Supplier Criticality & Tiering Model
Decides how much assurance each supplier warrants before any questionnaire is sent, which is the control that makes the whole programme sustainable.
Available soon
- Format
- Word
- Size
- 65 KB
- Length
- 20 pages
- Version
- 1.0
- Updated
What's inside
- Purpose
- The rules this model applies
- Principles
- Inputs
- Scales and criteria
- Decision logic
- How suppliers typically spread across the tiers
- Concentration: providers several critical services depend on
- Worked examples
- How to defend the model to an auditor
- Limitations
- Calibration and review
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This model decides how much assurance [[Organisation Name]] needs from each supplier before any questionnaire is sent. It sorts every supplier into one of four tiers on four questions — what it does for us, what data it holds, what access it has and how easily it could be replaced — and the tier then decides the questionnaire, the evidence, the contract clauses, how often the supplier is reassessed and how closely it is watched.
Without it, a small team either sends every supplier the same long questionnaire and never finishes, or sends none and relies on hope. With it, the effort goes where a supplier failure would hurt: in the EXAMPLE portfolio of 112 suppliers, about 35 assessments a year instead of 112, most of them short.
It applies the Third-Party Security Policy's rules TP-01 to TP-03 and TP-09, and every other document in the Third-Party Security Risk Management pack quotes the tiers from here. A tier is not a risk rating: it measures how much could go wrong, before anything is known about the supplier's controls. The assessment then scores the supplier's residual risk on the scale of the Risk Assessment Methodology & Scoring Model (TP-06).
Guidance — delete before approval
Keep the four tiers and the worst-case rule; they are what the questionnaire, the evidence checklist, the clause library and the dashboard are built around. Change the anchors' wording and the [[bracketed]] values to fit your organisation.
If you already sort suppliers by spend or by procurement category, keep that list for procurement and add the tier alongside it. Spend is not a security criterion: a free tool can hold all your customer data.
The rules this model applies
From the Third-Party Security Policy. This model sets out how each is carried out.
TP-01 No supplier may be engaged, and no contract renewed, until intake screening is done and a tier is recorded.
TP-02 The tier must be the highest any criterion reaches, and never below an override's minimum.
TP-03 Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it.
TP-07 Contracts must carry the security clauses for the supplier's tier and data type before they are signed.
TP-09 Suppliers must be reassessed within their tier's interval, and on any material change, incident or breach at the supplier.
TP-12 Coverage, overdue reviews, open findings and concentration must be reported to executive management every quarter.
Principles
- Tier the relationship before assessing the supplier. The tier comes from what we buy and how we use it, all of which we know on the first day. It never waits for the supplier's answers.
- The worst case decides. A supplier is as critical as its most critical criterion. Four middling answers do not add up to a higher tier, and one Tier 1 answer cannot be averaged away (TP-02).
- Overrides set a floor, never a ceiling. A regulated dependency or a processor of personal data has a minimum tier; the criteria can still put it higher.
- When an answer is unknown, assume the worst. An unanswered criterion counts as Tier 1 until the business owner answers it, so the person with the facts has a reason to supply them.
- One supplier, one tier. Where a supplier provides several services, it takes the highest tier any of them reaches, and its questionnaire covers all of them.
- The tier moves when the relationship moves. A new service, new data or new access is a new intake, not a note on the file (TP-09).
- Proportionate, not optional. Tier 4 is still screened and recorded. It is a decision that little assurance is needed, not an absence of one (TP-01).
Inputs
The intake screening questions are questionnaire set D, the whole of the assessment for a Tier 4 supplier. The business owner answers them, with Procurement, before a supplier is engaged or a contract renewed (TP-01). The Tiered Supplier Security Questionnaire holds them as set D.
# | Intake question | Answers |
|---|---|---|
1 | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | TC-1 Service |
2 | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | TC-2 Data |
3 | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | TC-3 Access |
4 | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | TC-4 Substitutability |
5 | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Overrides 1 and 2 |
Input | Where it comes from | If it is not known |
|---|---|---|
Critical services and important functions | [[The business continuity plan or service inventory]], with its list of critical services | Assume the service the supplier supports is critical |
Data the supplier will hold or see | The business owner; the Data Protection Officer for personal data | Assume customer or personal data at scale |
Access the supplier will have | IT: the remote access, accounts or network connections requested | Assume privileged access |
How long a replacement would take | The business owner, with Procurement | Assume more than [[3 months]] |
Whether an override applies | The Data Protection Officer (processor); Legal or Compliance (DORA scope) | Apply it until shown not to |
Scales and criteria
The four criteria
Each criterion points at a tier on its own. Read the anchor that fits; where an answer falls between two, use the higher tier.
