preloader

RANT Roundtable in partnership with Diligent

Thu, Mar 12, 2026
17:30 - 21:30
Sky Garden, London
Home / Events / RANT Roundtable in partnership with Diligent

'From ticking boxes to managing risk: Why teams must think beyond supplier questionnaires'

Supplier questionnaires are still the primary mechanism for assessing and managing third-party risk. But there’s good reason to be sceptical about their efficacy.
Were the questions you posed clear, concise and relevant? And can you really trust the answers? You send out a comprehensive questionnaire, and the supplier’s responses look reassuringly complete — until you notice they’re copy-pasted from last year’s assessment, despite significant changes to their IT environment. Even when answers are current, they have a shelf life: within six months, that ‘low-risk’ supplier may have migrated to new cloud infrastructure, experienced staff turnover, or faced emerging threats that render your assessment obsolete.
And then there’s the resource challenge. Security teams are drowning in questionnaires, lacking the time and capacity to thoroughly review hundreds of generic responses. Critical risks get lost in a sea of tick-box compliance exercises. But perhaps the biggest missed opportunity is treating questionnaires as a compliance endpoint rather than a collaboration starting point. The goal shouldn’t be to simply collect completed forms and file them away. Instead, questionnaires should open a dialogue — a chance to understand your supplier’s actual security posture, identify gaps together, and work collaboratively to strengthen defences on both sides. When security programmes shift from an adversarial ‘audit mentality’ to a partnership approach, both parties benefit. Your suppliers get valuable insights to improve their security maturity, and you build more resilient third-party relationships based on transparency and continuous improvement.Today’s fast-moving technology and threat landscape means point-in-time appraisals, by themselves, are no longer enough.
In an ideal world, your due diligence approach to suppliers should be as dynamic as the risk you need to manage.
The first step is to understand the criticality of each supplier. Then you can build out an appropriate third-party risk management (TPRM) programme.
That’s not to say questionnaires aren’t useful. When used correctly, they can provide a great starting point for TPRM initiatives. But equally they’re not a silver bullet. Too often they’re designed as a one-size-fits-all exercise. Questions might be overly long and complex — and not appropriate to the level of supplier risk involved.
A better way may be to complement security questionnaires with other assessment methods, such as real-time news monitoring, security ratings, and on-site visits. By combining multiple data sources, it’s possible to build a more accurate, multi-layered view of third-party risk.
To find out more, join Diligent and a select group of cybersecurity and risk leaders for an evening of insight and discussion. Hear how your peers are managing the challenges of TPRM. And how AI-powered tools can do more of the heavy lifting, to reduce “questionnaire fatigue” and support real-time monitoring.
It’s time to reduce compliance grind and focus on managing risk.

Agenda

17:30
Bubbly Reception
18:15
Seated Welcome & Introduction
18:20
Roundtable Discussion
19:30
Dinner Served, Networking until close
21:30
Event Close

Our Speaker

Matthew Ford
Matthew Ford
Third Party Risk Management Expert
Howden

Our Proud Partner

At Diligent, we believe in a world where transformational leaders can build more successful, equitable and sustainable organisations. One million users and more than 700,000 board members and leaders rely on Diligent software to connect insights across gove...rnance, risk, compliance, audit and ESG to drive greater impact and lead with purpose. As the leader in governance, risk and compliance (GRC), one of our goals is to help organisations around the world meet their ESG commitments. And as a responsible organization, we have our own ESG commitments that we need to meet too. When it comes to ESG, words are nothing without action. We’re on our journey of translating our commitments into tangible, measurable processes.

Read More

Venue

Fenchurch Restaurant, Sky Garden
1, Sky Garden Walk, London - EC3M 8AF

Interested? Request to Attend

Fill in our form below to express your interest in attending this event and we will get back to you as soon as possible to confirm your seat.

* Please note that attendance to our events is subject to availability and a membership approval.

    Please select all locations you are comfortable to travel to for an event

    LondonManchesterScotlandMidlandsIrelandInternational

    Every delegate attending a RANT event must become an individual member of the RANT community. Individual membership is free and the completion of this form constitutes a membership application. To be approved as a member, you must work for an End User organisation and have registered using a valid work email address, current job title and company name. If you do not meet these terms, your registration will be declined and your data deleted.
    Once you have been approved, you will receive an email notification.For information regarding the collection, controlling and processing of your personal data, please see our Privacy Policy.