Supplier Security Risk Register
Holds the assessed supplier population with tier, assessment status, findings, expiry dates and residual risk.
Available soon
- Format
- Excel
- Size
- 130 KB
- Length
- 11 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Register
- Findings
- Critical Services
- Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30, the example quarter end; replace it with today's date, or type =TODAY() to keep it current. Status, days past due and deadline flags use this date. Set the appetite level for third-party dependency from your approved P05 Cyber Risk Appetite Statement Template there too. |
| 2 | On the Critical Services sheet, list your critical services (the ones your business impact analysis or continuity plan names) and their owners. The register counts how many of them each supplier supports; two or more makes it a concentration provider (TPM-04). |
| 3 | Add one row per supplier: no supplier may be engaged, and no contract renewed, until intake screening is done and a tier is recorded (TP-01). Give it a Supplier ref (SUP-001, SUP-002 …) that never changes. Name its Business owner: [[the manager who buys and relies on the service]]. List the critical services it supports, separated by semicolons, using the names on the Critical Services sheet. |
| 4 | Tier it with the Supplier Criticality & Tiering Model (TP-02): choose the tier each criterion reaches (TC-1 service, TC-2 data, TC-3 access, TC-4 substitutability) and any override (an ICT service supporting a critical or important function of a DORA financial entity: at least Tier 1; a processor of personal data under GDPR Article 28: at least Tier 2). Tier, Tier set by, Questionnaire set and Reassess every calculate (Tier 1 Critical: set A, every 12 months; Tier 2 Important: set B, every 24 months; Tier 3 Standard: set C, every 36 months; Tier 4 Minimal: set D, only when the service changes). |
| 5 | Plan and record the assessment with the Supplier Security Assessment Procedure. Before the first assessment, enter the Planned assessment date. After it, enter Last assessed, whether the evidence was validated against the service you buy (TP-04), the residual impact and likelihood on the P05 scale (TP-06), and the Decision the business owner signed on the Supplier Security Review Report Template (TP-05). Next due and Assessment status calculate. |
| 6 | Enter each finding on the Findings sheet with its supplier ref, severity and the date raised (the review report date). The deadline calculates (High 90 calendar days, Medium 180 calendar days, Low at the next assessment), and the open counts come back to the register. When a High finding passes its deadline, escalate it to the business owner and record the date (TP-08). |
| 7 | Read the Position against appetite. A supplier outside appetite is escalated: enter it in the P05 Information Security Risk Register and put that register's reference here (TP-06). Record whether the contract carries the tier's clauses from the Supplier Contract Security Clause Library (TP-07) and whether an exit plan exists (TP-11). |
| 8 | Clear every Record check that does not say OK. Reassess each supplier by its Next due date, and sooner after a material change, an incident or a breach at the supplier (TP-09). Take the Summary figures to [[e.g. Executive Committee]] every quarter (TP-12). |
| 9 | Delete the EXAMPLE rows on the Register, Findings and Critical Services sheets, and the EXAMPLE portfolio counts on the Summary sheet, before the register is approved. Do not type over the white calculated columns. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30 (Q3 2026). It has 112 suppliers: 14 Tier 1, 22 Tier 2, 31 Tier 3, 45 Tier 4. To keep the example readable, only the 14 Tier 1 suppliers have rows here; the others are counted in the portfolio table on the Summary sheet. Your register lists every supplier, one row each.
In the EXAMPLE, 9 of the 14 Tier 1 suppliers have been assessed in the last 12 months (TPM-01; the board measure BM-05 in the P03 pack). The three logistics suppliers were assessed this quarter and the other five are planned for Q4. The managed IT service provider (SUP-001) is P05 risk R-06. F-01, a High finding at the ERP provider, is past its deadline and was escalated to the business owner.
Tailoring — small organisation: start with the suppliers that would stop a critical service or hold customer data; tier the rest at the next renewal. One person may assess, but the business owner still signs each decision (TP-05).
Tailoring — regulated entity: NIS2 Art 21(2)(d) and 21(3) expect supply chain security to take account of each direct supplier's vulnerabilities and security practice; the tier, evidence and findings here are that record. A DORA financial entity must keep a register of information on all contractual arrangements for ICT services, distinguishing those supporting critical or important functions (Art 28(3)), and assess concentration (Art 29(1)): add columns for the function supported and the contract reference and keep this register reconciled with it. Mark each processor of personal data with the GDPR override (Art 28(1)).
