Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Supplier Security Assessment Procedure

Defines the assessment path for each supplier tier, from intake through evidence review to a documented risk decision.

Available soon

Format
Word
Size
63 KB
Length
18 pages
Version
1.0
Updated

What's inside

  • Purpose
  • Scope
  • Roles
  • Triggers and inputs
  • Procedure steps
  • Decision points
  • Timing targets
  • Worked example — one Tier 1 supplier
  • Outputs and records produced
  • Escalation
  • Evidence retained
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose

This procedure sets out how [[Organisation Name]] assesses the security of a supplier, from the first intake questions to the end of the contract. It is the working routine behind the Third-Party Security Policy: the policy states the rules (TP-01 to TP-12); this procedure says who does what, in which order, by when, and what record each step leaves. It keeps the effort in proportion: the tier decides how much is asked, what evidence is checked and how often the supplier is looked at again.

It answers three questions for every supplier: how critical is it to us, how well is it protected, on evidence, and what did we decide, and when do we look again.

Scope

This procedure applies to:

  • every new supplier, every contract renewal, and every material change to what a supplier does for us (TP-01, TP-09);
  • existing suppliers that have never been tiered or assessed, taken in order of likely criticality;
  • everyone with a role in the table below.

It does not cover how a supplier risk outside appetite is treated once it is in the Information Security Risk Register (the Information Security Risk Management pack), how an exception to the policy is approved (the Security Exception & Waiver Standard), or how an incident at a supplier is handled (your incident response plan). It hands over to each of them at the step named.

Roles

Role

What they do in this procedure

Business owner

[[the manager who buys and relies on the service]]

Raises the intake; answers for the service's need; agrees findings with the supplier; signs the decision (TP-05); keeps the exit plan current.

Procurement

[[e.g. Procurement Manager]]

Makes sure nothing is ordered, signed or renewed without a tier (TP-01); issues the questionnaire with the tender where there is one; tells the assessor of renewals and changes.

Assessor

[[e.g. Information Security Manager]]

Tiers the supplier; sends the questionnaire and evidence request; validates evidence; records findings and residual risk; writes the review report; keeps the register.

Head of Information Security

[[e.g. Head of Information Security or CISO]]

Settles disputed tiers and ratings; checks Tier 1 assessments before the decision; escalates High findings past deadline; prepares the quarterly report.

Legal

[[in-house or external counsel]]

Puts the clauses for the tier and data type into the contract, and records any clause the supplier refuses (TP-07).

Data Protection Officer

[[where one is appointed]]

Advises on processors: the questions, the evidence and the processor terms.

Executive management

[[e.g. Executive Committee]]

Receives the quarterly report (TP-12); decides on escalated supplier risks and on rejecting or exiting a Tier 1 supplier.

Guidance — delete before approval

In a small organisation the assessor and the Head of Information Security may be one person. That is acceptable, but that person does not also sign as business owner: the decision belongs to the manager who relies on the service (TP-05).

Triggers and inputs

When this procedure runs

Event

What starts

Steps

A new supplier, a renewal, or a new service from an existing supplier

Intake, tiering and the assessment for the tier

1 to 20

An existing supplier that has never been tiered

The same, in order of likely criticality

1 to 20

A supplier reaches its tier's reassessment interval (TP-09)

Reassessment

22, then 6 to 20

A material change, incident or breach at a supplier (TP-09)

Triggered reassessment

23, then 3 to 20

A finding passes its deadline (TP-08)

Escalation

21

A contract ends, or the decision is Reject

Exit

24 to 25

The end of each quarter (TP-12)

The quarterly report

26

Inputs

Input

Where it comes from

Used at

Intake answers: service, data, access, substitutability, and the override questions

Business owner, on the intake form in the Supplier Criticality & Tiering Model

Steps 1 to 3

Criteria, overrides, sets and intervals

Supplier Criticality & Tiering Model

Steps 3, 6, 8, 19, 22

Questionnaire set for the tier

Tiered Supplier Security Questionnaire

Step 6

Evidence list and validation checks

Supplier Due Diligence Evidence Checklist

Steps 8, 9

The scale, bands and appetite for third-party risk

Risk Assessment Methodology & Scoring Model; Cyber Risk Appetite Statement Template

Steps 13, 14

Clauses for the tier and data type

Supplier Contract Security Clause Library

Step 17

The register

Supplier Security Risk Register

Steps 4, 19, 21, 22, 25

Procedure steps

Every step names who does it and when. "Working days" are Monday to Friday excluding [[public holidays]]; "calendar days" include every day. The targets for each tier are in Timing targets, below.

