Supplier risk management

Supplier risk management, without the headcount.

Supplier risk management is the programme that decides which suppliers you trust, on what evidence, and what happens when that evidence stops being true. Most programmes are limited not by method but by capacity — a team of three reviewing four hundred suppliers once a year is running a documentation exercise, not an assurance one. This page covers how to assess supplier risk, what good supplier assurance looks like, the best practices worth adopting, and where tooling genuinely changes the arithmetic.

What supplier risk actually is

Supplier risk is the exposure created by depending on an organisation you do not control. It is usually discussed as a security question, but it arrives in four distinguishable forms, and programmes that conflate them tend to manage the easiest one well and the others not at all.

  • Security risk. The supplier is compromised, and their access, their integration or your data goes with them.
  • Resilience risk. The supplier fails, is acquired, or suffers an outage, and a service you depend on stops.
  • Compliance risk. The supplier’s practices put you in breach of an obligation that is yours, not theirs — the effect of NIS2, DORA and the UK’s Cyber Security and Resilience Bill.
  • Concentration risk. Many suppliers, one underlying dependency. Invisible one supplier at a time.

A note on vocabulary, because it matters for finding things: UK organisations generally say supplier where US organisations say vendor, and “supplier assurance” where others say “third-party risk management”. The disciplines are the same. If you are comparing tooling, note that most of the market is documented in the US vocabulary — our third-party risk management software page covers that side.

How to run a supplier risk assessment

The order matters more than the questionnaire. Most of the wasted effort in supplier assurance comes from assessing everyone at the same depth.

  1. Segment on inherent risk before you assess anything
    What data do they hold, what access do they have, how quickly does their failure hurt, and what jurisdiction are they in? This is answerable from your own records without asking the supplier a single question, and it determines how much effort each relationship deserves.
  2. Match assessment depth to that tier
    A critical supplier with production access warrants a full control assessment and evidence. A low-impact supplier with no data and no access warrants a short screen. Sending the same 200-question document to both trains everyone to treat the exercise as paperwork.
  3. Collect what already exists before issuing a questionnaire
    SOC 2 reports, ISO 27001 certificates and scope statements, penetration test summaries, trust-centre content. A large share of a questionnaire is usually already answered in documents the supplier has published — and pre-populating from them is the difference between a two-week and a two-month cycle.
  4. Add an outside-in view
    An external assessment of the supplier’s attack surface, breach history and public record needs no cooperation and no waiting. It is also the only part of the assessment that stays true after the questionnaire is filed.
  5. Reconcile, and treat disagreement as the finding
    Where a supplier’s answers and their observable posture disagree, that is the most valuable output of the assessment. It is also the part almost no programme does, because the two data sets usually live in different systems owned by different teams.
  6. Turn findings into dated actions with an owner
    A finding without a remediation deadline and a named owner is an observation. Most registers are full of them.

Supplier risk management best practices

Drawn from what separates programmes that survive an audit from those that survive only until someone checks.

  • Tier by access and impact, never by spend
    The cheapest supplier in the estate is frequently the one with an API token into your customer data. Procurement value is not a risk signal.
  • Read the scope statement, not the certificate
    An ISO 27001 or Cyber Essentials Plus certificate covers whatever scope the supplier defined. The system you are buying may sit outside it, and the certificate will not say so.
  • Write incident notification windows that fit your own deadlines
    If you owe a regulator an early warning within 24 hours, a contract giving your supplier 72 hours to tell you has already made the deadline unmeetable.
  • Require subcontractor disclosure
    You have no relationship with your supplier’s suppliers. Disclosure in the contract is the only leverage you will ever have over fourth-party risk.
  • Define risk acceptance and who may sign it
    Without an explicit threshold every finding escalates, nothing closes, and the register grows until people stop reading it.
  • Reassess on events, not only on dates
    A breach, an acquisition, a new internet-facing service or a material drop in external posture should trigger a review regardless of when the last one was.
  • Offboard properly and keep the evidence
    Access revoked, data destroyed, destruction evidenced. Registers accumulate suppliers who left years ago and still hold credentials, and that is a finding waiting to be written by someone else.

Supplier assurance and its central limitation

Assurance is a claim about the future, made from evidence about the past.

