Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Tiered Supplier Security Questionnaire

Provides four proportionate questionnaire sets matched to supplier tier, so low-risk vendors are not sent a 200-question audit.

Available soon

Format
Excel
Size
136 KB
Length
14 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Question Bank
  • Set A
  • Set B
  • Set C
  • Set D
  • Results
  • Export
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Tier first. Every supplier is screened and tiered before it is assessed (TP-01, TP-02), using the Supplier Criticality & Tiering Model. The tier decides the set: Tier 1 (Critical) gets Set A; Tier 2 (Important) gets Set B; Tier 3 (Standard) gets Set C; Tier 4 (Minimal) gets Set D. Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. (TP-03)
2Question Bank sheet: read the questions and adapt them before first use. Change wording, add service-specific questions in the empty rows at the bottom (give each an ID, a domain and the smallest set it belongs in), or move a question to a different set by changing 'Smallest set'. The set sheets update themselves.
3Set D is the intake screening of the Supplier Criticality & Tiering Model, asked word for word: the business owner answers it at intake, with the supplier's help where needed. A Tier 4 supplier is sent nothing more.
4To send a set: right-click its tab, choose Move or Copy, tick 'Create a copy' and copy it to a new workbook. In the copy, select all, Copy, then Paste Special → Values, so it no longer depends on the bank. Delete the verdict, note, severity, finding and check columns (L to R) and send it. The supplier fills Answer (column J) and Evidence supplied (column K) and returns the evidence named in column I.
5When the answers come back, paste the Answer and Evidence supplied columns (values only) into the same rows of the set sheet in this workbook. Check the question IDs line up.
6Validate the evidence with the Supplier Due Diligence Evidence Checklist: scope, dates and the supplier's legal name are checked against the service we buy (TP-04). An answer the evidence does not support is not Meets.
7For each question choose a verdict (column L): Meets, Partly, Does not meet or Not applicable. Write a note (column M) for anything other than Meets: what falls short, or why it does not apply.
8For each Partly or Does not meet, propose a severity (column N) using the definitions on this sheet. High: a gap that could directly cause a significant incident or data loss at this supplier. Give the finding its reference (column O) when it is entered in the Supplier Security Risk Register.
9Clear every Check (column P) that does not say Complete or Finding proposed.
10Results sheet: enter the supplier, its tier, the set answered and the assessment date. Read the counts, the domain results and the proposed findings, with their deadlines. Take them into the Supplier Security Review Report Template, where the residual risk is scored on the P05 scale and the decision is made and signed by the business owner (TP-05, TP-06).
11Export sheet: the answered set in one table. Copy it and paste as values into your records or attach it to the Supplier Security Review Report Template.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The sets. Set A: 60 questions for Tier 1 — about 60. Set B: 35 questions for Tier 2 — about 35. Set C: 15 questions for Tier 3 — about 15. Set D: 5 questions for Tier 4 — about 5 (intake screening only). Sets nest: every question in Set D is also in Set C, every Set C question is in Set B, and every Set B question is in Set A. 'Smallest set' on the Question Bank says where a question first appears.

Answer scale. There is no score. Each question has an acceptable answer (its scoring anchor), and the assessor's verdict says whether the answer and evidence meet it: Meets — the answer, and the evidence where asked for, meets the acceptable answer. Partly — some of the acceptable answer is met; a gap remains. Propose a finding. Does not meet — the acceptable answer is not met, or the supplier could not show it. Propose a finding. Not applicable — the question does not apply to this service; the note says why.

Weights. Questions are not weighted and verdicts are not added up: one missing control can matter more than fifty good answers. Instead, each shortfall becomes a proposed finding with a severity, and the severity sets the remediation deadline, counted in calendar days from the assessment date: High 90 calendar days; Medium 180 calendar days; Low tracked to the next assessment (TP-08).

High: A gap that could directly cause a significant incident or data loss at this supplier.

Medium: A gap that weakens a control but has other protection around it.

Low: An improvement; tracked to the next assessment.

The EXAMPLE. Set A is filled in with the answers of SUP-004, the ERP software provider (hosted) used by the example organisation (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders), assessed on 2026-04-21. Column A of the Set A sheet says EXAMPLE on each answered row. Two answers fall short: ACC-03 (support staff without multi-factor authentication) becomes F-01, High, due 2026-07-20; DAT-05 (no evidence of deletion at contract end) becomes F-02, Medium, due 2026-10-18. The supplier was approved with conditions: those two findings fixed by their deadlines.

