The only moment you have real leverage over a supplier is before they have your signature. After that, every security improvement is a favour you are asking for, usually at renewal, usually at a price. This is why procurement is a security control - and why being bypassed in it is a structural problem rather than an annoyance.
Triage before requirements
Applying a full security schedule to every purchase is how security becomes the department that blocks the office coffee subscription. Tier by exposure:
- Critical - processes personal or regulated data at volume, or your service depends on their availability. Full assessment, full schedule, negotiated terms.
- Important - some data access or moderate dependency. Standard schedule, assurance report review.
- Low - no meaningful data access. Basic checks and standard terms.
Publish the tiering criteria so procurement can apply them without asking, and reserve your effort for the top tier. A process that is proportionate gets used; one that treats every purchase identically gets routed around.
What belongs in a security schedule
- Security standards to be maintained - ideally a named certification held for the duration, not merely at signing.
- Breach notification with a hard deadline. Push for 24 to 48 hours of becoming aware, and define "aware" - vague notification clauses are the single most common weakness. Your own regulatory clocks depend on this.
- Data location and residency, with a requirement to notify before it changes.
- Subprocessors - disclosure, flow-down of equivalent obligations, and notice before new ones are engaged. Their supply chain becomes yours.
- Right to audit or to receive assurance reports. Realistically, most suppliers will offer a SOC 2 or ISO certificate rather than an on-site audit - accept that for most tiers, but hold the audit right for critical suppliers.
- Vulnerability and patching commitments, with timeframes by severity.
- Personnel screening for anyone handling your data.
- Data return and deletion on exit, in a usable format, with certification of deletion.
- Incident cooperation - obliging them to support your investigation, including providing logs. Without this clause you may be unable to determine what happened in your own incident.
- Liability that is not capped below the realistic cost of a breach of your data. This is the hardest to negotiate and the most consequential.
Of these, breach notification and incident cooperation are the two most frequently used in anger. Prioritise them if you can only win a few points.
Assess suppliers before the contract, not after
GRC Copilot runs structured vendor assessments, tracks assurance evidence and expiry, and keeps supplier risk connected to the controls that depend on them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Negotiating realistically
A large SaaS provider will not amend standard terms for a mid-sized customer, and pretending otherwise wastes weeks. What actually works:
- Know which clauses are genuinely non-negotiable for you and which are preferences. Spending capital on all twenty means winning none.
- Accept published commitments where they are adequate - a solid trust centre and SOC 2 report may cover more than a negotiated clause would.
- Where a term cannot be obtained, record the gap as an accepted risk with the reason and a compensating control. That is a defensible position; silence is not.
- Use renewal. It is the one recurring moment leverage returns - keep a list of what you failed to get and raise it then.
The bypass problem
Most supplier risk enters through purchases security never saw: a departmental card, a free tier that quietly grew, an integration enabled inside an existing platform. Controls that help:
- Spend controls that route software purchases through a check regardless of amount - the expense system is a better enforcement point than policy.
- OAuth and integration governance in your major platforms, restricting which third-party applications users can connect to corporate data. This is now a larger channel than direct purchasing.
- Discovery - SaaS usage visible through expense analysis, identity provider logs and network telemetry.
- A fast path. If a low-risk assessment takes six weeks, people will route around it and you will lose visibility entirely. Speed is a security control here.
After signing
Contract terms only work if someone checks them: certificates expire, subprocessor lists change, and reports need reading rather than filing. Track expiry dates, re-assess critical suppliers periodically, and confirm deletion actually happened at exit. And on the way out, remember to revoke their access - departed suppliers with live accounts are the vendor-side equivalent of an unrevoked leaver.
Frequently asked questions
What if a critical supplier refuses our terms?
Escalate it as a business risk decision with the exposure stated plainly, and record who accepted it. That decision belongs to the business owner, not to security.
Is a SOC 2 report enough?
Often, if you read it - check the report period, the trust services criteria covered, the scope, and any exceptions noted. A filed report nobody opened provides no assurance.
How do we handle free tools?
They carry the same data risk with none of the contractual protection, and often worse terms. Treat them by data access, not by cost.
Do we need to assess every supplier annually?
No - critical annually, important on a longer cycle, low tier on change. Blanket annual reassessment consumes effort without changing decisions.
Key takeaways
- Leverage exists only before signing - and returns briefly at renewal.
- Prioritise breach notification with a hard deadline and incident cooperation.
- Tier suppliers so the process is proportionate, or it will be bypassed.
- Integration and OAuth governance now matters more than purchase approval.