Third-Party Risk Dashboard
Shows portfolio-level supplier exposure: assessment coverage, overdue reviews, open findings and concentration.
Available soon
- Format
- Excel
- Size
- 119 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Register Data
- Findings Data
- Metric Definitions
- Quarterly Report
- Trend
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Register Data sheet: in the Supplier Security Risk Register, copy the Register table's rows (columns A to AM, from row 4 down) and paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order. |
| 2 | Findings Data sheet: copy the register's Findings table rows (columns A to O, from row 4 down) and paste them as values into cell A4. |
| 3 | Delete the EXAMPLE rows on both data sheets before you paste, and check that dates are real dates (right-aligned), not text. |
| 4 | Quarterly Report sheet: enter the report date, normally the last day of the quarter. The EXAMPLE uses 2026-09-30; replace it with your quarter end. Assessment status, days past due and finding deadlines are recalculated at this date; tiers, residual scores and positions are as the register calculated them. Set the due-soon window and the TPM-01 target date to match the register's Summary sheet. |
| 5 | The Trend sheet holds last quarter's figures: type the three earlier quarters from the reports you kept. The last row comes from this quarter's data. |
| 6 | Read the four headline measures. Each has its target, its direction since last quarter and a status in words; the colour only repeats the word. Add a line of commentary to every measure that missed its target or moved. |
| 7 | For each High finding past its deadline, confirm it was escalated to the business owner and write what they decided (TP-08). For each supplier outside appetite, write the decision needed and the reference in the P05 Information Security Risk Register (TP-06). |
| 8 | Complete 'What to tell executive management' and take the report to [[e.g. Executive Committee]] every quarter (TP-12). Carry TPM-01 into the board report as BM-05 so both say the same. |
| 9 | Keep a copy of this workbook for each quarter as the record. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The EXAMPLE is a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, as at 2026-09-30: the same suppliers and findings as the Supplier Security Risk Register. 9 of 14 Tier 1 suppliers are assessed (was 6); 1 High finding is past its deadline; 6 providers support two or more critical services, 2 of them without an exit plan. The earlier quarters on the Trend sheet are EXAMPLE figures typed in.
Tailoring — small organisation: the report can be one page — the four measures, the late findings and the decisions. Take it to whoever runs the organisation, every quarter.
Tailoring — regulated entity: under NIS2 the management body approves and oversees the risk-management measures, which include supply chain security (Art 20(1), 21(2)(d)); take the report to it. A DORA financial entity assesses ICT concentration risk (Art 29(1)): show the providers several critical or important functions depend on, and keep each quarter's copy.
Tailoring — IT run by a service provider: ask the provider to confirm, before your quarter end, the status of any finding it owns and any change to the providers it relies on for your service.
Status words: In date, Due soon, Overdue, Planned, Not required for assessments; On target or Action needed for measures; "Within appetite", "Outside appetite, within tolerance", "Outside tolerance" for residual risk, the same words as the P05 pack.
Register Data
Paste the Register table of the Supplier Security Risk Register here as values (columns A–AM, from row 4). Columns AN–AY are calculated at the report date. The 14 EXAMPLE rows are that register's example — delete them first.
