Managing Third-Party Risk at Scale Without Drowning in Surveys - with Carey Smith artwork

Managing Third-Party Risk at Scale Without Drowning in Surveys - with Carey Smith

The AI in Business Podcast

March 26, 2026

The collapse of traditional, static survey models at scale creates a systemic visibility gap that transforms multi-tier supply chain dependencies into boardroom-level risks.
Speakers: Daniel Faggella, Carey Smith
**Daniel Faggella** (0:13)
Welcome everyone to the Emerge AI in Business Podcast. Today's guest is Carey Smith, Chief Technology Innovation Officer of Blue Cross and Blue Shield of Minnesota, and President and CIO of XcelerateHealth. XcelerateHealth is a health tech startup and business unit of Blue Cross and Blue Shield of Minnesota, focused on AI-driven digital products to transform healthcare insurance experiences. Carey discusses transitioning from static vendor questionnaires to continuous automated monitoring to maintain visibility across thousands of suppliers. This shift allows executives to prioritize material risks and automate pre-approved mitigation steps, ensuring that human oversight focuses on strategic decisions rather than repetitive administrative assessments. Today's episode is sponsored by Aravo. Please note the opinions shared by Carey Smith in this episode are his own and do not represent the official position of Blue Cross Blue Shield of Minnesota or XcelerateHealth. For our AI solution partners, position your brand alongside the Fortune 500 leaders defining the Enterprise AI roadmap. For the opportunity to showcase your solution to the executives currently funding and scaling global initiatives, partner with Emerge. Secure your partnership at go.emerge.com. That's go.emerj.com.
Now, the conversation with Carey.

**Daniel Faggella** (1:46)
Carey, welcome back to the show. It's fantastic to have you.

**Carey Smith** (1:49)
Yeah, glad I could join you.

**Daniel Faggella** (1:51)
Those taking a close look at the state of AI in the enterprise, and I guess those fanatics of looking deep into the details of these things, see that the era of treating third-party risk management is this kind of static, check the box, compliance exercise is over. With the way things are rolling out in 2026, the acceleration, deployment, power, energy, etc. The pressure is rising, and the mandate is more about predicting, maybe surviving the sheer complexity of multi-tier ecosystem risks. There's an explosion of tangled interdependencies, mountains of variables, and the complexity is just immense. When you are managing upwards of 10,000 suppliers, what breaks first? And then more broadly, I guess, what begins to evolve into boardroom level issues?

**Carey Smith** (2:56)
Oh, I think it's clear what breaks first is visibility.
At scale, you lose the ability to know where your actual risk concentrations are, not just which vendors are critical, but how risks actually cascade through the interconnected supplier network. So traditional third-party risk management relies on static questionnaires, annual certifications, and essentially reactive reviews. That model collapses at scale. You become essentially a survey-rich but insight-poor organization. And traditional survey-based approaches, they create the illusion of control, while your risk intelligence really becomes stale immediately after that information is collected. And so it does become a board-level issue. The first time that you have a Tier 4 supplier that you didn't even know existed, that caused a massive data breach, or a compliance violation, then it becomes a real concern for the organization.

**Daniel Faggella** (4:03)
Absolutely. Yeah, I mean, the level of complexity, as we said upfront, 10,000 suppliers. Yeah, just the sheer number of variables in there means visibility is virtually impossible. And so it feels like this is almost a prerequisite for the day and age that we're in. When we get to deployment, of course, and this is something we actually mentioned in our previous podcast, the idea of the black box problem and this to what you've just said, this lack of visibility once information and data is ingested into the system, how a decision is made, how is work flowing from one stakeholder to another, etc. It's a massive hurdle when deploying AI for risk scoring, for example. Enterprises need these kind of deterministic or need this deterministic explainability. They need strict data provenance, not just these kind of softer probabilistic alerts. And I guess that kind of brings us to the harsh reality of being in operations and getting things done. In that light, what does good look like when AI, the liberation of data and automation actually support third-party risk management day to day without making it this black box, this foggy place where visibility is zero?

**Carey Smith** (5:34)
Yeah. Lack of visibility adds a systemic threat to the brand's valuation and your regulatory standing. So good is really continuous risk-based monitoring. It's not annual paperwork. It's moving away from the point-in-time surveys to a real-time risk posture and being able to understand at any given point, where do we stand with our risk? And I think in a matured kind of AI-enabled model, that AI ingests those external threat seeds, the financial signal, the sanctioned data, the cyber telemetry. Risk scores then get dynamically updated in near real-time. And high-risk vendors, they trigger automated remediation workflows instead of just kind of annual reviews. But it's kind of tying this back to what we mentioned earlier around the visibility.

5 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000757479558