{"id":103,"date":"2026-09-02T23:30:50","date_gmt":"2026-09-02T23:30:50","guid":{"rendered":"https:\/\/bayrisk.com.au\/blog\/?p=103"},"modified":"2026-09-02T23:30:50","modified_gmt":"2026-09-02T23:30:50","slug":"the-rules-on-third-party-risk-changed-the-behaviour-hasnt-i-want-to-understand-why","status":"publish","type":"post","link":"https:\/\/bayrisk.com.au\/blog\/2026\/09\/02\/the-rules-on-third-party-risk-changed-the-behaviour-hasnt-i-want-to-understand-why\/","title":{"rendered":"The rules on third-party risk changed. The behaviour hasn&#8217;t. I want to understand why."},"content":{"rendered":"<body>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>TL;DR.<\/strong> ISACA has effectively called time on the supplier security questionnaire, and Australia\u2019s regulators have moved the same way. Under CPS 230, CPS 234, the SOCI Act and now Tranche 2, a critical supplier\u2019s signature on a self-assessment is no longer accepted as proof. The rule is clear. What puzzles me is that in my own client conversations the behaviour has barely shifted. The questionnaires still go out and the attestations still come back. So I want to put a genuine question to you, and I have made it a two-tap poll. Is the inertia because people do not know what to do instead, or because nobody else has moved yet?<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">For a couple of years now the conversation about third-party risk has been changing, and lately it has changed decisively. ISACA, the professional body that trains and certifies a large share of the world\u2019s auditors, has effectively called time on the security questionnaire as a source of assurance. The regulators here have arrived at the same place from their own directions. APRA\u2019s CPS 234 requires you to assess the information security capability of any third party that handles your data. CPS 230, fully in force since the middle of 2026, requires you to understand and manage the risk of your material service providers and to be able to demonstrate that resilience on a day the regulator chooses, not one you choose. The Security of Critical Infrastructure Act treats your supply chain as a hazard you must actively address in your risk management program. And AUSTRAC\u2019s Tranche 2 reforms now push supply-chain and customer due diligence into a whole population of professional-services firms for the first time.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Read together, they say one thing. A critical supplier telling you they are fine is no longer proof that they are. Self-attestation, the questionnaire you send and the signed response you file, is no longer enough.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">I think that is clear. Which is why the next part puzzles me.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">In the conversations I have with the people who carry this risk, I am not seeing the behaviour change. The questionnaires still go out on the same cadence. The attestations still come back and get filed. The annual ritual runs as it always has, and the spreadsheet that records it is treated as the control. Everyone I speak to can tell me the rules have moved. Very few of them are doing anything differently because of it.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">That gap is what I want to understand, and I have a couple of theories.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>The first is that people do not actually know what to do instead.<\/strong> The regulators have been clear about what is no longer acceptable, and much quieter about what should replace it. If you strip out the questionnaire, the obvious question is \u201cwhat do i replace it with?\u201d, and the honest answer, assess your critical suppliers from real evidence rather than their own say-so, can sound like boiling the ocean. Faced with a vague and enormous-sounding task, it is very human to accept the status quo<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>The second is that nobody else has moved.<\/strong> Risk teams look sideways at least as much as they look up. If every peer organisation is still running questionnaires, then continuing to run questionnaires feels defensible, and being the one who does something different feels exposed. So everyone waits, quite rationally, for a first mover or a first enforcement action to make the change safe. The herd does not turn until something turns it.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">There are other candidates. Perhaps the deadline still feels distant, or there has been no enforcement yet to concentrate minds, or the person who would own the change does not exist on a stretched team. But my two main suspects are those first two, and they point to very different fixes, which is exactly why I want to know which one it really is.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Because here is the part that does not depend on the reason. When the incident happens, or the audit lands, the reason you did not change will not help you. \u201cOur supplier told us they were fine\u201d is not a defence, and \u201ceveryone else was still doing it too\u201d is not a control. The question you will be asked is what you knew, and could prove, about the supplier you chose to rely on. And the timing of that question is not set by your peers. It is set by the incident, or the regulator.<\/p>\n\n\n\n<div id=\"tprm-camps\" style=\"font-family:Montserrat,Arial,Helvetica,sans-serif;background:#F5F2EA;border:1px solid rgba(198,161,91,.5);border-radius:12px;padding:26px 26px 18px;margin:28px 0;max-width:760px;\">\n  <div style=\"font-size:12px;letter-spacing:3px;text-transform:uppercase;color:#9C7A38;font-weight:700;margin-bottom:6px;\">A question for you<\/div>\n  <div style=\"font-size:23px;font-weight:800;color:#0C2340;letter-spacing:-.3px;line-height:1.15;margin-bottom:6px;\">Which camp are you in?