Tailoring — IT run by a service provider: the provider is a supplier in this register, usually Tier 1, and so are the providers it relies on for your service where you can name them. Ask it to report its own suppliers' changes as a material change (TP-09).
Tiers, sets, intervals, overrides, severities, deadlines, decisions, the P05 scale, bands and appetite levels are on the Lists sheet. If your Supplier Criticality & Tiering Model or Supplier Security Assessment Procedure sets different ones, change them there and nowhere else. A deviation from a supplier requirement is a P02 exception, recorded in the Security Exception Register.
Register
One row per supplier (TP-01). Yellow columns are inputs; white columns calculate. Every colour sits beside a word.
| Example | Supplier ref | Supplier | Supplier type | Business owner | Critical services supported | Critical services (number) | Data | Access | TC-1 Service | TC-2 Data | TC-3 Access | TC-4 Substitutability | Override | Tier | Tier set by | Questionnaire set | Reassess every (months) | Last assessed | Planned assessment | Next due | Assessment status | Days past due | Evidence validated (TP-04) | Open High findings | Open Medium findings | Open Low findings | High findings past deadline | Residual impact (1–4) | Residual likelihood (1–4) | Residual score | Residual band | Position against appetite | P05 risk register ref | Decision | Contract clauses in place (TP-07) | Exit plan (TP-11) | Record check | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | SUP-001 | Managed IT service provider | IT | Head of IT | Online ordering; Warehouse dispatch; Finance and payroll | 3 | Customer data | Privileged | Tier 1 | Tier 1 | Tier 1 | Tier 1 | GDPR processor | Tier 1 | TC-1, TC-2, TC-3, TC-4 | A | 12 | 18 Nov 2025 | 18 Nov 2026 | Due soon | Yes | 0 | 0 | 0 | 0 | 3 | 1 | 3 | Low | Within appetite | R-06 | Approve | Yes | Yes | OK | P05 risk R-06 (treatment: Transfer). | ||
| EXAMPLE | SUP-002 | Cloud hosting provider | IT | Head of IT | Online ordering; Finance and payroll | 2 | Customer data | Network | Tier 1 | Tier 1 | Tier 1 | Tier 1 | GDPR processor | Tier 1 | TC-1, TC-2, TC-3, TC-4 | A | 12 | 27 Jan 2026 | 27 Jan 2027 | In date | Yes | 0 | 0 | 0 | 0 | 3 | 1 | 3 | Low | Within appetite | Approve with conditions | Yes | Yes | OK | F-04 closed 2026-03-30. | |||
| EXAMPLE | SUP-003 | Payment service provider | Finance | Chief Financial Officer | Payments | 1 | Card data (held by the provider) | None | Tier 1 | Tier 1 | Tier 4 | Tier 1 | None | Tier 1 | TC-1, TC-2, TC-4 | A | 12 | 24 Feb 2026 | 24 Feb 2027 | In date | Yes | 0 | 0 | 0 | 0 | 3 | 1 | 3 | Low | Within appetite | Approve | Yes | Yes | OK | ||||
| EXAMPLE | SUP-004 | ERP software provider (hosted) | IT | Chief Financial Officer | Finance and payroll; Warehouse dispatch | 2 | Personal data | Remote support | Tier 1 | Tier 2 | Tier 2 | Tier 1 | GDPR processor | Tier 1 | TC-1, TC-4 | A | 12 | 21 Apr 2026 | 21 Apr 2027 | In date | Yes | 1 | 1 | 0 | 1 | 3 | 2 | 6 | Medium | Within appetite | Approve with conditions | Yes | Yes | High finding past deadline: escalate to the business owner (TP-08) | Conditions: F-01 and F-02 fixed by their deadlines. | |||
| EXAMPLE | SUP-005 | Email and office software provider | IT | Head of IT | Customer contact | 1 | Personal data | None | Tier 1 | Tier 2 | Tier 4 | Tier 2 | GDPR processor | Tier 1 | TC-1 | A | 12 | 19 May 2026 | 19 May 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 1 | 2 | Low | Within appetite | Approve | Yes | Yes | OK | ||||