Stage 1 — Intake

Step

What happens

Who

When

Output

1

Complete the intake: what the service is and which of our services it supports, what data the supplier will hold or see, what access it will have, how easily it could be replaced, and the override questions (is it an ICT service supporting a critical or important function; will it process personal data for us?).

Business owner

Before any order, signature or renewal: see Timing targets

Intake record

2

Check that an intake and a tier exist before any order, contract or renewal is signed. If not, stop the purchase and send the business owner to step 1 (TP-01).

Procurement

At every purchase request and renewal

Purchase released or held

Stage 2 — Tier

Step

What happens

Who

When

Output

3

Score each criterion in the Supplier Criticality & Tiering Model (TC-1 service, TC-2 data, TC-3 access, TC-4 substitutability). The tier is the highest any criterion reaches, and never below an override's minimum (TP-02). Record the score and reason for each criterion.

Assessor

Within [[5]] working days of a complete intake

Tier, with reasons

4

Enter the supplier in the Supplier Security Risk Register with its tier. For a Tier 4 supplier, stop here: no questionnaire or evidence; screen again only if the service changes.

Assessor

With step 3

Register entry

5

If the business owner disputes the tier, the Head of Information Security decides. A tier may be raised on judgement; it may never be set below what a criterion or override gives.

Head of Information Security

Within [[5]] working days of the dispute

Tier confirmed

The overrides, which set a minimum tier whatever the criteria say:

When

Minimum tier

An ICT service supporting a critical or important function of a DORA financial entity

Tier 1

A processor of personal data under GDPR Article 28

Tier 2

Stage 3 — Questionnaire

Step

What happens

Who

When

Output

6

Send the questionnaire set for the tier from the Tiered Supplier Security Questionnaire, with a response deadline (TP-03). Never send a set above the tier: a longer questionnaire does not buy more assurance, and it slows every assessment.

Assessor

Within [[2]] working days of step 3

Questionnaire sent

7

Remind the supplier before the deadline. If there is no answer by the deadline, tell the business owner (see Escalation).

Assessor

[[5]] working days before the deadline

Reminder

Stage 4 — Evidence

Step

What happens

Who

When

Output

8

Ask for the evidence the tier requires, using the Supplier Due Diligence Evidence Checklist. Send it with the questionnaire (step 6), so both arrive together.

Assessor

With step 6

Evidence request

9

Validate each item, not just receive it (TP-04): does its scope cover the service we buy, from the sites and systems that deliver it; are its dates current (certificate valid, report period and test within [[12]] months); is it in the name of the company we contract with? Evidence that fails a check counts as not received. For Tier 3, check a sample of [[3]] answers against evidence.

Assessor

See Timing targets

Completed evidence checklist

10

Where the supplier uses its own suppliers to deliver the service to us (cloud hosting, a data centre, a software component), ask how it assesses them, and check the evidence covers the part they deliver.

Assessor

With step 9

Supply chain notes

Stage 5 — Findings

Step

What happens

Who

When

Output

11

Record each gap as a finding (F-nn): what is missing, its severity, and its remediation deadline, counted from the date of the review report (TP-08). A finding has an owner at the supplier and is owned for us by the business owner.

Assessor

With step 15

Findings, with deadlines

12

Agree each finding and its deadline with the supplier. While a High finding is open, the decision cannot be a plain Approve (step 16).

Business owner; Assessor

Before step 16

Agreed findings

Severity and deadline, the same for every tier:

Severity

Meaning

Remediation deadline

High

A gap that could directly cause a significant incident or data loss at this supplier

90 calendar days from the review report

Medium

A gap that weakens a control but has other protection around it

180 calendar days from the review report

Low

An improvement; tracked to the next assessment

Tracked to the next assessment

Stage 6 — Residual risk

Step

What happens

Who

When

Output

13

Rate the residual risk the supplier leaves us, with its validated controls and our own around it, on the Risk Assessment Methodology & Scoring Model scale: impact and likelihood each 1 to 4, score = impact × likelihood, band from the score (TP-06). Write one sentence of reason for each rating.