| Example | Supplier ref | Supplier | Supplier type | Business owner | Critical services supported | Critical services (number) | Data | Access | TC-1 Service | TC-2 Data | TC-3 Access | TC-4 Substitutability | Override | Tier | Tier set by | Questionnaire set | Reassess every (months) | Last assessed | Planned assessment | Next due | Assessment status | Days past due | Evidence validated (TP-04) | Open High findings | Open Medium findings | Open Low findings | High findings past deadline | Residual impact (1–4) | Residual likelihood (1–4) | Residual score | Residual band | Position against appetite | P05 risk register ref | Decision | Contract clauses in place (TP-07) | Exit plan (TP-11) | Record check | Notes | Tier 1 assessed in 12 months (calc) | Status at report date (calc) | Days past due (calc) | Assessed this quarter (calc) | Due next quarter (calc) | Concentration (calc) | Outside appetite (calc) | This quarter no. (calc) | Next quarter no. (calc) | Overdue no. (calc) | Concentration no. (calc) | Outside no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | SUP-001 | Managed IT service provider | IT | Head of IT | Online ordering; Warehouse dispatch; Finance and payroll | 3 | Customer data | Privileged | Tier 1 | Tier 1 | Tier 1 | Tier 1 | GDPR processor | Tier 1 | TC-1, TC-2, TC-3, TC-4 | A | 12 | 18 Nov 2025 | 18 Nov 2026 | Due soon | Yes | 0 | 0 | 0 | 0 | 3 | 1 | 3 | Low | Within appetite | R-06 | Approve | Yes | Yes | OK | P05 risk R-06 (treatment: Transfer). | Yes | Due soon | Reassessment | Yes | 1 | 1 | ||||||||
| EXAMPLE | SUP-002 | Cloud hosting provider | IT | Head of IT | Online ordering; Finance and payroll | 2 | Customer data | Network | Tier 1 | Tier 1 | Tier 1 | Tier 1 | GDPR processor | Tier 1 | TC-1, TC-2, TC-3, TC-4 | A | 12 | 27 Jan 2026 | 27 Jan 2027 | In date | Yes | 0 | 0 | 0 | 0 | 3 | 1 | 3 | Low | Within appetite | Approve with conditions | Yes | Yes | OK | F-04 closed 2026-03-30. | Yes | In date | Yes | 2 | |||||||||||
| EXAMPLE | SUP-003 | Payment service provider | Finance | Chief Financial Officer | Payments | 1 | Card data (held by the provider) | None | Tier 1 | Tier 1 | Tier 4 | Tier 1 | None | Tier 1 | TC-1, TC-2, TC-4 | A | 12 | 24 Feb 2026 | 24 Feb 2027 | In date | Yes | 0 | 0 | 0 | 0 | 3 | 1 | 3 | Low | Within appetite | Approve | Yes | Yes | OK | Yes | In date | ||||||||||||||
| EXAMPLE | SUP-004 | ERP software provider (hosted) | IT | Chief Financial Officer | Finance and payroll; Warehouse dispatch | 2 | Personal data | Remote support | Tier 1 | Tier 2 | Tier 2 | Tier 1 | GDPR processor | Tier 1 | TC-1, TC-4 | A | 12 | 21 Apr 2026 | 21 Apr 2027 | In date | Yes | 1 | 1 | 0 | 1 | 3 | 2 | 6 | Medium | Within appetite | Approve with conditions | Yes | Yes | High finding past deadline: escalate to the business owner (TP-08) | Conditions: F-01 and F-02 fixed by their deadlines. | Yes | In date | Yes | 3 | |||||||||||
| EXAMPLE | SUP-005 | Email and office software provider | IT | Head of IT | Customer contact | 1 | Personal data | None | Tier 1 | Tier 2 | Tier 4 | Tier 2 | GDPR processor | Tier 1 | TC-1 | A | 12 | 19 May 2026 | 19 May 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 1 | 2 | Low | Within appetite | Approve | Yes | Yes | OK | Yes | In date | ||||||||||||||
| EXAMPLE | SUP-006 | Security monitoring provider | IT | Head of Information Security | Online ordering; Warehouse dispatch | 2 | Log data | Privileged | Tier 1 | Tier 3 | Tier 1 | Tier 2 | None | Tier 1 | TC-1, TC-3 | A | 12 | 16 Jun 2026 | 16 Jun 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 1 | 2 | Low | Within appetite | Approve | Yes | Yes | OK | Yes | In date | Yes | 4 | ||||||||||||
