Problems & solutions · Internal Tools

Third Party Risk Management Software Problems: The 5 That Break in a Crisis, and How to Avoid Them

Third Party Risk Management Software product interface illustration showing common problems and fixes.
The short answer

The most expensive failure mode is a system that cannot answer which business services are affected while the reporting clock is running. A supplier goes down at nine in the morning and the head of vendor risk has an hour to say which services are hit, which regulators need telling and by when, and what the contingency is. Her inventory holds 1,400 suppliers with a criticality column filled in during a programme two years ago. It says the supplier is high risk. It does not say the supplier provides the identity verification step inside customer onboarding, that a second process reaches the same firm through a reseller under a different name, or that the contract required notification within four hours and none came. The cost is a missed or wrong regulatory notification, and the credibility of the whole programme.

Why does a vendor risk project become a questionnaire library?

The requirement that reaches a build team is usually send assessments, collect evidence, score vendors, repeat annually. That is a well understood product and it is what most of the market sells, so it is what gets built. It also inverts the actual work. Sending a standard questionnaire or requesting a service organisation control report is evidence collection. The assessment is the judgement about whether this third party, performing this activity, at this criticality, with these controls, is acceptable.

Systems that make the questionnaire the centre of gravity produce a score, and the score becomes the risk. Then a supplier with a clean questionnaire and a critical dependency looks the same as one with a clean questionnaire and no dependency at all.

The regulatory direction is the other way. The 2023 interagency guidance on third party relationships issued by the United States banking agencies frames the obligation around the risk of the activity, and the European Union Digital Operational Resilience Act, applying from January 2025, requires a register of information about contractual arrangements and treats concentration in critical providers as a systemic issue. Both push toward mapping third parties to services and dependencies, which a questionnaire library does not do.

Scope the first release around inventory reconciliation, criticality tiering derived from business services, and an assessment workflow whose depth follows the tier. That is $70,000 to $150,000 over 12 to 18 weeks in our delivery experience. Build the incident impact view early rather than deferring it, because it is usually the capability that justifies the programme to the board.

What goes wrong when the inventory is imported rather than reconciled?

The single most common way these projects lose credibility is importing the existing spreadsheet. It is the fastest path to a populated system and it means the new platform inherits every blind spot the old one had, now with better reporting on top.

You do not have an inventory. You have three lists that disagree. Procurement holds a supplier master keyed to payment. Legal holds a contract repository. Technology holds applications and integrations, and identity management holds accounts belonging to external parties. The gaps between them are systematic rather than random: a supplier engaged on a corporate card never reached procurement, a contract auto-renewed after its owner left, a software service was adopted by a business team without any of the three knowing.

Reconcile instead of importing. Pull the supplier master, the contract repository, the application inventory, the accounts payable ledger and external identity records, normalise entity names, match them, and treat every difference as work: unmatched payees above a threshold, contracts without a supplier record, external accounts without a contract. Entity name normalisation is the part that takes real effort, because the same firm appears as three legal entities, an abbreviation and a former trading name.

Run it continuously rather than once. A programme built on an inventory nobody reconciles gets undermined the first time an examiner finds a supplier you did not know you had, and they find them by looking at your payments.

Why do the procurement, contract and identity feeds break after launch?

These integrations break in ordinary ways with disproportionate consequences. A procurement platform upgrade changes a supplier record structure. A contract repository migration renames document types. An identity management change alters how external accounts are flagged, so the population you were reconciling against silently shrinks.

The consequence is specific to this domain. When a feed degrades, the reconciliation reports fewer differences, which looks like improvement. A vendor risk platform whose exception count is falling is either genuinely improving or quietly blind, and nothing on the screen distinguishes the two. Teams celebrate the wrong thing for a quarter.

The fix is to monitor the inputs rather than the outputs. Track record counts and match coverage per source on every run and alarm on a shift, not just on a failure. Assert expected volumes: if accounts payable returns eleven thousand payees this month and fourteen thousand last month, that is an incident regardless of what the reconciliation says. Keep the entity normalisation rules versioned and reviewable, because a change there moves match rates across the whole estate.