Assessor

With step 15

Residual rating, score and band

14

Compare the band with the appetite for third-party risk in your Cyber Risk Appetite Statement Template, giving the position: within appetite, outside appetite, or outside tolerance.

Assessor

With step 13

Position

The bands of the Information Security Risk Management scale:

Band

Scores

Low

1–3

Medium

4–6

High

8–9

Critical

12–16

Stage 7 — Decision

Step

What happens

Who

When

Output

15

Write the Supplier Security Review Report Template: tier, questionnaire and evidence, findings, residual rating and position, and a recommended decision. For Tier 1, the Head of Information Security checks it before it goes to the business owner.

Assessor; Head of Information Security for Tier 1

See Timing targets

Review report

16

Decide, using the table below, and sign the report (TP-05). Conditions name the findings and their deadlines.

Business owner

See Timing targets

Signed decision

Which decision:

Decision

When

What follows

Approve

Residual risk within appetite; no High finding open.

Step 17

Approve with conditions

Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register.

Step 17; the conditions go into the contract or the register, with their deadlines

Escalate

Residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06).

Entered in the Information Security Risk Register (TP-06). Its owner decides treatment within [[30]] calendar days (RM-06); only then does the purchase go ahead or stop

Reject

Do not contract, or plan exit (TP-11).

Do not contract; for an existing supplier, run the exit plan (step 24)

Guidance — delete before approval

A decision the business owner signs, against a report the assessor wrote, is what an auditor looks for first. The security team recommends; the business owner decides, because the business owner relies on the service and owns the risk.

Stage 8 — Contract

Step

What happens

Who

When

Output

17

Put the clauses for the tier and data type from the Supplier Contract Security Clause Library into the contract before signature (TP-07), with any conditions from step 16. For a supplier that processes personal data, include the processor terms; for an ICT service supporting a critical or important function, the contract content DORA requires. Record any clause the supplier refuses as an exception under the Security Exception & Waiver Standard.

Legal; Procurement

Before signature

Signed contract with clauses

18

For Tier 1 and Tier 2: agree the exit plan — data return or deletion, access removal, transition period (TP-11). For Tier 1: add the supplier's named contacts and notification duties to the incident response and continuity plans (TP-10).

Business owner; Head of Information Security

Before the service starts

Exit plan; updated plans

Stage 9 — Register

Step

What happens

Who

When

Output

19

Update the Supplier Security Risk Register: tier, decision and date, residual score, band and position, findings with deadlines, exit plan reference, and the next reassessment date — the assessment date plus the tier's interval.

Assessor

Within [[2]] working days of step 16

Register entry

Stage 10 — Monitor and reassess

Step

What happens

Who

When

Output

20

Monitor the supplier as its tier requires (Timing targets, monitoring row).

Assessor

Continuously, or as the tier sets

Monitoring notes

21

Track findings to their deadlines. When a High finding passes its deadline, tell the business owner in writing (TP-08); the Head of Information Security raises it in the quarterly report. A Medium finding past its deadline is chased and shown in the register.

Assessor; Head of Information Security

High: within [[2]] working days of the deadline

Escalation record

22

Start the reassessment before it is due, at stage 3, with the same tier unless the intake answers have changed (TP-09).

Assessor

[[60]] calendar days before the due date

Reassessment started

23

On a material change, an incident or a breach at the supplier, start a reassessment at stage 2: the tier may change. An incident is also handled under your incident response plan (TP-10).

Assessor

Within [[10]] working days of learning of it

Triggered reassessment

Stage 11 — Exit

Step

What happens

Who

When

Output

24

Run the exit plan (TP-11): move the service, remove every account and connection the supplier had, have the supplier return or delete our live data and then its backup copies, and get written confirmation once deletion is complete.

Business owner; Assessor

Live data within [[30]] calendar days and backups within [[90]] calendar days of the service ending; confirmation within [[10]] working days of deletion being complete

Exit record

25

Close the register entry with the exit date. Keep it; never delete it.