| EXAMPLE | SUP-007 | National parcel carrier | Logistics | Head of Logistics | Warehouse dispatch | 1 | Customer addresses | Integration | Tier 1 | Tier 1 | Tier 2 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 14 Jul 2026 | 14 Jul 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 2 | 4 | Medium | Within appetite | Approve | Yes | Yes | OK | Yes | In date | Yes | 1 | ||||||||||||
| EXAMPLE | SUP-008 | Express courier | Logistics | Head of Logistics | Warehouse dispatch | 1 | Customer addresses | Integration | Tier 1 | Tier 1 | Tier 2 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 18 Aug 2026 | 18 Aug 2027 | In date | Yes | 0 | 0 | 0 | 0 | 2 | 1 | 2 | Low | Within appetite | Approve | Yes | Yes | OK | Yes | In date | Yes | 2 | ||||||||||||
| EXAMPLE | SUP-009 | Pallet network | Logistics | Head of Logistics | Warehouse dispatch | 1 | Customer addresses | Portal | Tier 1 | Tier 1 | Tier 4 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 15 Sep 2026 | 15 Sep 2027 | In date | Yes | 0 | 1 | 0 | 0 | 2 | 2 | 4 | Medium | Within appetite | Approve with conditions | Yes | Yes | OK | Condition: F-03 fixed by its deadline. | Yes | In date | Yes | 3 | |||||||||||
| EXAMPLE | SUP-010 | Warehouse management system provider | IT | Head of Logistics | Warehouse dispatch | 1 | Internal | Remote support | Tier 1 | Tier 3 | Tier 2 | Tier 1 | None | Tier 1 | TC-1, TC-4 | A | 12 | 20 Oct 2026 | 20 Oct 2026 | Planned | 0 | 0 | 0 | 0 | Yes | No | Agree an exit plan (TP-11) | No | Planned | First assessment | 2 | |||||||||||||||||||
| EXAMPLE | SUP-011 | Backup service provider | IT | Head of IT | Online ordering; Finance and payroll | 2 | Customer data | Network | Tier 1 | Tier 1 | Tier 1 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2, TC-3 | A | 12 | 3 Nov 2026 | 3 Nov 2026 | Planned | 0 | 0 | 0 | 0 | Yes | No | Agree an exit plan (TP-11) | No | Planned | First assessment | Yes | 3 | 5 | |||||||||||||||||
| EXAMPLE | SUP-012 | Payroll bureau | Finance | HR Director | Finance and payroll | 1 | Personal data (staff) | Portal | Tier 1 | Tier 1 | Tier 4 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 17 Nov 2026 | 17 Nov 2026 | Planned | 0 | 0 | 0 | 0 | Yes | No | Agree an exit plan (TP-11) | No | Planned | First assessment | 4 | |||||||||||||||||||
| EXAMPLE | SUP-013 | Outsourced customer contact centre | Service | Chief Operating Officer | Customer contact | 1 | Customer data | Remote user | Tier 1 | Tier 1 | Tier 2 | Tier 2 | GDPR processor | Tier 1 | TC-1, TC-2 | A | 12 | 1 Dec 2026 | 1 Dec 2026 | Planned | 0 | 0 | 0 | 0 | No | No | Add the tier's security clauses to the contract (TP-07) | Contract predates the policy; clauses added at renewal. | No | Planned | First assessment | 5 | ||||||||||||||||||
| EXAMPLE | SUP-014 | Network connectivity provider | IT | Head of IT | Online ordering; Warehouse dispatch | 2 | None stored | Network | Tier 1 | Tier 4 | Tier 1 | Tier 1 | None | Tier 1 | TC-1, TC-3, TC-4 | A | 12 | 8 Dec 2026 | 8 Dec 2026 | Planned | 0 | 0 | 0 | 0 | No | No | Add the tier's security clauses to the contract (TP-07) | Contract predates the policy; clauses added at renewal. | No | Planned | First assessment | Yes | 6 | 6 |
Findings Data
Paste the register's Findings table here as values (columns A–O, from row 4). Columns P–S are calculated at the report date. EXAMPLE: that register's example.
