The Startup's-Eye View of TPRM: Why Your Due Diligence Process Might Be Costing You the Best Suppliers
Third Party Therapy Podcast — featuring Ian Ellis, emerging technology adviser and angel investor
Most third party risk management (TPRM) conversations look at supplier onboarding from one direction: the corporate's. In this episode of Third Party Therapy, host Mike Day flips the lens, speaking with Ian Ellis — who has spent years working with emerging tech companies across banking, insurance and Microsoft's startup accelerator programme, and who now also invests in early-stage companies as an angel investor — about what a standard corporate due diligence process actually looks and feels like from the other side of the table.
Why a "Small" Delay Can Be an Existential Risk for a Startup
Ian's central concept is burn rate: the runway a startup has before it runs out of cash. What looks like a minor administrative delay to a large organisation's procurement or TPRM team — a questionnaire that takes an extra few weeks to process, a contract stuck in redlining — can push a deal past a funding quarter for the company on the other side. That matters far more than it sounds: investors judge companies against growth benchmarks (Ian cites the well-known VC shorthand of "triple, triple, double, double" year-on-year growth), and a missed quarter caused purely by a protracted corporate process can damage a genuinely good company's valuation or its ability to raise its next funding round.
This isn't about excusing weak controls. It's a reminder that the speed and manner of a TPRM process has real commercial consequences on the other end — consequences that can, ironically, end up harming the corporate too, if a strong potential supplier is lost or degraded by the process meant to protect against risk.
Two Questions to Right-Size Your Diligence
Rather than applying a single due diligence standard to every third party regardless of size, Ian suggests corporates ask two questions:
• How strategic is this supplier to what we're doing?
• How close to the core of our business will they sit?
A supplier operating at the edge of the business carries materially different risk to one embedded in a core process — and the level of scrutiny, and the controls reasonably expected, should scale accordingly.
The Danger of "Accidental Virality"
One of the sharpest points in the conversation concerns organic, uncontrolled adoption. A small pilot with three users can, if the tool is genuinely useful, spread to hundreds or thousands across an organisation with no formal scaling decision ever taken. From a resilience perspective, this is arguably a bigger risk than a large, deliberately negotiated contract — because the corporate has quietly built dependence on a supplier whose infrastructure, support model and pricing were never designed for that scale.
Ian's advice for spotting this early: has the startup itself thought about what happens when a major client starts calling at 2am expecting enterprise-grade support? If a young company's pricing looks too good to be true for the level of service now being consumed, it probably is — because early-stage companies are, in his words, "notoriously bad at underpricing their products."
You Can't Just Run a Credit Check on a VC-Backed Startup
Traditional financial viability checks — a standard credit reference report — don't work well for venture-backed companies, whose survival depends less on current revenue than on their relationship with their investors. Ian sets out what's actually worth understanding: the fund's investment cycle and how much dry powder it has left for follow-on rounds, whether that specific investor's mandate even permits follow-on investment, and where the company sits in that classic venture portfolio pattern — roughly three failures, four or five modest outcomes, and one or two genuine successes, out of every ten investments.
His practical recommendation for organisations with the internal capability: some large investment banks sign specific NDAs with prospective suppliers to review their financials in the same depth a VC would — and, where appropriate, even help a strategically important supplier secure additional funding to ensure continuity of the service being relied upon. For most TPRM functions without that specialist skill set, Ian is candid that this is a genuinely hard gap to close.
AI Has Made It Easier to Start a Company — and Harder to Judge One
Ian offers a memorable, deliberately provocative observation: "it's never been easier to start a company, and I don't think this is probably going to be a little controversial — it's never been harder to scale a company," because the sheer volume of companies now claiming AI capability has degraded the signal-to-noise ratio for anyone trying to assess the market. His challenge to innovation teams specifically: they tend to fixate on the exciting, emerging end of the market and never benchmark against mature incumbents already doing something similar — which is precisely why so many promising pilots get "skewered in procurement" once someone points out that an established player already offers the same capability.
Bring TPRM and Procurement in Early — It's a Positive Signal, Not a Blocker
Perhaps the most counterintuitive message for TPRM professionals: getting risk, procurement and governance functions involved early in a conversation with an emerging supplier is not received as friction. It signals genuine organisational commitment to the deal. Ian contrasts this with the alternative failure mode he's seen repeatedly — a senior executive (a CIO, say) meets an exciting company, generates real enthusiasm, and then nothing happens because the technical and risk assessment was never actually engaged. The result: reputational damage to the corporate, wasted hope for the supplier, and — because senior leaders rarely like delivering bad news directly — a slow, demoralising fade-out instead of a fast, honest no.
His recommended model, borrowed from a venture fund contact, is "middle out": engage someone senior enough to make a decision, but junior enough to actually have the time to make it.
On Proof of Concepts, Contracts, and Treating Suppliers With Respect
Asked about proof of concept engagements, Ian is relatively relaxed about whether they're paid or free — what matters far more is intent and pace. A slow, under-resourced PoC that drags on is worse for everyone than a fast, well-supported one. On contracting, he raises a genuine concern: many founders, especially pre-Series A, are not lawyers, and the pressure of landing a marquee client can push them into signing terms — particularly around liability and intellectual property — that a more experienced negotiator would query. His suggestion is refreshingly simple: corporates can offer guidance rather than a flat rejection when a supplier lacks a control ("you're too early for this yet, but here's what we'd want to see in 12-18 months"), turning an initial no into a longer-term, collaborative relationship.
As Ian puts it, quoting a colleague: "if the deal has been negotiated so hard, they've taken so much money off the table for the company that they can't afford to support the deal, it's not a good deal."
Where AI-Based Questionnaire Tools Cut Both Ways
The conversation also touches on a genuinely double-edged development: AI tools that help suppliers generate responses to due diligence questionnaires and RFPs automatically. Ian flags the obvious question mark over accuracy at scale — when a 300-400 question due diligence questionnaire is being answered largely by AI on the supplier side, how would a buyer know, and how much does that matter? It's a direct parallel to the "questionnaire killer" style tools discussed elsewhere on the podcast, just approached from the opposite side of the relationship, and outside the buyer's visibility or control.
What Doesn't Work: Lessons From Failed Engagements
Ian closes with hard-won observations on what goes wrong. Innovation teams sometimes fall in love with a shiny new solution without doing basic market research — Ian recounts backing a small two-person UK startup in a telemetry deal at British Airways, unaware a more mature US competitor already served other airlines in the same space, effectively boxing out the stronger option. He's also sceptical of chasing efficiency purely by cutting process duration (celebrating a due diligence cycle reduced from 365 days to 180, for instance) without first asking whether the process itself is asking the right questions at all.
His clearest, most human piece of advice concerns how relationships end. Communicating a rejection, a wind-down, or a company failure with empathy — a phone call rather than an email, early honesty rather than a slow fade — matters because "everybody wants to be treated fairly," and because the emerging company you treat well today, win or lose, may be the mature, well-funded supplier you're glad to have a relationship with in three years' time.
Listen to the full episode of Third Party Therapy, produced in association with CeFPro, on Apple Podcasts, Spotify, Amazon Music, Audacy and YouTube, or visit thirdpartytherapy.com to subscribe to the mailing list.
Tags
#ThirdPartyTherapy #TPRM #VendorRiskManagement #StartupRisk #EmergingTechnology #DueDiligence #SupplierRiskManagement #ProcurementRisk #VentureCapital #ThirdPartyRiskManagement #InnovationRisk #SupplierOnboarding #RiskManagementPodcast #HowDoesTPRMWorkWithStartups #DueDiligenceForEmergingSuppliers #TPRMPodcast


