Vendor risk management is important because the exposure has grown faster than anybody’s ability to see it. Four things changed.
Most of your attack surface now belongs to other people. A typical organisation runs on hundreds of SaaS products, API integrations, contractors holding standing credentials and managed providers with privileged access. The perimeter you can patch is a shrinking fraction of the perimeter that can be used against you.
Supervisory expectations moved from having a policy to showing evidence. The question is no longer whether you assess vendors, but what you knew about a specific critical vendor between reviews and when you knew it. That is answered with records or not at all.
Concentration turns one vendor’s failure into everybody’s incident. When an identity provider, a payments processor or a single cloud region fails, it does not take out one company — it takes out every company behind it at once, including the alternates you assumed were independent.
It gates your own revenue. Your customers run this process on you. A slow or unevidenced security review is a deal that closes a quarter late, which makes vendor risk a commercial function as much as a control function.