<\/div>\n  <div style=\"font-size:15px;color:#5a6478;margin-bottom:18px;\">Tap the one that sounds like your organisation.<\/div>\n\n  <details style=\"border-left:3px solid #C6A15B;background:#fff;border-radius:8px;padding:12px 16px;margin-bottom:10px;\">\n    <summary style=\"cursor:pointer;font-size:16px;font-weight:700;color:#0C2340;\">We don\u2019t know what \u201cgood\u201d looks like now<\/summary>\n    <div style=\"font-size:15px;color:#3a4453;line-height:1.55;margin-top:10px;\">The most common answer, and the most fixable. \u201cStop trusting attestation\u201d arrived without a replacement. The replacement is not a longer questionnaire, it is evidence: seeing your critical suppliers from the outside. Start with the few whose failure would actually hurt.<\/div>\n  <\/details>\n\n  <details style=\"border-left:3px solid #C6A15B;background:#fff;border-radius:8px;padding:12px 16px;margin-bottom:10px;\">\n    <summary style=\"cursor:pointer;font-size:16px;font-weight:700;color:#0C2340;\">We\u2019re waiting \u2014 nobody else has moved<\/summary>\n    <div style=\"font-size:15px;color:#3a4453;line-height:1.55;margin-top:10px;\">The quiet answer, and the riskiest. \u201cEveryone else still does it this way\u201d feels safe right up until the audit or the incident, when the regulator asks what you knew, not what your peers did. The first mover is not the exposed one. The last is.<\/div>\n  <\/details>\n\n  <details style=\"border-left:3px solid #C6A15B;background:#fff;border-radius:8px;padding:12px 16px;margin-bottom:10px;\">\n    <summary style=\"cursor:pointer;font-size:16px;font-weight:700;color:#0C2340;\">It\u2019s too hard \u2014 we don\u2019t have the capacity<\/summary>\n    <div style=\"font-size:15px;color:#3a4453;line-height:1.55;margin-top:10px;\">Fair, and honest. The answer is not more hours from a team that has none. It is a small, repeatable operation over the handful of suppliers that matter, run for you, rather than another portal to administer.<\/div>\n  <\/details>\n\n  <details style=\"border-left:3px solid #C6A15B;background:#fff;border-radius:8px;padding:12px 16px;margin-bottom:14px;\">\n    <summary style=\"cursor:pointer;font-size:16px;font-weight:700;color:#0C2340;\">We\u2019ve already changed<\/summary>\n    <div style=\"font-size:15px;color:#3a4453;line-height:1.55;margin-top:10px;\">Good, you are ahead of most. The real test is whether it is a live position or last year\u2019s report, and whether you could prove it on a day the regulator picks, not one you do.<\/div>\n  <\/details>\n\n  <div style=\"font-size:15px;color:#0C2340;font-weight:600;border-top:1px solid rgba(12,35,64,.12);padding-top:14px;\">\n    I\u2019m genuinely trying to find out which of these is most common. <a href=\"https:\/\/lnkd.in\/p\/gjhn74r2\" style=\"color:#9C7A38;font-weight:700;\">Add your vote in the poll on LinkedIn \u2192<\/a>\n  <\/div>\n<\/div>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">None of this means you have to boil the ocean. You do not need to assess every supplier from the outside overnight. You need to start with the handful whose failure would genuinely hurt, move from asking them to attest to seeing them from the outside on evidence, and turn it into a small, repeatable operation rather than a once-a-year ritual. That is a manageable first step, not a transformation program, and it is a great deal more defensible than another signed form.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">So I will end where I started, with a genuine question rather than a lecture. I do not think the regulation is the confusing part any more. The behaviour is. If you carry this risk, tell me which it is for you, the not-knowing or the waiting, because the honest answer changes what actually helps. I have put it to a vote, and I would value yours.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>References<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ISACA, guidance on third-party and vendor risk assessment, isaca.org<\/li>\n\n\n\n<li>APRA, Prudential Standard CPS 230 Operational Risk Management, and CPS 234 Information Security, apra.gov.au<\/li>\n\n\n\n<li>Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act and the CIRMP supply-chain hazard, cisc.gov.au<\/li>\n\n\n\n<li>AUSTRAC, AML\/CTF reforms (Tranche 2), austrac.gov.au<\/li>\n<\/ul>\n<\/body>","protected":false},"excerpt":{"rendered":"<p>TL;DR. ISACA has effectively called time on the supplier security questionnaire, and Australia\u2019s regulators have moved the same way. Under CPS 230, CPS 234, the SOCI&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[14,1],"tags":[24,36,41,40,28,33,31],"class_list":["post-103","post","type-post","status-publish","format-standard","hentry","category-supply-chain-risk","category-uncategorized","tag-cps-230","tag-grc","tag-soci-act","tag-supply-chain-risk","tag-third-party-risk","tag-tprm","tag-tranche-2"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/comments?post=103"}],"version-history":[{"count":4,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/103\/revisions"}],"predecessor-version":[{"id":107,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/103\/revisions\/107"}],"wp:attachment":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/media?parent=103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/categories?post=103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/tags?post=103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}