Supplier Due Diligence Evidence Checklist
Specifies exactly which evidence to request and how to validate it, so assessments rely on proof rather than self-declaration.
Available soon
- Format
- Excel
- Size
- 68 KB
- Length
- 10 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Evidence Items
- Supplier Checklist
- Review Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Tier first. The supplier's tier comes from the Supplier Criticality & Tiering Model (TP-01, TP-02). The Evidence Items sheet shows what each tier asks for, in columns I to L: Tier 1 — independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results; Tier 2 — a certification or independent report, or key policies with evidence they operate; Tier 3 — self-declaration, with evidence sampled; Tier 4 — none beyond the intake answers. |
| 2 | Before first use, read the Evidence Items sheet and set the [[placeholders]]: the gap after which a bridge letter is needed ([[3 months]]), the number of items sampled at Tier 3 ([[2]]) and the age of a patch report. Add your own items in the empty rows, with an EV-nn ID and a requirement for each tier. |
| 3 | For each supplier, save a copy of this workbook. On the Review Summary sheet, enter the supplier's details and its tier. Column E of the Supplier Checklist then shows what each item requires at that tier. |
| 4 | Request the evidence with the questionnaire set for the tier (the Tiered Supplier Security Questionnaire): every Required item; one Either/or item; each 'If it applies' item whose condition is true (answer Yes or No in column F); and any 'To support an answer' or Sampled item you choose (Yes in column F). Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. (TP-03) |
| 5 | When evidence arrives, set Received (column G) and the date (column H). If the supplier says it does not exist, choose 'Not available'. |
| 6 | Validate each item (TP-04): evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. Answer the four checks in columns I to L with Yes, No or N/A: the scope matches the service we buy; it is in date; it is issued to the legal entity we contract with; and, for a report or test result, the opinion and the exceptions have been read. Use the Evidence Items sheet's 'How to validate it' and 'Red flags'. |
| 7 | Set the Result (column M). Pass only when every check is Yes or N/A and the pass criterion is met. Fail: describe the issue (column N) and propose a severity (column O). N/A: give the reason (column N). Record who validated it and when (columns Q and R). |
| 8 | Evidence not available: follow the item's 'If it is unavailable' column. Either accept an alternative (answer Yes for the alternative item in column F and collect it), or set Fail with a finding. |
| 9 | Clear every Record status (column S) that is not Complete, Finding proposed, Covered by another item, Not applicable or Not requested. The Review Summary's completeness check must say Complete before the review report is written. |
| 10 | Take the proposed findings to the Supplier Security Review Report Template, where the residual risk is scored on the P05 scale and the business owner signs the decision (TP-05, TP-06). Enter each finding in the Supplier Security Risk Register, and put its F-nn reference in column P. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
What the tier columns mean. Required: Always requested from a supplier in this tier. Either/or: The tier's independent assurance: one of the items marked Either/or is enough (a certification with a matching scope, or an independent report; at Tier 2, key policies with evidence they operate also count). If it applies: Required whenever the condition in 'Applies when' is true for this supplier. To support an answer: Requested only when a questionnaire answer depends on it, or the assessor doubts an answer. Sampled: Tier 3: the assessor picks [[2]] of the items marked Sampled to check the supplier's self-declaration, choosing the answers that matter most for this supplier. Not requested: Not asked for at this tier. Accept it if the supplier offers it, but do not chase it (TP-03: no supplier is sent more than its tier's set).
Severity of a finding (TP-08), with its deadline in calendar days from the review: High — a gap that could directly cause a significant incident or data loss at this supplier (90 calendar days); Medium — a gap that weakens a control but has other protection around it (180 calendar days); Low — an improvement; tracked to the next assessment.
The EXAMPLE. The workbook opens with SUP-009, the pallet network used by the example organisation, a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It is Tier 1: its evidence arrived on 2026-09-01, at the start of the Supplier Security Assessment Procedure's validation window, and was reviewed on 2026-09-15. One item failed: the portal user list (EV-09) showed accounts shared by depot staff, which became F-03 (Medium, due 2027-03-14). The supplier was approved with conditions.
To clear the example: on the Supplier Checklist delete the contents of column A and columns F to R (not the rows); on the Review Summary replace every yellow cell. Nothing else needs changing.