Criterion | Tier 1 Critical | Tier 2 Important | Tier 3 Standard | Tier 4 Minimal |
|---|---|---|---|---|
TC-1 Service | Runs or supports a critical service, or a critical or important function | Supports an important internal service | Supports a minor service | No service dependency |
TC-2 Data | Sensitive or personal data at scale, or customer data | Personal data | Internal non-personal data | No data, or public data only |
TC-3 Access | Privileged or network-level access to critical systems | Remote user access to our systems | Limited or supervised on-site access | No access |
TC-4 Substitutability | Could not be replaced within [[3 months]] without harm to a critical service | Could be replaced within [[3 months]] with effort | Replaceable within [[3 months]] with little effort | Replaceable at once: many suppliers offer the same |
- Service. A critical service is one listed in [[your business continuity plan]]; for a financial entity, "critical or important function" has its DORA meaning. In the EXAMPLE, the critical services are online ordering, warehouse dispatch, payments, finance and payroll, customer contact.
- Data. Judge the data the supplier can reach, not the data it is meant to use. A support provider with administrator access to a customer database "holds" that data for this purpose. Customer data includes customers' names, contact details and delivery addresses: a carrier that receives our customers' addresses holds customer data.
- Access. Count the supplier's people and systems: accounts, remote support tools, network links and integrations. A supplier whose portal our staff use, with no route back into our systems, has no access.
- Substitutability. How long to move to another supplier or bring the service in house, and what stops in the meantime. The [[3 months]] threshold is a default; set it to the longest outage your critical services can bear.
Guidance — delete before approval
Write your own examples next to each anchor, taken from your supplier list — 'our payroll bureau', 'our cleaning contractor'. Assessors agree faster on examples than on definitions.
Overrides
Overrides set a minimum tier whatever the criteria say. They exist because the law, not our judgement, decides how much assurance these relationships need.
# | When | Minimum tier | Why |
|---|---|---|---|
1 | An ICT service supporting a critical or important function of a DORA financial entity | Tier 1 | DORA holds the financial entity fully responsible for the ICT services it uses and sets additional contract content for these functions (Article 28(1), Article 30(3)). |
2 | A processor of personal data under GDPR Article 28 | Tier 2 | GDPR allows only processors that give sufficient guarantees of appropriate measures, under a binding contract (Article 28(1), 28(3)). That needs evidence and contract clauses beyond Tier 3. |
Decision logic
The tiering steps
- Screen. The business owner answers the intake questions before the supplier is engaged or the contract renewed (TP-01).
- Place each criterion. Read each answer against the anchors and note its tier and a one-line reason. An unanswered criterion counts as Tier 1.
- Take the highest. The supplier's tier is the highest (most critical) tier any criterion reaches (TP-02).
- Apply the overrides. If an override's minimum is higher than the result, the override wins (TP-02).
- Record it. The tier, the four placements, any override and the reasons go in the Supplier Security Risk Register, signed off by the assessor.
- Send what the tier gets. The questionnaire set and evidence request for the tier, and no higher set (TP-03).
As a formula, with Tier 1 as 1 and Tier 4 as 4:
Tier = the lowest number of (TC-1, TC-2, TC-3, TC-4, override minimum), where an unanswered criterion counts as 1 and an override that does not apply is ignored.
Guidance — delete before approval
A supplier or business owner who disagrees with a tier may give a reason; the assessor may re-read an anchor, but nobody chooses a tier. A request to lower a tier because assessment is inconvenient is a request for an exception under the Security Exception & Waiver Standard, recorded as one.
What each tier gets
The tier sets five things. The questionnaire sets are in the Tiered Supplier Security Questionnaire, the evidence and how to validate it in the Supplier Due Diligence Evidence Checklist, and the clauses in the Supplier Contract Security Clause Library.
