Third-party risk is the area where compliance programmes most often look complete and function least well. There is usually a questionnaire, a spreadsheet and a folder of certificates — and no answer to the question that matters: if this supplier were breached tomorrow, what of ours would be exposed, and would we find out in time?
Tier first, or the process collapses
Applying the same due diligence to a payroll platform and a design tool is how vendor risk becomes theatre. Tier by exposure:
- Critical — holds regulated or personal data at volume, or your service depends on their availability. Full assessment, negotiated contract terms, annual reassessment, monitored.
- Important — some data access or moderate dependency. Standard security schedule, assurance report reviewed, periodic reassessment.
- Low — no meaningful data access. Basic checks, standard terms.
Publish the tiering criteria so procurement can apply them without asking you. A process that treats every purchase identically gets routed around, and the vendors you never see are the ones carrying unmanaged risk.
What due diligence should actually establish
Not "do you have a security policy?" — every vendor says yes. The questions that discriminate:
- What data of ours will you hold, where, and for how long?
- Who are your sub-processors, and how are we told when they change?
- What independent assurance do you hold — and can we see the report, not just the badge?
- How quickly will you tell us about a breach, and will you support our investigation with logs?
- What happens to our data when the contract ends?
Read assurance reports rather than filing them: check the period, the scope, the criteria covered, any exceptions, and the complementary user entity controls — the obligations the report transfers back to you.
Assess suppliers before the contract, not after
GRC Copilot runs structured vendor assessments, tracks assurance evidence and expiry dates, and connects supplier risk to the controls that depend on them.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Contracts are where the leverage is
Every security requirement is negotiable before signature and almost none afterwards. Prioritise, in order: breach notification with a hard deadline and a definition of "aware"; incident cooperation obliging them to support your investigation; sub-processor disclosure and flow-down; data location and change notice; deletion and return on exit; and liability that is not capped far below the realistic cost of a breach of your data.
Where a term cannot be won, record the gap as an accepted risk with a reason and a compensating control. That is defensible; silence is not.
Monitoring after signature
Assessment is a point in time; the relationship is continuous. Certificates expire, sub-processor lists change, and reports need reading rather than filing. Track expiry dates, reassess critical vendors on a cycle, and watch for the events that should trigger an off-cycle review: a breach, an acquisition, a change of hosting region, or a material change in what they do for you.
The two risks nobody tiers for
Concentration risk. Twenty vendors can be one dependency if they all run on the same cloud region or the same identity provider. Tiering by individual vendor hides this entirely — map the shared dependencies underneath your supplier list.
Fourth parties. Your supplier's suppliers hold your data too. You will not assess them directly; the control is contractual flow-down plus disclosure, so you at least know the chain exists.
Offboarding
The step that gets skipped. On termination: confirm deletion in writing, revoke their access to your systems, remove their accounts, rotate any shared credentials, and retrieve your data in a usable format. Departed suppliers with live accounts are the vendor-side equivalent of an unrevoked leaver, and they are found in audits regularly.
Detailed guidance
AI & Automation
- Assessing AI vendors: the questions standard due diligence misses — Your existing vendor questionnaire was not written for AI. The additional questions that matter - training data, retention, model changes, h…
Australia & APAC
- Who must comply with the Essential Eight in Australia? — Where the Essential Eight is legally mandated, where it arrives through procurement and contracts, and how it interacts with the SOCI Act an…
Buyer Guides
- Choosing a GRC platform for GCC operations — Organisations operating across Saudi Arabia, the UAE and Qatar face several national frameworks at once. What that means for platform select…
- What GRC software actually costs: the line items nobody quotes you — Licence price is the part you can compare. Implementation, integrations, audit fees, per-framework charges and internal effort are the parts…
Checklists
- DORA readiness checklist for financial entities — Five pillars, a register of information the regulator will ask for, and incident reporting on a clock shorter than most teams expect. A prac…
- SaaS approval checklist: a review fast enough that people use it — If approving a tool takes six weeks, teams stop asking. A tiered checklist that clears low-risk tools in a day and reserves real scrutiny fo…
- Vendor onboarding security checklist: from request to go-live — A step-by-step checklist for onboarding a supplier securely - triage, tiering, due diligence, contract terms, technical setup and the offboa…
Guides
- Security in procurement: the leverage you only have before signing — Every security requirement is negotiable before the contract is signed and almost none afterwards. What belongs in a security schedule, whic…
Saudi & GCC
- Aramco SACS compliance: what suppliers need to know — The Saudi Aramco Cybersecurity Compliance Standard applies to third parties working with Aramco. What it covers, how it differs from a gener…
Sectors
- Supplying the public sector: the compliance bar for vendors — Selling to government entities means inheriting their cybersecurity obligations. What flows down to suppliers, how it appears in tenders, an…
Templates
- Supplier security schedule template: the clauses worth negotiating — Every security requirement is negotiable before signature and almost none afterwards. The clauses that get used in anger, the ones vendors c…
- Vendor risk assessment template: tiering, questions and review — A practical vendor risk assessment template - how to tier suppliers by criticality, which questions to ask at each tier, what evidence to de…
Frequently asked questions
How often should we reassess vendors?
Critical annually, important on a longer cycle, low tier on change. Blanket annual reassessment consumes effort without changing decisions.
Is a SOC 2 report enough?
Often, if you read it — period, scope, criteria, exceptions and the complementary user entity controls. A filed report nobody opened provides no assurance at all.
What if a critical vendor refuses our terms?
Escalate as a business risk decision with the exposure stated plainly, and record who accepted it. That decision belongs to the business owner, not to security.
How do we find vendors nobody told us about?
Expense analysis, identity provider logs and OAuth grants in your major platforms. Integration approvals are now a bigger inbound channel than purchasing.
Key takeaways
- Tier by exposure or the process gets bypassed.
- Breach notification and incident cooperation are the clauses used in anger.
- Read assurance reports — especially the controls they hand back to you.
- Concentration risk and offboarding are the two most commonly missed areas.