Tailoring — small organisation: ask for less, check it properly. For most suppliers the questionnaire answers and a certificate whose scope you have actually read are enough; the value is in the four checks, not in the volume of paper. Keep the full Tier 1 list for the few suppliers that run a critical service.
Tailoring — regulated entity: NIS2 Article 21(3) expects you to take account of each direct supplier's vulnerabilities and cybersecurity practices, so keep the penetration test (EV-06) and secure development (EV-08) items for Tier 1. Under DORA Article 28(1) the financial entity stays fully responsible for services it outsources: for an ICT provider supporting a critical or important function (Tier 1 by override), treat EV-03, EV-06 and EV-14 as Required, record the arrangement in the register of information (Article 28(3)) and keep the validated evidence with it. Under GDPR Article 28(1) you may use only processors that give sufficient guarantees: EV-10 and EV-15 are how you show you checked.
Tailoring — IT run by a service provider: if a managed service provider selects or runs suppliers for you, ask it for the evidence of those suppliers too (EV-15), and check it yourself; the provider's assurance of its own suppliers is not a substitute. The decision and the sign-off stay with your business owner (TP-05).
Evidence Items
16 evidence items in 5 areas. Columns I to L say what each tier asks for; the Supplier Checklist reads them. Add your own items in the empty rows.
| EV ID | Area | Evidence | What to request | How to validate it (TP-04) | Pass criterion | Red flags | If it is unavailable | Tier 1 | Tier 2 | Tier 3 | Tier 4 | Applies when | Questions that ask for it (Tiered Supplier Security Questionnaire) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EV-01 | Assurance | Completed questionnaire for the supplier's tier | The questionnaire set for the tier (Set A to D of the Tiered Supplier Security Questionnaire), every question answered, signed or sent by a named person who is accountable for the answers. | Every question answered; answers are about the service we buy, not the company in general; the sender works for the legal entity we contract with; answers agree with the other evidence received. | Every question answered for the service we buy, by an accountable person at the contracting entity. | Answers copied from a marketing document; 'Yes' to everything with no detail; answers for a different product or a parent company; unanswered questions. | No assessment without it. For a Tier 4 supplier the intake answers are enough. If the supplier refuses, escalate to the business owner: the decision is Reject or Escalate (TP-05). | Required | Required | Required | Required | Every question (the answers themselves) | |
| EV-02 | Assurance | Security certification with its scope statement | The current certificate (for example ISO/IEC 27001) and its scope statement; for a cloud service, the statement of which controls cover it. | Scope names the service, sites and teams we rely on; certificate in date and not suspended; issued to the legal entity we contract with (not only a parent or sister company); issued by a certification body that is itself accredited. | In date, issued to our contracting entity, and its scope covers the service we buy. | Scope limited to a head office or one product; certificate issued to a different company in the group; expired or expiring before contract signature; issuer not accredited. | Accept an independent report (EV-03) instead. At Tier 2, key policies with evidence they operate (EV-05) are also enough. If none of these exists at Tier 1, propose a finding and consider Escalate. | Either/or | Either/or | Sampled | Not requested | GOV-02, GOV-05, GOV-06, PHY-02 | |
| EV-03 | Assurance | Independent assurance report | The latest report by an independent auditor on the controls of the service (for example a service-auditor report on operating effectiveness over a period), with the auditor's opinion, the exceptions found and management's responses. | Covers the service we buy; the period ended recently (otherwise ask for a bridge letter, EV-04); addressed to or about the right legal entity; opinion read (unqualified or qualified) and every exception read; the controls it expects us to operate ourselves noted. | Covers our service, period recent or bridged, opinion and exceptions read, no unresolved exception that affects us. | Qualified opinion; exceptions in access control or change management; a report on the design of controls only, at a single date; our own responsibilities (complementary controls) never passed on to us. | Accept a certification with a matching scope (EV-02) instead. If neither exists at Tier 1, propose a finding and consider Escalate. | Either/or | Either/or | Not requested | Not requested | GOV-02, GOV-06, PHY-03 | |
| EV-04 | Assurance | Bridge letter | A letter signed by the supplier's management saying whether the controls in the EV-03 report have changed, or failed, between the end of its period and today. | Covers the whole gap since the report's period ended; signed by a named manager of the right legal entity; any change it declares is read and followed up. | Covers the gap to today, signed by the contracting entity, changes followed up. | A gap longer than 12 months; a letter that declares no change while the questionnaire describes one; unsigned. | Ask when the next report is due and set a reminder. If the gap is more than 12 months, treat EV-03 as out of date and look for other assurance. | If it applies | If it applies | Not requested | Not requested | An EV-03 report is used and its period ended more than [[3 months]] before the review. | None directly: it completes EV-03 |
