Supplier risk management, without the headcount.
Supplier risk management is the programme that decides which suppliers you trust, on what evidence, and what happens when that evidence stops being true. Most programmes are limited not by method but by capacity — a team of three reviewing four hundred suppliers once a year is running a documentation exercise, not an assurance one. This page covers how to assess supplier risk, what good supplier assurance looks like, the best practices worth adopting, and where tooling genuinely changes the arithmetic.
What supplier risk actually is
Supplier risk is the exposure created by depending on an organisation you do not control. It is usually discussed as a security question, but it arrives in four distinguishable forms, and programmes that conflate them tend to manage the easiest one well and the others not at all.
- Security risk. The supplier is compromised, and their access, their integration or your data goes with them.
- Resilience risk. The supplier fails, is acquired, or suffers an outage, and a service you depend on stops.
- Compliance risk. The supplier’s practices put you in breach of an obligation that is yours, not theirs — the effect of NIS2, DORA and the UK’s Cyber Security and Resilience Bill.
- Concentration risk. Many suppliers, one underlying dependency. Invisible one supplier at a time.
A note on vocabulary, because it matters for finding things: UK organisations generally say supplier where US organisations say vendor, and “supplier assurance” where others say “third-party risk management”. The disciplines are the same. If you are comparing tooling, note that most of the market is documented in the US vocabulary — our third-party risk management software page covers that side.
How to run a supplier risk assessment
The order matters more than the questionnaire. Most of the wasted effort in supplier assurance comes from assessing everyone at the same depth.
- Segment on inherent risk before you assess anythingWhat data do they hold, what access do they have, how quickly does their failure hurt, and what jurisdiction are they in? This is answerable from your own records without asking the supplier a single question, and it determines how much effort each relationship deserves.
- Match assessment depth to that tierA critical supplier with production access warrants a full control assessment and evidence. A low-impact supplier with no data and no access warrants a short screen. Sending the same 200-question document to both trains everyone to treat the exercise as paperwork.
- Collect what already exists before issuing a questionnaireSOC 2 reports, ISO 27001 certificates and scope statements, penetration test summaries, trust-centre content. A large share of a questionnaire is usually already answered in documents the supplier has published — and pre-populating from them is the difference between a two-week and a two-month cycle.
- Add an outside-in viewAn external assessment of the supplier’s attack surface, breach history and public record needs no cooperation and no waiting. It is also the only part of the assessment that stays true after the questionnaire is filed.
- Reconcile, and treat disagreement as the findingWhere a supplier’s answers and their observable posture disagree, that is the most valuable output of the assessment. It is also the part almost no programme does, because the two data sets usually live in different systems owned by different teams.
- Turn findings into dated actions with an ownerA finding without a remediation deadline and a named owner is an observation. Most registers are full of them.
Supplier risk management best practices
Drawn from what separates programmes that survive an audit from those that survive only until someone checks.
- Tier by access and impact, never by spendThe cheapest supplier in the estate is frequently the one with an API token into your customer data. Procurement value is not a risk signal.
- Read the scope statement, not the certificateAn ISO 27001 or Cyber Essentials Plus certificate covers whatever scope the supplier defined. The system you are buying may sit outside it, and the certificate will not say so.
- Write incident notification windows that fit your own deadlinesIf you owe a regulator an early warning within 24 hours, a contract giving your supplier 72 hours to tell you has already made the deadline unmeetable.
- Require subcontractor disclosureYou have no relationship with your supplier’s suppliers. Disclosure in the contract is the only leverage you will ever have over fourth-party risk.
- Define risk acceptance and who may sign itWithout an explicit threshold every finding escalates, nothing closes, and the register grows until people stop reading it.
- Reassess on events, not only on datesA breach, an acquisition, a new internet-facing service or a material drop in external posture should trigger a review regardless of when the last one was.
- Offboard properly and keep the evidenceAccess revoked, data destroyed, destruction evidenced. Registers accumulate suppliers who left years ago and still hold credentials, and that is a finding waiting to be written by someone else.
Supplier assurance and its central limitation
Assurance is a claim about the future, made from evidence about the past.
Every artefact a supplier assurance programme collects — questionnaire, certificate, audit report, penetration test — describes a moment. The questionnaire describes the day it was completed. The certificate describes the day of the audit. The penetration test describes the week it ran.
The decision you make on that evidence, though, is not about that day. It is about the following twelve months, during which the supplier will change hosting providers, ship new services, be acquired, lose staff, and inherit vulnerabilities in software they did not write. None of that generates a notification to you.
This is not an argument against questionnaires. Inside-out evidence tells you things no external view can — governance, policy, who is accountable, what happens at offboarding. It is an argument that inside-out evidence alone leaves you blind for everything except the assessment window, and that the fix is not a longer questionnaire but a second, continuous source of signal that requires no cooperation from the supplier to keep flowing.
Supplier cyber security: what to actually check
Beneath the framework mappings, a small number of things predict whether a supplier will be a problem.
- External attack surface. What of theirs is reachable from the internet, and does it look maintained? Expired certificates, unsupported software and forgotten subdomains are cheap to observe and strongly correlated with the rest.
- Patch discipline. Not whether they have a policy — whether observable services are current.
- Authentication. MFA on the systems that touch your data, including the SaaS tools bought outside their IT function.
- Access model. How their staff reach your environment, whether that access is time-bound, and who reviews it.
- Breach and disclosure history. Not disqualifying in itself — how an organisation handled an incident is often more informative than whether it had one.
- Their fourth parties. Who they depend on, and whether those dependencies concentrate with your other suppliers.
Choosing a supplier risk assessment tool
Tooling is worth buying when it removes human effort per supplier. It is worth avoiding when it only relocates it.
Five questions separate the two:
- Does it produce evidence, or only collect it? A tool that stores questionnaires is a filing system. Ask what it tells you that you did not put in.
- Does it pre-populate? If your team still types answers from a SOC 2 report into a questionnaire, the tool has not addressed the actual cost.
- Does it monitor between assessments? Point-in-time tooling inherits the limitation described above.
- Does it reconcile inside-out and outside-in? Holding both and never comparing them is the common case.
- Does it chase suppliers for you? Follow-up is where the calendar actually goes — not analysis.
RiskXchange’s answer to the last two is The Agency: NOVA runs the supplier conversation across email, WhatsApp and in-app chat and does the chasing; ARIA pre-populates questionnaires from documents against 157 universal controls and validates answers against evidence; REX watches the outside-in signal continuously and flags material change. Autonomy is set per supplier, so a critical one can require sign-off on every action while a low-risk one runs hands-off.
Supplier risk, answered.
What is supplier risk management?
What is the difference between supplier risk management and third-party risk management?
How do you assess supplier cyber security?
How often should supplier risk assessments be repeated?
Is a supplier’s ISO 27001 or Cyber Essentials certificate enough?
What does supplier assurance mean?
Go deeper.
Four hundred suppliers. One team.
Book a 30-minute call and we will run a full supplier assessment on one of your live suppliers inside 24 hours — questionnaire pre-populated, answers validated, posture scored.