Every artefact a supplier assurance programme collects — questionnaire, certificate, audit report, penetration test — describes a moment. The questionnaire describes the day it was completed. The certificate describes the day of the audit. The penetration test describes the week it ran.

The decision you make on that evidence, though, is not about that day. It is about the following twelve months, during which the supplier will change hosting providers, ship new services, be acquired, lose staff, and inherit vulnerabilities in software they did not write. None of that generates a notification to you.

This is not an argument against questionnaires. Inside-out evidence tells you things no external view can — governance, policy, who is accountable, what happens at offboarding. It is an argument that inside-out evidence alone leaves you blind for everything except the assessment window, and that the fix is not a longer questionnaire but a second, continuous source of signal that requires no cooperation from the supplier to keep flowing.

Supplier cyber security: what to actually check

Beneath the framework mappings, a small number of things predict whether a supplier will be a problem.

  • External attack surface. What of theirs is reachable from the internet, and does it look maintained? Expired certificates, unsupported software and forgotten subdomains are cheap to observe and strongly correlated with the rest.
  • Patch discipline. Not whether they have a policy — whether observable services are current.
  • Authentication. MFA on the systems that touch your data, including the SaaS tools bought outside their IT function.
  • Access model. How their staff reach your environment, whether that access is time-bound, and who reviews it.
  • Breach and disclosure history. Not disqualifying in itself — how an organisation handled an incident is often more informative than whether it had one.
  • Their fourth parties. Who they depend on, and whether those dependencies concentrate with your other suppliers.

Choosing a supplier risk assessment tool

Tooling is worth buying when it removes human effort per supplier. It is worth avoiding when it only relocates it.

Five questions separate the two:

  • Does it produce evidence, or only collect it? A tool that stores questionnaires is a filing system. Ask what it tells you that you did not put in.
  • Does it pre-populate? If your team still types answers from a SOC 2 report into a questionnaire, the tool has not addressed the actual cost.
  • Does it monitor between assessments? Point-in-time tooling inherits the limitation described above.
  • Does it reconcile inside-out and outside-in? Holding both and never comparing them is the common case.
  • Does it chase suppliers for you? Follow-up is where the calendar actually goes — not analysis.

RiskXchange’s answer to the last two is The Agency: NOVA runs the supplier conversation across email, WhatsApp and in-app chat and does the chasing; ARIA pre-populates questionnaires from documents against 157 universal controls and validates answers against evidence; REX watches the outside-in signal continuously and flags material change. Autonomy is set per supplier, so a critical one can require sign-off on every action while a low-risk one runs hands-off.

Supplier risk, answered.

What is supplier risk management?
The programme for identifying which suppliers introduce risk, assessing it in proportion to what they can access and how critical they are, reducing it through contracts and remediation, and keeping that view current between assessments.
What is the difference between supplier risk management and third-party risk management?
Largely vocabulary. UK organisations tend to say supplier and supplier assurance; US organisations tend to say vendor and third-party risk management. The practices are the same, though “supplier” often carries a broader procurement connotation covering commercial and delivery risk as well as security.
How do you assess supplier cyber security?
With two sources rather than one. Inside-out evidence — questionnaires, certifications, audit reports — covers governance and policy. Outside-in evidence — external attack surface, breach history, public record — covers what is observably true and keeps updating without the supplier’s involvement. The disagreements between them are the findings worth acting on.
How often should supplier risk assessments be repeated?
Set cadence by tier, and add event-driven triggers: a breach, an acquisition, a new integration, or a material change in external posture. Annual review for everything is common because it matches team capacity, not because it matches how quickly risk changes.
Is a supplier’s ISO 27001 or Cyber Essentials certificate enough?
It is useful evidence, not a conclusion. Certificates cover the scope the supplier defined, which may exclude the system you are buying, and they describe the day of the audit. Ask for the scope statement and the issue date, and treat the certificate as a floor rather than an answer. See Cyber Essentials Plus for what that certificate does and does not prove.
What does supplier assurance mean?
The activity of obtaining and maintaining confidence that a supplier meets your security and compliance requirements — the evidence-gathering and verification side of supplier risk management, as distinct from the commercial relationship.

Four hundred suppliers. One team.

Book a 30-minute call and we will run a full supplier assessment on one of your live suppliers inside 24 hours — questionnaire pre-populated, answers validated, posture scored.