Who this is for: CIOs, IT managers and owner-operators who rely on a growing list of suppliers for hosting, software, payroll, email, support or data processing, and who have been asked by a customer, auditor or insurer how those suppliers are controlled. It is written for organisations without a dedicated third-party risk team.
Start with the question, not the questionnaire
Vendor risk work usually begins with a questionnaire because it is something you can send. That is the wrong starting point. A 200-question form sent to every supplier produces 200 answers you cannot verify and a folder nobody reads.
Begin with three questions about each supplier:
- What does it hold or touch? Which of your data, credentials or systems can it read, change or delete?
- What happens to you if it fails? Not “is it important”, but how long you could operate without it and what you would do in the meantime.
- What can you realistically find out? For a large cloud provider you cannot audit the datacentre; for a three-person developer shop you may be able to ask one person direct questions.
The answers drive everything else: how much assurance to ask for, which contract clauses matter, and how often to look again.
Tier your suppliers
You cannot give every supplier the same scrutiny. A coffee-machine service and your payroll processor are both “vendors”. Sort the list into tiers using two dimensions: access to data or systems, and criticality to operations.
| Tier | Typical profile | Examples (illustrative) | Depth of review |
|---|---|---|---|
| 1 | Holds sensitive or regulated data, or a failure would stop a core service | Payroll processor, core line-of-business SaaS, managed IT provider with admin access, primary hosting | Full review before onboarding; assurance report or equivalent evidence; contract security terms; annual re-review; named internal owner |
| 2 | Holds limited internal data or supports a non-core service | HR portal, marketing automation, secondary SaaS | Short questionnaire; check for a published assurance report; review at renewal |
| 3 | No data access; easily replaced | Office supplies, generic subscriptions | Basic due diligence only; no recurring review |
Two rules keep tiering honest. First, a supplier with privileged access to your systems is Tier 1 regardless of how “small” the service looks, because the access is the risk. Managed service providers and software that holds API keys to your environment are the classic examples. Second, tier by what the supplier *can* reach, not what the contract says it *should* reach. If a support tool has a service account that is a domain administrator, that is the fact that counts.
What assurance evidence actually tells you
For Tier 1 suppliers you will often be offered an independent assurance report or certificate. Understanding what these cover is more valuable than collecting them.
Service organisation control reports (SOC 2). A SOC 2 report is an auditor’s report on a supplier’s controls, produced under frameworks developed by the AICPA. Reading one takes about twenty minutes if you know where to look:
- Type I or Type II. Type I describes whether controls were suitably designed at a point in time. Type II also tests whether they operated over a period. For anything important, Type II is the one that tells you something about behaviour.
- The period covered. A report ending fourteen months ago leaves a gap. Ask for a bridge or comfort letter if the gap matters.
- Scope and system description. Does it cover the product you actually use, or a different one the supplier also sells? Which locations and subservice providers are included?
- Trust services categories. Security is always present; availability, confidentiality, processing integrity and privacy are optional. If you care about availability and it is not in scope, the report does not speak to it.
- The auditor’s opinion. Unqualified is the normal good result. A qualified opinion, or listed exceptions in the tests section, need reading, not skipping.
- Exceptions. Controls tested that did not operate as described. A short list of minor exceptions with management responses is normal; repeated exceptions in access or change controls are not.
- Complementary user entity controls. The part nearly everyone misses. These are controls the supplier expects *you* to operate, for example reviewing your own user list or enabling MFA. If you do not do them, the report’s assurance does not transfer to you.
ISO/IEC 27001 certification. A certificate shows that a certification body audited an information security management system against the standard within a stated scope. Check the scope statement (which sites, services and processes), the issuing body, validity dates and the Statement of Applicability if the supplier will share it. A certificate for “the head office HR process” says nothing about the product you use. Confirm the certificate with the issuer where it matters. Neither a SOC report nor a certificate means the supplier is “secure”; they mean specific controls were examined against a defined scope.
Questionnaires. Shared or standard questionnaires exist (the Shared Assessments SIG and the Cloud Security Alliance’s CAIQ are two commonly seen formats), and accepting a completed standard form is often reasonable. Treat the answers as claims. Ask for evidence on the three or four items that bear directly on your risk, such as how administrators authenticate, how long backups are kept and where your data is stored.
