Supplier Security Assessment Procedure
Defines the assessment path for each supplier tier, from intake through evidence review to a documented risk decision.
Available soon
- Format
- Word
- Size
- 63 KB
- Length
- 18 pages
- Version
- 1.0
- Updated
What's inside
- Purpose
- Scope
- Roles
- Triggers and inputs
- Procedure steps
- Decision points
- Timing targets
- Worked example — one Tier 1 supplier
- Outputs and records produced
- Escalation
- Evidence retained
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose
This procedure sets out how [[Organisation Name]] assesses the security of a supplier, from the first intake questions to the end of the contract. It is the working routine behind the Third-Party Security Policy: the policy states the rules (TP-01 to TP-12); this procedure says who does what, in which order, by when, and what record each step leaves. It keeps the effort in proportion: the tier decides how much is asked, what evidence is checked and how often the supplier is looked at again.
It answers three questions for every supplier: how critical is it to us, how well is it protected, on evidence, and what did we decide, and when do we look again.
Scope
This procedure applies to:
- every new supplier, every contract renewal, and every material change to what a supplier does for us (TP-01, TP-09);
- existing suppliers that have never been tiered or assessed, taken in order of likely criticality;
- everyone with a role in the table below.
It does not cover how a supplier risk outside appetite is treated once it is in the Information Security Risk Register (the Information Security Risk Management pack), how an exception to the policy is approved (the Security Exception & Waiver Standard), or how an incident at a supplier is handled (your incident response plan). It hands over to each of them at the step named.
Roles
Role | What they do in this procedure |
|---|---|
Business owner [[the manager who buys and relies on the service]] | Raises the intake; answers for the service's need; agrees findings with the supplier; signs the decision (TP-05); keeps the exit plan current. |
Procurement [[e.g. Procurement Manager]] | Makes sure nothing is ordered, signed or renewed without a tier (TP-01); issues the questionnaire with the tender where there is one; tells the assessor of renewals and changes. |
Assessor [[e.g. Information Security Manager]] | Tiers the supplier; sends the questionnaire and evidence request; validates evidence; records findings and residual risk; writes the review report; keeps the register. |
Head of Information Security [[e.g. Head of Information Security or CISO]] | Settles disputed tiers and ratings; checks Tier 1 assessments before the decision; escalates High findings past deadline; prepares the quarterly report. |
Legal [[in-house or external counsel]] | Puts the clauses for the tier and data type into the contract, and records any clause the supplier refuses (TP-07). |
Data Protection Officer [[where one is appointed]] | Advises on processors: the questions, the evidence and the processor terms. |
Executive management [[e.g. Executive Committee]] | Receives the quarterly report (TP-12); decides on escalated supplier risks and on rejecting or exiting a Tier 1 supplier. |
Guidance — delete before approval
In a small organisation the assessor and the Head of Information Security may be one person. That is acceptable, but that person does not also sign as business owner: the decision belongs to the manager who relies on the service (TP-05).
Triggers and inputs
When this procedure runs
Event | What starts | Steps |
|---|---|---|
A new supplier, a renewal, or a new service from an existing supplier | Intake, tiering and the assessment for the tier | 1 to 20 |
An existing supplier that has never been tiered | The same, in order of likely criticality | 1 to 20 |
A supplier reaches its tier's reassessment interval (TP-09) | Reassessment | 22, then 6 to 20 |
A material change, incident or breach at a supplier (TP-09) | Triggered reassessment | 23, then 3 to 20 |
A finding passes its deadline (TP-08) | Escalation | 21 |
A contract ends, or the decision is Reject | Exit | 24 to 25 |
The end of each quarter (TP-12) | The quarterly report | 26 |
Inputs
Input | Where it comes from | Used at |
|---|---|---|
Intake answers: service, data, access, substitutability, and the override questions | Business owner, on the intake form in the Supplier Criticality & Tiering Model | Steps 1 to 3 |
Criteria, overrides, sets and intervals | Supplier Criticality & Tiering Model | Steps 3, 6, 8, 19, 22 |
Questionnaire set for the tier | Tiered Supplier Security Questionnaire | Step 6 |
Evidence list and validation checks | Supplier Due Diligence Evidence Checklist | Steps 8, 9 |
The scale, bands and appetite for third-party risk | Risk Assessment Methodology & Scoring Model; Cyber Risk Appetite Statement Template | Steps 13, 14 |
Clauses for the tier and data type | Supplier Contract Security Clause Library | Step 17 |
The register | Supplier Security Risk Register | Steps 4, 19, 21, 22, 25 |
Procedure steps
Every step names who does it and when. "Working days" are Monday to Friday excluding [[public holidays]]; "calendar days" include every day. The targets for each tier are in Timing targets, below.