Name an owner for each feed, in the business rather than in technology. The person who will be asked by an examiner why a supplier was missing is the one who keeps the feed alive.

What happens when contract obligations and exit plans are not covered?

An assessment finds a supplier has no tested recovery arrangement for the service you depend on. The finding is logged, and then nothing happens, because the remedy lives in the contract and the contract is a document in a different system. Most programmes cannot answer whether a given agreement contains a right to audit, an incident notification window, a subcontracting consent requirement, a data location commitment or an exit assistance clause, which means a finding stays a note instead of becoming a negotiating position at renewal.

Model contracts as structured obligations extracted at signature: term and renewal mechanics, notice periods, right to audit, incident notification window, subcontracting consent, data location and transfer terms, service levels with remedies, exit assistance and data return. Then link findings to obligations. Document extraction has a legitimate role proposing that structure from executed agreements for a lawyer to confirm, and it is usually the only realistic way to clear a historic backlog nobody was ever going to read.

Exit planning is the deferred item that costs most when it is needed. For critical relationships the question is not whether the supplier is good, it is what happens if they stop. That means a documented alternative, an estimate of the time to move, the data you would need returned and in what format, and the contractual right to get it. Firms discover the gap when they try to leave. Hold exit plans as living records with a review date, tied to the same criticality tier that drives assessment depth.

Should you build custom or configure what you already own?

If you carry a few hundred third parties, no operational resilience regime applies to you, and your main need is running assessments on a cycle and retaining the evidence, do not build. Venminder, Prevalent and ProcessUnity all do that well, and Venminder in particular suits mid-market financial institutions because it combines the platform with assessment services. A build would be an expensive way to reach the same place. Keep BitSight or a comparable ratings provider regardless of what you build, since external monitoring data is a subscription rather than a project, and keep any questionnaire content you licence rather than rewriting it.

Before commissioning anything, do the reconciliation once by hand. Export your supplier master, your accounts payable payees for the last twelve months and your external identity accounts, and match them in a spreadsheet. It is a week of unglamorous work and it will tell you the size of your real problem more honestly than any vendor demonstration. Most firms find suppliers nobody registered, and that finding is the business case.

Build when two or more of these are true. You must map third parties to business services with disruption tolerances and no product's data model matches your service taxonomy. Your inventory cannot be reconciled to your payments and identity records, which means the programme's foundation is not credible. You need contractual obligations linked to findings so renewals actually change something. You need concentration analysis across fourth parties and shared infrastructure. Or your licence is priced per assessment and the cost has started shaping which vendors you assess.

How do hidden costs get into the quote?

Four items produce most of the overrun.

  • Source system count. Each procurement, contract, application and identity platform in the reconciliation is its own integration with its own access approval, and quotes routinely price the reconciliation as one piece of work.
  • Contract repository condition. It is almost always worse than expected. Whether obligation extraction is a project or an ordeal depends on how many agreements exist only as scanned documents with no consistent naming, and nobody knows the answer until someone samples them.
  • Regulatory scope. A register of information for one regime is not the same artefact as another's. Each has its own required fields, and supporting two is close to twice the mapping work rather than a report variant.
  • Service taxonomy. Agreeing what your business services actually are, and their disruption tolerances, is a workshop exercise with your resilience function and the business. It is not a coding task and it gates everything downstream.

The unpriced cost is legal time. Obligation structures need a lawyer to confirm, and exit plans need one to review. Book it early, because legal capacity is usually the constraint.

What separates a build that works from one that fails here?

Ask how they would reconcile your vendor inventory. A team that has done this starts with accounts payable, because payments are the ground truth that catches suppliers nobody registered, and asks about entity name normalisation and thresholds. A team that starts by importing your existing spreadsheet has agreed to inherit your blind spots and will deliver a tidier version of the problem.

Ask how tiering works. It should derive from the activity, the data touched and the business service supported, not from the vendor or the spend. If the demonstration shows a criticality dropdown on a vendor record, ask what happens when one supplier provides both a critical and a trivial service, because that is common and it breaks vendor-level tiering immediately.