| Example | Finding ID | Supplier ref | Supplier | Severity | Finding | Owner | Raised | Deadline | Status | Closed on | Days past deadline | Deadline flag | Escalated to business owner on | Notes | Open (calc) | Days to deadline (calc) | Past deadline (calc) | Open no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | F-01 | SUP-004 | ERP software provider (hosted) | High | Support staff reach our ERP without multi-factor authentication | Chief Financial Officer | 21 Apr 2026 | 20 Jul 2026 | Open | 72 | Past deadline | 21 Jul 2026 | Escalated to the business owner the day after the deadline (TP-08). | Yes | -72 | Past deadline | 1 | |
| EXAMPLE | F-02 | SUP-004 | ERP software provider (hosted) | Medium | No evidence that our data is deleted at contract end | Chief Financial Officer | 21 Apr 2026 | 18 Oct 2026 | Open | Yes | 18 | 2 | ||||||
| EXAMPLE | F-03 | SUP-009 | Pallet network | Medium | Shared portal accounts used by depot staff | Head of Logistics | 15 Sep 2026 | 14 Mar 2027 | Open | Yes | 165 | 3 | ||||||
| EXAMPLE | F-04 | SUP-002 | Cloud hosting provider | High | Penetration test older than 12 months | Head of IT | 27 Jan 2026 | 27 Apr 2026 | Closed | 30 Mar 2026 | New penetration test summary received and checked. |
Metric Definitions
Metric definitions
The four headline measures of the Third-Party Security Policy, defined once so every quarter is calculated the same way (TP-12).
| Measure | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| TPM-01 Tier 1 suppliers assessed | Tier 1 suppliers with an assessment within the last 12 months, out of all Tier 1 suppliers. | Tier 1 rows whose last assessment is within the 12 months up to the report date, out of all Tier 1 rows. On target while every other Tier 1 supplier has a planned assessment before the target date. | All Tier 1 by [[year end]] | The board measure BM-05 in the P03 pack, in the same words: "n of N critical suppliers". Higher is better. |
| TPM-02 Reassessments overdue | Suppliers past their tier's reassessment interval. | Rows whose next due date is before the report date, including a supplier never assessed whose planned date has passed; and of those, more than 90 calendar days past it. | Zero Tier 1; none more than 90 days overdue | An overdue reassessment is a supplier whose security nobody has checked within its tier's interval (TP-09). Name each one with its business owner. |
| TPM-03 High findings past deadline | Open High findings past their remediation deadline. | Open High findings whose deadline is before the report date. | Zero | Each must have been escalated to the supplier's business owner (TP-08). Show the escalation date and what the owner decided. |
| TPM-04 Concentration | Providers that two or more critical services depend on. | Rows supporting 2 or more of the critical services on the register's Critical Services sheet; and of those, without an exit plan. | Each one known, with an exit plan (TP-11) | Not a number to drive down: it shows where one failure would stop several services. What matters is that each has an exit plan (TP-11). |
Quarterly Report
Third-party security risk — quarterly report
Yellow cells are yours: the report settings, the commentary and the decisions. Everything else is calculated. Every status is in words; the colour only repeats it.
Report settings
| Setting | Value | |
|---|---|---|
| Report date (the quarter end) | 30 Sep 2026 | EXAMPLE report date: replace with your quarter end. |
| Quarter | Q3 2026 | |
| Due soon: calendar days before the next due date | 90 | As on the register's Summary sheet. |
| Target date: all Tier 1 suppliers assessed (TPM-01) | 31 Dec 2026 | EXAMPLE: the year end, from the target "All Tier 1 by [[year end]]". |
Summary
9 of 14 Tier 1 suppliers assessed in the last 12 months; the other 5 are all planned by 2026-12-31. 1 High finding is past deadline; 0 reassessments are overdue.