Stage 1 — Intake
Step | What happens | Who | When | Output |
|---|---|---|---|---|
1 | Complete the intake: what the service is and which of our services it supports, what data the supplier will hold or see, what access it will have, how easily it could be replaced, and the override questions (is it an ICT service supporting a critical or important function; will it process personal data for us?). | Business owner | Before any order, signature or renewal: see Timing targets | Intake record |
2 | Check that an intake and a tier exist before any order, contract or renewal is signed. If not, stop the purchase and send the business owner to step 1 (TP-01). | Procurement | At every purchase request and renewal | Purchase released or held |
Stage 2 — Tier
Step | What happens | Who | When | Output |
|---|---|---|---|---|
3 | Score each criterion in the Supplier Criticality & Tiering Model (TC-1 service, TC-2 data, TC-3 access, TC-4 substitutability). The tier is the highest any criterion reaches, and never below an override's minimum (TP-02). Record the score and reason for each criterion. | Assessor | Within [[5]] working days of a complete intake | Tier, with reasons |
4 | Enter the supplier in the Supplier Security Risk Register with its tier. For a Tier 4 supplier, stop here: no questionnaire or evidence; screen again only if the service changes. | Assessor | With step 3 | Register entry |
5 | If the business owner disputes the tier, the Head of Information Security decides. A tier may be raised on judgement; it may never be set below what a criterion or override gives. | Head of Information Security | Within [[5]] working days of the dispute | Tier confirmed |
The overrides, which set a minimum tier whatever the criteria say:
When | Minimum tier |
|---|---|
An ICT service supporting a critical or important function of a DORA financial entity | Tier 1 |
A processor of personal data under GDPR Article 28 | Tier 2 |
Stage 3 — Questionnaire
Step | What happens | Who | When | Output |
|---|---|---|---|---|
6 | Send the questionnaire set for the tier from the Tiered Supplier Security Questionnaire, with a response deadline (TP-03). Never send a set above the tier: a longer questionnaire does not buy more assurance, and it slows every assessment. | Assessor | Within [[2]] working days of step 3 | Questionnaire sent |
7 | Remind the supplier before the deadline. If there is no answer by the deadline, tell the business owner (see Escalation). | Assessor | [[5]] working days before the deadline | Reminder |
Stage 4 — Evidence
Step | What happens | Who | When | Output |
|---|---|---|---|---|
8 | Ask for the evidence the tier requires, using the Supplier Due Diligence Evidence Checklist. Send it with the questionnaire (step 6), so both arrive together. | Assessor | With step 6 | Evidence request |
9 | Validate each item, not just receive it (TP-04): does its scope cover the service we buy, from the sites and systems that deliver it; are its dates current (certificate valid, report period and test within [[12]] months); is it in the name of the company we contract with? Evidence that fails a check counts as not received. For Tier 3, check a sample of [[3]] answers against evidence. | Assessor | See Timing targets | Completed evidence checklist |
10 | Where the supplier uses its own suppliers to deliver the service to us (cloud hosting, a data centre, a software component), ask how it assesses them, and check the evidence covers the part they deliver. | Assessor | With step 9 | Supply chain notes |
Stage 5 — Findings
Step | What happens | Who | When | Output |
|---|---|---|---|---|
11 | Record each gap as a finding (F-nn): what is missing, its severity, and its remediation deadline, counted from the date of the review report (TP-08). A finding has an owner at the supplier and is owned for us by the business owner. | Assessor | With step 15 | Findings, with deadlines |
12 | Agree each finding and its deadline with the supplier. While a High finding is open, the decision cannot be a plain Approve (step 16). | Business owner; Assessor | Before step 16 | Agreed findings |
Severity and deadline, the same for every tier:
Severity | Meaning | Remediation deadline |
|---|---|---|
High | A gap that could directly cause a significant incident or data loss at this supplier | 90 calendar days from the review report |
Medium | A gap that weakens a control but has other protection around it | 180 calendar days from the review report |
Low | An improvement; tracked to the next assessment | Tracked to the next assessment |
Stage 6 — Residual risk
Step | What happens | Who | When | Output |
|---|---|---|---|---|
13 | Rate the residual risk the supplier leaves us, with its validated controls and our own around it, on the Risk Assessment Methodology & Scoring Model scale: impact and likelihood each 1 to 4, score = impact × likelihood, band from the score (TP-06). Write one sentence of reason for each rating. | Assessor | With step 15 | Residual rating, score and band |