| EXAMPLE | SUP-006 | Security monitoring provider | IT | Head of Information Security | Online ordering; Warehouse dispatch | 2 | Log data | Privileged | Tier 1 | Tier 3 | Tier 1 | Tier 2 | None | Tier 1 | TC-1, TC-3 | A | 12 | 16 Jun 2026 | 16 Jun 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 1 | 2 | Low | Within appetite | Approve | Yes | Yes | OK | ||||
| EXAMPLE | SUP-007 | National parcel carrier | Logistics | Head of Logistics | Warehouse dispatch | 1 | Customer addresses | Integration | Tier 1 | Tier 1 | Tier 2 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 14 Jul 2026 | 14 Jul 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 2 | 4 | Medium | Within appetite | Approve | Yes | Yes | OK | ||||
| EXAMPLE | SUP-008 | Express courier | Logistics | Head of Logistics | Warehouse dispatch | 1 | Customer addresses | Integration | Tier 1 | Tier 1 | Tier 2 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 18 Aug 2026 | 18 Aug 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 1 | 2 | Low | Within appetite | Approve | Yes | Yes | OK | ||||
| EXAMPLE | SUP-009 | Pallet network | Logistics | Head of Logistics | Warehouse dispatch | 1 | Customer addresses | Portal | Tier 1 | Tier 1 | Tier 4 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 15 Sep 2026 | 15 Sep 2027 | In date | Yes | 0 | 1 | 0 | 0 | 2 | 2 | 4 | Medium | Within appetite | Approve with conditions | Yes | Yes | OK | Condition: F-03 fixed by its deadline. | |||
| EXAMPLE | SUP-010 | Warehouse management system provider | IT | Head of Logistics | Warehouse dispatch | 1 | Internal | Remote support | Tier 1 | Tier 3 | Tier 2 | Tier 1 | None | Tier 1 | TC-1, TC-4 | A | 12 | 20 Oct 2026 | 20 Oct 2026 | Planned | 0 | 0 | 0 | 0 | Yes | No | Agree an exit plan (TP-11) | |||||||||||
| EXAMPLE | SUP-011 | Backup service provider | IT | Head of IT | Online ordering; Finance and payroll | 2 | Customer data | Network | Tier 1 | Tier 1 | Tier 1 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2, TC-3 | A | 12 | 3 Nov 2026 | 3 Nov 2026 | Planned | 0 | 0 | 0 | 0 | Yes | No | Agree an exit plan (TP-11) | |||||||||||
| EXAMPLE | SUP-012 | Payroll bureau | Finance | HR Director | Finance and payroll | 1 | Personal data (staff) | Portal | Tier 1 | Tier 1 | Tier 4 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 17 Nov 2026 | 17 Nov 2026 | Planned | 0 | 0 | 0 | 0 | Yes | No | Agree an exit plan (TP-11) | |||||||||||
| EXAMPLE | SUP-013 | Outsourced customer contact centre | Service | Chief Operating Officer | Customer contact | 1 | Customer data | Remote user | Tier 1 | Tier 1 | Tier 2 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 1 Dec 2026 | 1 Dec 2026 | Planned | 0 | 0 | 0 | 0 | No | No | Add the tier's security clauses to the contract (TP-07) | Contract predates the policy; clauses added at renewal. | ||||||||||
| EXAMPLE | SUP-014 | Network connectivity provider | IT | Head of IT | Online ordering; Warehouse dispatch | 2 | None stored | Network | Tier 1 | Tier 4 | Tier 1 | Tier 1 | None | Tier 1 | TC-1, TC-3, TC-4 | A | 12 | 8 Dec 2026 | 8 Dec 2026 | Planned | 0 | 0 | 0 | 0 | No | No | Add the tier's security clauses to the contract (TP-07) | Contract predates the policy; clauses added at renewal. |
Findings
One row per finding from a Supplier Security Review Report Template (TP-08). The deadline is set by severity, in calendar days from the date raised.
