The TPRM PodcastThreats, Pitfalls & Risk Myths
Listen onYouTubeSpotifyApple PodcastsiHeartRadio
EP 1October 29, 2025

Beyond the Checklist: Continuous Vendor Oversight

Jadee Hanson

CISO, Vanta

Jadee Hanson

Episode Overview

In this episode, Nate and Jadee dive deep into how security leaders can rethink third-party risk management. They explore the shift from static compliance checklists to dynamic, ongoing vendor evaluations that better reflect real-world risk.

Jadee shares how companies can use automation and transparency to strengthen partnerships without slowing the business down. She also offers insight into buyer leverage, shared responsibility, and how to manage vendor risk without creating bottlenecks.

Key Takeaways

  • Annual vendor reviews don’t cut it anymore; security needs to be continuous.
  • The best CISOs create a culture of accountability with their vendors, not friction.
  • Compliance frameworks are useful, but they’re not the full picture.
  • Continuous monitoring and clear communication lead to better business outcomes.
  • Security leaders have more leverage than they think it’s about using it wisely.