81filers, current period
63the period before
3controls it touches
3frameworks
Third Party Risk Management in 10-K and 10-Q filings, by month.
The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
Companies disclosing it
81
wrote this into a filing with the SEC
What it obligates
3
controls across 3 frameworks whose text speaks to it
Employers hiring for it
1,423
open US roles name it, and the ones below are hiring now
The long view, in annual and quarterly filings
A 10-K or 10-Q is a periodic report, so this counts how often the phrase appears in routine annual and quarterly reporting. It moves far more slowly and the numbers are larger.
Every month since 2008. The last point is the current month and is still
filling, so it always looks lower than it will be.
2008
peak 506 in February 2025
2026
Who disclosed it
From SEC full-text search over 8-K filings. Every row links to the filing itself.
| Company | Form | Filed | |
| PATHWARD FINANCIAL, INC. CASH | 8-K | 2026-07-22 | filing |
| EQUITY BANCSHARES INC EQBK | 8-K | 2026-07-14 | filing |
| ALLIANT ENERGY CORP LNT | 8-K | 2026-07-31 | filing |
| INTERSTATE POWER & LIGHT CO | 8-K | 2026-07-31 | filing |
| WISCONSIN POWER & LIGHT CO | 8-K | 2026-07-31 | filing |
| Aether Holdings, Inc. ATHR | 8-K | 2026-08-11 | filing |
| SideChannel, Inc. SDCH | 10-Q | 2026-08-12 | filing |
| ServiceNow, Inc. NOW | 8-K | 2026-07-22 | filing |
| FIRST BUSEY CORP /NV/ | 8-K | 2026-07-28 | filing |
| Bridgewater Bancshares Inc | 8-K | 2026-08-12 | filing |
| Black Rock Petroleum Co | 10-K | 2026-08-06 | filing |
| Regional Management Corp. RM | 10-Q | 2026-07-31 | filing |
| Paylocity Holding Corp PCTY | 10-K | 2026-08-05 | filing |
| Q2 Holdings, Inc. QTWO | 10-Q | 2026-07-29 | filing |
| AUTOMATIC DATA PROCESSING INC ADP | 10-K | 2026-08-05 | filing |
| HUNTINGTON BANCSHARES INC /MD/ | 10-Q | 2026-07-28 | filing |
The full search on EDGAR
Who is hiring for it
A sample of the open roles naming this phrase. An employer paying a salary
against something is the least ambiguous demand signal there is, and every row links to the
posting so the claim can be checked rather than believed. The total above is the whole US
market; these are the ones we hold the posting for.
| Role | Posted |
| Senior Technical Program Manager, Third Party Risk Management CoreWeave, Inc. · Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA | 2026-09-16 |
| Technical Program Manager, Third Party Risk Management CoreWeave, Inc. · Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA | 2026-09-16 |
| Security Assurance Analyst, Security and Privacy Lyft, Inc. · Mexico City, Mexico | 2026-09-07 |
| Litigation Operations Manager (Recovery) SoFi Technologies, Inc. · UT - Cottonwood Heights | 2026-08-21 |
| Security Risk Management Specialist II Affirm Holdings, Inc. · Remote Canada | 2026-08-20 |
| Security Risk Management Specialist II Affirm Holdings, Inc. · Remote US | 2026-08-18 |
| Information Security Risk and Compliance Analyst CarGurus, Inc. · Boston, Massachusetts, United States | 2026-08-04 |
| Security Risk and Compliance Lead Asana, Inc. · Warsaw | 2026-07-27 |
| Associate Compliance Manager, Complaints Upstart Holdings, Inc. · United States | Remote | 2026-07-15 |
| Head of Risk and Compliance Applied Digital Corp. · Sunnyvale | 2026-03-13 |
Which industries file it
Companies grouped by the industry classification on their own filing. A count, not a
survey.
| Industry | | Companies |
|---|
| Banking | | 268 |
| Chemicals and pharmaceuticals | | 142 |
| Software and IT services | | 126 |
| Securities and investment | | 68 |
| Holding and investment offices | | 63 |
| Instruments and medical devices | | 51 |
| Services and entertainment | | 45 |
| Industrial machinery | | 43 |
| Retail | | 43 |
| Not classified | | 43 |
What it obligates
Our corpus holds 3 controls across
3 frameworks whose text speaks to this. Not a judgement:
these controls say so, and each is one lookup from its source document. Ordered by how much each
framework has to say about it, so the one that will cost you the most work is first. Every name
opens that framework in the corpus.
What an auditor will ask you to produce
The artefacts named on those controls, most frequently cited first.
- TPRM policy
- Vendor inventory
- Due diligence files
- SOC 2 reports
- Vendor risk assessment library
- PRA SS2/21 alignment evidence
- Critical Third Party (CTP) designation tracking
- Concentration risk analysis
How it usually fails
Recorded when each control was verified against its source. This is where programmes
that think they are covered turn out not to be.
- Third party inventory is incomplete and excludes fourth party dependencies
- Due diligence is performed at onboarding but not refreshed periodically
- Vendor risk tiering criteria are subjective and not consistently applied
- Right to audit clauses are present but not exercised
- No PRA SS2/21 alignment
- No CTP analysis
NIST SP 800-161 Cybersecurity Supply Chain Risk Management Evidence & Implementation Kit
191 controls sit behind NIST SP 800-161 Rev 1, and this is the documentation set for them: an adopt-ready artifact per control, and the evidence an auditor asks for against each.