Tier 1 Critical | Tier 2 Important | Tier 3 Standard | Tier 4 Minimal | |
|---|---|---|---|---|
Questionnaire set | Set A: about 60 questions | Set B: about 35 questions | Set C: about 15 questions | Set D: about 5 questions (intake screening only) |
Evidence | Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results | A certification or independent report, or key policies with evidence they operate | Self-declaration, with evidence sampled | None beyond the intake answers |
Contract clauses | CL-01, CL-02, CL-03, CL-04, CL-05, CL-07, CL-08, CL-09, CL-10, CL-11, CL-12, CL-13, CL-14, CL-15, CL-16, CL-18, CL-19, CL-20 If they apply: CL-06, CL-17, CL-21 | CL-01, CL-02, CL-03, CL-04, CL-05, CL-07, CL-08, CL-09, CL-11, CL-13, CL-14, CL-15, CL-16, CL-19, CL-20 If they apply: CL-06, CL-10, CL-12, CL-17, CL-18, CL-21 | CL-01, CL-07, CL-15 If they apply: CL-03, CL-04, CL-05, CL-06, CL-08, CL-09, CL-13, CL-17, CL-19, CL-21 | CL-01, short form |
Reassessment | At least every 12 months, and on any trigger (TP-09) | At least every 24 months, and on any trigger (TP-09) | At least every 36 months, and on any trigger (TP-09) | None scheduled; re-screen at renewal and on any change |
Monitoring between assessments | Continuous: breach news, certificate and report expiry, material changes | Certificate expiry and material changes | At renewal | Only when the service changes |
- A supplier is never sent a set above its tier (TP-03). A longer questionnaire does not buy more assurance from a supplier that holds nothing of ours; it buys a late answer and a strained relationship.
- Contract clauses marked "if they apply" depend on the data or the service: processor terms (CL-06) for any processor of personal data, cooperation with authorities (CL-17) for a regulated entity, cloud terms (CL-21) for a cloud service. The Supplier Contract Security Clause Library has the full selection matrix.
- The assessment ends in one of 4 decisions — Approve, Approve with conditions, Escalate, Reject — whatever the tier (TP-05). Tier 4 ends at intake: the tier itself is the decision.
When a supplier is tiered again
A new intake, and possibly a new tier, is required when any of these happens (TP-09):
- the contract is renewed or extended (TP-01);
- the supplier takes on a new service, new data or new access, or a service it supports becomes critical;
- the supplier has a security incident or breach, or changes ownership or its own key subcontractors;
- our list of critical services, or our regulatory status, changes.
A supplier that moves up a tier is assessed at its new tier within [[3 months]]; one that moves down keeps its current evidence until its next scheduled reassessment.
How suppliers typically spread across the tiers
The EXAMPLE portfolio is the P03 and P05 distributor: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It has 112 suppliers with a live contract as at 30 September 2026 (EXAMPLE; replace with your own count and date).
Tier | EXAMPLE suppliers | Share | Reassessed every | Assessments a year (suppliers × 12 ÷ months) |
|---|---|---|---|---|
Tier 1 Critical | 14 | 13% | 12 months | 14 |
Tier 2 Important | 22 | 20% | 24 months | 11 |
Tier 3 Standard | 31 | 28% | 36 months | about 10 |
Tier 4 Minimal | 45 | 40% | — | 0 (intake only) |
Total | 112 | 100% | about 35, about 3 a month |
The shape — a small Tier 1 at the top, the largest group at Tier 4 — is typical. If more than about [[1 in 5]] of your suppliers are Tier 1, the anchors are probably being read too broadly, or the critical service list is too long. If none are, check that the managed IT, cloud hosting and payroll providers have been screened at all.
Tier 1 progress. Of the 14 Tier 1 suppliers, 9 have an assessment within the last 12 months: TPM-01 (Tier 1 suppliers assessed), reported to the board as BM-05 in the Board Reporting Narrative Model — "9 of 14 critical suppliers", better (was 6). The 5 remaining are planned for Q4 2026.
The 14 EXAMPLE Tier 1 suppliers. Every one supports a critical service, so TC-1 alone places it in Tier 1; the other criteria are recorded all the same, because they decide the questions that matter at assessment.
