Home
/
Case Studies
/
Vendor Risk Doesn't End at the Assessment

Vendor Risk Doesn't End at the Assessment

About the Company

Klaviyo

Klaviyo is the autonomous CRM for B2C brands, built to turn what you know about your customers into real growth.

  • Headquarters:
    Boston, Massachusetts
  • Company Size:
    1K-5K
  • Industry:
    Marketing Services

Klaviyo is an autonomous B2C CRM serving more than 167,000 businesses globally. Behind that scale is a security organization that touches almost every part of the company, and a third-party risk program that had had to grow to keep up with the surge of AI tools coming into the business.

Richa Kaur leads cybersecurity risk management at Klaviyo, covering both the internal environment and the third-party side. Over the last year, the third-party side has reshaped how her team spends its time.

"When I joined Klaviyo, TPRM was 20% of our work. Now it's 80%. Every week there are new AI vendors coming in, and the volume isn't slowing down."

The volume isn't the only thing that changed. The kinds of vendors coming in are different. People want to bring up apps that didn't exist a year ago. Engineering teams are vibe-coding with tools that are themselves chains of other tools.

Richa's read on it is steady.

"You'll meet a lot of leaders who say, oh, jump on this, this is the next best thing. No, we want to take a step back, assess what's best for us."

How the TPRM team balances risk while keeping up with the business

Richa is clear about what her team is for.

"My role is not to disapprove or reject a tool. My role is to approve, keeping risk in mind."

The pressure inside any growing company runs in one direction. Marketing has a tool they wanted yesterday. Engineering has a vendor they're already piloting.

Saying no doesn't scale, and it doesn't actually reduce risk. It just pushes the work underground.

So the question her team is really answering is not should this vendor exist in our environment. It's what we need to know to approve it with our eyes open, and what do we need to keep watching after.

Why the work doesn't stop at the assessment

The part of TPRM that gets the most attention is the front door. The questionnaires. The SOC 2 review. The assessment that decides whether a vendor gets approved.

But the day a vendor is approved is not the last day the team needs to look at them until their next assessment.

Vendors ship new features. They adopt new sub-processors. Their AI capabilities change what data flows where. An assessment represents a point in time. The risk does not.

Richa came into the Klaviyo TPRM evaluation with a clear point of view on this, shaped by her previous programs.

"Every other tool my previous teams have assessed - one tool does not give you the ability to both assess and continuously monitor. That's what Lema committed to."

Continuous monitoring, in her framing, isn't a feature. It's a posture. It's the team admitting that approval is a moment, and risk is a state.

Assessment and continuous monitoring, in one place

The Klaviyo team evaluated roughly twenty options. Lema stood out for two reasons.

The first was the combination Klaviyo had been looking for - one platform that handled both vendor assessment and continuous monitoring, instead of stitching together two tools that didn't share a view of the vendor.

The second was Lema’s approach. The team came in willing to work on the specific problems Klaviyo was trying to solve.

"They were trying to work with us to help us, not hand us something off the shelf. From the first conversation, it felt like genuine people trying to make an impact on the problem we were actually trying to solve"

Where the Klaviyo team got their time back

The team's day-to-day is built around a small number of people doing a lot of work. The program holds together because each part of the workflow earns its place.

SOC 2 validation, behind the scenes.
Validating a vendor's SOC 2 against Klaviyo's control requirements used to be a 30 to 40 minute manual exercise per vendor. Sometimes closer to an hour.

"Lema came back saying, hey, you can just upload a vendor's SOC 2 report and behind the scenes we'll do the validations. That itself took away 30 minutes of my team's time in the manual comparison work."

Custom controls, sharper questionnaires. Klaviyo built out custom controls that map to how their security team actually thinks about vendor risk. The questionnaire shrank accordingly.

"The recent custom control feature is taking us down from around 400 questions to closer to 100."

In the team's own words

"With Lema and custom controls in place, the process now starts working before we even send out a questionnaire. As soon as a vendor is onboarded, Lema automatically scans for intelligence, builds an inherent risk profile, and pulls in any publicly available documents relevant to our assessment. It then continues to evaluate questionnaire responses against our custom controls once they come in. This has cut down our manual review time significantly. The part of the old process I'm most glad to be done with is the upfront manual digging we used to do - researching each vendor and hunting down documentation ourselves before an assessment could even begin."

Dhana Michael
Security Engineer at Klaviyo

What continuous monitoring actually means

When people hear "continuous monitoring," they usually think it means a flood of noise and a backlog of alerts. That's not what this is about. This is about connecting to the environment to see what's actually happening, whether what a vendor was approved to do matches what they're doing, and weighing that against how risky the vendor is and how deep their access goes.

"The vendor we assessed six months ago isn't the same vendor today. They've shipped new features, added AI capabilities, changed who has access to what. The assessment is just a snapshot”.

That distinction shapes how Klaviyo is building out the next phase of the program,  connecting Lema's findings into the rest of the security stack so each finding lands with the context the team needs to act on it.

The throughline

Richa has built this kind of program before. What she's running at Klaviyo now is shaped by what she has seen actually hold up under pressure.

A team that approves with risk in mind. An assessment process that doesn't bury people in manual work. A view of vendors that doesn't go dark the moment they're onboarded.

"Every quarter I see Lema giving us features where my team feels more and more effective and efficient. The response is always very positive."