Third-Party Security Risk Pack — Guide
- Version 1.0
- Updated
- Next review
Third-Party Security Risk Pack
Every supplier gets the same 200-question audit, whether it runs payments or delivers office plants. Nobody reads the answers, certificates are filed without checking what they cover, and the review stalls after a dozen vendors. This pack helps you assess suppliers in proportion to the harm they could do, so the process scales to all.
Is this for you?
This pack is for you if:
- you have more suppliers than you could review by hand;
- you cannot say which suppliers could stop a critical service;
- certificates are accepted without checking their scope.
Tier first, questionnaire second
Every supplier is tiered at intake, before any questionnaire (TP-01). The tier is the highest any criterion reaches: service, data, access or substitutability (TP-02).
| Tier | What puts a supplier there | Questions | Evidence | Reassessed every |
|---|---|---|---|---|
| 1 Critical | Runs a critical service; customer or large-scale personal data; privileged access; not replaceable within three months | Set A, about 60 | Independent assurance matching the service; penetration and continuity test results | 12 months |
| 2 Important | Supports an important internal service; personal data; remote user access | Set B, about 35 | Certification or independent report, or policies shown to operate | 24 months |
| 3 Standard | Supports a minor service; internal non-personal data; supervised access | Set C, about 15 | Self-declaration, sampled | 36 months |
| 4 Minimal | No dependency, data or access | Set D, 5 intake questions | None | When the service changes |
Two overrides set a floor: an ICT service supporting a DORA critical or important function is Tier 1, and a GDPR processor at least Tier 2. Evidence is checked, not just received: scope, dates and name against the service you buy (TP-04).
Why proportionality scales
Take a distributor with 112 suppliers: 14 in Tier 1, 22 in Tier 2, 31 in Tier 3 and 45 in Tier 4. The largest group answers five questions; 76 answer fifteen or fewer. One audit for all means 22,400 answers; tiering cuts that to about 2,300, about a third from the 14 suppliers that matter most. The intervals mean roughly 35 assessments a year.
Start with these three
- Supplier Criticality & Tiering Model — the criteria and what each tier receives.
- Tiered Supplier Security Questionnaire — the four question sets, one per tier.
- Supplier Security Risk Register — every supplier, its decision, findings and next review.
Your first month
| When | What to do | You’re done when |
|---|---|---|
| Week 1 | List suppliers from accounts payable; set the tiering criteria. | Management has approved them. |
| Week 2 | Tier each supplier with its business owner. | Every supplier has a tier and owner. |
| Week 3 | Send Set A to Tier 1 suppliers not assessed in 12 months. | Each has a return date. |
| Week 4 | Fill the register; validate the first evidence returned. | Each Tier 1 supplier has an assessment date. |
Four numbers to report
Report these to executive management quarterly.
| Number | Target |
|---|---|
| Tier 1 suppliers assessed within 12 months | All by year end |
| Reassessments overdue | Zero Tier 1; none more than 90 days overdue |
| High findings past their deadline | Zero |
| Providers two or more critical services depend on | Each known, with an exit plan |
The first is the supplier measure in a board report. Supplier risk outside appetite goes to the risk register (TP-06).
Everything in the pack
| Document | What it does | Format |
|---|---|---|
| Third-Party Security Policy | The twelve rules management approves | Word |
| Supplier Security Assessment Procedure | From intake to decision | Word |
| Supplier Criticality & Tiering Model | Which tier, and what follows | Word |
| Tiered Supplier Security Questionnaire | Four question sets, one per tier | Excel |
| Supplier Due Diligence Evidence Checklist | Evidence to request and check | Excel |
| Supplier Contract Security Clause Library | Clauses by tier and data type | Word |
| Supplier Security Risk Register | Every supplier, decision and finding | Excel |
| Supplier Security Review Report Template | One assessment’s findings and decision | Word |
| Third-Party Risk Dashboard | The four numbers, quarter by quarter | Excel |
Adapting it
- Small organisation: tier everyone, then assess Tier 1 first; the rest fall due within their intervals. Business owners still sign each decision.
- Regulated entity: NIS2 Article 21(2)(d) names supply chain security; 21(3) asks you to weigh each direct supplier’s vulnerabilities and practices. Under DORA Articles 28 to 30 you stay responsible for ICT services, keep a register of information on every ICT contract (28(3)), assess concentration (29) and set contract content (30), with more for critical or important functions.
- Processors of personal data: GDPR Article 28 requires sufficient guarantees and a binding contract; the clause library carries its terms.
- IT run by an outside provider: the managed service provider is usually your most critical supplier. Assess it first and plan its exit.
Where it maps
- ISO/IEC 27001:2022 — Annex A 5.19 and 5.20.
- NIST CSF 2.0 — GV.SC-01 and GV.SC-04.
- NIS2 — Article 21(2)(d) and 21(3).
- DORA — Articles 28 to 30.
- GDPR — Article 28.