What to put in the contract
Assurance tells you how a supplier behaves today. The contract decides what you can do when it stops behaving. For Tier 1 suppliers, ask your legal adviser to confirm terms such as:
- Incident notification. A defined maximum time for the supplier to tell you of a security incident affecting your data, and what information they must provide. Your own obligations may be tighter than the supplier’s default terms; where the GDPR applies, for example, a controller generally has a short window to notify the supervisory authority after becoming aware of a personal data breach, so the supplier’s notice to you has to fit inside that. Check the rules that apply to you.
- Subprocessors. A list, notice of changes, and a right to object. Your supplier’s supplier is your fourth party, and you inherit its failures.
- Audit and evidence rights. At minimum the right to receive current assurance reports and answers to reasonable security questions.
- Data location and handling. Where data is stored and processed, how it is segregated, and how long backups persist after deletion.
- Exit. The most neglected clause. How you retrieve your data, in what format, within what time, and for what price; what happens to data afterwards; and what support exists during transition.
- Liability. Caps on liability are common and are often small compared with the cost of an incident. Know the number, and decide whether cyber insurance or a different supplier closes the gap. See risk treatment for how to record that decision.
A vendor record that does its job
Keep one short record per Tier 1 and Tier 2 supplier, linked from the register entry. Illustrative example:
supplier: Example Payroll Ltd
service: Payroll processing and payslip portal
tier: 1 (holds employee personal and bank data)
internal_owner: Finance Director
data_held: Names, addresses, national ID numbers, bank details
access_to_us: None to our network; SFTP file exchange only
assurance: SOC 2 Type II, period ended 2026-03-31, security + confidentiality,
no qualified opinion; two minor exceptions in access removal (noted)
user_controls: Quarterly review of our portal users (owner: Finance Director)
contract_checks: Incident notice 48h; subprocessor list received; exit: CSV export
within 30 days (confirmed in writing)
concentration: No alternative processor tested; manual fallback documented
last_review: 2026-09-14
next_review: 2027-09-14
register_entries: R-021 (portal credential compromise), R-022 (supplier outage at month-end)
The “user_controls” line is the one that closes the loop on complementary user entity controls. The “concentration” line records an honest gap rather than hiding it.
Concentration and the hidden dependency
Your list of suppliers may look diverse while resting on one underlying provider: several SaaS products hosted on the same cloud region, or the same identity provider used to sign in to everything. When the underlying provider has an outage, many apparently independent suppliers fail together.
Map the dependencies for Tier 1 services at least once. Ask “what is this running on?” and “what do I use to log in?” For each shared dependency, decide whether you accept the concentration, build a workaround (a documented manual process, a local copy of critical data) or diversify. The decision belongs in the register, not in someone’s head.
Ongoing monitoring that is proportionate
Annual re-review is the floor for Tier 1. Between reviews, a few cheap signals are worth having: the supplier’s status page and incident notifications routed to the internal owner, a calendar reminder when the assurance report expires, and a standing agenda line in the owner’s regular meeting with the supplier. Triggers for an out-of-cycle review include a publicised breach, an acquisition, a change in hosting provider, a service outage longer than your tolerance, and the supplier asking for broader access.
When a supplier relationship ends, the work is not finished. Remove their accounts and API tokens, rotate any shared secrets, confirm data return or deletion in writing, and close the register entries. Offboarding is the step most often skipped, and a forgotten supplier account is a standing access path.
How this fails
- Questionnaire theatre. Collecting answers, filing them and never acting on a gap.
- Reading the certificate but not the scope. The product you use is not in it.
- Ignoring user entity controls. The supplier’s assurance depends on you doing your part.
- Tiering by contract value. Cheap tools with broad access are often the riskiest.
- No exit plan. You discover the export format during the crisis.
- No owner. Without a named internal owner nobody notices the report has expired.
- One-off onboarding. Review at signing and never again.
What to do next
List your suppliers, tier them using the table above, and start with the five highest-tier ones: read each one’s report scope, check the contract for notification and exit terms, and write the findings as entries in your risk register. Score them on the scoring scale, and when you reach audit preparation, the vendor records become part of your evidence set.