What department typically owns the Third Party due diligence/assessment process?
Procurement14%
Operational Risk44%
Audit20%
Vendor Risk Management 10%
Cybersecurity9%
Legal2%
86 PARTICIPANTS
Procurement14%
Operational Risk44%
Audit20%
Vendor Risk Management 10%
Cybersecurity9%
Legal2%
Yes54%
No44%
Unsure1%
Data breaches due to remote work8%
Ransomware attacks50%
Lack of a corporate security plan23%
Missing security patches9%
Failure to inform employees of threats4%
Other (please specify)2%
No selling.
No recruiting.
No self promotion.
Rules of EngagementFAQsPrivacy
© 2026 Gartner, Inc. and/or its affiliates. All rights reserved.