To clear the example: on the Set A sheet delete the contents of columns A and J to O (not the rows). On the Results sheet replace the yellow assessment details. Nothing else needs changing.

Tailoring — small organisation: most suppliers will be Tier 3 or 4, so Set C and the intake are what you will use most. Keep Set A for the few suppliers that run a critical service. Where a supplier's certification or report (EV-02, EV-03) covers a question and its scope matches the service, write 'Covered by EV-02' in Evidence supplied rather than asking for more.

Tailoring — regulated entity: NIS2 Article 21(2)(d) and 21(3) expect supply-chain security that takes account of each direct supplier's vulnerabilities, the quality of its products and cybersecurity practices, and its secure development: keep the Vulnerabilities and Secure development domains in Sets A and B. Under DORA (Articles 28 to 30), an ICT provider supporting a critical or important function is Tier 1 whatever the criteria say; add questions on audit and access rights, participation in your testing and exit strategies (Article 30(3)), and keep the answered set with the contract record. Under GDPR Article 28(1), the Data protection and Subcontractors answers are the processor's 'sufficient guarantees': have the Data Protection Officer review them.

Tailoring — IT run by a service provider: a managed IT provider is almost always Tier 1 (like the example's SUP-001). Send it Set A, and ask it to answer the Subcontractors questions for every provider it uses on your behalf. If the provider manages other suppliers for you, the business owner still makes and signs the decision (TP-05).

Limitations: see the foot of the Results sheet.

Question Bank

60 questions in 10 domains. 'Smallest set' decides which sets include a question (D = every set). Columns I to P are calculated. Add your own questions in the empty rows below.

