How to Build a Third-Party Risk Management Budget Case When There Is No ROI Number

How to Build a Third-Party Risk Management Budget Case When There Is No ROI Number

Budget season arrives with the same problem every year. You know what your program needs. You know what happens if it does not get it. And you cannot produce the one thing the process is built to compare: a return. 

Every other request in the room has one. A sourcing initiative promises savings. A systems project promises hours. Yours promises that something will not happen, which is real, and which no budget template has a field for. 

This is not a presentation problem, and a better slide will not fix it. It is a structural mismatch between what prevention work produces and what a budget process is designed to evaluate. Understanding the mismatch is what lets you argue around it.

Why the ROI Model Fails for Prevention Work 

A working third-party risk program produces an absence. No fraud loss. No sanctions exposure discovered by a regulator before you found it. No supplier failure that nobody saw building. 

The problem is that a year in which nothing went wrong looks identical to a year in which nothing was going to go wrong anyway. From outside the program, and certainly from a finance seat, there is no observable difference between the two. 

So when you build an ROI model for prevention work, you end up projecting a return that cannot be evidenced, and everyone in the room knows it. The number gets larger to compensate for being unprovable, which makes it less credible rather than more. The most common failure in a TPRM budget request is not asking for too much. It is asking with a number nobody believes, including the person presenting it. 

Three panels under the heading "What You Cannot Prove." Panel one, blue accent: "The Fraud That Never Happened," a working control produces no incident to report, so there is nothing to point at and nothing to count. Panel two, blue-teal accent: "The Failure Nobody Managed," a supplier problem caught early never becomes an escalation, and success leaves no record behind it. Panel three, teal accent: "The Audit With Nothing to Chase," evidence produced on request looks like an ordinary day, so good preparation is invisible in the result.
Click image to enlarge

Why the Request Gets Deferred Instead of Refused 

Notice what actually happens to these requests. They are rarely rejected outright. 

Rejecting one means someone puts their name to the position that the current exposure is acceptable. Few people will write that down about third-party risk, because if the exposure is later realised, the record of that decision is the first thing anyone looks for. 

So the request gets deferred instead. Next cycle. When there is more room. Once the current program lands. 

Deferral achieves the same outcome as a refusal, with one important difference: nobody owns it. There is no decision to point at, no name attached, and no record that a judgement was ever made about the underlying exposure. 

Meanwhile, the work still has to happen. The commitments still get made, the exceptions still get granted, and the system records that they happened without recording why. That is the position you are actually asking to change.

What to Count Instead of What to Project 

Here is the shift that makes the request arguable: stop projecting a return and start describing an exposure. 

A projected return is an argument about the future, and the committee has to take it on trust. An exposure is a fact about the present, and someone can go and verify it. The second is a smaller claim and a far more durable one. 

Three things are worth counting before your next budget conversation. None of them requires new tooling, and all of them can be produced in an afternoon. 

Commitments that live nowhere in the system of record. Take your active supplier list and sample twenty relationships. For each, ask the relationship owner what has been agreed beyond the signed contract: pricing concessions, service commitments, remediation promises, agreed exceptions. Then check how many of those appear anywhere in your system. The gap is your number. 

Decisions that cannot be reconstructed. Pull the exceptions and approvals from the last twelve months. For each one, ask whether you could produce who approved it and on what basis, without asking a person. Count the ones where the answer is no. Then note how many of those people still work there. 

Exceptions with no documented owner. Pull everything currently open. Count the items with no named owner and no remediation date. These are the ones that surface during an audit, and they surface as findings rather than as managed risks. 

These numbers tend to come back worse than anyone expects, which is uncomfortable and useful in equal measure. They also change the shape of the conversation. You are no longer asking the organization to believe a projection. You are describing what it is already carrying, and asking whether it intended to.

Three panels under the heading "What You Can Count," visually paired with the "What You Cannot Prove" graphic. Panel one, blue accent: "Commitments With No Record," sample twenty suppliers, ask what was agreed beyond the contract, and count how much of it appears in your system. Panel two, blue-teal accent: "Decisions You Cannot Rebuild," take last year's approvals and count the ones nobody could reconstruct without asking a person who was there. Panel three, teal accent: "Exceptions With No Owner," pull everything currently open and count the items with no named owner and no remediation date attached.
Click image to enlarge

We cover topics like this every week. Practical supplier management insights for procurement and supply chain teams. Get it in your inbox →

Making the Cost of Waiting Visible 

The second argument is about time, and it is the one most often left out. 

Deferral looks like a neutral pause. It is not, because a supplier risk record is only worth what its history is worth. A record you start this year answers real questions in three years. A record you start in three years begins the same wait again from nothing. 

That time cannot be bought back later or reconstructed after the fact. It is worth saying plainly to a committee that believes it is delaying a decision rather than making one. 

This matters more than it sounds if your organization is growing, acquiring, or consolidating suppliers. The volume you will be managing in three years is the volume the deferred capability was meant to handle. 

What to Actually Put in Front of the Committee 

Three gaps with owners and numbers beat nineteen gaps with neither. Pick the three that carry the most exposure and give each one four short answers. 

What is missing. The gap itself, in plain terms, with no adjectives. 

What it exposes us to. The consequence, stated once. Resist the temptation to stack three consequences onto one gap; it reads as inflation. 

What closing it would take. People, process, or tooling, with an honest estimate of effort. A modest, defensible figure survives scrutiny. A large one takes the rest of your case down with it. 

What happens if we do not. Write the sentence you would have to say in the review afterwards. "We did not verify the bank details because we had never funded a way to." Two minutes per gap, and it turns an abstraction into a specific future conversation nobody wants to have. 

That last field does more work than the other three combined, and almost nobody includes it.

One Benchmark Worth Citing 

Practitioners consistently report that they cannot find peer spending benchmarks for third-party risk, and that is largely true. What is available is where peers already spend. 

The 2026 KPMG Global Third-Party Risk Management Survey of 851 organizations found spending concentrated in risk assessment and due diligence (52%), technology and tools (51%), cybersecurity and data protection (49%), and regulatory audits (45%). The same survey found only 17% of organizations rate their third-party risk data as fully reliable. 

That will not tell you how much to ask for. It will tell a committee that your request sits inside where the field already invests rather than proposing something novel, which is a materially easier approval. 

Start With What You Can Count 

If the argument above is useful, the first step is knowing which gaps you actually have. 

Our supplier risk checklist runs nineteen questions across supplier discovery, onboarding and qualification, fraud prevention, regulatory readiness, and audit visibility. It takes about five minutes. Your answers stay in your browser, nothing is submitted, and it returns a ranked list of your gaps with the reason each one matters. 

Take the summary into your next budget or governance conversation. Gaps you can name are easier to fund than benefits you have to project. 

Take the Supplier Risk Checklist → 

Blog TPRM ROI
Previous reading
How to Build a Third-Party Risk Management Budget Case When There Is No ROI Number
Next reading
The AI You Never Approved Is Already Scoring Your Suppliers