14 | Compare the band with the appetite for third-party risk in your Cyber Risk Appetite Statement Template, giving the position: within appetite, outside appetite, or outside tolerance. | Assessor | With step 13 | Position |
The bands of the Information Security Risk Management scale:
Band | Scores |
|---|---|
Low | 1–3 |
Medium | 4–6 |
High | 8–9 |
Critical | 12–16 |
Stage 7 — Decision
Step | What happens | Who | When | Output |
|---|---|---|---|---|
15 | Write the Supplier Security Review Report Template: tier, questionnaire and evidence, findings, residual rating and position, and a recommended decision. For Tier 1, the Head of Information Security checks it before it goes to the business owner. | Assessor; Head of Information Security for Tier 1 | See Timing targets | Review report |
16 | Decide, using the table below, and sign the report (TP-05). Conditions name the findings and their deadlines. | Business owner | See Timing targets | Signed decision |
Which decision:
Decision | When | What follows |
|---|---|---|
Approve | Residual risk within appetite; no High finding open. | Step 17 |
Approve with conditions | Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. | Step 17; the conditions go into the contract or the register, with their deadlines |
Escalate | Residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06). | Entered in the Information Security Risk Register (TP-06). Its owner decides treatment within [[30]] calendar days (RM-06); only then does the purchase go ahead or stop |
Reject | Do not contract, or plan exit (TP-11). | Do not contract; for an existing supplier, run the exit plan (step 24) |
Guidance — delete before approval
A decision the business owner signs, against a report the assessor wrote, is what an auditor looks for first. The security team recommends; the business owner decides, because the business owner relies on the service and owns the risk.
Stage 8 — Contract
Step | What happens | Who | When | Output |
|---|---|---|---|---|
17 | Put the clauses for the tier and data type from the Supplier Contract Security Clause Library into the contract before signature (TP-07), with any conditions from step 16. For a supplier that processes personal data, include the processor terms; for an ICT service supporting a critical or important function, the contract content DORA requires. Record any clause the supplier refuses as an exception under the Security Exception & Waiver Standard. | Legal; Procurement | Before signature | Signed contract with clauses |
18 | For Tier 1 and Tier 2: agree the exit plan — data return or deletion, access removal, transition period (TP-11). For Tier 1: add the supplier's named contacts and notification duties to the incident response and continuity plans (TP-10). | Business owner; Head of Information Security | Before the service starts | Exit plan; updated plans |
Stage 9 — Register
Step | What happens | Who | When | Output |
|---|---|---|---|---|
19 | Update the Supplier Security Risk Register: tier, decision and date, residual score, band and position, findings with deadlines, exit plan reference, and the next reassessment date — the assessment date plus the tier's interval. | Assessor | Within [[2]] working days of step 16 | Register entry |
Stage 10 — Monitor and reassess
Step | What happens | Who | When | Output |
|---|---|---|---|---|
20 | Monitor the supplier as its tier requires (Timing targets, monitoring row). | Assessor | Continuously, or as the tier sets | Monitoring notes |
21 | Track findings to their deadlines. When a High finding passes its deadline, tell the business owner in writing (TP-08); the Head of Information Security raises it in the quarterly report. A Medium finding past its deadline is chased and shown in the register. | Assessor; Head of Information Security | High: within [[2]] working days of the deadline | Escalation record |
22 | Start the reassessment before it is due, at stage 3, with the same tier unless the intake answers have changed (TP-09). | Assessor | [[60]] calendar days before the due date | Reassessment started |
23 | On a material change, an incident or a breach at the supplier, start a reassessment at stage 2: the tier may change. An incident is also handled under your incident response plan (TP-10). | Assessor | Within [[10]] working days of learning of it | Triggered reassessment |
Stage 11 — Exit
Step | What happens | Who | When | Output |
|---|---|---|---|---|
24 | Run the exit plan (TP-11): move the service, remove every account and connection the supplier had, have the supplier return or delete our live data and then its backup copies, and get written confirmation once deletion is complete. | Business owner; Assessor | Live data within [[30]] calendar days and backups within [[90]] calendar days of the service ending; confirmation within [[10]] working days of deletion being complete | Exit record |
25 | Close the register entry with the exit date. Keep it; never delete it. | Assessor | With step 24 | Register history |