IDDomainQuestionAnswered byWhy we askAcceptable answerEvidence to request (Evidence Checklist item)Smallest set it is inIn Set AIn Set BIn Set CIn Set DSet A no.Set B no.Set C no.Set D no.
GOV-01GovernanceWill it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)?Business owner, at intakeAn override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02).A clear yes or no to each part.EV-01 Completed questionnaire for the supplier's tierDYesYesYesYes1111
GOV-02GovernanceDo you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers.SupplierShows how much of your security someone independent has checked, and whether that check covers our service.A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy.EV-02 Security certification with its scope statement; EV-03 Independent assurance reportCYesYesYes—222
GOV-03GovernanceDo you have an information security policy approved by your senior management and reviewed in the last 12 months?SupplierShows that security has an owner at the top of your organisation and is kept current.Yes: approved by a named senior role and reviewed within the last 12 months.EV-05 Key security policies with evidence they operateBYesYes——33
GOV-04GovernanceWho is accountable for information security in your organisation, and how do we reach them?SupplierWe need a named person who can answer for security decisions that affect our service.A named role with the authority to act, and contact details.EV-01 Completed questionnaire for the supplier's tierBYesYes——44
GOV-05GovernanceHow do you assess and treat the information security risks to the service you provide to us?SupplierA supplier that manages its own risks is less likely to pass them on to its customers.A documented method, a risk register reviewed at least once a year, and named owners for treatment.EV-05 Key security policies with evidence they operate; EV-02 Security certification with its scope statementAYes———5
GOV-06GovernanceHas an internal audit or independent review of your security controls been done in the last 12 months? What did it find, and what is still open?SupplierWhat an audit found, and how quickly it was fixed, tells us more than a certificate alone.Yes; the findings summarised; any open finding has an owner and a date.EV-02 Security certification with its scope statement; EV-03 Independent assurance reportAYes———6
GOV-07GovernanceHow do you tell customers about a material change to the service, such as a new hosting location, a new sub-processor or a change of ownership?SupplierA material change can change our risk, and it triggers a reassessment (TP-09).Written notice in advance, with a stated notice period and a way for us to object.EV-10 Data processing termsAYes———7
ACC-01Access and identityWhat access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level?Business owner, at intakePlaces the supplier on tiering criterion TC-3 (Access).A clear answer: none, supervised on site, remote user, or privileged or network-level.EV-01 Completed questionnaire for the supplier's tierDYesYesYesYes8532
ACC-02Access and identityDoes every person who can reach our data or systems have their own named account, with no shared log-ins?SupplierWith shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave.Yes: named accounts only; any service accounts listed with an owner.EV-09 Access control evidence for people who reach our data or systemsCYesYesYes—964
ACC-03Access and identityIs multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff?SupplierStolen passwords are the most common way in; multi-factor authentication stops most attacks that use them.Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited.EV-09 Access control evidence for people who reach our data or systemsCYesYesYes—1075
ACC-04Access and identityHow quickly is a person's access to our data or systems removed when they leave or change role?SupplierAccess left behind by leavers is a common route for misuse.Within one working day of leaving, through a joiner, mover and leaver process that leaves a record.EV-09 Access control evidence for people who reach our data or systemsBYesYes——118
ACC-05Access and identityHow often is access to our data or systems reviewed, and by whom?SupplierReviews catch access that is no longer needed.At least every [[6]] months, by a manager who does not hold the access, with the removals recorded.EV-09 Access control evidence for people who reach our data or systemsBYesYes——129
ACC-06Access and identityHow is administrator (privileged) access controlled: who has it, is it separate from everyday accounts, and is its use logged?SupplierAdministrator accounts can do the most damage if misused or taken over.Few named people; separate administrator accounts; use logged and reviewed.EV-09 Access control evidence for people who reach our data or systemsAYes———13
ACC-07Access and identityHow does your remote access to our systems work: by what route, can we see who connected, and can we suspend it?SupplierRemote support routes are a common way attackers reach a supplier's customers.One secured route; every session logged; we can see who connected and suspend access.EV-09 Access control evidence for people who reach our data or systemsAYes———14
ACC-08Access and identityAre access logs for our data and systems kept, for how long, and can we have them for an investigation?SupplierWithout logs an incident cannot be investigated.Kept at least [[12 months]]; given to us on request within an agreed time.EV-09 Access control evidence for people who reach our data or systemsAYes———15
DAT-01Data protectionWhat data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale?Business owner, at intakePlaces the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28.A clear list of the kinds of data, or 'none'.EV-01 Completed questionnaire for the supplier's tierDYesYesYesYes161063
DAT-02Data protectionIs our data encrypted when it travels over networks and when it is stored, including in backups?SupplierEncryption keeps data safe if a network, disk or backup is exposed.Yes: current encryption in transit on every network, and at rest including backups.EV-05 Key security policies with evidence they operateCYesYesYes—17117
DAT-03Data protectionIn which countries is our data stored, processed and supported, including backups?SupplierLocation affects legal duties, such as rules on transferring personal data, and who could demand access to it.Every location named, including backups and support, matching the contract.EV-11 Data location and hosting statementBYesYes——1812
DAT-04Data protectionIf you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)?SupplierThe law requires a binding contract with every processor (GDPR Article 28(3)).Yes: covering documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits.EV-10 Data processing termsBYesYes——1913
