Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Third-Party Security Risk Pack — Guide

Third-Party Security Risk Pack

Every supplier gets the same 200-question audit, whether it runs payments or delivers office plants. Nobody reads the answers, certificates are filed without checking what they cover, and the review stalls after a dozen vendors. This pack helps you assess suppliers in proportion to the harm they could do, so the process scales to all.

Is this for you?

This pack is for you if:

  • you have more suppliers than you could review by hand;
  • you cannot say which suppliers could stop a critical service;
  • certificates are accepted without checking their scope.

Tier first, questionnaire second

Every supplier is tiered at intake, before any questionnaire (TP-01). The tier is the highest any criterion reaches: service, data, access or substitutability (TP-02).

TierWhat puts a supplier thereQuestionsEvidenceReassessed every
1 CriticalRuns a critical service; customer or large-scale personal data; privileged access; not replaceable within three monthsSet A, about 60Independent assurance matching the service; penetration and continuity test results12 months
2 ImportantSupports an important internal service; personal data; remote user accessSet B, about 35Certification or independent report, or policies shown to operate24 months
3 StandardSupports a minor service; internal non-personal data; supervised accessSet C, about 15Self-declaration, sampled36 months
4 MinimalNo dependency, data or accessSet D, 5 intake questionsNoneWhen the service changes

Two overrides set a floor: an ICT service supporting a DORA critical or important function is Tier 1, and a GDPR processor at least Tier 2. Evidence is checked, not just received: scope, dates and name against the service you buy (TP-04).

Why proportionality scales

Take a distributor with 112 suppliers: 14 in Tier 1, 22 in Tier 2, 31 in Tier 3 and 45 in Tier 4. The largest group answers five questions; 76 answer fifteen or fewer. One audit for all means 22,400 answers; tiering cuts that to about 2,300, about a third from the 14 suppliers that matter most. The intervals mean roughly 35 assessments a year.

Start with these three

  1. Supplier Criticality & Tiering Model — the criteria and what each tier receives.
  2. Tiered Supplier Security Questionnaire — the four question sets, one per tier.
  3. Supplier Security Risk Register — every supplier, its decision, findings and next review.

Your first month

WhenWhat to doYou’re done when
Week 1List suppliers from accounts payable; set the tiering criteria.Management has approved them.
Week 2Tier each supplier with its business owner.Every supplier has a tier and owner.
Week 3Send Set A to Tier 1 suppliers not assessed in 12 months.Each has a return date.
Week 4Fill the register; validate the first evidence returned.Each Tier 1 supplier has an assessment date.

Four numbers to report

Report these to executive management quarterly.

NumberTarget
Tier 1 suppliers assessed within 12 monthsAll by year end
Reassessments overdueZero Tier 1; none more than 90 days overdue
High findings past their deadlineZero
Providers two or more critical services depend onEach known, with an exit plan

The first is the supplier measure in a board report. Supplier risk outside appetite goes to the risk register (TP-06).

Everything in the pack

DocumentWhat it doesFormat
Third-Party Security PolicyThe twelve rules management approvesWord
Supplier Security Assessment ProcedureFrom intake to decisionWord
Supplier Criticality & Tiering ModelWhich tier, and what followsWord
Tiered Supplier Security QuestionnaireFour question sets, one per tierExcel
Supplier Due Diligence Evidence ChecklistEvidence to request and checkExcel
Supplier Contract Security Clause LibraryClauses by tier and data typeWord
Supplier Security Risk RegisterEvery supplier, decision and findingExcel
Supplier Security Review Report TemplateOne assessment’s findings and decisionWord
Third-Party Risk DashboardThe four numbers, quarter by quarterExcel

Adapting it

  • Small organisation: tier everyone, then assess Tier 1 first; the rest fall due within their intervals. Business owners still sign each decision.
  • Regulated entity: NIS2 Article 21(2)(d) names supply chain security; 21(3) asks you to weigh each direct supplier’s vulnerabilities and practices. Under DORA Articles 28 to 30 you stay responsible for ICT services, keep a register of information on every ICT contract (28(3)), assess concentration (29) and set contract content (30), with more for critical or important functions.
  • Processors of personal data: GDPR Article 28 requires sufficient guarantees and a binding contract; the clause library carries its terms.
  • IT run by an outside provider: the managed service provider is usually your most critical supplier. Assess it first and plan its exit.

Where it maps

  • ISO/IEC 27001:2022 — Annex A 5.19 and 5.20.
  • NIST CSF 2.0 — GV.SC-01 and GV.SC-04.
  • NIS2 — Article 21(2)(d) and 21(3).
  • DORA — Articles 28 to 30.
  • GDPR — Article 28.