How to integrate AI for a smarter approach to third-party risk management in Sofy GRC

Executive summary:
Organizations increasingly depend on third parties to deliver essential services, process data, support operations, and enable growth. Yet accountability for regulatory compliance, continuity, ethical conduct, and risk oversight generally remains with the organization itself.
That accountability is becoming more explicit. DORA places ICT third-party risk within the regulated entity’s own risk-management framework, while NIS2 incorporates supply-chain security and top-management accountability into its supervisory model.
The challenge is no longer a lack of information. It is the inability to transform contracts, assessments, certifications, audit reports, regulatory obligations, findings, external signals, and remediation records into a clear and defensible view of exposure. AI can help by summarizing evidence, mapping obligations, identifying inconsistencies, and prioritizing action. But AI output should remain a recommendation: reviewed, challenged, approved, and traceable to its sources
Third-party risk has become an executive accountability issue
For many organizations, third-party risk management still revolves around onboarding forms, annual questionnaires, document requests, and spreadsheet-based ratings. These activities may create records, but they do not automatically create oversight.
A regulator, auditor, or board is unlikely to be satisfied by the response: “The supplier completed the questionnaire.” The more important questions are:
- What obligation applies?
- What evidence supports the conclusion?
- What has changed since the last review?
- Who accepted the residual risk?
- Which remediation remains overdue?
- What would happen if this supplier—or a shared fourth party—failed?
This distinction can be seen in current regulatory expectations. DORA similarly third-party risk, concentration, contractual arrangements, registers of information, and oversight while emphasizing that external oversight complements rather than replaces the financial entity’s own responsibility. NIS2 extends the governance conversation beyond financial services. It covers 18 critical sectors, includes supply-chain security within cybersecurity risk management, and introduces accountability for top management when required measures are not implemented. Although these regimes differ in scope, they point in the same direction: outsourcing an activity does not outsource the need for demonstrable oversight.
The real problem is fragmented compliance evidence:
Most organizations already possess substantial supplier information. It may sit across procurement systems, contract repositories, email, GRC tools, audit files, security platforms, privacy assessments, sanctions screening, incident-management tools, and business-owner records.
The problem is that these sources rarely tell one consistent story. A supplier may have an approved onboarding assessment, an expired certification, an unresolved audit finding, a contract without sufficient audit rights, and a remediation plan that no longer has an active owner. Each record can look reasonable in isolation while the aggregate exposure remains unclear.
That data problem is material. KPMG’s 2026 global TPRM survey of 851 organizations found that only 15 percent of leaders expressed high confidence in the data underpinning their program. It also found that only 18 percent of TPRM programs were fully integrated with enterprise risk management, while more than half of organizations were exploring AI and 22 percent considered it very effective. The 2026 KPMG Global Third-Party Risk Management Survey
The implication is uncomfortable but important: automating an unreliable risk view does not make it reliable. Data structure, ownership, provenance, and quality must come before confident AI-enabled decisions.
From third-party assessment to third-party compliance intelligence:
A mature TPRM capability should do more than assign suppliers a score. It should connect five layers of information:
- Relationship: What does the supplier provide, to whom, in which locations, and in support of which critical products, processes, or services?
- Obligation: Which laws, regulations, policies, standards, contractual clauses, and customer commitments are relevant?
- Evidence: What demonstrates that required controls exist and operate—and how current and reliable is that evidence?
- Exposure: What risks, dependencies, sub-suppliers, concentration points, findings, incidents, and control gaps remain?
- Action: Who must remediate, approve, monitor, escalate, accept, or exit—and by when?
This connected model changes executive reporting. Instead of receiving hundreds of red, amber, and green ratings, leaders receive a concise explanation: what the exposure is, why it matters, how reliable the evidence is, what decision is required, and who owns the next action.
Where AI creates practical value:
Used carefully, AI can provide a compliance-intelligence layer across the third-party lifecycle. It can summarize supplier questionnaires, certifications, SOC reports, policies, contracts, assessments, and supporting evidence. It can compare evidence with defined requirements, flag missing or inconsistent information, identify obligations affected by a regulatory update, draft an assessment rationale, and consolidate findings and remediation into an executive narrative.
AI can also help identify patterns that conventional assessments may obscure: multiple critical services dependent on the same provider, repeated findings across suppliers, deteriorating evidence quality, overdue risk acceptance, or remediation plans that address symptoms without resolving the underlying obligation.
How KPMG Sofy GRC can help:
KPMG Sofy GRC helps organizations transform fragmented supplier information into actionable third-party risk and compliance intelligence. By connecting suppliers, contracts, assessments, evidence, risks, controls, findings, remediation actions, and approvals in a single governed platform, organizations gain a clear and defensible view of third-party exposure.
Embedded AI capabilities help accelerate and enhance third-party oversight by:
- Summarizing supplier assessments, contracts, certifications, policies, and SOC reports into concise risk-focused insights.
- Identifying missing evidence, control gaps, and inconsistent responses across supplier assessments.
- Supporting AI-assisted supplier profiling, screening, and deduplication to improve data quality and onboarding efficiency.
- Generating supplier risk summaries and management-ready narratives to support decision-making and reporting.
- Detecting patterns across suppliers, findings, and remediation activities that may indicate emerging risks or concentrations of exposure.
Most importantly, every insight remains fully traceable to its underlying evidence, ensuring that AI supports decision-making without replacing human judgment. The result is greater visibility, stronger accountability, and a scalable foundation for AI-enabled third-party risk management.
Share this article