DAT-05Data protectionAt the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give?SupplierExit is where data is most often forgotten; every Tier 1 and Tier 2 contract needs an exit plan (TP-11).Returned in a usable format; deleted from live systems and backups within a stated time; a written certificate of deletion.EV-12 Data return and deletion procedureBYesYes——2014
DAT-06Data protectionHow is our data kept apart from other customers' data?SupplierIn a shared service a weakness in separation exposes every customer.Separation described, and tested, for example in the penetration test.EV-06 Penetration test summaryAYes———21
DAT-07Data protectionIs our data used for anything other than providing the service to us, such as testing, analytics or training software?SupplierOther uses multiply the places our data can leak from and may be unlawful for personal data.No; or only as the contract allows, with personal data removed first.EV-10 Data processing termsAYes———22
VUL-01Vulnerabilities and patchingHow quickly do you apply security updates to the systems that deliver our service?SupplierMost attacks use weaknesses for which an update already exists.Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded.EV-07 Vulnerability and patch status reportCYesYesYes—23158
VUL-02Vulnerabilities and patchingDo you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed?SupplierScanning finds what patching missed.At least monthly; findings tracked with an owner and a deadline.EV-07 Vulnerability and patch status reportBYesYes——2416
VUL-03Vulnerabilities and patchingDoes the service run on any system or software its maker no longer supports (end of life)?SupplierUnsupported software no longer gets security updates.No; or each one listed with extra protection and a replacement date.EV-07 Vulnerability and patch status reportAYes———25
VUL-04Vulnerabilities and patchingWhen was the service last penetration tested by an independent tester, what was in scope, and are the serious findings fixed?SupplierA test shows how an attacker would actually get in.Within the last 12 months; the service we use in scope; High and Critical findings fixed or on a dated plan.EV-06 Penetration test summaryAYes———26
VUL-05Vulnerabilities and patchingHow do you protect the service against malware, and how do you detect an attack on it?SupplierPrevention fails sometimes; detection limits the damage.Malware protection on servers and staff devices, and security monitoring with alerts that are acted on at any hour.EV-05 Key security policies with evidence they operateAYes———27
DEV-01Secure developmentIf you write the software we use, do you follow a documented secure development process?SupplierSecurity built in during development costs less than fixing weaknesses after release (NIS2 Article 21(3) names secure development).Yes: documented, covering security requirements, peer review and security testing before release. Or Not applicable: you do not write it.EV-08 Secure development evidenceBYesYes——2817
DEV-02Secure developmentAre changes to the service tested and approved before they go live, and can they be rolled back?SupplierUntested changes cause outages and open security gaps.Yes: a separate test environment, approval recorded, and a rollback plan.EV-08 Secure development evidenceBYesYes——2918
DEV-03Secure developmentDo you check your code, and the open-source components it uses, for known vulnerabilities before release?SupplierMost applications are largely made of open-source components, each with its own weaknesses.Automated checks on every build; release stopped on a Critical finding.EV-08 Secure development evidenceAYes———30
DEV-04Secure developmentWho can change the live code or data of the service, and are they different from the people who write the code?SupplierSeparating those who write code from those who release it stops one person making an unchecked change.Releases through an approved pipeline only; developers cannot change live systems directly.EV-08 Secure development evidence; EV-09 Access control evidence for people who reach our data or systemsAYes———31
DEV-05Secure developmentHow do you tell customers about security vulnerabilities in your product, and about their fixes?SupplierWe need to know when we are exposed and what to do.Security notices to customers' administrators, with the fix and any action we must take.EV-08 Secure development evidenceAYes———32
INC-01Incident managementWho do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service?SupplierCritical suppliers are part of our incident response, with named contacts and notification duties (TP-10).A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time.EV-13 Incident contacts and notification commitmentCYesYesYes—33199
INC-02Incident managementDo you have a documented incident response plan, and when was it last tested?SupplierAn untested plan usually fails at the first real incident.Yes: tested within the last 12 months.EV-13 Incident contacts and notification commitmentCYesYesYes—342010
INC-03Incident managementWhat will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2?SupplierWe may have to report within fixed times, and we cannot do it without your facts.Initial facts quickly, regular updates and a final report; help with our reporting written into the contract.EV-13 Incident contacts and notification commitment; EV-10 Data processing termsBYesYes——3521
INC-04Incident managementHave you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards?SupplierHow a supplier learnt from an incident says more than a clean record.An open answer; any lessons and changes described.EV-13 Incident contacts and notification commitmentBYesYes——3622
INC-05Incident managementWill you take part in our incident exercises, or share the results of your own for the service we use?SupplierExercising together finds the gaps between our plans and yours (TP-10).Yes, on reasonable notice, at least once a year for a critical service.EV-14 Continuity and recovery test resultsAYes———37
INC-06Incident managementHow would you preserve evidence and support an investigation of an incident affecting our data?SupplierEvidence lost in the first hours cannot be recovered.Logs and system images preserved; we or our investigator can have them.EV-13 Incident contacts and notification commitmentAYes———38
CON-01Continuity and exitWhich of our services does it run or support, and would any critical service stop or degrade if it failed?Business owner, at intakePlaces the supplier on tiering criterion TC-1 (Service).The services named, and what would stop or degrade.EV-01 Completed questionnaire for the supplier's tierDYesYesYesYes3923114
