IDC & Diligent Webinar
The Vendor Blind Spot: Third-Party AI Risk in the GCC
Hosted By
AI risk is expanding beyond the walls of the enterprise and into the vendor ecosystem organizations already depend on. IDC’s GRC survey shows that third-party risk management (TPRM) is the GCC’s largest governance program, named by 51% of Saudi and UAE enterprises ahead of regulatory compliance.
But very few organizations run integrated AI guardrails with continuous monitoring. Most still rely on basic, siloed controls, even as AI activity within the same vendor ecosystem continues to expand.
IDC and Diligent are hosting an exclusive webinar for senior TPRM, risk and security leaders across the GCC to explore how to close that gap before it widens further. This curated session sets out how organizations are governing their vendors’ use of AI today, and what an AI-ready TPRM model looks like in practice.
Key Takeaways
The AI exposure that’s growing outside the enterprise
The fastest-growing AI risk for GCC organizations sits inside vendor and supplier systems, not internal deployments.
live AI behavior that annual reviews cannot see
Static due diligence and contract language cannot track how vendor AI changes, learns, or accesses systems after onboarding.
The sharpest fear is unauthorized autonomy, not abstract ethics.
IDC forecasts more than 1 billion AI agents in active deployment by 2029, executing roughly 217 billion actions a day. The sharpest executive fear is agents overstepping authorized access inside vendor systems.
TPRM is the fastest path to AI governance, not a new program.
Explore how to extend the vendor risk program you already run to cover continuous vendor and vendor-AI monitoring.
Agenda
IDC & Diligent Webinar
One Day Event
Welcome Address
IDC Keynote: Third-party risk is where AI Governance becomes real
Shilpi Handa
Associate Research Director (META), IDC
From Static Due Diligence to Continuous Vendor Oversight
Chlōe Dellow
Director – Sales, Diligent
Governing what your Vendors’ AI is doing, not just what they signed
Jelle Groenendaal
Senior Director, 3rdRisk, A Diligent Brand
Panel Discussion : What TPRM, procurement, CRO, and CISO leaders are seeing on the ground
Open Discussion, Summary & Close
Speakers
Shilpi Handa
Event Sessions
One Day Event 11:05 am
IDC Keynote: Third-party risk is where AI Governance becomes real
Chlōe Dellow
Chlōe holds 7+ years of experience partnering with organisations including FTSE 100 and Fortune 100/500 companies on third-party risk and GRC transformation initiatives, advising organisations on best practices, innovation, emerging risks and considerations.
Chlōe is a strategic advisor focused on supporting organisations with different levels of programme maturity. She supports customers in developing and scaling their risk, compliance and third-party risk strategies, and ensuring consistent, measurable, and outcome-focused results.
She combines this with a strong focus on sharing market trends, peer benchmarks and real-world observations to help organisations stay ahead of an evolving risk and regulatory landscape.
She has deep expertise in navigating complex frameworks such as NIST, DORA, NIS2 and ISO 27001, with particular focus on highly regulated industries including financial services.
Event Sessions
One Day Event 11:25 am
From Static Due Diligence to Continuous Vendor Oversight
Jelle Groenendaal
Jelle Groenendaal is Senior Director at 3rdRisk, a Diligent brand. He holds a Ph.D. in Risk Management and has over 20 years of experience as a researcher, consultant and practitioner in risk and resilience. Throughout his career, he has advised and worked with large corporations and government organisations on strengthening governance, risk management and operational resilience.