Continuous Assessment
In third-party and supply chain risk management, continuous assessment refers to the ongoing evaluation of a supplier or business partner over the life of the relationship, rather than a single check at onboarding. It is intended to detect changes in a third party's risk profile as they occur, so that decisions can be updated in near real time. The evidence available here does not establish a settled definition of this term as used in the risk-management field.
The evidence packet provided contains only sources describing 'continuous assessment' as an educational examination method, the practice of evaluating a student's progress through regular activities across a course rather than a single final exam, and does not contain any material describing continuous assessment as applied to third-party, vendor, or supply chain risk management. As a result, a precise practitioner-level definition anchored to recognized TPRM or SCRM frameworks (for example ISO 27036, NIST SP 800-161, or shared assessment approaches) cannot be sourced from this evidence. In general practice the term denotes an approach in which a third party's risk is reassessed on an ongoing or event-driven basis; where such a definition is required, it should be developed from risk-management sources not present in this packet. A key limitation to note is that 'continuous' monitoring feeds (such as external security ratings or news signals) are not equivalent to periodic in-depth due diligence, and their scope, timeliness, and independence vary by program and risk tier.
Why it matters
In third-party and supply chain risk management, a supplier's risk profile is not static. Financial health, ownership, geographic exposure, security posture, and regulatory standing can all shift after onboarding, and a point-in-time assessment captures only a single moment. Continuous assessment matters because it is intended to close the gap between what was true at onboarding and what is true today, allowing risk decisions to be updated as conditions change rather than waiting for the next scheduled review cycle.
It is important to be candid about the limits of the evidence available here. The sources provided describe 'continuous assessment' exclusively as an educational examination method, the practice of evaluating a student's progress through regular activities across a course rather than through a single final exam. None of the supplied material addresses continuous assessment as applied to vendors, suppliers, or supply chains. Practitioners should therefore treat any risk-management framing of the term as requiring corroboration from TPRM or SCRM sources not present in this packet.
Where the concept is applied in practice, its value depends heavily on the quality and independence of the underlying signals. Continuous monitoring feeds such as external security ratings or news alerts are not equivalent to periodic in-depth due diligence, and their timeliness, coverage, and reliability vary by program and risk tier. Overstating what a continuous feed can detect, or treating it as a substitute for deeper, independently verified assessment, can create a false sense of assurance.
Who it's relevant to
Inside Continuous Assessment
Common questions
Answers to the questions practitioners most commonly ask about Continuous Assessment.