Ask to see an incident impact view. Given a supplier, it should name the affected business services, their tolerances, the regulatory notification requirements with their clocks, the contractual notice obligations and the documented contingency, on one screen. If that view does not exist, the system will not help on the morning it is needed.

Ask how continuous monitoring signals are routed, because an unrouted feed becomes wallpaper and, worse, creates a record showing you were informed and did nothing. Then settle ownership in writing before kickoff. You should own the repository, the infrastructure accounts and the right to hire another firm. At Digital Heroes the code is yours from the first commit. There is an obvious irony in a third party risk programme that is itself an unmanaged single-vendor dependency.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. An independent Forrester Total Economic Impact study of OutSystems found a 363% three-year ROI with payback in under 6 months, illustrating that faster, lower-labor build approaches can materially shift the payback math. Source: Forrester Consulting (commissioned by OutSystems) (2024) →
  2. The federal government spends about 80% of its IT budget on operations and maintenance of existing systems rather than on development or modernization, with many critical systems being decades old. Source: U.S. Government Accountability Office (GAO) (2025) →
  3. McKinsey found that currently demonstrated technologies can fully automate about 42% of finance activities and mostly automate a further 19%, indicating roughly 60% of finance work is technically automatable. Source: McKinsey & Company (2018) →
  4. The 2024 DORA report found AI adoption significantly increases individual productivity, flow, and job satisfaction, but negatively impacts software delivery throughput and stability - a paradox leaders must manage with fundamentals like smaller batch sizes and robust testing. Source: DORA / Google Cloud (2024) →
Devon W. · Senior Account Director · DTC · New York

Devon looks after direct to consumer accounts, where the store is the business and a bad checkout costs money the same day. He works with brands on commerce builds and site changes, and writes about what to prioritize when every request looks urgent.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