| Example | Finding ID | Supplier ref | Supplier | Severity | Finding | Owner | Raised | Deadline | Status | Closed on | Days past deadline | Deadline flag | Escalated to business owner on | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | F-01 | SUP-004 | ERP software provider (hosted) | High | Support staff reach our ERP without multi-factor authentication | Chief Financial Officer | 21 Apr 2026 | 20 Jul 2026 | Open | 72 | Past deadline | 21 Jul 2026 | Escalated to the business owner the day after the deadline (TP-08). | |
| EXAMPLE | F-02 | SUP-004 | ERP software provider (hosted) | Medium | No evidence that our data is deleted at contract end | Chief Financial Officer | 21 Apr 2026 | 18 Oct 2026 | Open | |||||
| EXAMPLE | F-03 | SUP-009 | Pallet network | Medium | Shared portal accounts used by depot staff | Head of Logistics | 15 Sep 2026 | 14 Mar 2027 | Open | |||||
| EXAMPLE | F-04 | SUP-002 | Cloud hosting provider | High | Penetration test older than 12 months | Head of IT | 27 Jan 2026 | 27 Apr 2026 | Closed | 30 Mar 2026 | New penetration test summary received and checked. |
Critical Services
Your critical services and their owners. The Register sheet counts how many of these each supplier supports.
| Example | Critical service | Service owner | Suppliers supporting it | Of those, without an exit plan | Of those, not assessed or overdue |
|---|---|---|---|---|---|
| EXAMPLE | Online ordering | Chief Operating Officer | 5 | 2 | 2 |
| EXAMPLE | Warehouse dispatch | Head of Logistics | 8 | 2 | 2 |
| EXAMPLE | Payments | Chief Financial Officer | 1 | 0 | 0 |
| EXAMPLE | Finance and payroll | Chief Financial Officer | 5 | 2 | 2 |
| EXAMPLE | Customer contact | Chief Operating Officer | 2 | 1 | 1 |
Summary
Register summary
Every figure is calculated from the Register and Findings sheets as at the date shown. Use them for the quarterly report to executive management (TP-12); the Third-Party Risk Dashboard adds the trend.
| As-at date | 30 Sep 2026 | EXAMPLE date (the example quarter end). Replace it with today's date, or type =TODAY(). |
| Appetite level: third-party dependency | Cautious | EXAMPLE: the level in the P05 Cyber Risk Appetite Statement Template for RC-05 third-party dependency. Use your own. |
| Due soon: calendar days before the next due date | 90 | One quarter, the reporting interval. Change it if you report more often. |
| Target date: all Tier 1 suppliers assessed (TPM-01) | 31 Dec 2026 | EXAMPLE: the year end, from the target "All Tier 1 by [[year end]]". Use your own. |
Headline measures
| Measure | Result | Target | Status | What it means | |||||
|---|---|---|---|---|---|---|---|---|---|
| TPM-01 Tier 1 suppliers assessed | 9 of 14 | All Tier 1 by [[year end]] | On target | Tier 1 suppliers with an assessment within the last 12 months, out of all Tier 1 suppliers. On target while the rest are planned before the target date (C8). The board measure BM-05 in the P03 pack. | |||||
| TPM-02 Reassessments overdue | 0 | Zero Tier 1; none more than 90 days overdue | On target | Suppliers past their tier's reassessment interval. A supplier never assessed whose planned date has passed counts as overdue. | |||||
| TPM-03 High findings past deadline | 1 | Zero | Action needed | Open High findings past their remediation deadline. Each is escalated to the supplier's business owner (TP-08); see the Findings sheet. | |||||
| TPM-04 Concentration | 6 | Each one known, with an exit plan (TP-11) | Action needed | Providers that two or more critical services depend on. Counted from the critical services each supplier supports. | |||||
| of those, without an exit plan | 2 | 0 | Every Tier 1 and Tier 2 contract needs an exit plan (TP-11); a concentration provider without one is the first to fix. | ||||||
Portfolio by tier
| Tier | Questionnaire set | Reassess every (months) | Suppliers in the portfolio | Rows in the register | Not yet in the register | In date | Due soon | Overdue | Planned |
|---|---|---|---|---|---|---|---|---|---|
| Tier 1 Critical | A | 12 | 14 | 14 | 0 | 8 | 1 | 0 | 5 |
| Tier 2 Important | B | 24 | 22 | 0 | 22 | 0 | 0 | 0 | 0 |
| Tier 3 Standard | C | 36 | 31 | 0 | 31 | 0 | 0 | 0 | 0 |
| Tier 4 Minimal | D | On change | 45 | 0 | 45 | 0 | 0 | 0 | 0 |
| All tiers | 112 | 14 | 98 | 8 | 1 | 0 | 5 |
EXAMPLE: the suppliers in each tier are typed in (yellow). Only the 14 Tier 1 suppliers have rows in this example; in your register every supplier has a row and "Not yet in the register" is 0.