Ref | Supplier (EXAMPLE) | Critical services supported | Data | Access | TC-1 to TC-4 (tier each reaches) | Last assessed |
|---|---|---|---|---|---|---|
SUP-001 | Managed IT service provider | Online ordering; Warehouse dispatch; Finance and payroll | Customer data | Privileged | 1 · 1 · 1 · 1 | 2025-11-18 |
SUP-002 | Cloud hosting provider | Online ordering; Finance and payroll | Customer data | Network | 1 · 1 · 1 · 1 | 2026-01-27 |
SUP-003 | Payment service provider | Payments | Card data (held by the provider) | None | 1 · 1 · 4 · 1 | 2026-02-24 |
SUP-004 | ERP software provider (hosted) | Finance and payroll; Warehouse dispatch | Personal data | Remote support | 1 · 2 · 2 · 1 | 2026-04-21 |
SUP-005 | Email and office software provider | Customer contact | Personal data | None | 1 · 2 · 4 · 2 | 2026-05-19 |
SUP-006 | Security monitoring provider | Online ordering; Warehouse dispatch | Log data | Privileged | 1 · 3 · 1 · 2 | 2026-06-16 |
SUP-007 | National parcel carrier | Warehouse dispatch | Customer addresses | Integration | 1 · 1 · 2 · 2 | 2026-07-14 |
SUP-008 | Express courier | Warehouse dispatch | Customer addresses | Integration | 1 · 1 · 2 · 2 | 2026-08-18 |
SUP-009 | Pallet network | Warehouse dispatch | Customer addresses | Portal | 1 · 1 · 4 · 2 | 2026-09-15 |
SUP-010 | Warehouse management system provider | Warehouse dispatch | Internal | Remote support | 1 · 3 · 2 · 1 | Planned 2026-10-20 |
SUP-011 | Backup service provider | Online ordering; Finance and payroll | Customer data | Network | 1 · 1 · 1 · 2 | Planned 2026-11-03 |
SUP-012 | Payroll bureau | Finance and payroll | Personal data (staff) | Portal | 1 · 1 · 4 · 2 | Planned 2026-11-17 |
SUP-013 | Outsourced customer contact centre | Customer contact | Customer data | Remote user | 1 · 1 · 2 · 2 | Planned 2026-12-01 |
SUP-014 | Network connectivity provider | Online ordering; Warehouse dispatch | None stored | Network | 1 · 4 · 1 · 1 | Planned 2026-12-08 |
Concentration: providers several critical services depend on
Tiering looks at one supplier at a time. Concentration looks across them: a provider that 2 or more critical services depend on can stop several at once. It is the headline measure TPM-04 (Concentration: providers that two or more critical services depend on. Target: each one known, with an exit plan (tp-11)). A financial entity must also assess concentration risk under DORA Article 29(1): providers that are not easily substitutable, or several arrangements with the same provider.
In the EXAMPLE, 6 of the 14 Tier 1 suppliers support two or more critical services. The count comes from the services column of the Tier 1 list above.
Ref | Provider (EXAMPLE) | Critical services that depend on it | Count | Exit plan (TP-11) |
|---|---|---|---|---|
SUP-001 | Managed IT service provider (P05 risk R-06) | Online ordering; Warehouse dispatch; Finance and payroll | 3 | [[Yes / In progress / No]] |
SUP-002 | Cloud hosting provider | Online ordering; Finance and payroll | 2 | [[Yes / In progress / No]] |
SUP-004 | ERP software provider (hosted) | Finance and payroll; Warehouse dispatch | 2 | [[Yes / In progress / No]] |
SUP-006 | Security monitoring provider | Online ordering; Warehouse dispatch | 2 | [[Yes / In progress / No]] |
SUP-011 | Backup service provider | Online ordering; Finance and payroll | 2 | [[Yes / In progress / No]] |
SUP-014 | Network connectivity provider | Online ordering; Warehouse dispatch | 2 | [[Yes / In progress / No]] |
Seen from the other side, each critical service and the Tier 1 suppliers it depends on:
Critical service (EXAMPLE) | Tier 1 suppliers | Count |
|---|---|---|
Online ordering | SUP-001, SUP-002, SUP-006, SUP-011, SUP-014 | 5 |
Warehouse dispatch | SUP-001, SUP-004, SUP-006, SUP-007, SUP-008, SUP-009, SUP-010, SUP-014 | 8 |
Payments | SUP-003 | 1 |
Finance and payroll | SUP-001, SUP-002, SUP-004, SUP-011, SUP-012 | 5 |
Customer contact | SUP-005, SUP-013 | 2 |
- For each concentration provider: confirm an exit plan exists (TP-11), confirm the substitutability answer (TC-4) is still true, and report the list every quarter (TP-12).
- SUP-001 (Managed IT service provider) supports 3 critical services and is the P05 risk R-06 ("Managed IT provider fails or is compromised", category RC-05 Third-party dependency) in the Information Security Risk Register. Concentration is not a finding against the supplier; it is a fact about our dependence, managed by exit planning and continuity arrangements.
- Look for hidden concentration too: several suppliers that all run on the same cloud platform, or use the same software. Ask Tier 1 suppliers for their own critical providers at assessment.
Guidance — delete before approval
Keep the concentration list in the risk register rather than a separate spreadsheet: add a column for the critical services each Tier 1 supplier supports, and count the rows with two or more.