Assessor

With step 24

Register history

Stage 12 — Report

Step

What happens

Who

When

Output

26

Report TPM-01 (Tier 1 suppliers assessed), TPM-02 (Reassessments overdue), TPM-03 (High findings past deadline), TPM-04 (Concentration) to executive management using the Third-Party Risk Dashboard (TP-12). TPM-01 is also the board measure "critical suppliers assessed" in the Board Cybersecurity Reporting pack.

Head of Information Security

Within [[10]] working days of quarter end

Quarterly report

Decision points

Decision

Who decides

Rule

Recorded in

Can we order or sign?

Procurement

Only with an intake and a tier (TP-01)

Purchase record

Which tier?

Assessor; Head of Information Security if disputed

Highest criterion; never below an override (TP-02)

Supplier Security Risk Register

Which questionnaire and evidence?

The tier, not a person

The tier's set and evidence (TP-03)

Tiered Supplier Security Questionnaire

Does the evidence count?

Assessor

Scope, dates and name checked (TP-04)

Supplier Due Diligence Evidence Checklist

How severe is a gap, and by when is it fixed?

Assessor

Severity and deadline table (TP-08)

Supplier Security Review Report Template

Is the residual risk within appetite?

The rules, not a person

Band against the appetite for third-party risk (TP-06)

Supplier Security Review Report Template

Approve, conditions, escalate or reject?

Business owner

Decision table (TP-05)

Supplier Security Review Report Template

Is it outside appetite?

The risk's owner, in the risk register

Treatment within [[30]] calendar days (RM-06)

Information Security Risk Register

Timing targets

By tier. Working-day targets shown as placeholders are this template's defaults; change them to fit your purchasing cycle. The intake lead time covers the steps after it with no slack for a late supplier, so start earlier where you can.

Activity

Tier 1

Tier 2

Tier 3

Tier 4

Intake completed before planned signature, at least

[[50]] working days

[[45]] working days

[[25]] working days

[[5]] working days

Tier recorded, from a complete intake

[[5]] working days

[[5]] working days

[[5]] working days

[[5]] working days

Questionnaire set

Set A: about 60 questions

Set B: about 35 questions

Set C: about 15 questions

Set D: about 5 questions (intake screening only)

Supplier's time to answer and send evidence

[[20]] working days

[[15]] working days

[[10]] working days

—

Evidence

Independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results

A certification or independent report, or key policies with evidence they operate

Self-declaration, with evidence sampled

None beyond the intake answers

Evidence validated, from receipt

[[10]] working days

[[10]] working days

[[5]] working days

—

Review report and signed decision, from validation

[[10]] working days

[[10]] working days

[[5]] working days

At tiering

Reassessment

At least every 12 months

At least every 24 months

At least every 36 months

Only when the service changes

Monitoring between assessments

Continuous: breach news, certificate and report expiry, material changes

Certificate expiry and material changes

At renewal

Only when the service changes

Activity

Target

Basis

High finding fixed

90 calendar days from the review report

TP-08

Medium finding fixed

180 calendar days from the review report

TP-08

Low finding fixed

Tracked to the next assessment

TP-08

Business owner told of a High finding past deadline

Within [[2]] working days

TP-08

Reassessment started

[[60]] calendar days before it is due

TP-09

Triggered reassessment started

Within [[10]] working days of learning of the trigger

TP-09

Treatment decision for an escalated supplier risk

Within [[30]] calendar days of the risk first being assessed outside appetite

RM-06, Information Security Risk Management pack

Live data returned or deleted at exit

Within [[30]] calendar days of the service ending

TP-11

Backup copies deleted at exit

Within [[90]] calendar days of the service ending

TP-11

Written confirmation of deletion

Within [[10]] working days of the deletion being complete

TP-11

Quarterly report

Within [[10]] working days of quarter end

TP-12

TPM-01 Tier 1 suppliers assessed

All Tier 1 by [[year end]]

TP-12

TPM-02 Reassessments overdue

Zero Tier 1; none more than 90 days overdue

TP-12

TPM-03 High findings past deadline

Zero

TP-12

TPM-04 Concentration

Each one known, with an exit plan (TP-11)

TP-12

Guidance — delete before approval

Tiers, sets, evidence, intervals and monitoring come from the Supplier Criticality & Tiering Model; the severities and deadlines are the pack's own, used unchanged in the Supplier Security Review Report Template. Change them there, not here. The working-day targets are this procedure's own.

