The Two-Front Threat: Using AI to Govern Vendors in a Post-Quantum World
11:00 AM - 11:50 AM
The third-party risk function is caught between two converging threats and most programs are equipped for neither.
On one front: AI-enabled vendors deploy adaptive systems that drift, bias, and change behavior long after onboarding. Annual questionnaires can't catch it. On the other: nation-state actors are executing "Harvest Now, Decrypt Later" campaigns right now, banking on quantum computers to crack your suppliers' encrypted data within the decade. NIST finalized post-quantum cryptographic standards in 2024. Most organizations still have no structured way to assess whether their vendors are even aware.
This session makes the case that TPRM by Exception - using AI to auto-collect evidence, score continuously, and surface exceptions for human judgment - is the same operating model needed to tackle both problems at scale. Attendees will leave with a practical framework for governing AI-enabled vendors in real time and launching a PQC readiness program across their supplier base, and a clear argument for why these two mandates belong in the same program, run by the same team.