| EV-05 | Assurance | Key security policies with evidence they operate | The information security policy and the access control policy, with evidence that they are followed (for example the last access review record or the approval record for the policy). | Approved by the supplier's senior management and reviewed in the last 12 months; the evidence shows the policy working, not only written; issued by the contracting entity or applies to it. | Current, approved, and at least one record shows it operating. | A template with the supplier's name added; no approval or review date; the evidence predates the policy. | At Tier 2, use EV-02 or EV-03 instead. At Tier 3, sample another item. | To support an answer | Either/or | Sampled | Not requested | GOV-03, GOV-05, DAT-02, VUL-05 | |
| EV-06 | Testing | Penetration test summary | The summary of the latest penetration test by an independent tester: date, scope, the tester's organisation, findings by severity and their fix status. | Tested within the last 12 months; scope includes the service or application we use; findings rated High or Critical fixed, or with a dated plan; a retest confirms the fixes. | Within 12 months, our service in scope, serious findings fixed or on a dated plan. | Older than 12 months; a scope that excludes the part we use; a vulnerability scan presented as a penetration test; no fix status. | Propose a finding — High where the service faces the internet or holds our data, because untested weaknesses could directly cause an incident — and ask for the date of the next test. | Required | To support an answer | Not requested | Not requested | DAT-06, VUL-04 | |
| EV-07 | Testing | Vulnerability and patch status report | A recent report from the supplier's vulnerability scanning or patch management: how many systems behind our service are up to date, and the oldest missing security update. | Dated within the last [[3 months]]; covers the systems behind our service; the oldest missing update is within the supplier's stated deadline. | Recent, covers our service, no security update older than the supplier's stated deadline. | Unsupported (end-of-life) systems; critical updates missing for months; a report that covers office laptops only. | Ask for a screenshot or an extract instead. If nothing can be shown, rate the patching answers Partly. | To support an answer | To support an answer | Sampled | Not requested | VUL-01, VUL-02, VUL-03 | |
| EV-08 | Testing | Secure development evidence | For software the supplier writes and we use: its secure development procedure, and the record for a recent release (review, security testing, approval). | The procedure covers security requirements, peer review and security testing before release; the release record shows it was followed; applies to the product we use. | Procedure exists and a recent release record shows it was followed. | No code review; security testing only once a year; open-source components never checked for known vulnerabilities. | Ask for the penetration test summary (EV-06) and rate the development answers on what it shows. | To support an answer | To support an answer | Not requested | Not requested | DEV-01, DEV-02, DEV-03, DEV-04, DEV-05 | |
| EV-09 | Access and data | Access control evidence for people who reach our data or systems | The list of the supplier's accounts that can reach our data or systems (name, role, access level), and the setting or report that shows multi-factor authentication is enforced for them. | Every account belongs to a named person or a listed service account; multi-factor authentication enforced by setting, not by habit; the list is current (leavers removed); it covers support and administrator staff. | Named accounts only, multi-factor authentication enforced, list current. | Shared or generic accounts; support staff excluded from multi-factor authentication; accounts of people who have left. | A supplier that cannot show who reaches our data does not control it: propose a finding, High if the access is privileged or reaches personal data at scale. | If it applies | To support an answer | Sampled | Not requested | The supplier's people or systems can reach our data or systems (tiering criterion TC-3). | ACC-02, ACC-03, ACC-04, ACC-05, ACC-06, ACC-07, ACC-08, DEV-04 |
| EV-10 | Access and data | Data processing terms | The data processing agreement or contract schedule that meets GDPR Article 28(3), and the supplier's security measures annex. | Signed by the legal entity that processes the data; covers documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits; the security annex matches the questionnaire answers. | Signed with the processing entity and covers every Article 28(3) point. | The supplier's standard terms that allow it to change sub-processors without notice; no deletion or return clause; signed by a different group company. | Do not share personal data until the terms are signed. Involve Legal and the Data Protection Officer. | If it applies | If it applies | Not requested | Not requested | The supplier processes personal data on our behalf (GDPR Article 28). A processor is at least Tier 2. | GOV-07, DAT-04, DAT-07, INC-03, SUB-03 |