Stage 12 — Report
Step | What happens | Who | When | Output |
|---|---|---|---|---|
26 | Report TPM-01 (Tier 1 suppliers assessed), TPM-02 (Reassessments overdue), TPM-03 (High findings past deadline), TPM-04 (Concentration) to executive management using the Third-Party Risk Dashboard (TP-12). TPM-01 is also the board measure "critical suppliers assessed" in the Board Cybersecurity Reporting pack. | Head of Information Security | Within [[10]] working days of quarter end | Quarterly report |
Decision points
Decision | Who decides | Rule | Recorded in |
|---|---|---|---|
Can we order or sign? | Procurement | Only with an intake and a tier (TP-01) | Purchase record |
Which tier? | Assessor; Head of Information Security if disputed | Highest criterion; never below an override (TP-02) | Supplier Security Risk Register |
Which questionnaire and evidence? | The tier, not a person | The tier's set and evidence (TP-03) | Tiered Supplier Security Questionnaire |
Does the evidence count? | Assessor | Scope, dates and name checked (TP-04) | Supplier Due Diligence Evidence Checklist |
How severe is a gap, and by when is it fixed? | Assessor | Severity and deadline table (TP-08) | Supplier Security Review Report Template |
Is the residual risk within appetite? | The rules, not a person | Band against the appetite for third-party risk (TP-06) | Supplier Security Review Report Template |
Approve, conditions, escalate or reject? | Business owner | Decision table (TP-05) | Supplier Security Review Report Template |
Is it outside appetite? | The risk's owner, in the risk register | Treatment within [[30]] calendar days (RM-06) | Information Security Risk Register |
Timing targets
By tier. Working-day targets shown as placeholders are this template's defaults; change them to fit your purchasing cycle. The intake lead time covers the steps after it with no slack for a late supplier, so start earlier where you can.
Activity | Tier 1 | Tier 2 | Tier 3 | Tier 4 |
|---|---|---|---|---|
Intake completed before planned signature, at least | [[50]] working days | [[45]] working days | [[25]] working days | [[5]] working days |
Tier recorded, from a complete intake | [[5]] working days | [[5]] working days | [[5]] working days | [[5]] working days |
Questionnaire set | Set A: about 60 questions | Set B: about 35 questions | Set C: about 15 questions | Set D: about 5 questions (intake screening only) |
Supplier's time to answer and send evidence | [[20]] working days | [[15]] working days | [[10]] working days | — |
Evidence | Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results | A certification or independent report, or key policies with evidence they operate | Self-declaration, with evidence sampled | None beyond the intake answers |
Evidence validated, from receipt | [[10]] working days | [[10]] working days | [[5]] working days | — |
Review report and signed decision, from validation | [[10]] working days | [[10]] working days | [[5]] working days | At tiering |
Reassessment | At least every 12 months | At least every 24 months | At least every 36 months | Only when the service changes |
Monitoring between assessments | Continuous: breach news, certificate and report expiry, material changes | Certificate expiry and material changes | At renewal | Only when the service changes |
Activity | Target | Basis |
|---|---|---|
High finding fixed | 90 calendar days from the review report | TP-08 |
Medium finding fixed | 180 calendar days from the review report | TP-08 |
Low finding fixed | Tracked to the next assessment | TP-08 |
Business owner told of a High finding past deadline | Within [[2]] working days | TP-08 |
Reassessment started | [[60]] calendar days before it is due | TP-09 |
Triggered reassessment started | Within [[10]] working days of learning of the trigger | TP-09 |
Treatment decision for an escalated supplier risk | Within [[30]] calendar days of the risk first being assessed outside appetite | RM-06, Information Security Risk Management pack |
Live data returned or deleted at exit | Within [[30]] calendar days of the service ending | TP-11 |
Backup copies deleted at exit | Within [[90]] calendar days of the service ending | TP-11 |
Written confirmation of deletion | Within [[10]] working days of the deletion being complete | TP-11 |
Quarterly report | Within [[10]] working days of quarter end | TP-12 |
TPM-01 Tier 1 suppliers assessed | All Tier 1 by [[year end]] | TP-12 |
TPM-02 Reassessments overdue | Zero Tier 1; none more than 90 days overdue | TP-12 |
TPM-03 High findings past deadline | Zero | TP-12 |
TPM-04 Concentration | Each one known, with an exit plan (TP-11) | TP-12 |
Guidance — delete before approval
Tiers, sets, evidence, intervals and monitoring come from the Supplier Criticality & Tiering Model; the severities and deadlines are the pack's own, used unchanged in the Supplier Security Review Report Template. Change them there, not here. The working-day targets are this procedure's own.