Decisions and residual risk
| Decision (TP-05) | Suppliers | Residual band | Suppliers | Position against appetite | Suppliers | ||||
|---|---|---|---|---|---|---|---|---|---|
| Approve | 6 | Low (1–3) | 6 | Within appetite | 9 | ||||
| Approve with conditions | 3 | Medium (4–6) | 3 | Outside appetite, within tolerance | 0 | ||||
| Escalate | 0 | High (8–9) | 0 | Outside tolerance | 0 | ||||
| Reject | 0 | Critical (12–16) | 0 | Not yet scored | 5 | ||||
Findings
| Severity | Deadline (calendar days from the report) | Open | Past deadline | Closed |
|---|---|---|---|---|
| High | 90 | 1 | 1 | 1 |
| Medium | 180 | 2 | 0 | 0 |
| Low | Next assessment | 0 | 0 | 0 |
Record checks to resolve
| Check | Suppliers |
|---|---|
| Complete the supplier and business owner | 0 |
| Rate the four tiering criteria (TP-01, TP-02) | 0 |
| Not yet assessed: set a planned date (TP-09) | 0 |
| Overdue: reassess now (TP-09) | 0 |
| Validate the evidence: scope, dates and legal entity (TP-04) | 0 |
| Record the decision, signed by the business owner (TP-05) | 0 |
| Score the residual risk on the P05 scale (TP-06) | 0 |
| Outside appetite: enter it in the P05 risk register (TP-06) | 0 |
| High finding past deadline: escalate to the business owner (TP-08) | 1 |
| Add the tier's security clauses to the contract (TP-07) | 2 |
| Agree an exit plan (TP-11) | 3 |
| All rows with a check to resolve | 6 |
Each row shows only its first unresolved check; clear it and the next one, if any, appears.
Quarterly review record
| Item | Entry | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Reviewed by (name, role) and date | [[Name, role, YYYY-MM-DD]] | ||||||||
| Suppliers assessed this quarter, and their decisions | [[e.g. SUP-007, SUP-008, SUP-009: two Approve, one Approve with conditions]] | ||||||||
| Findings escalated, and to whom | [[e.g. F-01 to the Chief Financial Officer, 2026-07-21]] | ||||||||
| Decisions needed from executive management | [[e.g. exit plans for the two concentration providers without one]] | ||||||||
Lists
| TierName | TierLabel | TierSet | TierMonths | OverrideName | OverrideMinTier | Status | YesNo | Decision | Severity | SeverityDays | FindingStatus | Level | Band | BandMinScore | AppetiteLevel | LevelAppetite | LevelTolerance | Position |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Tier 1 | Tier 1 Critical | A | 12 | None | In date | Yes | Approve | High | 90 | Open | 1 | Low | 1 | Averse | Low | Medium | Within appetite | |
| Tier 2 | Tier 2 Important | B | 24 | DORA critical or important function | Tier 1 | Due soon | No | Approve with conditions | Medium | 180 | Closed | 2 | Medium | 4 | Cautious | Medium | High | Outside appetite, within tolerance |
| Tier 3 | Tier 3 Standard | C | 36 | GDPR processor | Tier 2 | Overdue | Escalate | Low | Next assessment | 3 | High | 8 | Open | High | High | Outside tolerance | ||
| Tier 4 | Tier 4 Minimal | D | On change | Planned | Reject | 4 | Critical | 12 |
Not required
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Supplier | Any third party that provides goods or services and could affect the security of our information or services, including cloud and software providers, outsourcers and their own suppliers where we rely on them. |
| Supplier ref | Your unique reference for the supplier, such as SUP-004. It stays the same while the supplier is in the register. |
| Business owner | [[the manager who buys and relies on the service]]. Signs the decision after each assessment (TP-05) and receives escalated findings (TP-08). |
| Critical service | A service whose loss would seriously harm the organisation or its customers, listed on the Critical Services sheet. |
| Tiering criteria | TC-1 Service — Tier 1: runs or supports a critical service, or a critical or important function; Tier 2: supports an important internal service; Tier 3: supports a minor service; Tier 4: no service dependency. TC-2 Data — Tier 1: sensitive or personal data at scale, or customer data; Tier 2: personal data; Tier 3: internal non-personal data; Tier 4: no data, or public data only. TC-3 Access — Tier 1: privileged or network-level access to critical systems; Tier 2: remote user access to our systems; Tier 3: limited or supervised on-site access; Tier 4: no access. TC-4 Substitutability — Tier 1: could not be replaced within [[3 months]] without harm to a critical service; Tier 2: could be replaced within [[3 months]] with effort; Tier 3: replaceable within [[3 months]] with little effort; Tier 4: replaceable at once: many suppliers offer the same. |
| Override | An ICT service supporting a critical or important function of a DORA financial entity: at least Tier 1. A processor of personal data under GDPR Article 28: at least Tier 2. |