| EV-11 | Access and data | Data location and hosting statement | Where our data is stored, processed and supported from (countries and hosting providers), including backups. | Names every location, including backups and support; matches the sub-processor list (EV-15) and the contract; any transfer of personal data outside the agreed countries has a legal basis. | All locations named, consistent with EV-15 and the contract. | 'Worldwide' or 'as required'; backups or support in a country the contract does not name; locations that differ from the sub-processor list. | Treat the location as unknown: propose a finding if personal data is involved. | To support an answer | To support an answer | Not requested | Not requested | DAT-03, SUB-05, PHY-01, PHY-02, PHY-03 | |
| EV-12 | Access and data | Data return and deletion procedure | The procedure for returning and deleting customer data at contract end, including backups, and an example (anonymised) deletion certificate. | States the format for return, the time to delete from live systems and from backups, and the written confirmation given; the example certificate shows it has been done before. | Return, deletion from live and backup, and written confirmation all covered. | 'Data is deleted in line with our retention policy' with no time or confirmation; backups excluded. | Propose a finding and add the deletion clause and the exit plan to the contract (TP-11). | If it applies | If it applies | Not requested | Not requested | The supplier holds our data (TP-11: every Tier 1 and Tier 2 contract has an exit plan). | DAT-05, CON-06, PHY-04 |
| EV-13 | Incidents and continuity | Incident contacts and notification commitment | Named incident contacts reachable at all times for a critical service, the contract term that commits the supplier to tell us about incidents affecting us, and a summary of its incident response plan with the date it was last tested. | Contacts named and tested (a test call or email answered); the commitment has a time limit short enough for our own reporting duties; plan tested within 12 months. | Contacts named and tested, notification time stated, plan tested within 12 months. | A general sales inbox as the only contact; notification 'as soon as practicable' with no limit; no plan test. | Add the contacts and the notification clause before signature (TP-07, TP-10). | Required | To support an answer | Sampled | Not requested | INC-01, INC-02, INC-03, INC-04, INC-06 | |
| EV-14 | Incidents and continuity | Continuity and recovery test results | The results of the latest continuity or disaster recovery test for the service we use: date, what was tested, the recovery time and data loss achieved, and what failed. | Tested within the last 12 months; the test covered our service; the recovery time and data loss achieved meet what we need; failures have fixes. | Within 12 months, our service covered, results meet our recovery needs. | A plan with no test; a test of the office, not the service; results worse than the contract promises. | Propose a finding and plan for the service's failure in our own continuity plan (TP-10). | Required | To support an answer | Sampled | Not requested | INC-05, CON-03, CON-04, CON-05, CON-07 | |
| EV-15 | Supply chain and people | Subcontractor and sub-processor list | The companies that handle our data or deliver part of the service, what each does, and where. | Complete (hosting, support, software and any partner that touches our data); locations match EV-11; the supplier checks their security; changes notified to us. | Complete, locations consistent, the supplier checks each one. | A provider we already rely on for other critical services (concentration, TPM-04); unnamed 'partners'; a list that has not changed in years. | For a processor, no sub-processor may be used without our authorisation (GDPR Article 28(2)): hold the processing until the list is given. | If it applies | If it applies | Sampled | Not requested | Other companies handle our data or deliver part of the service, or the supplier processes personal data for us. | CON-07, SUB-01, SUB-02, SUB-03, SUB-04, SUB-05, SUB-06 |
| EV-16 | Supply chain and people | Staff screening and training summary | A summary of the screening done before staff can reach customer data, and security training completion for those staff in the last 12 months. | Screening described for the roles that reach our data; training completion stated for the last 12 months; applies to the staff and subcontractors who deliver our service. | Screening described and training completed within 12 months for the staff who reach our data. | Screening only for permanent staff when contractors deliver the service; no training records. | Accept a statement signed by the supplier's HR lead; rate the people answers Partly if even that is not given. | To support an answer | To support an answer | Sampled | Not requested | PPL-01, PPL-02, PPL-03, PPL-04 |
Supplier Checklist
One supplier's evidence. Column E follows the tier on the Review Summary sheet. Yellow cells are yours. EXAMPLE rows: SUP-009 (Pallet network), reviewed 2026-09-15.