CON-02Continuity and exitIf it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime?Business owner, at intakePlaces the supplier on tiering criterion TC-4 (Substitutability).An estimate of the time to replace it, and the effect meanwhile.EV-01 Completed questionnaire for the supplier's tierDYesYesYesYes4024125
CON-03Continuity and exitIf your service stopped, how quickly would it be restored, and how much of our data could be lost?SupplierWe need to know whether your recovery meets what our services need.A recovery time and a maximum data loss, both within [[what our service needs]].EV-14 Continuity and recovery test resultsCYesYesYes—412513
CON-04Continuity and exitAre backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored?SupplierBackups on the same system are lost with it.Yes: separate, protected against deletion or change, and restores tested at least every [[3 months]].EV-14 Continuity and recovery test resultsBYesYes——4226
CON-05Continuity and exitDo you have a continuity plan for the service, and when was it last tested?SupplierA plan that has not been tested may not work when it is needed.Yes: tested within the last 12 months, with the results and fixes available to us.EV-14 Continuity and recovery test resultsBYesYes——4327
CON-06Continuity and exitIf our contract ends, or you stop trading, how would we get our data back and move the service elsewhere?SupplierEvery Tier 1 and Tier 2 contract needs an exit plan: data return or deletion, access removal and a transition period (TP-11).Export in a usable format, help with the move, and a transition period, all written into the contract.EV-12 Data return and deletion procedureBYesYes——4428
CON-07Continuity and exitWhat happens to our service if one of your own key suppliers, such as your hosting provider, fails?SupplierYour suppliers' failures become ours.The dependency named, with a tested alternative or recovery plan.EV-14 Continuity and recovery test results; EV-15 Subcontractor and sub-processor listAYes———45
SUB-01Subcontractors and sub-processorsWill any other company handle our data or deliver part of the service to us? If so, which companies, and for what?SupplierEach such company is part of our supply chain, and for personal data it is a sub-processor.A list, or 'none'.EV-15 Subcontractor and sub-processor listCYesYesYes—462914
SUB-02Subcontractors and sub-processorsDo your contracts hold those companies to security requirements at least as strict as ours?SupplierOur requirements mean little if they stop at your door.Yes: in their contracts, with their assurance checked.EV-15 Subcontractor and sub-processor listBYesYes——4730
SUB-03Subcontractors and sub-processorsWill you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data?SupplierA processor may not use another processor without the controller's prior written authorisation (GDPR Article 28(2)).Yes: advance notice with the right to object, written into the contract.EV-10 Data processing terms; EV-15 Subcontractor and sub-processor listBYesYes——4831
SUB-04Subcontractors and sub-processorsHow do you assess and monitor the security of your own critical suppliers?SupplierShows whether you manage your supply chain as we manage ours.Suppliers ranked by risk, assessed before contract and reviewed at least once a year.EV-15 Subcontractor and sub-processor listAYes———49
SUB-05Subcontractors and sub-processorsIs any part of the service delivered from outside [[our country or region]]? Which, and with what safeguards?SupplierDelivery from other countries can bring legal duties and access risks.None; or each one named, with the safeguards for any transfer of personal data.EV-11 Data location and hosting statement; EV-15 Subcontractor and sub-processor listAYes———50
SUB-06Subcontractors and sub-processorsPlease name the providers the service depends on (for example cloud, network and software providers) so that we can check them against our other critical suppliers.SupplierSeveral critical services relying on one provider is concentration risk (TPM-04).The providers named.EV-15 Subcontractor and sub-processor listAYes———51
PPL-01PeopleAre the staff who can reach our data screened before they start, as far as the law allows?SupplierScreening reduces the risk from people in trusted roles.Yes: identity, right to work and references at least; more for administrators.EV-16 Staff screening and training summaryCYesYesYes—523215
PPL-02PeopleDo staff receive security awareness training when they join and at least once a year?SupplierMost incidents involve a human mistake.Yes: at joining and at least once a year, with completion tracked.EV-16 Staff screening and training summaryBYesYes——5333
PPL-03PeopleAre staff bound by confidentiality duties that continue after they leave?SupplierConfidentiality should outlast employment.Yes: in employment and contractor agreements.EV-16 Staff screening and training summaryAYes———54
PPL-04PeopleDo staff with administrator access receive extra security training, for example on social engineering and safe administration?SupplierAttackers target the people with the most access.Yes: at least once a year, for every administrator.EV-16 Staff screening and training summaryAYes———55
PHY-01Physical security and hostingWhere is the service hosted: your own premises, a data centre or a cloud provider? Please name them.SupplierTells us who else holds our data, and whose physical security we rely on.The hosting named.EV-11 Data location and hosting statementBYesYes——5634
PHY-02Physical security and hostingHow are the premises or data centres that hold our data protected against unauthorised entry?SupplierPhysical access can bypass every other control.Entry control, visitor records and monitoring; or the hosting provider's certification or report covering them.EV-02 Security certification with its scope statement; EV-11 Data location and hosting statementBYesYes——5735
PHY-03Physical security and hostingAre those facilities protected against fire, flood and power loss, and is the protection tested?SupplierEnvironmental failures stop services as surely as attacks do.Yes: covered by an independent report or certification, or by test records.EV-03 Independent assurance report; EV-11 Data location and hosting statementAYes———58
PHY-04Physical security and hostingHow are equipment and storage media that held our data disposed of?SupplierDiscarded disks are a common source of data leaks.Secure erasure or destruction, with a record.EV-12 Data return and deletion procedureAYes———59
PHY-05Physical security and hostingWill your staff visit our premises or connect equipment to our network? If so, under what supervision?SupplierVisits and connected equipment bring access inside our defences.No; or visits supervised and equipment approved before connection.EV-01 Completed questionnaire for the supplier's tierAYes———60