Worked examples
Four EXAMPLE suppliers of the distributor, as at 30 September 2026 (EXAMPLE; replace with your own date). SUP-001 and SUP-012 are from the Tier 1 list; SUP-031 and SUP-094 are two of the other 98 suppliers. Every tier is worked out by the rules above, and the build checks it.
Example 1 — SUP-001, Tier 1 on every criterion
Step | EXAMPLE — SUP-001 Managed IT service provider |
|---|---|
What it does for us | Online ordering; Warehouse dispatch; Finance and payroll. Data: Customer data. Access: Privileged. |
TC-1 Service | Tier 1 — Runs the servers behind three critical services: online ordering, warehouse dispatch, and finance and payroll. |
TC-2 Data | Tier 1 — Administers the systems that hold customer data. |
TC-3 Access | Tier 1 — Privileged administrator access to our servers and network. |
TC-4 Substitutability | Tier 1 — A new provider would need [[4 to 6 months]] to take over three services safely. |
Overrides | Processes personal data on our behalf, so at least Tier 2 — already exceeded. |
Tier (TP-02) | Tier 1 Critical. Highest criterion: TC-1, TC-2, TC-3, TC-4. |
What it gets (TP-03, TP-07) | Set A: about 60 questions. Evidence: Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results. Clauses: CL-01, CL-02, CL-03, CL-04, CL-05, CL-07, CL-08, CL-09, CL-10, CL-11, CL-12, CL-13, CL-14, CL-15, CL-16, CL-18, CL-19, CL-20; if they apply, CL-06, CL-17, CL-21. At least every 12 months. Monitoring: Continuous: breach news, certificate and report expiry, material changes. |
Status as at 30 September 2026 | Assessed 18 November 2025; residual 3 × 1 = 3, Low on the P05 scale; decision Approve. Next reassessment due by 18 November 2026 (TP-09). |
What it shows. Service or access alone would have been enough. Tier 1 is not a verdict on the supplier: its residual risk is Low, and it is approved. Tier 1 means the assurance must be deep because the stakes are.
Example 2 — SUP-012, Tier 1 through data and service, with no access
Step | EXAMPLE — SUP-012 Payroll bureau |
|---|---|
What it does for us | Finance and payroll. Data: Personal data (staff). Access: Portal. |
TC-1 Service | Tier 1 — Runs payroll, part of the finance and payroll critical service. |
TC-2 Data | Tier 1 — Personal data of every member of staff, about 900 people, including bank details and pay: personal data at scale. |
TC-3 Access | Tier 4 — No access to our systems: our payroll team uploads to the bureau's portal. |
TC-4 Substitutability | Tier 2 — Another bureau could take over within [[3 months]], with effort, between pay runs. |
Overrides | A processor of staff personal data, so at least Tier 2 — already exceeded. |
Tier (TP-02) | Tier 1 Critical. Highest criterion: TC-1, TC-2. |
What it gets (TP-03, TP-07) | Set A: about 60 questions. Evidence: Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results. Clauses: CL-01, CL-02, CL-03, CL-04, CL-05, CL-07, CL-08, CL-09, CL-10, CL-11, CL-12, CL-13, CL-14, CL-15, CL-16, CL-18, CL-19, CL-20; if they apply, CL-06, CL-17, CL-21. At least every 12 months. Monitoring: Continuous: breach news, certificate and report expiry, material changes. |
Status as at 30 September 2026 | Not yet assessed; assessment planned for 17 November 2026, one of the 5 Tier 1 suppliers still to be assessed in Q4 2026 (TPM-01). |
What it shows. A supplier with no access to our systems can still be Tier 1. The bureau holds all staff bank details and runs a critical service; its lack of access changes which questions matter at assessment, not the tier. The processor override applies, but the criteria already put it higher.