Worked example — one Tier 1 supplier

EXAMPLE, not part of the procedure. The organisation is the one used throughout the pack: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It has 14 Tier 1, 22 Tier 2, 31 Tier 3, 45 Tier 4 suppliers. SUP-009, the pallet network, is one of its 14 Tier 1 suppliers and one of the 3 logistics suppliers (SUP-007, SUP-008, SUP-009) assessed in Q3 2026. It is an existing supplier, tiered when the organisation screened its whole supplier base. Replace every date and figure with your own.

Step

What happened

Result

1 to 4 — Intake and tier

Service: Warehouse dispatch. Data: customer addresses. Access: through the supplier's portal. TC-1 service: Tier 1 (it carries pallet deliveries for Warehouse dispatch, one of the organisation's critical services). TC-2 data: Tier 1 (customer names and delivery addresses are customer data). TC-3 access: Tier 4 (no access). TC-4 substitutability: Tier 2 (could be replaced within [[3 months]] with effort). The tier is the highest any criterion reaches (TP-02): Tier 1, from TC-1 and TC-2. (EXAMPLE)

Tier 1 (Critical)

6 to 10 — Questionnaire and evidence

Set A (about 60 questions) sent with the Tier 1 evidence request: independent assurance (a certification with a matching scope, or an independent audit report), recent penetration test summary, continuity test results. Each item validated for scope, dates and the name of the company contracted with (TP-04). (EXAMPLE)

Evidence checklist complete

11, 12 — Findings (review report 15 Sept 2026)

F-03: shared portal accounts used by depot staff. Severity Medium: a gap that weakens a control but has other protection around it. Deadline 180 calendar days from the review report. Agreed with the supplier. (EXAMPLE)

F-03 due 14 Mar 2027

13, 14 — Residual risk

Impact 2 Moderate: if the pallet network failed or were compromised, pallet deliveries would stop or be delayed and customer delivery addresses held in its portal could be exposed; the two parcel carriers (SUP-007, SUP-008) keep parcels moving. Likelihood 2 Possible: the Tier 1 evidence was received and validated and showed no other gap; but depot staff share portal accounts (F-03), so a misused account could not be traced to a person or removed when one of them leaves. 2 × 2 = 4. The example's appetite for third-party risk is Cautious (Information Security Risk Management pack). (EXAMPLE)

Medium, within appetite

15, 16 — Decision (15 Sept 2026)

Within appetite and no High finding open, so Approve was allowed; the assessor recommended Approve with conditions so that the Medium finding F-03 becomes a condition with its deadline. The Head of Logistics, as business owner, signs Approve with conditions: proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. The condition is F-03 by 14 Mar 2027. (EXAMPLE)

Approve with conditions

17, 18 — Contract

The existing contract is checked against the Tier 1 clauses for customer data in the Supplier Contract Security Clause Library; [[any missing clause is added at the next variation or renewal, or recorded as an exception]]. The condition is recorded in the register. As a Tier 1 supplier it needs an exit plan (TP-11) and named contacts in the incident response and continuity plans (TP-10). (EXAMPLE)

Clauses checked; exit plan and contacts confirmed

19 — Register

Tier, decision, residual 4 Medium, F-03 and its deadline recorded. Next reassessment due 15 Sept 2027 (12 months after 15 Sept 2026); it starts on 17 Jul 2027, [[60]] calendar days before. (EXAMPLE)

Register entry

20 to 23 — Monitoring

Continuous: breach news, certificate and report expiry, material changes. If depot account sharing led to a breach at the supplier, that would trigger a reassessment at stage 2 (TP-09). SUP-009 supports one critical service, so it is not one of the 6 providers counted in TPM-04. (EXAMPLE)

F-03 tracked to 14 Mar 2027

26 — Report (as at 30 Sept 2026)

TPM-01: 9 of 14 Tier 1 suppliers assessed in the last 12 months, including SUP-009. F-03 is open but not past its deadline, so it is not counted in TPM-03. (EXAMPLE)

9 of 14

Had the residual score been High, the decision would have been Escalate: an entry in the Information Security Risk Register, and a treatment decision by its owner within [[30]] calendar days (RM-06), before the contract went ahead.

