How to Measure the Exposure Window in Your Third-Party Risk Program

How to measure the exposure window in your third-party risk program.

A supplier's certification lapses. A director changes. A sanctions list adds a name already under contract. Your risk prevention program should catch each of these, eventually. What it probably can't tell you is how long the gap sat open before anyone noticed. 

That gap has a name: the exposure window. It's the time between an event happening and someone catching it, and most third-party risk programs cannot currently produce that number. Not because the number is unflattering, but because no one is recording it. 

Why the Exposure Window Is Worth Measuring 

Most of what a prevention program reports is a coverage fraction: how much of the supplier base has been screened, verified, or reassessed. Coverage fractions are useful, and they can also hold steady for years without telling you much about whether the program is actually funded to do its job. 

The exposure window behaves differently. It's close to a real performance measure for prevention work, which is rare. It can move visibly within a single budget cycle. And when a program is underfunded, this number tends to say so before anything else does, including before an incident forces the conversation. 

It's also one of the only things a program can report, whether or not anything goes wrong. No incident, no near-miss, no audit finding required. Just the honest answer to one question: the next time a certification lapses or a detail changes, how long does it take you to know? 

Why You Probably Don't Have This Number Yet 

Recording the exposure window requires logging the date an event was detected, not just the date it was resolved. Most programs that catch a lapsed certification or an altered bank detail only keep the second date. The system records that the problem got fixed. It doesn't record how long the problem sat there first. 

That's a gap in the data, not a gap in the work. Most teams doing the actual remediation already know roughly how late they caught something. It just never gets written down as its own number. That means no one can report it, improve against it, or use it to make a funding case.

How to Start Tracking It This Quarter 

You don't need new tooling to start. You need one field and a decision about where to look. 

Pick two or three event types to start with. Certification lapses, director or beneficial-owner changes, sanctions hits, altered bank details, whatever already shows up in your current workflow. You're not trying to cover everything on day one. 

Add a "detected on" date, separate from "resolved on." If your system of record doesn't have a field for it, track it alongside for now, even informally. The point is to stop collapsing two different moments into one timestamp. 

Report each event type on its own. Don't average a ninety-day certification-lapse window with a two-day sanctions-hit window into a single number. A lapsed certification and a sanctions match don't behave the same way, and blending them hides both. 

Expect the first number to look bad, and report it anyway. A ninety-day detection window in year one isn't a failure. It's a baseline. A program that can state its own exposure window, however long, has already demonstrated a discipline that a program with no number at all cannot claim. 

A single timeline spans about two years. Above it, a bracket over an early span is labeled This Year, 90 days to detect, with Event and Detected points marked below the line. A teal marker at the midpoint of the line reads "the program funds faster detection." Further along the same timeline, a second, much shorter bracket above the line is labeled Next Year, 9 days to detect, with its own Event and Detected points marked below the line.

 

We cover topics like this every week. Practical supplier management insights for procurement and supply chain teams. Get it in your inbox →

What the Number Buys You by Next Year 

A ninety-day detection window this year and a nine-day window next year is a story about funding that holds up whether or not anything else happened in between. You don't need an incident to make the number move, and you don't need to claim you prevented one for the improvement to be real. 

That matters most in a budget conversation. A coverage fraction tells a committee what the program touched. An exposure window that's shrinking year over year tells them the program is working, and it does it without asking anyone to trust a projection. A program that starts recording the gap today will have a number to show by the next budget cycle, however it looks.  

Start With What You Can Count 

If you're not sure where your own exposure windows stand, that's the first gap worth closing, before the metric itself. 

Our supplier risk checklist runs nineteen questions across supplier discovery, onboarding and qualification, fraud prevention, regulatory readiness, and audit visibility. It takes about five minutes. Your answers stay in your browser, nothing is submitted, and it returns a ranked list of your gaps with the reason each one matters. 

Take the Supplier Risk Checklist → 

Blog TPRM ROI
Previous reading
How to Measure the Exposure Window in Your Third-Party Risk Program
Next reading
Gigawatt launches the Utility Supplier Network, built through a strategic partnership with Trust Your Supplier