Example 3 — SUP-031, Tier 2 by several criteria and the processor override
Step | EXAMPLE — SUP-031 Recruitment software provider (hosted) |
|---|---|
What it does for us | Recruitment (an important internal service). Data: Personal data (job applicants). Access: None. |
TC-1 Service | Tier 2 — Supports recruitment, an important internal service; no critical service depends on it. |
TC-2 Data | Tier 2 — Personal data of job applicants, a few hundred a year: personal, not at scale. |
TC-3 Access | Tier 4 — No access to our systems; HR staff use the provider's web application. |
TC-4 Substitutability | Tier 2 — Could be replaced within [[3 months]], with effort: applicant records have to be moved. |
Overrides | A processor of applicants' personal data, so at least Tier 2 — the same as the criteria. |
Tier (TP-02) | Tier 2 Important. Highest criterion: TC-1, TC-2, TC-4. |
What it gets (TP-03, TP-07) | Set B: about 35 questions. Evidence: A certification or independent report, or key policies with evidence they operate. Clauses: CL-01, CL-02, CL-03, CL-04, CL-05, CL-07, CL-08, CL-09, CL-11, CL-13, CL-14, CL-15, CL-16, CL-19, CL-20; if they apply, CL-06, CL-10, CL-12, CL-17, CL-18, CL-21. At least every 24 months. Monitoring: Certificate expiry and material changes. |
Status as at 30 September 2026 | Intake done; questionnaire set sent with the evidence request (TP-03). |
What it shows. Three Tier 2 answers stay Tier 2. The processor override would have lifted it to Tier 2 anyway, so the processor terms (CL-06) and at least a certification or independent report are needed.
Example 4 — SUP-094, Tier 4
Step | EXAMPLE — SUP-094 Office stationery supplier |
|---|---|
What it does for us | None: office supplies ordered on the supplier's website. Data: Public only: our office address. Access: None. |
TC-1 Service | Tier 4 — No service depends on it. |
TC-2 Data | Tier 4 — Our office delivery address, which is public. |
TC-3 Access | Tier 4 — No access; deliveries are left at reception. |
TC-4 Substitutability | Tier 4 — Replaceable at once: many suppliers offer the same, delivered the next working day. |
Overrides | Neither override applies: no personal data processed for us, and not a regulated financial entity's ICT service. |
Tier (TP-02) | Tier 4 Minimal. Highest criterion: TC-1, TC-2, TC-3, TC-4. |
What it gets (TP-03, TP-07) | Set D: about 5 questions (intake screening only). Evidence: None beyond the intake answers. Clauses: CL-01. No scheduled reassessment; re-screened at renewal (TP-01) and when the service changes. Monitoring: Only when the service changes. |
Status as at 30 September 2026 | Intake screening only: no questionnaire, no evidence request. Re-screened at renewal (TP-01). |
What it shows. Most suppliers look like this one. Screening takes minutes, and the answer is recorded so that an auditor can see the decision and a change at renewal is caught.
How to defend the model to an auditor
An auditor will usually test that suppliers are identified and prioritised by criticality, that the assurance applied matches that priority, that the priority is kept current, and that it follows a defined method rather than habit. Regulated entities will also be asked how the approach is proportionate and how concentration is assessed.
Evidence to have ready
- This model, approved, and the list of critical services it relies on.
- The Supplier Security Risk Register: every supplier with its tier, the four criterion placements with reasons, any override, and the date of screening.
- For a sample of suppliers: the intake answers, the questionnaire set sent and the evidence received, matching the tier (TP-03).
- Contracts signed in the last 12 months, with the clauses for the tier (TP-07).
- The concentration list and the exit plans for it (TPM-04, TP-11).
- The calibration record (see 'Calibration and review').
The re-derivation test
Invite the auditor to pick [[10]] suppliers from the register, from every tier. For each, take the recorded criterion placements and overrides, apply the worst-case rule, and compare with the recorded tier; then check that the questionnaire set, the evidence and the reassessment date match that tier. Run this test yourself each quarter.
Questions auditors commonly ask
Question | Answer the model gives |
|---|---|
How do you decide which suppliers matter? | Four criteria with written anchors, the worst-case rule and two legal overrides, applied at intake to every supplier (TP-01, TP-02). |
Why do so many suppliers get no questionnaire? | Tier 4 suppliers have no data, no access, no service dependency and are easily replaced. They are still screened and recorded; the intake answers are their assessment. In the EXAMPLE they are 40% of suppliers. |
How do you know the tiers are still right? | Every renewal is a new intake (TP-01); a new service, data, access or incident triggers another (TP-09); the quarterly re-derivation test checks the records. |
How do you handle a supplier that supports several critical services? | It is Tier 1, and it is on the concentration list (TPM-04) with an exit plan (TP-11). |
Is a Tier 1 supplier a high risk? | Not necessarily. The tier measures what is at stake; residual risk after assessment is scored on the P05 scale (TP-06), and a Tier 1 supplier can be Low. |
Limitations
Limitation | Effect | How it is managed |
|---|---|---|
Answers come from the business owner. | An owner who wants a quick contract may understate data or access. | IT confirms access requests; the Data Protection Officer confirms personal data; an unknown answer counts as Tier 1. |
Four levels are coarse. | Two quite different suppliers can share a tier. | The tier decides the depth of assurance only. The assessment and the residual risk score tell them apart. |
The worst case can over-tier. | A supplier with one Tier 1 answer gets the full Tier 1 treatment. | Deliberate: a single route to a critical system is enough to cause the harm. The questionnaire's answers can be brief where a topic does not apply. |
Substitutability is an estimate. | Nobody knows how long a switch takes until they try it. | Tested in exit planning for Tier 1 and Tier 2 (TP-11); revised when an exit plan shows otherwise. |
Fourth parties are not tiered. | A supplier's own providers can be the real dependency. | Asked at Tier 1 assessment; hidden concentration checked in the concentration review. |
Tiers age. | Services and data drift during a contract. | Triggers (TP-09) and re-screening at every renewal (TP-01). |
Calibration and review
Calibration between assessors
- Before first use, and every year after, two people tier the same [[10]] suppliers independently, including at least one from each tier.
