Found this on LinkedIn.
Our advice: don't do use it even though it might sound very helpful.
Why? AI already do much better than manual questionnaire like this.
And, do you really have time to complete each assessment like this for all your vendors?
Receiving a clean SOC 2 report from your vendor is not the end; it's actually only the beginning.
But do you really have time to read so many SOC 2 reports because you have multiple vendors?
We actually read SOC 2 reports, analyze them and evaluate them against your own rules.
People think that the pain of dealing with security questionnaires is only for the vendors. Especially the startups and SMBs.
Actually it’s also painful for those who work on the other side.
We are here to fix both sides altogether.
We never plan or even want to replace anyone working on third party risk management tasks.
We actually want to empower them so that they can be more happy with their job.
Yes: Happy!
Why? Because our founder @FeHa did the role for several years and he hate it down to his bones
2026 yet there are still large service providers who gated their SOC 2 report only for enterprise customers.
Glad that at 3rdComply we can still do vendor risk assessments using publicly available information.
Ideal? Of course not, but we have to work with what we have, right?
Founders, would you rather buying a tool to automatically answer security questionnaires for you or better buying a service that will handle everything for you?
Be honest!
Do you know that most TPRM platforms today are still glorifying security questionnaires?
Their narrative: companies can manage security questionnaires better, faster and at scale.
Why can’t they prevent companies to send security questionnaires in the first place?
Anyone working in TPRM hate chasing vendors to complete or fix their answer to the security questionnaires.
Why sending security questionnaires at all?
@ConsumerBankers The amount vendors and work pressure in TPRM ar eno longer healthy and sustainable.
And why in 2026 many companies still managing TPRM manually while the vendors themselves already using AI in many aspects of the process?
If today's quality of ISO 27001 or SOC 2 audits are as bad as many security gurus claim, then why TPRM analysts still reviewing security questionnaires answer and supporting documents manually?
@withkarann_ Awesome. AI is the way to go for this security questionnaire drama.
We are offering the same thing, but also with human support as service. Why? Because tech alone is never enough based on our experience.