| Row | EV ID | Area | Evidence | Required at this tier | Applies or requested | Received | Date received | Scope matches the service | In date | Right legal entity | Opinion and exceptions read | Result | Issue found, or reason for N/A | Proposed severity | Finding ref | Validated by | Date validated | Record status | Finding no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | EV-01 | Assurance | Completed questionnaire for the supplier's tier | Required | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Set A answered for the pallet network service by its Head of IT. | Information Security Manager | 15 Sep 2026 | Complete | ||||
| EXAMPLE | EV-02 | Assurance | Security certification with its scope statement | Either/or | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Certificate valid to 2027-05; scope covers network operations, the consignment portal and hub IT; issued to the operating company we contract with. | Information Security Manager | 15 Sep 2026 | Complete | ||||
| EXAMPLE | EV-03 | Assurance | Independent assurance report | Either/or | Not available | N/A | No independent report: the certificate (EV-02) is accepted instead. | Information Security Manager | 15 Sep 2026 | Covered by another item | |||||||||
| EXAMPLE | EV-04 | Assurance | Bridge letter | If it applies | No | Not applicable | |||||||||||||
| EV-05 | Assurance | Key security policies with evidence they operate | To support an answer | Not requested | |||||||||||||||
| EXAMPLE | EV-06 | Testing | Penetration test summary | Required | Yes | 1 Sep 2026 | Yes | Yes | Yes | Yes | Pass | Tested 2026-03 by an independent tester: portal and hub network in scope; both Medium findings fixed and retested. | Information Security Manager | 15 Sep 2026 | Complete | ||||
| EXAMPLE | EV-07 | Testing | Vulnerability and patch status report | To support an answer | Yes | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Requested to support the patching answers. Report dated 2026-08; no security update older than 30 days. | Information Security Manager | 15 Sep 2026 | Complete | |||
| EV-08 | Testing | Secure development evidence | To support an answer | Not requested | |||||||||||||||
| EXAMPLE | EV-09 | Access and data | Access control evidence for people who reach our data or systems | If it applies | Yes | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Fail | The portal user list shows accounts named after depots, shared by shift staff: access to our customer addresses cannot be traced to a person or removed when one leaves. The portal enforces multi-factor authentication and limits these accounts to consignment look-up. | Medium | F-03 | Information Security Manager | 15 Sep 2026 | Finding proposed | 1 |
| EXAMPLE | EV-10 | Access and data | Data processing terms | If it applies | Yes | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Data processing agreement is schedule 4 of the contract; covers every Article 28(3) point. | Information Security Manager | 15 Sep 2026 | Complete | |||
| EV-11 | Access and data | Data location and hosting statement | To support an answer | Not requested | |||||||||||||||
| EXAMPLE | EV-12 | Access and data | Data return and deletion procedure | If it applies | Yes | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Deletion from live systems and backups, with a written certificate; an anonymised certificate from another customer was supplied. | Information Security Manager | 15 Sep 2026 | Complete | |||
| EXAMPLE | EV-13 | Incidents and continuity | Incident contacts and notification commitment | Required | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Duty manager line and named security contact, both tested; notification commitment in the contract; plan exercised 2026-02. | Information Security Manager | 15 Sep 2026 | Complete | ||||
| EXAMPLE | EV-14 | Incidents and continuity | Continuity and recovery test results | Required | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Hub failover test 2026-05: consignment tracking restored within the time the contract promises. | Information Security Manager | 15 Sep 2026 | Complete | ||||
| EXAMPLE | EV-15 | Supply chain and people | Subcontractor and sub-processor list | If it applies | Yes | Yes | 1 Sep 2026 | Yes | Yes | Yes | N/A | Pass | Member depots and the portal's hosting provider listed, with what each does. | Information Security Manager | 15 Sep 2026 | Complete | |||
| EV-16 | Supply chain and people | Staff screening and training summary | To support an answer | Not requested |
Review Summary
Review summary and sign-off
The supplier's details drive the checklist. Completeness, the proposed findings and the reassessment date are calculated; the decision and sign-off are yours.
