

Third Party Risk Management in the Age of AI and Fourth Parties with Michael Berman
Send us Fan Mail Greg hosts Michael Berman, CEO of End Contracts and author of The Upside of Third Party Risk Management, for a practical conversation about how vendor risk is changing. The discussion focuses on moving beyond static compliance, managing fourth party and shadow AI exposure, and using contracts and frameworks to make third-party governance more actionable. Key topics Greg introduces the episode as a short, practical discussion for risk leaders, then frames the core question: are financial institutions truly reducing vendor risk or mainly satisfying examiners? Michael Berman shares his background as a recovering attorney turned entrepreneur, plus 17 years leading End Contracts and prior experience handling third-party risk as general counsel. Michael says his morning routine is cardio for fitness and stress relief, and he identifies as a technology enthusiast who enjoys learning how new tech works. The conversation opens with Michael's book, The Upside of Third Party Risk Management, which argues that risk management can be an organizational advantage instead of just a fear-driven obligation. Michael says third-party risk is improving, but many programs still overfocus on point-in-time assessments instead of real-world monitoring and response. He uses the Dwell AI startup controversy as an example of why trust but verify matters, especially when funding, AI outputs, and vendor claims collide. Greg and Michael compare vendor reviews to employee reviews, arguing that vendors deserve at least as much ongoing attention as internal staff because they often have deeper access to data and systems. Michael explains the gap between traditional GRC and threat hunting: one asks whether a vendor was secure at onboarding, while the other asks whether something is happening right now that needs action. He emphasizes that organizations need both approaches, plus a shared taxonomy between cybersecurity teams and compliance teams, so risk ratings and threat intelligence align. Michael describes how vendor management must shift from static questionnaires to real-time governance, especially when incidents like MoveIt show the value of knowing which vendors and fourth parties are affected immediately. On fourth party and shadow AI risk, Michael says the governance perimeter has dissolved because vendors now rely on cloud, model providers, subprocessors, APIs, and other hidden dependencies. He recommends expanding governance from just the vendor to the data flows themselves, with continuous discovery, clear escalation paths, and the ability to cut off risky tools quickly. For AI vendors, Michael recommends stronger contractual controls, including notice of material model changes, AI incident notifications, clarity on subprocessors and model providers, and audit or evidence rights. Greg suggests using the term security assessment instead of audit in some cases to reduce friction, and Michael agrees that evidence rights are especially important. Michael cautions that startups can be attractive but risky if they cannot provide maturity, controls, or evidence comparable to more established vendors. Greg adds that vendor requirements should be positioned as business guardrails, not just a flat no, especially when regulators and enterprise risk thresholds are involved. Michael closes by noting that risk leaders should focus first on contractual controls and a usable framework, since those two tools can reduce the need for constant manual intervention. Timestamps 00:00 - Guest introduction and why third-party risk matters 01:14 - The upside of third-party risk management 02:08 - Why Michael would have chosen medicine 02:28 - Technology as Michael's unexpected hobby 02:59 - Favorite place to unplug by the ocean 03:29 - A recent non-business book recommendation 04:11 - Are banks reducing risk or just satisfying examiners? 05:00 - Why vendor failures and fourth parties matter more now 06:14 - Vendor reviews should be as routine as employee reviews 07:22 - Moving from static compliance to active threat hunting 08:14 - Point-in-time assessments versus live monitoring 09:22 - Cyber, financial, and business continuity risks are connected 10:50 - Turning vendor data into action instead of overload 11:43 - Shared taxonomy between security and compliance teams 12:17 - Real-time governance for critical vendors 13:14 - Why MoveIt showed the weakness of one-time vendor questions 14:03 - Why contract terms matter when breaches happen 14:59 - AI is making third-party governance much harder 17:44 - Why AI dissolves the governance perimeter 18:37 - Shadow AI and incomplete vendor inventories 20:02 - Why vendors may not understand their own AI supply chain 21:01 - Expand governance from vendors to data flows 21:57 - Continuous discovery and escalation paths 23:24 - Evidence requirements for AI vendors 24:53 - Material model-change notice and incident notification 25:55 - Security assessment versus audit language 26:52 - Evidence rights and documented validation 27:22 - Why startup AI vendors may be too immature 28:27 - How to push back when the business wants a risky vendor 29:25 - Regulators still show up after a breach 30:16 - Not every AI tool is equally critical 31:12 - Why leaders should not wait for regulation 32:14 - Pick a defensible AI risk framework and stick to it 33:23 - Final advice: contract controls plus a framework Key frameworks Point-in-time vendor assessment versus continuous threat hunting Governance should cover both vendors and data flows Contractual controls should be built at relationship inception AI risk management should be supported by evidence rights, notice obligations, and escalation paths Risk treatment should be proportional to the use case, not just the presence of AI Notable quotes "You might have eight hundred vendors, but that doesn't mean I need to do threat monitoring for eight hundred vendors." "If it wasn't documented, it wasn't done." "Think about what contractual controls you can put in place at the inception of relationships to make your life easier." Action items Review vendor contracts for AI-specific notice, incident, and evidence obligations. Identify which vendors are critical enough to justify continuous monitoring. Build a shared taxonomy between security, compliance, procurement, and legal teams. Treat data flow visibility as part of vendor governance. Pick one defensible AI risk framework and apply it consistently. It works because the title and sectioning make the episode feel practical and high-value, while the timestamps and action items create instant scanability for busy LinkedIn readers. Support the show
- Transcript

