The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on June 25, 2026, and appears here lightly edited for the web.
The Signal
Third-party and vendor risk is the densest non-AI cluster in the last 30 days of member submissions. And the submissions have changed shape. Members are not asking who is in the category anymore. They are naming specific tools and putting them against what they already own.
A business-services VP of information security is weighing Black Kite against an incumbent GRC platform whose third-party module he calls bare-bones. A software IT-operations leader has decided to leave OneTrust and is shopping replacements. An IT-services director put SecurityScorecard and Daylight Security on one evaluation list. A law firm is standing up a vendor assessment program because its own clients now require it.
Underneath all of it is one move: away from the once-a-year questionnaire and toward continuous monitoring. It is showing up in regulated and unregulated industries at the same time. The trigger is increasingly external. Clients and contracts are forcing the upgrade, not internal policy.
Vendor Risk Watchlist — 30 Days
These are the vendor-risk, GRC, and identity-governance tools your peers put in play over the last 30 days:
Black Kite · SecurityScorecard · OneTrust · Complyance · HALO · Strivacity · Daylight Security · TrustOnCloud
Eight different tools in active evaluation across the network in a single month, and no clear front-runner. The category is wide open, which is exactly why your peers are re-shopping it rather than renewing.
From the Network
“We are looking for a Vendor Information Security Assessment and tracking tool to comply with our Vendor Management requirements from our clients.”
Manager of Information Security, Law Firms & Legal Services
“We conduct an evaluation of TPRM solutions every 36 months to ensure that we are using the best solution we can in this space.”
Vice President & Chief Information Security Officer, Business Services
“Learn more about risk detection for our GRC/Vendor Management Platform.”
Senior Director, Information Technology, IT Services
Three industries, one move. The incumbent GRC suite stays in place, but the vendor-risk layer is being re-evaluated on its own. For the law firm, the pressure is coming straight from its clients.
Top Open Priorities
“We use Complyance as a GRC platform and it’s got a bare-bones TPRM module but I’m open to learning how Black Kite runs things.”
VP of Information Security, Business Services
“Need to implement a GRC program organization wide.”
Senior Director, IT Infrastructure & Security, Organizations
Working on either of these? These are live asks in the network.
One is modernizing a stack it already owns. The other is building governance from zero. Neither has an incumbent vendor locked in, which is why both are live, winnable asks right now.
Member Spotlight
Joe Letizia, Armstrong International. This week the network is busy scrutinizing its vendors. Joe Letizia built a career on the other side of that table. He has run global IT at Armstrong International for nearly two decades, and he put it plainly in his DoGood spotlight: “When you buy software as a service now, ask for sixty days on the front end, because you’re going to be running two systems at once while you stand the new one up.”
Deep Dive: Third-Party & Vendor Risk
Thirty-three member submissions touched third-party and vendor risk in the last 90 days. The dominant pattern is a shift away from the annual questionnaire toward continuous monitoring, pushed as often by clients and contracts as by internal policy.
Where activity is concentrated
TPRM and continuous vendor monitoring is the largest piece, around a dozen submissions. The recurring complaint is that existing programs are questionnaire-driven, and the questionnaires come back late, incomplete, or not at all. One law-firm security leader put it plainly: they pay a TPRM provider, but it is “just questionnaires that go to our vendors,” and the remediation work still lands on them.
Compliance and framework alignment is nearly as large. Members are syncing vendor risk to CIS, SOC 2, GLBA, and HIPAA, and want it tied to those frameworks rather than tracked on the side.
GRC platform and program builds is smaller but high-intent. Some are replacing incumbents: one government team swapped ServiceNow for HALO and is already eyeing the next replacement, and a software team is leaving OneTrust. Others are standing up a GRC program for the first time.
Identity and access governance shows up alongside vendor risk, with members comparing tools like Strivacity for both internal and external identity.
What your peers are buying
Active evaluations, not closed deals. Vendor, then buyer title and industry:
| Vendor | Activity |
|---|---|
| SecurityScorecard | IT Services director · June |
| Black Kite | VP InfoSec, Business Services · June |
| Strivacity | Head of Risk, Government · June |
| TrustOnCloud | Cybersecurity Director, Construction · June |
What’s still open
Continuous, factual vendor monitoring is the clearest gap. The government GRC team wants vendor risk tracked without sending annual questionnaires and hoping for honest answers. No member named a tool they were satisfied with here. The incumbents, the ServiceNow-class GRC suites and OneTrust, are the ones being left, not the ones being praised.
Greenfield GRC is the second open lane. Members standing up a program from zero have no incumbent to displace, which makes them the most winnable and least contested buyers in the category.
If your TPRM is still a once-a-year questionnaire, treat that as a gap, not a process. Map your vendors by data sensitivity, then ask your current provider one question: what does it tell you about your top-tier vendors between assessments? If the answer is nothing, you already know what your next evaluation is.
The Context
The headlines are catching up to what the network already knew.
ISACA’s 2026 third-party risk guidance makes the same call your peers are making: move from questionnaire fatigue to what it calls contextual assurance, built on continuous monitoring instead of point-in-time surveys. The standards bodies are now writing down what members started buying months ago.
Bottom Line
The questionnaire is not dying because it asks the wrong questions. It is dying because the vendors receiving it stopped answering honestly, and your peers figured that out before the standards did.
What to Do About It
Pull your vendor list and tier it by data sensitivity before your next risk review. For the top tier, ask your current TPRM tool what signal it gives you between annual assessments. If the answer is a questionnaire and nothing else, that gap is your Q3 evaluation.