Supplier and review
| Field | Value | Note | ||||
| Supplier reference | SUP-009 | EXAMPLE — replace with your supplier's reference. | ||||
| Supplier name | Pallet network | EXAMPLE. | ||||
| Services it supports | Warehouse dispatch | EXAMPLE. | ||||
| Our data it holds | Customer addresses | EXAMPLE. | ||||
| Its access to us | Portal | EXAMPLE. | ||||
| Tier | Tier 1 | EXAMPLE. From the Supplier Criticality & Tiering Model. Drives column E of the Supplier Checklist. | ||||
| Evidence reviewed on | 15 Sep 2026 | EXAMPLE date (SUP-009's assessment). Replace it with the date of your review: finding deadlines and the reassessment date count from it. | ||||
| Assessor | [[Name, role]] | |||||
| Questionnaire set | Set A — about 60 | Calculated: the Tiered Supplier Security Questionnaire set for this tier (TP-03). | ||||
| Evidence this tier asks for | Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results | Calculated (TIERS). | ||||
| Reassess by | 15 Sep 2027 | Calculated: the tier's maximum interval from the review date (TP-09); sooner on any material change, incident or breach. | ||||
Completeness
| Measure | Count | Independent assurance (Either/or) | ||||
|---|---|---|---|---|---|---|
| Items listed | 16 | Met: at least one Either/or item has passed. | ||||
| Complete (passed) | 9 | Tier 3 sample | ||||
| Finding proposed (failed) | 1 | Not used at this tier. | ||||
| Covered by another item | 1 | Completeness check | ||||
| Not applicable | 1 | Complete, with 1 finding(s) proposed below. | ||||
| Not requested at this tier | 4 | |||||
| Outstanding | 0 | |||||
Proposed findings
| Evidence item | Severity | Evidence | Deadline | Due date | Finding ref | Issue found |
|---|---|---|---|---|---|---|
| EV-09 | Medium | Access control evidence for people who reach our data or systems | 180 calendar days | 14 Mar 2027 | F-03 | The portal user list shows accounts named after depots, shared by shift staff: access to our customer addresses cannot be traced to a person or removed when one leaves. The portal enforces multi-factor authentication and limits these accounts to consignment look-up. |
Deadlines are calendar days from the review date (TP-08). Enter each finding in the Supplier Security Risk Register.
Decision and sign-off
| Field | Value | Note | ||||
| Residual risk (P05 scale) | EXAMPLE: impact 2 × likelihood 2 = 4 (Medium) | Scored in the Supplier Security Review Report Template. Outside appetite: enter it in the P05 risk register (TP-06). | ||||
| Decision | Approve with conditions | EXAMPLE. Approve / Approve with conditions / Escalate / Reject (TP-05). | ||||
| Conditions | EXAMPLE: F-03 fixed by 2027-03-14. | For Approve with conditions: the findings, with their deadlines. | ||||
| Business owner | [[Name, role]] | Signs the decision (TP-05). EXAMPLE: the Head of Logistics. | ||||
| Business owner's signature date | [[YYYY-MM-DD]] | |||||
| Assessor | [[Name, role]] | Confirms the evidence was validated as recorded. | ||||
| Assessor's signature date | [[YYYY-MM-DD]] | |||||
| The decision follows the residual risk and the findings, not the number of items passed. A Tier 1 or Tier 2 supplier also needs its contract clauses (TP-07) and an exit plan (TP-11) before signature. | ||||||
Lists
| Tier | Requirement | YesNo | Received | Check | Result | Severity | SeverityDays | SeverityDeadline | Decision | Area | TierSet | TierMonths | TierEvidence |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Tier 1 | Required | Yes | Yes | Yes | Pass | High | 90 | 90 calendar days | Approve | Assurance | Set A — about 60 | 12 | Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results |
| Tier 2 | Either/or | No | Not available | No | Fail | Medium | 180 | 180 calendar days | Approve with conditions | Testing | Set B — about 35 | 24 | A certification or independent report, or key policies with evidence they operate |
| Tier 3 | If it applies | N/A | N/A | Low | None | Next assessment | Escalate | Access and data | Set C — about 15 | 36 | Self-declaration, with evidence sampled | ||
| Tier 4 | To support an answer | Reject | Incidents and continuity | Set D — about 5 (intake screening only) | None | None beyond the intake answers | |||||||
| Sampled | Supply chain and people |
Not requested
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Evidence item (EV-nn) | A piece of evidence this checklist defines, with how to validate it. The questionnaire's 'Evidence to request' column names these IDs. |
| Required | Always requested from a supplier in this tier. |
