Third party risk management services fail in a predictable way: every supplier gets the same 200-question spreadsheet, nobody reads the answers, and the small analytics tool with a live API token into your production database is assessed with the same rigour as the office stationery account.
Risk is not proportional to invoice value. It is proportional to what the vendor can reach (your data, your network, your customers, your ability to operate) and to how quickly you would notice if they were compromised. Tiering on that basis is what makes the programme sustainable, because it concentrates the effort where it changes something.
We build the register, tier the population, run proportionate diligence, get the security terms into the contract while you still have leverage, and monitor what matters after signature. Where a vendor needs formal examination, that is a third-party vendor audit; where their exposure appears publicly, dark web monitoring catches it.