Headline measures
| Measure | This quarter | Last quarter | Direction | Target | Status | Commentary — what changed, and why | ||
|---|---|---|---|---|---|---|---|---|
| TPM-01 Tier 1 suppliers assessed | 9 of 14 | 6 of 14 | Better (was 6) | All Tier 1 by [[year end]] | On target | [[EXAMPLE: Better: the three logistics suppliers (SUP-007, SUP-008, SUP-009) were assessed this quarter; the remaining five are planned for Q4. SUP-001's reassessment falls due on 2026-11-18 and must be done to keep 14 of 14 at year end.]] | ||
| TPM-02 Reassessments overdue | 0 | 0 | Same | Zero Tier 1; none more than 90 days overdue | On target | |||
| more than 90 days overdue | 0 | 0 | Same | 0 | ||||
| TPM-03 High findings past deadline | 1 | 0 | Worse (was 0) | Zero | Action needed | [[EXAMPLE: F-01 (ERP software provider (hosted): support staff reach our ERP without multi-factor authentication) passed its deadline on 2026-07-20 and was escalated to the Chief Financial Officer on 2026-07-21 (TP-08).]] | ||
| TPM-04 Concentration: providers | 6 | 6 | Same | Each one known, with an exit plan (TP-11) | Action needed | |||
| of those, without an exit plan | 2 | 2 | Same | 0 | [[EXAMPLE: Backup service provider (SUP-011) and network connectivity provider (SUP-014) have no exit plan yet; each is written at its Q4 assessment (TP-11).]] | |||
TPM-01 is the board measure BM-05. Last quarter comes from the Trend sheet. Tiers, scores and positions are as the register calculated them; status and deadlines are recalculated at the report date.
Assessments completed this quarter
| Supplier | Business owner | Assessed | Residual | Position | Decision | Open findings | Exit plan | Next due |
|---|---|---|---|---|---|---|---|---|
| SUP-007 National parcel carrier | Head of Logistics | 14 Jul 2026 | 4 (Medium) | Within appetite | Approve | 0 | Yes | 14 Jul 2027 |
| SUP-008 Express courier | Head of Logistics | 18 Aug 2026 | 2 (Low) | Within appetite | Approve | 0 | Yes | 18 Aug 2027 |
| SUP-009 Pallet network | Head of Logistics | 15 Sep 2026 | 4 (Medium) | Within appetite | Approve with conditions | 1 | Yes | 15 Sep 2027 |
Due next quarter: first assessments and reassessments
| Supplier | Business owner | Type | Due or planned | Tier | Critical services | Exit plan | Contract clauses | Status now |
|---|---|---|---|---|---|---|---|---|
| SUP-001 Managed IT service provider | Head of IT | Reassessment | 18 Nov 2026 | Tier 1 | 3 | Yes | Yes | Due soon |
| SUP-010 Warehouse management system provider | Head of Logistics | First assessment | 20 Oct 2026 | Tier 1 | 1 | No | Yes | Planned |
| SUP-011 Backup service provider | Head of IT | First assessment | 3 Nov 2026 | Tier 1 | 2 | No | Yes | Planned |
| SUP-012 Payroll bureau | HR Director | First assessment | 17 Nov 2026 | Tier 1 | 1 | No | Yes | Planned |
| SUP-013 Outsourced customer contact centre | Chief Operating Officer | First assessment | 1 Dec 2026 | Tier 1 | 1 | No | No | Planned |
| SUP-014 Network connectivity provider | Head of IT | First assessment | 8 Dec 2026 | Tier 1 | 2 | No | No | Planned |
Overdue reassessments (TPM-02)
| Supplier | Business owner | Tier | Next due | Days past due | Residual | Decision | Exit plan | Notes |
|---|
None overdue
Open findings (TPM-03 and TP-08)
| Finding | Supplier | Severity | Owner | Deadline | Days to deadline | Flag | Escalated on | Notes |
|---|---|---|---|---|---|---|---|---|
| F-01 Support staff reach our ERP without multi-factor authentication | SUP-004 ERP software provider (hosted) | High | Chief Financial Officer | 20 Jul 2026 | -72 | Past deadline | 21 Jul 2026 | Escalated to the business owner the day after the deadline (TP-08). |
| F-02 No evidence that our data is deleted at contract end | SUP-004 ERP software provider (hosted) | Medium | Chief Financial Officer | 18 Oct 2026 | 18 | |||