- Compare the criterion placements. A different placement that does not change the tier is worth a conversation; one that changes the tier shows an anchor that needs clearer wording or an example.
- Change the anchor or add an example in this document, and record the change below.
- Run the test cases below on the Supplier Security Risk Register and any tool that applies the model. Each must give the expected tier.
Calibration test cases
Criterion values are tiers (1 = Tier 1). Overrides: 1 = DORA critical or important function, 2 = processor of personal data.
Case | TC-1 | TC-2 | TC-3 | TC-4 | Override | Expected tier | What it tests |
|---|---|---|---|---|---|---|---|
1 | 4 | 4 | 4 | 4 | — | Tier 4 | Nothing at stake: Tier 4, intake only |
2 | 4 | 4 | 1 | 4 | — | Tier 1 | One criterion is enough: privileged access alone makes Tier 1 |
3 | 2 | 2 | 2 | 2 | — | Tier 2 | Four Tier 2 answers do not add up to Tier 1: no averaging, no adding |
4 | 3 | 2 | 3 | 3 | — | Tier 2 | The worst case wins: personal data lifts a Tier 3 supplier |
5 | 3 | 3 | 3 | 3 | — | Tier 3 | A minor service, internal data, supervised access, replaceable with little effort |
6 | 3 | 3 | 4 | 3 | 2 | Tier 2 | Override 2: a processor of personal data is at least Tier 2 |
7 | 2 | 1 | 3 | 2 | 2 | Tier 1 | An override sets a minimum; it never lowers a tier |
8 | 3 | 4 | 4 | 3 | 1 | Tier 1 | Override 1: an ICT service for a critical or important function (DORA) is Tier 1 |
9 | 3 | Unknown | 4 | 3 | — | Tier 1 | An unanswered criterion counts as Tier 1 until it is answered |
10 | 4 | 4 | 3 | 4 | — | Tier 3 | Supervised on-site access alone: Tier 3, not Tier 4 |
11 | 4 | 4 | 4 | 3 | — | Tier 3 | Nothing at stake but a few weeks to replace: Tier 3, not Tier 4 |
Every quarter
Head of Information Security checks the following alongside the quarterly report to executive management (TP-12) and records the result. The signals are prompts to investigate, not targets.
Check | Signal that the model needs attention |
|---|---|
Re-derivation test | Any supplier whose recorded tier cannot be reproduced from its placements and overrides. |
Tier distribution | More than [[1 in 5]] suppliers in Tier 1, or a known critical provider outside Tier 1. |
Unscreened suppliers | Any supplier paid in the quarter with no tier on the register (TP-01). |
Incidents | An incident at a Tier 3 or Tier 4 supplier that affected a critical service: its tier was wrong. |
Headline measures | Any of TPM-01, TPM-02, TPM-03, TPM-04 off target for two quarters running. |
Review
This model is reviewed at least every 12 months, and also when the list of critical services changes, after an incident involving a supplier, when the quarterly checks show the same signal twice, or when the organisation's regulatory status changes. The review is approved by executive management.
