There are stories we tell ourselves in third-party risk management (TPRM) to make ourselves feel better about the corners we cut.
One of those stories is that the longer the questionnaire, the better. Weโve got everything covered this way. Exceptโฆ Who has time to properly review all those answers? And are all those answers really addressing the risks we want addressed by this vendor?