Why does importing the existing vendor spreadsheet undermine the whole programme?
Because it carries every blind spot forward and adds better reporting on top. The suppliers that cause problems are the ones nobody registered: engaged on a corporate card, auto-renewed after the owner left, or adopted by a business team without procurement. Examiners find them by looking at your payment ledger, so reconcile against accounts payable, the contract repository, the application inventory and external identity records rather than importing, and treat every unmatched record as work rather than as noise.
Should criticality be set on the vendor or on the service?
On the service, derived from what the third party actually does: the data it touches, the business service it supports, that service's tolerance for disruption, whether the activity is customer facing or regulated, and how quickly it could be substituted. Vendor-level tiering breaks as soon as one supplier provides both a critical and a trivial service, which is common. Assessment depth then follows the tier, which usually reduces total assessment volume while increasing rigour where it matters.
How can a vendor risk platform be quietly blind rather than visibly broken?
When a source feed degrades, the reconciliation reports fewer differences, which looks like improvement. A falling exception count is either genuine progress or lost visibility, and nothing on the dashboard distinguishes them. Monitor the inputs: track record counts and match coverage per source on every run, alarm on a shift rather than only on a failure, and assert expected volumes so a payables extract returning three thousand fewer payees than last month becomes an incident regardless of what the reconciliation shows.
Why do assessment findings never lead to anything changing?
Because the remedy lives in the contract and the contract is a document in a different system. If nobody can say whether an agreement contains a right to audit, an incident notification window, a subcontracting consent requirement or an exit assistance clause, a finding stays a logged note. Extract obligations into structure at signature and link findings to them, so a gap becomes a negotiating position at renewal. Document extraction can propose the structure for a lawyer to confirm.
What is usually missing from exit planning?
Everything except the intention. For a critical relationship you need a documented alternative, an estimate of the time to move, the data you would need returned and in what format, and the contractual right to obtain it, held as a living record with a review date rather than a document written once during an onboarding. Firms typically discover the gap when they try to leave, which is the worst moment to learn that exit assistance was never negotiated into the agreement.
How do we map fourth party and concentration risk without complete disclosure?
Model dependencies as a graph from business service to third party to disclosed material subcontractors to shared infrastructure, then query which providers sit beneath more than a defined number of critical services. You will not get full disclosure, so record what you asked for and did not receive and leave the gaps visible rather than presenting a map that looks finished. A complete looking map with silent holes is more dangerous than an honest one with named unknowns.
What should we do by hand before commissioning a build?
Reconcile once in a spreadsheet. Export your supplier master, twelve months of accounts payable payees and your external identity accounts, and match them. It is a week of unglamorous work and it sizes your real problem more honestly than any vendor demonstration. Most firms find suppliers nobody registered, and that list is the business case. It also tells you how bad entity name normalisation will be, which is the largest variable in the eventual build.
Which costs are usually left out of a vendor risk quote?
The number of source systems in the reconciliation, each with its own integration and access approval. The condition of the contract repository, which determines whether obligation extraction is a project or an ordeal and which nobody knows until someone samples it. Regulatory scope, since a register of information for one regime is not the same artefact as another's. And agreeing your service taxonomy with the business, which gates everything downstream. Legal review time is the unpriced item on your side.
What does an internal tool cost for a small business with 20 to 50 employees?
Plan on $5,000 to $15,000 for a focused tool that replaces one painful spreadsheet workflow, such as job scheduling, quoting, or PTO tracking. In Digital Heroes projects at this size, the sweet spot is one core workflow, two or three user roles, and a single integration, usually QuickBooks or Google Workspace. Quotes far below $5,000 usually mean a template with your logo on it rather than software built around your process.
Can I build my product on a no-code tool like Bubble instead of hiring developers?
For testing whether anyone wants the product, yes, and Bubble's paid plans start at $29 a month, which is the cheapest validation you will ever buy. The ceiling arrives with complex data relationships, heavy integrations, performance at a few thousand users, and the fact that you cannot export a Bubble app to servers you control. A path many Digital Heroes clients take: prove demand on no-code, then rebuild custom once revenue justifies it, treating the no-code version as a paid prototype rather than a foundation.
How do we migrate years of spreadsheet or Airtable data into a new internal tool?
Migration is a standard part of the build, not a separate project: the agency writes import scripts that clean, deduplicate, and map your existing rows into the new database. On typical spreadsheet and Airtable histories, Digital Heroes budgets 3 to 10 extra days, most of it spent resolving inconsistencies like the same customer spelled four different ways. The safe sequence is a trial migration first, a review of flagged conflicts with your team, then final cutover over a weekend so nobody loses a working day.
How do I calculate the ROI of a custom internal tool?
Count hours first: multiply the weekly hours staff spend on the manual process by their loaded hourly cost, then add the cost of errors such as mispriced quotes or missed renewals. A tool saving a 10-person team 5 hours each per week recovers about 2,500 hours a year, which repays a $20,000 to $30,000 build well inside a year at typical wages. Most internal tools Digital Heroes delivers reach payback in 6 to 18 months, with quoting and billing tools at the fast end because they plug revenue leaks, not just time.
What should I prepare before contacting an agency about an internal tool?
Bring the spreadsheet or document you run the process on today, a list of everyone who touches the workflow and what each person does, and one sentence describing the outcome you want. You do not need wireframes or a technical spec; a 30-minute screen-share of the current process beats a 20-page requirements document. Decide your rough budget band and name a single internal decision-maker, because projects without one take noticeably longer in Digital Heroes experience.
Can we start on Airtable or Retool now and move to custom software later?
Yes, and it is often the smartest sequence: run the workflow on Airtable or Retool for 6 to 12 months to learn what you actually need, then go custom once the process stabilizes. The no-code version becomes free requirements documentation, and its data exports cleanly into a custom database. The one risk is waiting too long, because teams stack automations and workarounds until migration becomes a project of its own, so set a concrete trigger in advance, such as hitting Airtable's 50,000-record Team plan cap.
Should we build the whole internal tool at once or start with an MVP?
Start with a version that fully replaces one workflow, ship it in 4 to 6 weeks, and let real usage set the roadmap. Internal tools have a captive audience, so you learn within days which features matter, and across Digital Heroes projects roughly a third of initially requested features never get built once staff work with version one. Phasing also spreads the spend: a $40,000 vision becomes a $15,000 phase one that starts paying for itself while phase two is scoped.
Who can build a custom internal tools system?

Digital Heroes builds custom internal tools systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other internal tools companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?