| F-03 Shared portal accounts used by depot staff | SUP-009 Pallet network | Medium | Head of Logistics | 14 Mar 2027 | 165 |
Concentration: providers 2 or more critical services depend on (TPM-04)
| Supplier | Critical services supported | Number | Tier | Status now | Residual | Exit plan | Contract clauses | Business owner |
|---|---|---|---|---|---|---|---|---|
| SUP-001 Managed IT service provider | Online ordering; Warehouse dispatch; Finance and payroll | 3 | Tier 1 | Due soon | 3 (Low) | Yes | Yes | Head of IT |
| SUP-002 Cloud hosting provider | Online ordering; Finance and payroll | 2 | Tier 1 | In date | 3 (Low) | Yes | Yes | Head of IT |
| SUP-004 ERP software provider (hosted) | Finance and payroll; Warehouse dispatch | 2 | Tier 1 | In date | 6 (Medium) | Yes | Yes | Chief Financial Officer |
| SUP-006 Security monitoring provider | Online ordering; Warehouse dispatch | 2 | Tier 1 | In date | 2 (Low) | Yes | Yes | Head of Information Security |
| SUP-011 Backup service provider | Online ordering; Finance and payroll | 2 | Tier 1 | Planned | No | Yes | Head of IT | |
| SUP-014 Network connectivity provider | Online ordering; Warehouse dispatch | 2 | Tier 1 | Planned | No | No | Head of IT |
Suppliers outside appetite for third-party dependency (TP-06)
| Supplier | Business owner | Residual | Position | Decision | P05 register ref | Decision needed | ||
|---|---|---|---|---|---|---|---|---|
None: every assessed supplier is within appetite
A supplier outside appetite is entered in the P05 Information Security Risk Register; its owner decides the treatment there (TP-06).
What to tell executive management
| Point | What to say | |||||||
|---|---|---|---|---|---|---|---|---|
| Summary (one sentence) | 9 of 14 Tier 1 suppliers assessed in the last 12 months; the other 5 are all planned by 2026-12-31. 1 High finding is past deadline; 0 reassessments are overdue. | |||||||
| Direction: better or worse, and why | [[EXAMPLE: Better: 9 of 14 critical suppliers assessed, up from 6; all five remaining are planned for Q4, so 14 of 14 by year end is on target.]] | |||||||
| What could hurt us most | [[EXAMPLE: One High finding past its deadline at the ERP software provider (hosted) (F-01): support staff reach our ERP without multi-factor authentication.]] | |||||||
| Decisions needed | [[EXAMPLE: Ask the Chief Financial Officer for the supplier's fix date for F-01, or a decision to restrict its support access until it is fixed. Note that two concentration providers still need exit plans.]] | |||||||
| Prepared by (name, role) and date | [[Name, role, YYYY-MM-DD]] | |||||||
Trend
Trend — the last four quarters
The headline measures at each of the last four quarter ends. Type the three earlier quarters from the reports you kept; the last row is calculated from this quarter's data. Direction compares each quarter with the one before.
| Quarter end | Quarter | TPM-01 assessed | Tier 1 suppliers | TPM-02 overdue | TPM-02 over 90 days | TPM-03 High past deadline | TPM-04 providers | TPM-04 without exit plan | TPM-01 direction | Commentary |
|---|---|---|---|---|---|---|---|---|---|---|
| 31 Dec 2025 | Q4 2025 | 1 | 14 | 0 | 0 | 0 | 6 | 5 | — | [[EXAMPLE figures: replace with your own]] |
| 31 Mar 2026 | Q1 2026 | 3 | 14 | 0 | 0 | 0 | 6 | 4 | Better (was 1) | [[EXAMPLE figures: replace with your own]] |
| 30 Jun 2026 | Q2 2026 | 6 | 14 | 0 | 0 | 0 | 6 | 2 | Better (was 3) | [[EXAMPLE figures: replace with your own]] |
| 30 Sep 2026 | Q3 2026 | 9 | 14 | 0 | 0 | 1 | 6 | 2 | Better (was 6) |
EXAMPLE: the three earlier quarters are typed in, as you would from the reports kept for them. 2026-06-30: 6 of 14 Tier 1 suppliers assessed — the "was 6" in the board report.
