Back to blog
Guides

Vendor and third-party risk management: the complete guide

Your suppliers' security is your exposure, and their breaches become your incidents. How to tier vendors so the process is proportionate, what to assess, what to put in contracts, and how to monitor a relationship after signing.
GRC Copilot Team
Vendor and third-party risk management: the complete guide

Third-party risk is the area where compliance programmes most often look complete and function least well. There is usually a questionnaire, a spreadsheet and a folder of certificates — and no answer to the question that matters: if this supplier were breached tomorrow, what of ours would be exposed, and would we find out in time?

Tier first, or the process collapses

Applying the same due diligence to a payroll platform and a design tool is how vendor risk becomes theatre. Tier by exposure:

  • Critical — holds regulated or personal data at volume, or your service depends on their availability. Full assessment, negotiated contract terms, annual reassessment, monitored.
  • Important — some data access or moderate dependency. Standard security schedule, assurance report reviewed, periodic reassessment.
  • Low — no meaningful data access. Basic checks, standard terms.
Publish the tiering criteria so procurement can apply them without asking you. A process that treats every purchase identically gets routed around, and the vendors you never see are the ones carrying unmanaged risk.

What due diligence should actually establish

Not "do you have a security policy?" — every vendor says yes. The questions that discriminate:

  • What data of ours will you hold, where, and for how long?
  • Who are your sub-processors, and how are we told when they change?
  • What independent assurance do you hold — and can we see the report, not just the badge?
  • How quickly will you tell us about a breach, and will you support our investigation with logs?
  • What happens to our data when the contract ends?

Read assurance reports rather than filing them: check the period, the scope, the criteria covered, any exceptions, and the complementary user entity controls — the obligations the report transfers back to you.

Assess suppliers before the contract, not after

GRC Copilot runs structured vendor assessments, tracks assurance evidence and expiry dates, and connects supplier risk to the controls that depend on them.

Contracts are where the leverage is

Every security requirement is negotiable before signature and almost none afterwards. Prioritise, in order: breach notification with a hard deadline and a definition of "aware"; incident cooperation obliging them to support your investigation; sub-processor disclosure and flow-down; data location and change notice; deletion and return on exit; and liability that is not capped far below the realistic cost of a breach of your data.

Where a term cannot be won, record the gap as an accepted risk with a reason and a compensating control. That is defensible; silence is not.

Monitoring after signature

Assessment is a point in time; the relationship is continuous. Certificates expire, sub-processor lists change, and reports need reading rather than filing. Track expiry dates, reassess critical vendors on a cycle, and watch for the events that should trigger an off-cycle review: a breach, an acquisition, a change of hosting region, or a material change in what they do for you.

The two risks nobody tiers for

Concentration risk. Twenty vendors can be one dependency if they all run on the same cloud region or the same identity provider. Tiering by individual vendor hides this entirely — map the shared dependencies underneath your supplier list.

Fourth parties. Your supplier's suppliers hold your data too. You will not assess them directly; the control is contractual flow-down plus disclosure, so you at least know the chain exists.

Offboarding

The step that gets skipped. On termination: confirm deletion in writing, revoke their access to your systems, remove their accounts, rotate any shared credentials, and retrieve your data in a usable format. Departed suppliers with live accounts are the vendor-side equivalent of an unrevoked leaver, and they are found in audits regularly.

Detailed guidance

AI & Automation

Australia & APAC

Buyer Guides

Checklists

Guides

Saudi & GCC

Sectors

Templates

Frequently asked questions

How often should we reassess vendors?

Critical annually, important on a longer cycle, low tier on change. Blanket annual reassessment consumes effort without changing decisions.

Is a SOC 2 report enough?

Often, if you read it — period, scope, criteria, exceptions and the complementary user entity controls. A filed report nobody opened provides no assurance at all.

What if a critical vendor refuses our terms?

Escalate as a business risk decision with the exposure stated plainly, and record who accepted it. That decision belongs to the business owner, not to security.

How do we find vendors nobody told us about?

Expense analysis, identity provider logs and OAuth grants in your major platforms. Integration approvals are now a bigger inbound channel than purchasing.

Key takeaways

  • Tier by exposure or the process gets bypassed.
  • Breach notification and incident cooperation are the clauses used in anger.
  • Read assurance reports — especially the controls they hand back to you.
  • Concentration risk and offboarding are the two most commonly missed areas.
#vendor-risk #tprm #complete-guide #pillar #supply-chain #due-diligence