the vendor: external attack surface exposure signals, threat intelligence alerts (leaked credentials, underground forum mentions), incident news, changes in public certifications, and relevant corporate structure changes.
When one of these signals triggers, a targeted reassessment workflow is activated — without needing to go through the full cycle. The vendor is notified about the specific concern and asked to respond with targeted evidence.
The role of AI in this transition
The feasibility of continuous monitoring at scale depends on automation. Processing threat intelligence signals from dozens of vendors simultaneously, correlating with assessment history, and generating prioritized alerts is not humanly scalable without technological support.
AI models applied in this context can identify risk deterioration patterns before they become incidents — correlating variables that human analysts could not process in parallel. The result is not replacing human judgment, but directing it to where it matters.