Worked example — one Tier 1 supplier
EXAMPLE, not part of the procedure. The organisation is the one used throughout the pack: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It has 14 Tier 1, 22 Tier 2, 31 Tier 3, 45 Tier 4 suppliers. SUP-009, the pallet network, is one of its 14 Tier 1 suppliers and one of the 3 logistics suppliers (SUP-007, SUP-008, SUP-009) assessed in Q3 2026. It is an existing supplier, tiered when the organisation screened its whole supplier base. Replace every date and figure with your own.
Step | What happened | Result |
|---|---|---|
1 to 4 — Intake and tier | Service: Warehouse dispatch. Data: customer addresses. Access: through the supplier's portal. TC-1 service: Tier 1 (it carries pallet deliveries for Warehouse dispatch, one of the organisation's critical services). TC-2 data: Tier 1 (customer names and delivery addresses are customer data). TC-3 access: Tier 4 (no access). TC-4 substitutability: Tier 2 (could be replaced within [[3 months]] with effort). The tier is the highest any criterion reaches (TP-02): Tier 1, from TC-1 and TC-2. (EXAMPLE) | Tier 1 (Critical) |
6 to 10 — Questionnaire and evidence | Set A (about 60 questions) sent with the Tier 1 evidence request: independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results. Each item validated for scope, dates and the name of the company contracted with (TP-04). (EXAMPLE) | Evidence checklist complete |
11, 12 — Findings (review report 15 Sept 2026) | F-03: shared portal accounts used by depot staff. Severity Medium: a gap that weakens a control but has other protection around it. Deadline 180 calendar days from the review report. Agreed with the supplier. (EXAMPLE) | F-03 due 14 Mar 2027 |
13, 14 — Residual risk | Impact 2 Moderate: if the pallet network failed or were compromised, pallet deliveries would stop or be delayed and customer delivery addresses held in its portal could be exposed; the two parcel carriers (SUP-007, SUP-008) keep parcels moving. Likelihood 2 Possible: the Tier 1 evidence was received and validated and showed no other gap; but depot staff share portal accounts (F-03), so a misused account could not be traced to a person or removed when one of them leaves. 2 × 2 = 4. The example's appetite for third-party risk is Cautious (Information Security Risk Management pack). (EXAMPLE) | Medium, within appetite |
15, 16 — Decision (15 Sept 2026) | Within appetite and no High finding open, so Approve was allowed; the assessor recommended Approve with conditions so that the Medium finding F-03 becomes a condition with its deadline. The Head of Logistics, as business owner, signs Approve with conditions: proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. The condition is F-03 by 14 Mar 2027. (EXAMPLE) | Approve with conditions |
17, 18 — Contract | The existing contract is checked against the Tier 1 clauses for customer data in the Supplier Contract Security Clause Library; [[any missing clause is added at the next variation or renewal, or recorded as an exception]]. The condition is recorded in the register. As a Tier 1 supplier it needs an exit plan (TP-11) and named contacts in the incident response and continuity plans (TP-10). (EXAMPLE) | Clauses checked; exit plan and contacts confirmed |
19 — Register | Tier, decision, residual 4 Medium, F-03 and its deadline recorded. Next reassessment due 15 Sept 2027 (12 months after 15 Sept 2026); it starts on 17 Jul 2027, [[60]] calendar days before. (EXAMPLE) | Register entry |
20 to 23 — Monitoring | Continuous: breach news, certificate and report expiry, material changes. If depot account sharing led to a breach at the supplier, that would trigger a reassessment at stage 2 (TP-09). SUP-009 supports one critical service, so it is not one of the 6 providers counted in TPM-04. (EXAMPLE) | F-03 tracked to 14 Mar 2027 |
26 — Report (as at 30 Sept 2026) | TPM-01: 9 of 14 Tier 1 suppliers assessed in the last 12 months, including SUP-009. F-03 is open but not past its deadline, so it is not counted in TPM-03. (EXAMPLE) | 9 of 14 |
Had the residual score been High, the decision would have been Escalate: an entry in the Information Security Risk Register, and a treatment decision by its owner within [[30]] calendar days (RM-06), before the contract went ahead.