Calibration record
Date | Assessors | Suppliers tiered | Tier differences | Change made | Approved by |
|---|---|---|---|---|---|
[[YYYY-MM-DD]] | [[Names]] | [[n]] | [[n]] | [[None / description]] | [[Name]] |
Related documents
Document | Relationship |
|---|---|
Third-Party Security Policy | States the rules TP-01 to TP-12 this model applies |
Supplier Security Assessment Procedure | The steps from intake to decision, starting with tiering |
Tiered Supplier Security Questionnaire | The questionnaire sets A, B, C, D, one per tier |
Supplier Due Diligence Evidence Checklist | The evidence each tier requires, and how to validate it (TP-04) |
Supplier Contract Security Clause Library | The contract clauses for each tier and data type (TP-07) |
Supplier Security Risk Register | Records each supplier's tier, placements, overrides and reassessment dates |
Supplier Security Review Report Template | Records the outcome of each assessment |
Third-Party Risk Dashboard | Reports TPM-01, TPM-02, TPM-03, TPM-04, including concentration |
Risk Assessment Methodology & Scoring Model | The scale on which supplier residual risk is scored (TP-06) |
Information Security Risk Register | Where a supplier risk outside appetite is recorded |
Security Exception & Waiver Standard | Where a request to depart from a tier's requirements is decided |
Adapting this template
Guidance — delete before approval
Small organisation: keep the four criteria, the worst-case rule and the overrides. With [[30]] suppliers you may have only [[3 to 5]] in Tier 1: assess those properly and screen the rest. One person can run the model if the business owner answers the intake questions; use an outside reviewer for the yearly calibration.
Regulated entity: NIS2 Article 21(2)(d) requires supply chain security measures, and 21(3) that they take account of each direct supplier's specific vulnerabilities and the quality of its products and cybersecurity practices; tiering is how that is made proportionate. A DORA financial entity keeps override 1, manages ICT third-party risk proportionately while remaining fully responsible (Article 28(1)), records its ICT arrangements in the register of information (Article 28(3)) and assesses concentration (Article 29(1)). Use the DORA meaning of "critical or important function" in TC-1, and consider a separate flag for ICT services in the register.
Personal data: keep override 2. The Data Protection Officer confirms which suppliers are processors; the processor terms (CL-06) apply whatever the tier (GDPR Article 28).
IT run by a service provider: your managed IT provider is almost certainly Tier 1 and on the concentration list, as SUP-001 is. Ask it to list the providers it relies on to serve you, and screen those it gives access to your data.
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR).
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | Whole model: supplier risk addressed in proportion to what the supplier does for us |
ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Reassessment intervals and monitoring by tier; when a supplier is tiered again |
NIST CSF 2.0 | GV.SC-04 — “Suppliers are known and prioritized by criticality” | The criteria, the worst-case rule and the tier register |
NIST CSF 2.0 | GV.SC-03 — “Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes” | Tier and residual risk: residual supplier risk scored on the enterprise (P05) scale |
NIS2 — Directive (EU) 2022/2555 | Article 21(2)(d) — “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” | Whole model, as part of supply chain security |
NIS2 — Directive (EU) 2022/2555 | Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development | Criteria that take account of each direct supplier; proportionate assurance by tier |
DORA — Regulation (EU) 2022/2554 | Article 28(1) — ICT third-party risk managed as part of ICT risk, proportionately; the financial entity remains fully responsible | Override 1; proportionate assurance while remaining fully responsible |
DORA — Regulation (EU) 2022/2554 | Article 29(1) — assessing concentration risk: providers not easily substitutable, or several arrangements with the same provider | Concentration: providers several critical services depend on; substitutability (TC-4) |
GDPR — Regulation (EU) 2016/679 | Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures | Override 2: processors must give sufficient guarantees, so at least Tier 2 |
Definitions
Term | Meaning in this model |
|---|---|
Concentration | Dependence of 2 or more critical services on one provider (TPM-04). |
Critical service | A service listed as critical in [[the business continuity plan]]; for a DORA financial entity, a critical or important function. |
Criterion | One of the four questions that place a supplier: service, data, access and substitutability (TC-1 to TC-4). |
DORA | The Digital Operational Resilience Act, Regulation (EU) 2022/2554, which applies to financial entities. |
Intake screening | The questions answered before a supplier is engaged or renewed: questionnaire set D. |
NIS2 | Directive (EU) 2022/2555 on a high common level of cybersecurity. |
Override | A rule that sets a minimum tier whatever the criteria say. |
Processor | A supplier that processes personal data on our behalf (GDPR Article 28). |
Residual risk | The supplier's risk after its controls are assessed, scored on the P05 scale (TP-06). |
Substitutability | How quickly and safely a supplier could be replaced (TC-4). |
Tier | One of four levels — Tier 1 Critical, Tier 2 Important, Tier 3 Standard, Tier 4 Minimal — that sets the assurance a supplier needs. |
Worst-case rule | The tier is the highest any criterion reaches (TP-02). |