For this workbook's example, the earlier figures assume the example firm's supplier assessments began in November 2025 and each exit plan was agreed at the first assessment.
Lists
| Status | Position | MeasureStatus | NextQuarterType |
|---|---|---|---|
| In date | Within appetite | On target | First assessment |
| Due soon | Outside appetite, within tolerance | Action needed | Reassessment |
| Overdue | Outside tolerance |
Planned
Not required
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Report date | The quarter end the report is for. Assessment status, days past due and finding deadlines are calculated at this date. |
| Assessment status | In date; Due soon (next due within the due-soon window, 90 calendar days by default); Overdue (next due date passed, or never assessed and the planned date passed); Planned (not yet assessed, planned date ahead); Not required (a tier reassessed only on change). |
| Assessed this quarter | Last assessed after the previous quarter end and on or before the report date. |
| Due next quarter | Next due (or planned) after the report date and on or before the end of the next quarter: a first assessment if the supplier has never been assessed, otherwise a reassessment. |
| Concentration provider | A supplier 2 or more critical services depend on (TPM-04). Every Tier 1 and Tier 2 contract must have an exit plan: data return or deletion, access removal, and a transition period. |
| Past deadline | An open finding whose deadline is before the report date. Every finding must have an owner and a deadline set by its severity; a High finding past its deadline must be escalated to the business owner. |
| Position | Within appetite; Outside appetite, within tolerance; Outside tolerance: the supplier's residual band against the appetite for third-party dependency, as the register calculated it (TP-06). |
| Direction | Better, Same or Worse than last quarter, with last quarter's figure: for example Better (was 6). For TPM-01 higher is better; for the others lower is better. |
| TPM-01 Tier 1 suppliers assessed | Tier 1 suppliers with an assessment within the last 12 months, out of all Tier 1 suppliers. Target: all Tier 1 by [[year end]]. |
| TPM-02 Reassessments overdue | Suppliers past their tier's reassessment interval. Target: zero Tier 1; none more than 90 days overdue. |
| TPM-03 High findings past deadline | Open High findings past their remediation deadline. Target: zero. |
| TPM-04 Concentration | Providers that two or more critical services depend on. Target: each one known, with an exit plan (TP-11). |
| (calc) | A column the workbook calculates. Do not type or paste over it. |
| TP-nn, TPM-nn | Rule and measure numbers in the Third-Party Security Policy. |
| EXAMPLE | The example organisation's figures as at 2026-09-30. Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | The workbook as a whole: four defined measures, calculated the same way each quarter, analysed and reported |
| ISO/IEC 27001:2022 | Annex A 5.22 — Monitoring, review and change management of supplier services | Assessments this quarter, due next quarter and overdue; open findings and their deadlines: supplier security monitored and reviewed |
| NIST CSF 2.0 | GV.SC-09 — “Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle” | Headline measures against targets and the Trend: supply chain security performance monitored and reported to executive management |
| NIST CSF 2.0 | GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship” | Open findings, escalation and suppliers outside appetite: supplier risk responded to and monitored through the relationship |
| DORA — Regulation (EU) 2022/2554 | Article 29(1) — assessing concentration risk: providers not easily substitutable, or several arrangements with the same provider | Concentration: providers several critical services depend on, with their exit plans |
| NIS2 — Directive (EU) 2022/2555 | Article 21(2)(d) — “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” | The quarterly report as management's oversight of supply chain security |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)