Girish Redekar is Co-founder and CEO of Sprinto, building the future of trust for high-growth companies.
For most of business history, trust was a relationship. You knew the vendor’s CEO. Legal read the contract. A deal got done over lunch. That works for 20 vendors, but it doesn’t work for 200.
You used to get a loan because the banker knew your father. Now you get one because of a number a bureau calculated. Nobody’s going back, because the number scales and the relationship doesn’t. Enterprise trust is having the same moment.
Relationships aren’t wrong. They’re just not infrastructure.
A CISO trusts a vendor because she’s known the account team for five years. That’s reasonable, given what she has to work with. Then the account team leaves. The vendor gets acquired, a developer three layers down ships a misconfiguration that exposes customer data and the relationship catches none of it.
Worse, relationship-based trust is inconsistent. The vendor that gets grilled is the one where somebody happened to raise a flag. The one that sails through on a warm introduction might get a fraction of the scrutiny. And the vendor that eventually burns you might be the one you were never even worried about.
Your vendors have vendors.
Here’s the part most companies haven’t priced in: You don’t just have vendors. You also have your vendors’ vendors.
A healthcare provider doesn’t just use an EHR platform. That platform may run on a cloud provider, an identity service and a handful of data processors. A telehealth product may depend on video infrastructure, a messaging service and an AI transcription model it didn’t build and can’t fully see.
Nobody has one-to-one vendor relationships anymore. They have chains, and accountability doesn’t travel the same path as visibility.
If patient information is exposed or an AI system causes harm four layers down, the customer doesn’t distinguish between the primary vendor and its subcontractor, the way a car manufacturer takes responsibility for a recall rather than the component supplier.
Most companies are governing a snapshot.
That’s the depth problem, but there’s also a timing problem sitting right underneath it.
Most vendor risk programs still work like this: questionnaire, certification, rating, contract, done. The business feels like it assessed the vendor, though what it actually assessed was a snapshot. The moment the ink dries, that snapshot starts to go stale. Infrastructure changes. People join and leave. Subprocessors get added. Data flows shift. Controls drift. Then nobody looks again until next year’s review.
Picture a bank that turns on its security cameras once a year, confirms everything looks fine and then switches them off. Nobody would call that surveillance. That’s what much of vendor risk management actually is.
SOC 2 and ISO 27001 are still valuable, but they’re a baseline, not a live picture. A certificate tells you that controls were reviewed during a particular window. It doesn’t tell you what changed the day after. Companies that treat certification as the whole answer aren’t managing risk. They’re managing paperwork.
Here are the questions that help trust systems make a difference.
A relationship asks, “Do I trust this vendor?” A system asks, “Is this vendor’s behavior, right now, still consistent with what they told me?” Only one holds up under scale.
Technology is the easy half. The harder half is knowing what to do when the system flags something. That comes down to three decisions.
1. What triggers a relook?
Don’t let the calendar be the only trigger. A new subprocessor, change of control, lapsed or qualified certificate, incident anywhere in the vendor chain or expansion of the data a vendor can access should all prompt a fresh review. The annual review can still serve as a backstop, but it shouldn’t be the mechanism that determines when you look again.
2. Where does the bar sit?
Set it in advance as policy, not in a Slack thread when a concern appears. A vendor handling regulated customer data should clear a different bar than one running an internal scheduling tool. Get the tiers right, and routine changes can clear automatically, risky ones can be restricted and only genuine judgment calls reach a person. The system isn’t there to replace judgment. It’s there to ration it.
3. Who can say no?
Most companies define who investigates but not who decides. Security owns controls, legal owns contracts and the business owner owns the relationship. What matters is that the veto sits with someone whose incentives aren’t tied to the deal and that every override is logged with a name and date. Programs don’t fail because nobody spotted the risk. They fail because the person who did couldn’t stop it.
Most of the monitoring already exists. What doesn’t is visibility four layers down. With AI vendors, the problem is even harder: A model can change behind a stable API without an obvious version change. That gap has to be closed in the contract before it can be closed with tooling. The terms you write this year determine what you can see next year.
This is also a revenue conversation.
Every week a deal sits in security review is a week revenue doesn’t close. Every customer who walks over lost confidence is a churn number nobody wants to explain. Security reviews that once took weeks can instead take days for companies that have built this because the evidence was already sitting there when the buyer asked.
I’ve heard CISOs call their trust system the single most direct thing they’ve done for revenue—not the firewall or the SOC 2, but the system that made trust visible on demand.
If your board treats security spend as a cost center, put this reframe in front of them: Trust infrastructure isn’t overhead. It’s a commercial asset with a return you can point to.
Trust will become the price of entry.
Building this is a differentiator today, but it won’t stay one. Once enough companies run continuous trust infrastructure, it becomes the price of entry, just as SOC 2 went from “impressive” to table stakes.
The CISOs building this now can see what’s coming: Trust is becoming a regulated, commercially priced asset. Building it before the pressure arrives will be cheaper than building it after.
The handshake still matters, but nobody asks the banker’s opinion anymore before approving the loan. What would it take for your board to see trust the same way?
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