Outputs and records produced
Output | Produced at step | Held in | Maintained by |
|---|---|---|---|
Intake record and tier, with reasons | 1, 3 | Supplier Security Risk Register | Assessor |
Questionnaire answers | 6 | Tiered Supplier Security Questionnaire; [[evidence location]] | Assessor |
Evidence and validation checks | 8 to 10 | Supplier Due Diligence Evidence Checklist; [[evidence location]] | Assessor |
Findings, residual rating, decision | 11 to 16 | Supplier Security Review Report Template | Assessor; Business owner signs |
Contract with clauses; refused clauses as exceptions | 17 | [[Contract repository]]; Security Exception Register | Legal; Procurement |
Exit plan; supplier contacts in plans | 18 | [[Contract file]]; incident response and continuity plans | Business owner; Head of Information Security |
Register entry and history | 4, 19, 21, 25 | Supplier Security Risk Register | Assessor |
Quarterly report | 26 | Third-Party Risk Dashboard | Head of Information Security |
Escalation
When | Escalated to | By | Basis |
|---|---|---|---|
Order or contract signed without an intake and tier | Executive management | Head of Information Security | TP-01 |
Supplier does not answer or send evidence by the deadline | Business owner; then Head of Information Security | Assessor | TP-03, TP-04 |
Tier or ratings disputed | Head of Information Security | Assessor | TP-02 |
Residual risk outside appetite | Risk owner, through the Information Security Risk Register | Assessor | TP-06; RM-06 |
High finding past its deadline | Business owner; then executive management in the quarterly report | Assessor; Head of Information Security | TP-08 |
Reassessment overdue | Business owner; named in the quarterly report (TPM-02) | Assessor | TP-09 |
Supplier refuses a required clause | Security Exception & Waiver Standard (an exception request) | Legal | TP-07 |
Rejecting or exiting a Tier 1 supplier | Executive management | Business owner | TP-11 |
EXAMPLE: as at 30 Sept 2026, finding F-01 at SUP-004, the ERP software provider (hosted) — "support staff reach our ERP without multi-factor authentication" — is High and was due on 20 Jul 2026. It is open 72 calendar days past its deadline, so the business owner has been told and it is counted in TPM-03.
Evidence retained
Evidence | Shows | Minimum retention |
|---|---|---|
Intake and tier, with reasons | Every supplier screened and tiered before signature (TP-01, TP-02) | [[Life of the contract plus 3 years]] |
Questionnaire answers and validated evidence | The tier's set and evidence, checked (TP-03, TP-04) | [[Until the next assessment plus 3 years]] |
Review reports with signed decisions | Every assessment decided by the business owner (TP-05, TP-06) | [[Life of the contract plus 3 years]] |
Findings and their closure | Deadlines met or escalated (TP-08) | [[3 years after closure]] |
Signed contracts and exit plans | Clauses and exit in place (TP-07, TP-11) | [[As your contract retention policy sets]] |
Exit records and deletion confirmations | Data returned or deleted, access removed (TP-11) | [[6 years]] |
Quarterly reports | Reporting (TP-12) | [[5 years]] |
Guidance — delete before approval
An auditor typically picks a few suppliers — at least one Tier 1 and one recent contract — and asks for the intake, the tier with reasons, the questionnaire, the validated evidence, the signed decision, the contract clauses and the next reassessment date. Test this yourself each quarter on two suppliers.
