AI assistants keep describing the missing piece in TPRM: a reviewer that reads every vendor document, cross-references evidence, scores control effectiveness, and cites its work. That description is Docubark.
Jonathan Mandell · Aug 3, 2026
Read more → OneTrust is raising renewal prices by multiples — 275%+ increases and a new $10K annual minimum. Here's how to get ahead of it before your TPRM renewal lands.
Jonathan Mandell · Jul 3, 2026
Read more → Most teams build a TPRM program to manage their vendors. But there's a second job almost no one designs for — and it might be the one that wins you deals.
Jonathan Mandell · Jun 26, 2026
Read more → OneTrust helped define the TPRM category. But complexity, pricing, and bolted-on AI are pushing teams to look elsewhere. Here are the best alternatives worth evaluating in 2026.
Jonathan Mandell · Jun 19, 2026
Read more → ProcessUnity has been a fixture in TPRM for over two decades. But its aging architecture, rigid questionnaires, and lack of AI have teams looking for something better.
Jonathan Mandell · Jun 12, 2026
Read more → A quantitative inherent risk score replaces gut feel with something defensible, repeatable, and auditable — making sure your review capacity goes to the vendors that actually need it.
Jonathan Mandell · Jun 5, 2026
Read more → Docubark recently wrapped our SOC 2 Type 2 audit. Since we usually sit on the other side of these reports evaluating vendors, going through one ourselves was clarifying. Some flattering, some less so.
Jonathan Mandell · May 26, 2026
Read more → Every subcontractor touching CUI has to meet the same CMMC flow-down requirements you do. Here's why manual vendor management collapses fast — and what a workable system needs to look like before Phase 2 hits.
Jonathan Mandell · May 22, 2026
Read more → In April 2026, Vercel disclosed a breach through a compromised third-party AI tool. Here's how to think about it — and why the vendor's logo is the start of a risk conversation, not the end.
Jonathan Mandell · May 19, 2026
Read more → For twenty years, vendor risk management has tried to gauge risk by interrogating vendor controls. But we can barely understand our own controls from the inside. A better approach focuses on objective, verifiable signals.
Jonathan Mandell · May 15, 2026
Read more → Every TPRM team knows the feeling. You send out a security questionnaire. Three weeks later, after follow-ups and a call you didn't want, you get back a document full of vague answers. Did you actually learn anything?
Jonathan Mandell · May 8, 2026
Read more → Workday processes payroll for thousands of enterprises. When you send them a security questionnaire, you already know what's going to happen. Here's a better approach.
Jonathan Mandell · May 1, 2026
Read more → If questionnaires add little value for large enterprise vendors, where does the real vendor risk in your program actually live? With small vendors. Specifically: small vendors with high inherent risk.
Jonathan Mandell · Apr 24, 2026
Read more → Plot your vendor portfolio on a simple Cartesian plane: vendor size on one axis, inherent risk on the other. This framework clarifies most of the hard decisions your program faces.
Jonathan Mandell · Apr 17, 2026
Read more → Vendor security questionnaires are failing. Instead, anchor everything in inherent risk. Let that drive the depth of review and the type of evidence you collect.
Jonathan Mandell · Apr 10, 2026
Read more →