| Either/or | The tier's independent assurance: one of the items marked Either/or is enough (a certification with a matching scope, or an independent report; at Tier 2, key policies with evidence they operate also count). |
| If it applies | Required whenever the condition in 'Applies when' is true for this supplier. |
| To support an answer | Requested only when a questionnaire answer depends on it, or the assessor doubts an answer. |
| Sampled | Tier 3: the assessor picks [[2]] of the items marked Sampled to check the supplier's self-declaration, choosing the answers that matter most for this supplier. |
| Not requested | Not asked for at this tier. Accept it if the supplier offers it, but do not chase it (TP-03: no supplier is sent more than its tier's set). |
| Validation (TP-04) | Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. |
| Scope statement | The part of a certificate or report that says which services, sites and teams it covers. Evidence counts only for what is in scope. |
| Legal entity | The company named in the contract. Evidence issued to a parent, sister or subsidiary company may not cover it. |
| Independent assurance report | A report by an independent auditor on how well a supplier's controls worked over a period, with an opinion and a list of exceptions. |
| Opinion | The auditor's overall conclusion in an assurance report: unqualified (controls worked as described) or qualified (they did not, in some respect). |
| Exception | A test in an assurance report where a control did not work as described. |
| Bridge letter | A letter from the supplier's management covering the time between the end of an assurance report's period and today; needed when the gap is more than [[3 months]]. |
| Complementary controls | Controls an assurance report expects the customer to operate for the supplier's controls to work, such as reviewing its own users' access. |
| Accredited certification body | A certification company that a national accreditation body has checked is competent to certify. |
| Record status | Column S of the Supplier Checklist: what each row still needs. Complete, Finding proposed, Covered by another item, Not applicable and Not requested need nothing more. |
| High finding | A gap that could directly cause a significant incident or data loss at this supplier. Deadline: 90 calendar days from the review. |
| Medium finding | A gap that weakens a control but has other protection around it. Deadline: 180 calendar days from the review. |
| Low finding | An improvement; tracked to the next assessment. Deadline: tracked to the next assessment. |
| Finding | A shortfall with an owner and a deadline, recorded in the Supplier Security Risk Register as F-nn (TP-08). |
| Processor, sub-processor | Under GDPR, a company that processes personal data on our behalf; a sub-processor is a company the processor engages to do part of that processing. |
| EXAMPLE | The example organisation's review of SUP-009 (Pallet network) on the Supplier Checklist and the Review Summary. Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | Whole workbook: evidence requested in proportion to the supplier's tier |
| ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Evidence Items (in date, red flags) and the Review Summary's reassessment date |
| NIST CSF 2.0 | GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship” | Supplier Checklist and Review Summary: supplier risks assessed, recorded and responded to |
| NIS2 — Directive (EU) 2022/2555 | Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development | EV-06, EV-07 and EV-08: the supplier's vulnerabilities, practices and secure development |
| DORA — Regulation (EU) 2022/2554 | Article 28(1) — ICT third-party risk managed as part of ICT risk, proportionately; the financial entity remains fully responsible | Tailoring for regulated entities; the financial entity stays responsible for what it outsources |
| GDPR — Regulation (EU) 2016/679 | Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures | EV-10 and EV-15: the processor's sufficient guarantees |
| GDPR — Regulation (EU) 2016/679 | Article 28(2) — no sub-processor without the controller's prior written authorisation | EV-15 |
| GDPR — Regulation (EU) 2016/679 | Article 28(3) — a binding contract with the processor, covering documented instructions, confidentiality, security, sub-processors, assistance, return or deletion of data, and audits | EV-10 |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)