Related documents
Document | Relationship |
|---|---|
Third-Party Security Policy | The rules this procedure runs (TP-01 to TP-12) |
Supplier Criticality & Tiering Model | Criteria, overrides, sets, evidence, intervals and monitoring (steps 3, 6, 8, 20, 22) |
Tiered Supplier Security Questionnaire | The questionnaire set for each tier (step 6) |
Supplier Due Diligence Evidence Checklist | What evidence to ask for, and how to validate it (steps 8, 9) |
Supplier Contract Security Clause Library | The clauses for each tier and data type (step 17) |
Supplier Security Risk Register | Where every supplier is recorded (steps 4, 19, 25) |
Supplier Security Review Report Template | The record of one assessment and its decision (steps 11 to 16) |
Third-Party Risk Dashboard | The quarterly report (step 26) |
Risk Assessment Methodology & Scoring Model; Cyber Risk Appetite Statement Template; Information Security Risk Register | The scale, the appetite, and where an escalated supplier risk goes (steps 13, 14, 16); Information Security Risk Management pack |
Security Exception & Waiver Standard | The route for a refused clause or any other exception (step 17); Security Exception, Waiver & Segregation of Duties pack |
Adapting this template
Guidance — delete before approval
Small organisation: a spreadsheet register and a shared mailbox are enough. Tier your existing suppliers first and assess the Tier 1 ones in order of criticality; Tier 3 and Tier 4 take minutes. Keep the signed decision, the evidence checks and the reassessment dates: they are what an auditor tests. Where the assessor and the Head of Information Security are one person, have [[an external adviser]] check Tier 1 reports before the decision.
Regulated entity (NIS2, DORA, GDPR): NIS2 Article 21(3) expects you to take account of each direct supplier's vulnerabilities and the overall quality of its products and security practices, including secure development: steps 9 and 10 do this; add secure development questions to the set for software suppliers. A DORA financial entity manages ICT third-party risk proportionately and remains fully responsible (Article 28(1)): the tiers are that proportionality, and the override makes every ICT service supporting a critical or important function Tier 1. It must also keep the register of information on all ICT contracts (Article 28(3)), assess concentration (Article 29) and include the Article 30 contract content (step 17). Under the GDPR, use only processors that give sufficient guarantees (Article 28(1)): the processor override sets them at Tier 2 or above, and the DPO advises on their assessment.
IT run by a service provider: your managed IT provider is usually Tier 1, and often the first supplier to assess. It may help collect evidence for other suppliers, but the tier, the evidence checks and the decision stay with your organisation. Ask it how it assesses the suppliers it uses to serve you (step 10).
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR).
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | Whole procedure: supplier risk assessed and decided before and during the relationship |
ISO/IEC 27001:2022 | Annex A 5.21 — Managing information security in the ICT supply chain | Step 10: the supplier's own suppliers that deliver our service |
ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Stage 10: monitoring, findings and reassessment on interval and change |
NIST CSF 2.0 | GV.SC-06 — “Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships” | Stages 1 to 7: due diligence before the contract |
NIST CSF 2.0 | GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship” | Stages 5, 6 and 10: supplier risk recorded, assessed, responded to and monitored |
NIS2 — Directive (EU) 2022/2555 | Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development | Steps 9 and 10; regulated-entity tailoring |
DORA — Regulation (EU) 2022/2554 | Article 28(1) — ICT third-party risk managed as part of ICT risk, proportionately; the financial entity remains fully responsible | Tier-based effort; regulated-entity tailoring |
GDPR — Regulation (EU) 2016/679 | Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures | Stages 3 and 4 for processors; the GDPR override |
Definitions
Term | Meaning in this procedure |
|---|---|
Business owner | The manager who buys and relies on a supplier's service; signs the decision (TP-05). |
Calendar day | Every day, including weekends and public holidays. |
Finding | A gap found in an assessment, with a severity and a remediation deadline (TP-08). |
Intake | The short set of questions about a supplier's service, data, access and substitutability that sets its tier. |
Material change | A change in what the supplier does for us, the data or access it has, its ownership, location or subcontractors that could change its tier or risk. |
Override | A condition that sets a minimum tier whatever the criteria say. |
Position | Where a residual band sits against the appetite for third-party risk: within appetite, outside appetite, or outside tolerance. |
Residual risk | The risk a supplier leaves us with its validated controls and ours in place, scored on the Risk Assessment Methodology & Scoring Model scale. |
Review report | The Supplier Security Review Report Template: the record of one assessment and its signed decision. |
Tier | One of Tier 1 (Critical), Tier 2 (Important), Tier 3 (Standard), Tier 4 (Minimal), set by the Supplier Criticality & Tiering Model. |
Validation | Checking that a piece of evidence covers the service we buy, is current and is in the contracting company's name (TP-04). |
Working day | Monday to Friday, excluding [[public holidays where you are]]. |