There are stories we tell ourselves in third-party risk management (TPRM) to make ourselves feel better about the corners we cut.
One of those stories is that the longer the questionnaire, the better. We’ve got everything covered this way. Except… Who has time to properly review all those answers? And are all those answers really addressing the risks we want addressed by this vendor?



