A point-in-time approach to risk management is no longer effective – Help Net Security
With a point-in-time risk management approach, compliance leaders attempt to identify potential third-party risks upfront with extensive due diligence before contracting and again at recertification. However, this approach is largely ineffective: Not only does it contribute to longer onboarding and waiting periods, it also fails to capture any risks that may arise due to ongoing changes throughout the relationship. Among survey respondents who identified risks post-due diligence, 31% of those risks had a material impact on the business.