October 5, 2026

Vendor Risk Tiering with AI: How to Clean Up a Messy Vendor Inventory

Vendor risk tiering sorts third parties by potential damage. AI can tier a whole inventory in minutes, but only as accurately as the data you give it.
October 5, 2026

What is vendor risk tiering? Vendor risk tiering sorts third parties by how much damage they could do, usually based on the data they touch, the access they hold and how critical they are to operations. Tiers decide how deeply and how often each vendor gets reviewed. AI can apply a tiering rubric to an entire inventory in minutes, but it can only be as accurate as the data you give it.

That was one of four experiments Trustero CEO Phillip Liu ran live at Onspring GRC Day in Denver using Claude, an off-the-shelf AI assistant. This one started where most TPRM programs actually start: a spreadsheet.

Why most vendor inventories are a mess

Most teams can't see their whole vendor list. In the SecurityScorecard 2026 Supply Chain Cybersecurity Trends Report, about 78% of organizations said their cybersecurity oversight covers fewer than half of their vendors. Meanwhile, Verizon's 2026 DBIR found a third party involved in 48% of breaches.

In the talk's fictional scenario, Redrock Outdoor Co. has 38 rows in a vendor spreadsheet that three departments maintain separately. Three people own it, which means nobody does. It looks like a lot of real inventories:

  • Duplicates with conflicting facts. The same vendor appears twice, with different owners and different data descriptions.
  • Owners that aren't people. Eight vendors are "owned" by a team mailbox.
  • Tiers assigned by vibes. Criticality was set by whoever added the row, on whatever day it was.
  • Blind spots in "no data" vendors. A janitorial vendor with after-hours badge access to headquarters is rated Low because it touches "no data."
  • No review schedule. Nobody knows who's overdue, because nobody has ever computed it.

Regulators have noticed. Mitratech's look at TPRM exams in 2026 says examiners now expect one vendor record that every team draws from, tiered by risk so the highest-exposure relationships get watched continuously.

The test: clean it up and tier it

The prompt gave Claude the inventory export and an explicit rubric:

  • Tier 1: SSN, bank, card or health data; admin access; or critical to store operations.
  • Tier 2: Other PII, or physical access.
  • Tier 3: Everything else.

It asked Claude to find duplicates and data problems, tier every vendor, flag where the existing Criticality column disagreed, list who's overdue, and name the five things to fix first.

The result, in about three minutes:

  • 38 rows, 33 unique vendors. 19 Tier 1, 12 Tier 2, 2 Tier 3.
  • 27 of 33 overdue for review. 14 had never been reviewed at all.
  • 4 duplicate pairs. One print vendor appeared under both HR and Marketing with two owners. Only one row mentioned W-2s.
  • 15 vendors rated too low, none too high. A chat vendor marked "Low" had notes saying card numbers land in chat transcripts. That's PCI scope.
  • Top fix: An ERP consulting firm whose contractors had production admin access to the SOX system, with no criticality rating and no SOC 2 on file. For a public company, that's a gap that shows up in the SOX audit.

Notice the direction of the errors. Every tier disagreement was a vendor rated too low. Informal tiering tends to underestimate risk, and those are the vendors that surprise you.

Where AI stops: your columns are its ground truth

Bad data in, confident tiers out. A vendor whose data field said "contains everything" got Tier 1 on faith. An HVAC vendor marked "None" was taken at face value until the notes said otherwise. AI tiers what the spreadsheet says, not what's true.

It can't tell you who owns anything. Eight vendors belonged to a mailbox, and one had two owners. Claude listed the conflicts and stopped. Resolving ownership is a hallway conversation, not a prompt.

It remembers nothing. Close the chat, and the tiers, the overdue list and the reasoning are gone. A spreadsheet plus a chatbot is still a spreadsheet. The answers need somewhere to live.

How to tier vendors with AI

  1. Write the rubric down first. "Tier my vendors" gets generic output. A rubric based on data type, access and operational criticality gets defensible tiers.
  2. Separate criticality from risk. How much you depend on a vendor and how risky it is are different questions. Our evidence-first, gap-driven TPRM workflow shows how to score each and match due diligence depth to the tier.
  3. Include the notes column. In this test, the riskiest facts were in free-text notes, not the structured fields. That's the connect-the-dots problem at the heart of TPRM.
  4. Ask for disagreements, not just tiers. Where AI and your current rating differ is where your review should start.
  5. Compute review dates. Overdue reviews should be scheduled, not discovered.
  6. Resolve owners with people. Every vendor needs a named human owner, not a mailbox.
  7. Move the results into your GRC platform. Tiers, owners and review dates are records. If they aren't in your system of record, they didn't happen. Trustero integrates with the GRC platforms teams already use, so AI output lands where the rest of the program lives.

As the talk put it: AI reads everything, remembers nothing, and signs off nothing. It's excellent at the sorting. The judgment calls, the owner conversations and the system of record are still yours.

FAQ

How many tiers should a vendor risk program have? Three is common and easy to operate: high-risk vendors with sensitive data or privileged access, moderate-risk vendors with limited PII or physical access, and low-risk vendors. The rubric matters more than the number of tiers.

Can AI assign vendor risk tiers? Yes, if you give it a written rubric and complete data. It will apply the rubric consistently, but it takes your inventory's fields at face value.

Why do vendors with "no data access" still need risk review? Physical access, admin access and operational dependency are risks too. A vendor with after-hours badge access to headquarters can be a bigger risk than one handling marketing lists.

Trustero builds a multi-agent AI system for GRC teams that works alongside the GRC platforms you already use. Book a demo.