See what is in it, $249
The same set every buyer of this kit receives. Nothing here is produced on request.
NIST SP 800-161 Rev 1 holds 191 controls. They appear again inside
34 other frameworks in our corpus; the 10 strongest are shown. Thickness and
size both carry the number of controls shared, so work done once counts in every framework on
this diagram.
191If you already run NIST SP 800-161 Rev 1, that is the 191 controls behind this disclosure, already evidenced.
460And ISO 27701:2019 is not a separate programme. 460 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
376And ISO 27002:2022 is not a separate programme. 376 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
228And ISO 22301:2019 is not a separate programme. 228 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
Run as two programmes
651 controls
NIST SP 800-161 Rev 1 and ISO 27701:2019 scoped separately, each with its own
evidence, its own owner and its own budget line. This is how almost everybody does it.
Run once, counted twice
460 already done
460 of ISO 27701:2019's controls are controls you evidenced for
NIST SP 800-161 Rev 1. Same artefacts, same owner, no second effort. The mapping is the
only reason anybody knows.
Third Party Risk Management in 10-K and 10-Q filings, by month.
The marked line is the first month any public company in our record used the phrase; everything left of it is nobody writing it down.
What this actually means
- Why now
- 81 public companies wrote this into an 8-K in the last seven days, 29% more than the seven before. That is not sentiment or a survey. It is a count of companies choosing to put a phrase into a document they are legally accountable for.
- Who already cares
- 1,423 open US roles name this work today, which suggests increased attention to it beyond what any filing says. A job advertisement clears a budget holder and a filing clears legal, so the two answer to different people. We have not measured which moves first, only that both are moving.
- What comes into scope
- Once the phrase is on the record it maps to obligations within NIST SP 800-161 Rev 1, ISO 27001:2013, ISO 27001:2022. 458 controls behind those, and the difference between asserting them and evidencing them is the whole of the work.
- Who is quietly ahead
- Anyone already running NIST SP 800-161 Rev 1 has done 460 of the controls that carry ISO 27701:2019 too. Same evidence, second standard. Most organisations run those as two programmes with two budgets because nobody told them the mapping existed.
- Who is exposed
- 8 companies disclosed this for the first time in the last ninety days, out of 1264 in total. A first mention is a company deciding it can no longer not say it. Whoever has not yet is either genuinely unaffected or has not looked, and nothing here distinguishes the two.
What this obligates
The instruments in our corpus that govern this disclosure, and how many controls sit
behind each. This is not a filing count. It is what applies once a company has written the
phrase down.
5 frameworks, 458 controls between them.
NIST SP 800-161 Rev 1 holds 191 controls. They appear again inside
34 other frameworks in our corpus; the 10 strongest are shown. Thickness and
size both carry the number of controls shared, so work done once counts in every framework on
this diagram.
What closing it also moves
The same controls appear in other frameworks through mappings held in our corpus. Work
done here is already progress there. This is the part that is not in EDGAR and not in any public
dataset: it comes from mappings built and verified by hand, control by control.
ISO 27701:2019460
ISO 27002:2022376
ISO 22301:2019228
ISO/IEC 42001:2023161
COBIT 2019148
NIS2 Directive136
PCI DSS 4.0120
Counted as controls reached through cross-framework mappings. It measures
overlap of work, not compliance with the named framework.
Run as two programmes
651 controls
NIST SP 800-161 Rev 1 and ISO 27701:2019 scoped separately, each with its own
evidence, its own owner and its own budget line. This is how almost everybody does it.
Run once, counted twice
460 already done
460 of ISO 27701:2019's controls are controls you evidenced for
NIST SP 800-161 Rev 1. Same artefacts, same owner, no second effort. The mapping is the
only reason anybody knows.
191If you already run NIST SP 800-161 Rev 1, that is the 191 controls behind this disclosure, already evidenced.
460And ISO 27701:2019 is not a separate programme. 460 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
376And ISO 27002:2022 is not a separate programme. 376 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
228And ISO 22301:2019 is not a separate programme. 228 of its controls are the same controls. If it is on next year's plan, that part of it is already done.
Tell me when Third Party Risk Management files something new
One email when a public company newly discloses this, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.
Where this comes from
The left half is public record: SEC full-text search over 8-K filings, counted across a
14 day window against the equivalent window before it. You can check
every row.
The right half is ours: 723 frameworks and
20,473 controls, 531 of those frameworks verified against
their source documents, with the auditor evidence and common failure modes recorded control by
control. Controls appear here because their own text names this term.
Cite this
The Art of Service Signals. Third Party Risk Management corporate disclosure activity: 81 filers against 63 in the prior period, in 10-K and 10-Q filings, this quarter against the same quarter last year. Accessed 23 September 2026. https://signals.theartofservice.com/t/third-party-risk-management/
Free to use with attribution, no permission needed. The chart downloads as an SVG
with the source printed on it. If you cite it we would like to know, but you do not need to
ask.
Today's edition ·
How programmes fail ·
The obligation index