Outputs and records produced

Output

Produced at step

Held in

Maintained by

Intake record and tier, with reasons

1, 3

Supplier Security Risk Register

Assessor

Questionnaire answers

6

Tiered Supplier Security Questionnaire; [[evidence location]]

Assessor

Evidence and validation checks

8 to 10

Supplier Due Diligence Evidence Checklist; [[evidence location]]

Assessor

Findings, residual rating, decision

11 to 16

Supplier Security Review Report Template

Assessor; Business owner signs

Contract with clauses; refused clauses as exceptions

17

[[Contract repository]]; Security Exception Register

Legal; Procurement

Exit plan; supplier contacts in plans

18

[[Contract file]]; incident response and continuity plans

Business owner; Head of Information Security

Register entry and history

4, 19, 21, 25

Supplier Security Risk Register

Assessor

Quarterly report

26

Third-Party Risk Dashboard

Head of Information Security

Escalation

When

Escalated to

By

Basis

Order or contract signed without an intake and tier

Executive management

Head of Information Security

TP-01

Supplier does not answer or send evidence by the deadline

Business owner; then Head of Information Security

Assessor

TP-03, TP-04

Tier or ratings disputed

Head of Information Security

Assessor

TP-02

Residual risk outside appetite

Risk owner, through the Information Security Risk Register

Assessor

TP-06; RM-06

High finding past its deadline

Business owner; then executive management in the quarterly report

Assessor; Head of Information Security

TP-08

Reassessment overdue

Business owner; named in the quarterly report (TPM-02)

Assessor

TP-09

Supplier refuses a required clause

Security Exception & Waiver Standard (an exception request)

Legal

TP-07

Rejecting or exiting a Tier 1 supplier

Executive management

Business owner

TP-11

EXAMPLE: as at 30 Sept 2026, finding F-01 at SUP-004, the ERP software provider (hosted) — "support staff reach our ERP without multi-factor authentication" — is High and was due on 20 Jul 2026. It is open 72 calendar days past its deadline, so the business owner has been told and it is counted in TPM-03.

Evidence retained

Evidence

Shows

Minimum retention

Intake and tier, with reasons

Every supplier screened and tiered before signature (TP-01, TP-02)

[[Life of the contract plus 3 years]]

Questionnaire answers and validated evidence

The tier's set and evidence, checked (TP-03, TP-04)

[[Until the next assessment plus 3 years]]

Review reports with signed decisions

Every assessment decided by the business owner (TP-05, TP-06)

[[Life of the contract plus 3 years]]

Findings and their closure

Deadlines met or escalated (TP-08)

[[3 years after closure]]

Signed contracts and exit plans

Clauses and exit in place (TP-07, TP-11)

[[As your contract retention policy sets]]

Exit records and deletion confirmations

Data returned or deleted, access removed (TP-11)

[[6 years]]

Quarterly reports

Reporting (TP-12)

[[5 years]]

Guidance — delete before approval

An auditor typically picks a few suppliers — at least one Tier 1 and one recent contract — and asks for the intake, the tier with reasons, the questionnaire, the validated evidence, the signed decision, the contract clauses and the next reassessment date. Test this yourself each quarter on two suppliers.

Related documents

Document

Relationship

Third-Party Security Policy

The rules this procedure runs (TP-01 to TP-12)

Supplier Criticality & Tiering Model

Criteria, overrides, sets, evidence, intervals and monitoring (steps 3, 6, 8, 20, 22)

Tiered Supplier Security Questionnaire

The questionnaire set for each tier (step 6)

Supplier Due Diligence Evidence Checklist

What evidence to ask for, and how to validate it (steps 8, 9)

Supplier Contract Security Clause Library

The clauses for each tier and data type (step 17)

Supplier Security Risk Register

Where every supplier is recorded (steps 4, 19, 25)

Supplier Security Review Report Template

The record of one assessment and its decision (steps 11 to 16)

Third-Party Risk Dashboard

The quarterly report (step 26)

