CeFPro Connect

Article
Third-Party Contracting: Cyber, Regulatory, AI, and the Road to 2030
As regulatory expectations continue to evolve and AI becomes embedded throughout the vendor ecosystem, organizations must rethink how contracts support effective third-party risk management. Elizabeth Blosh-Myers discusses actionable approaches to cyber accountability, resilience requirements, audit rights, AI governance, continuous monitoring, and emerging risks that will shape contract frameworks through 2030 and beyond.
Oct 07, 2026
Elizabeth Blosh-Myers
Elizabeth Blosh-Myers, VP Director TPRM, Thread Bank
Tags: Vendor and Third Party Risk
Third-Party Contracting: Cyber, Regulatory, AI, and the Road to 2030
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
  • Effective third-party contracts focus on practical cyber accountability measures that vendors are willing to accept.
  • Regulators increasingly expect contractual evidence that organizations are actively monitoring vendor performance and resilience.  
  • AI governance remains one of the largest contractual gaps, particularly around data usage, model transparency, and liability.
  • Dynamic contracting is expected to integrate continuous monitoring and automated risk-triggered processes.
  • Future frameworks must address concentration risk, AI autonomy, regulatory change, and critical supplier dependencies. 
Log in to continue or register for free
WHAT'S INCLUDED:
Unlimited access to peer-contribution articles and insights
Global research and market intelligence reports
Discover Connect Magazine, a monthly publication
Panel discussion and presentation recordings
Sign in to view comments
ad
Related insights —