Most vendor oversight programs run on a yearly cycle. Sign the agreement, file it, revisit it next year. For a long time, that was a reasonable cadence, since vendor relationships changed slowly and the tools to track them in real time barely existed.
Neither of those things is true anymore.
A vendor's risk profile can shift on any given day. Ownership changes hands. A subcontractor gets added without notice. An employee who was clean at hire time turns up on the federal exclusion list eighteen months later. A vendor experiences a breach of their own, one that has nothing to do with your organization directly, but everything to do with the data they hold on your behalf.
None of that waits for your annual review date. And when it happens between cycles, an annual process has no way to catch it until the damage is already done.
The scale makes this worse, not better. The average hospital manages over 1,000 vendor relationships at once, each one a live account with its own contract terms, credentialing status and compliance obligations.** Reviewing that volume thoroughly once a year is already a stretch. Catching what changes in the 11 months in between is close to impossible without a different approach entirely.
"Continuous monitoring" gets used loosely, so it's worth being specific about what it actually requires. It isn't reviewing every vendor more frequently by hand. That's the same annual model, just repeated more often, and it still depends on someone remembering to check. Real continuous monitoring means a small number of specific things are tracked on an ongoing basis, automatically, without a person needing to initiate the check.
At minimum, that includes:
The federal exclusion list is updated monthly. A vendor, contractor or employee who was clear at onboarding can appear on it later, and continuous screening is the only way to catch that change before it becomes a billing or compliance issue.
Business associate agreements aren't evergreen. They can lapse, go unrenewed or fail to reflect a vendor relationship that's expanded since the original agreement was signed. Ongoing tracking means knowing the current status of every BAA at any moment, not just at signing.
Not every vendor carries the same risk, and that risk isn't static. A vendor that started as a low-risk office supplier can become higher risk if their role expands to include access to patient data. Continuous monitoring means risk tier gets reassessed as circumstances change, not locked in at the start of the relationship.
This includes things like a change in ownership, a publicly reported breach, or a shift in the vendor's own subcontracting arrangements. These are the kinds of changes an annual questionnaire is structurally unable to catch in real time.
The practical difference between annual review and continuous monitoring isn't more meetings or more paperwork. It's a shift in what a compliance team is able to answer at any given moment.
Under an annual model, a straightforward question, "is this vendor's BAA current," or "has anything changed with this vendor since we signed," often takes real digging to answer. Someone has to go find the file, check the date, and hope nothing material happened in the months since the last look.
Under continuous monitoring, that same question has an immediate answer, because the underlying data is current by design, not refreshed once a year and left to go stale in between.
This also changes what an audit or a survey looks like. Instead of assembling documentation under time pressure, a compliance team can produce current status on demand, because the system has been keeping that status current all along.
Few compliance leaders would argue against continuous monitoring in principle. The gap is almost always operational: spreadsheets and shared drives were never built to update themselves, and asking a lean compliance team to manually re-check 1,000+ vendors on a rolling basis simply isn't realistic. Continuous monitoring at any meaningful scale requires infrastructure built for it, not more diligence layered onto tools that were never designed for it.
Ntracts connects vendor contracts, compliance status and exclusion screening in one system, so vendor oversight doesn't depend on a once-a-year manual check. Exclusion screening runs on an ongoing basis against federal and state lists. BAA status, risk tier and contract terms live in the same record instead of scattered across separate systems. When something changes, it surfaces as part of the system's normal operation, not something a compliance team has to go looking for.
That's what turns vendor oversight from an annual scramble into an ongoing, current practice, the same shift from paperwork to proof, made operational.
*KLAS and EY, Third-Party Risk Management in Healthcare, 2025.
**Neotas, Healthcare Third-Party Risk Management: 2026 Guide (average hospital vendor count).