Risk Assessment Methodology & Scoring Model; Cyber Risk Appetite Statement Template; Information Security Risk Register

The scale, the appetite, and where an escalated supplier risk goes (steps 13, 14, 16); Information Security Risk Management pack

Security Exception & Waiver Standard

The route for a refused clause or any other exception (step 17); Security Exception, Waiver & Segregation of Duties pack

Adapting this template

Guidance — delete before approval

Small organisation: a spreadsheet register and a shared mailbox are enough. Tier your existing suppliers first and assess the Tier 1 ones in order of criticality; Tier 3 and Tier 4 take minutes. Keep the signed decision, the evidence checks and the reassessment dates: they are what an auditor tests. Where the assessor and the Head of Information Security are one person, have [[an external adviser]] check Tier 1 reports before the decision.

Regulated entity (NIS2, DORA, GDPR): NIS2 Article 21(3) expects you to take account of each direct supplier's vulnerabilities and the overall quality of its products and security practices, including secure development: steps 9 and 10 do this; add secure development questions to the set for software suppliers. A DORA financial entity manages ICT third-party risk proportionately and remains fully responsible (Article 28(1)): the tiers are that proportionality, and the override makes every ICT service supporting a critical or important function Tier 1. It must also keep the register of information on all ICT contracts (Article 28(3)), assess concentration (Article 29) and include the Article 30 contract content (step 17). Under the GDPR, use only processors that give sufficient guarantees (Article 28(1)): the processor override sets them at Tier 2 or above, and the DPO advises on their assessment.

IT run by a service provider: your managed IT provider is usually Tier 1, and often the first supplier to assess. It may help collect evidence for other suppliers, but the tier, the evidence checks and the decision stay with your organisation. Ask it how it assesses the suppliers it uses to serve you (step 10).

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR).

Framework

Reference

Supported by

ISO/IEC 27001:2022

Annex A 5.19 — Information security in supplier relationships

Whole procedure: supplier risk assessed and decided before and during the relationship

ISO/IEC 27001:2022

Annex A 5.21 — Managing information security in the ICT supply chain

Step 10: the supplier's own suppliers that deliver our service

ISO/IEC 27001:2022

Annex A 5.22 — Monitoring, review and change management of supplier services

Stage 10: monitoring, findings and reassessment on interval and change

NIST CSF 2.0

GV.SC-06 — “Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships”

Stages 1 to 7: due diligence before the contract

NIST CSF 2.0

GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship”

Stages 5, 6 and 10: supplier risk recorded, assessed, responded to and monitored

NIS2 — Directive (EU) 2022/2555

Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development

Steps 9 and 10; regulated-entity tailoring

DORA — Regulation (EU) 2022/2554

Article 28(1) — ICT third-party risk managed as part of ICT risk, proportionately; the financial entity remains fully responsible

Tier-based effort; regulated-entity tailoring

GDPR — Regulation (EU) 2016/679

Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures

Stages 3 and 4 for processors; the GDPR override

Definitions

Term

Meaning in this procedure

Business owner

The manager who buys and relies on a supplier's service; signs the decision (TP-05).

Calendar day

Every day, including weekends and public holidays.

Finding

A gap found in an assessment, with a severity and a remediation deadline (TP-08).

Intake

The short set of questions about a supplier's service, data, access and substitutability that sets its tier.

Material change

A change in what the supplier does for us, the data or access it has, its ownership, location or subcontractors that could change its tier or risk.

Override

A condition that sets a minimum tier whatever the criteria say.

Position

Where a residual band sits against the appetite for third-party risk: within appetite, outside appetite, or outside tolerance.

Residual risk

The risk a supplier leaves us with its validated controls and ours in place, scored on the Risk Assessment Methodology & Scoring Model scale.

Review report

The Supplier Security Review Report Template: the record of one assessment and its signed decision.

Tier

One of Tier 1 (Critical), Tier 2 (Important), Tier 3 (Standard), Tier 4 (Minimal), set by the Supplier Criticality & Tiering Model.

Validation

Checking that a piece of evidence covers the service we buy, is current and is in the contracting company's name (TP-04).

Working day

Monday to Friday, excluding [[public holidays where you are]].