| Tier | The tier must be the highest any criterion reaches, and never below an override's minimum. Tier 1 Critical, Tier 2 Important, Tier 3 Standard, Tier 4 Minimal. |
| Tier set by | The criteria that reached the supplier's tier, or Override where an override raised it above every criterion. |
| Questionnaire set | A: Tier 1, about 60 questions; B: Tier 2, about 35 questions; C: Tier 3, about 15 questions; D: Tier 4, about 5 (intake screening only) questions. The sets are in the Tiered Supplier Security Questionnaire. |
| Reassess every | Tier 1: 12 months; Tier 2: 24 months; Tier 3: 36 months; Tier 4: only when the service changes. The most time allowed between assessments; a material change, incident or breach brings it forward (TP-09). |
| Next due | Last assessed plus the tier's interval. For a supplier not yet assessed, its planned assessment date. |
| Assessment status | In date: next due more than the due-soon window away. Due soon: next due within the window (90 calendar days by default). Overdue: next due date passed, or no assessment and no planned date. Planned: not yet assessed, planned date still ahead. Not required: a tier reassessed only when the service changes. |
| Evidence validated | Evidence must be validated, not just received: its scope, dates and legal entity must match the service we buy. |
| Finding severity | High: a gap that could directly cause a significant incident or data loss at this supplier; deadline 90 calendar days after the review report. Medium: a gap that weakens a control but has other protection around it; deadline 180 calendar days after the review report. Low: an improvement; tracked to the next assessment; deadline the next assessment. |
| Residual risk | The risk the supplier still poses with the controls it and we have in place, scored on the P05 scale: impact × likelihood, each 1 to 4 (TP-06). Bands: Low 1–3, Medium 4–6, High 8–9, Critical 12–16. |
| Position against appetite | Within appetite: the band is at or below the appetite for third-party dependency. Outside appetite, within tolerance: above appetite, at or below tolerance. Outside tolerance: above tolerance. Outside appetite, the supplier risk goes to the P05 Information Security Risk Register. |
| Decision | Approve: residual risk within appetite; no High finding open. Approve with conditions: proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. Escalate: residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06). Reject: do not contract, or plan exit (TP-11). |
| Concentration provider | Providers that two or more critical services depend on. Each one known, with an exit plan (TP-11). |
| Exit plan | Every Tier 1 and Tier 2 contract must have an exit plan: data return or deletion, access removal, and a transition period. |
| Record check | A calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding. |
| As-at date | The date status, days past due and deadline flags are measured against. Set on the Summary sheet. |
| EXAMPLE row | A worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30. Delete before approval. |
| TP-nn, TPM-nn | Rule and measure numbers in the Third-Party Security Policy. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | The register as a whole: each supplier identified, tiered by the risk it brings, and managed to its tier's requirements |
| ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Last assessed, next due, status, findings and deadlines: supplier security monitored, reviewed and reassessed on change |
| NIST CSF 2.0 | GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship” | Residual score, band, position, decision and findings: supplier risk assessed, recorded, prioritised, responded to and monitored |
| NIST CSF 2.0 | GV.SC-04 — “Suppliers are known and prioritized by criticality” | Tiering criteria, override and tier: suppliers known and prioritised by criticality |
| DORA — Regulation (EU) 2022/2554 | Article 28(3) — a register of information on all contractual arrangements for ICT services, distinguishing those supporting critical or important functions | One row per ICT arrangement with the critical services it supports; add the function and contract columns for the register of information |
| DORA — Regulation (EU) 2022/2554 | Article 29(1) — assessing concentration risk: providers not easily substitutable, or several arrangements with the same provider | Critical services (number) and TPM-04: providers several critical services depend on, with substitutability (TC-4) and exit plan |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)