Set A

Set A, for Tier 1 (Critical) suppliers: 60 questions. EXAMPLE: answered by SUP-004 (ERP software provider (hosted)), assessed 2026-04-21. Clear columns A and J to O to use it.

RowNo.IDDomainQuestionAnswered byWhy we askAcceptable answerEvidence to attachAnswerEvidence suppliedAssessor verdictAssessor noteProposed severityFinding refCheckBank row (calc)Finding key (calc)
EXAMPLE1GOV-01GovernanceWill it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)?Business owner, at intakeAn override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02).A clear yes or no to each part.EV-01 Completed questionnaire for the supplier's tierYes: it processes staff and supplier personal data for us. We are not a regulated financial entity.Intake recordMeetsProcessor override: at least Tier 2. The criteria already reach Tier 1.Complete1
EXAMPLE2GOV-02GovernanceDo you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers.SupplierShows how much of your security someone independent has checked, and whether that check covers our service.A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy.EV-02 Security certification with its scope statement; EV-03 Independent assurance reportISO/IEC 27001 certification; scope: development, hosting and support of the hosted ERP service. Valid to 2027-02.EV-02MeetsCertificate and scope statement checked: scope covers the service we use.Complete2
EXAMPLE3GOV-03GovernanceDo you have an information security policy approved by your senior management and reviewed in the last 12 months?SupplierShows that security has an owner at the top of your organisation and is kept current.Yes: approved by a named senior role and reviewed within the last 12 months.EV-05 Key security policies with evidence they operateYes: approved by the Chief Executive, last reviewed January 2026.Covered by EV-02MeetsComplete3
EXAMPLE4GOV-04GovernanceWho is accountable for information security in your organisation, and how do we reach them?SupplierWe need a named person who can answer for security decisions that affect our service.A named role with the authority to act, and contact details.EV-01 Completed questionnaire for the supplier's tierHead of Information Security, named, with a direct email address and phone number.MeetsComplete4
EXAMPLE5GOV-05GovernanceHow do you assess and treat the information security risks to the service you provide to us?SupplierA supplier that manages its own risks is less likely to pass them on to its customers.A documented method, a risk register reviewed at least once a year, and named owners for treatment.EV-05 Key security policies with evidence they operate; EV-02 Security certification with its scope statementAnnual risk assessment under our certified management system; risk register reviewed every quarter by the security committee.Covered by EV-02MeetsComplete5
EXAMPLE6GOV-06GovernanceHas an internal audit or independent review of your security controls been done in the last 12 months? What did it find, and what is still open?SupplierWhat an audit found, and how quickly it was fixed, tells us more than a certificate alone.Yes; the findings summarised; any open finding has an owner and a date.EV-02 Security certification with its scope statement; EV-03 Independent assurance reportCertification surveillance audit, March 2026: two minor nonconformities, both closed by May 2026.Audit summary letterMeetsComplete6
EXAMPLE7GOV-07GovernanceHow do you tell customers about a material change to the service, such as a new hosting location, a new sub-processor or a change of ownership?SupplierA material change can change our risk, and it triggers a reassessment (TP-09).Written notice in advance, with a stated notice period and a way for us to object.EV-10 Data processing termsCustomers are told by email 30 days in advance; the contract lets customers object to a new sub-processor.EV-10MeetsComplete7
EXAMPLE8ACC-01Access and identityWhat access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level?Business owner, at intakePlaces the supplier on tiering criterion TC-3 (Access).A clear answer: none, supervised on site, remote user, or privileged or network-level.EV-01 Completed questionnaire for the supplier's tierRemote support access to our ERP application for the provider's support staff; no access to our network.Intake recordMeetsTC-3 at Tier 2 (remote user access).Complete8
EXAMPLE9ACC-02Access and identityDoes every person who can reach our data or systems have their own named account, with no shared log-ins?SupplierWith shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave.Yes: named accounts only; any service accounts listed with an owner.EV-09 Access control evidence for people who reach our data or systemsYes: named accounts only. Two service accounts run integrations; the support lead owns both.EV-09MeetsUser list checked: named accounts only.Complete9
EXAMPLE10ACC-03Access and identityIs multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff?SupplierStolen passwords are the most common way in; multi-factor authentication stops most attacks that use them.Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited.EV-09 Access control evidence for people who reach our data or systemsCustomer users must use multi-factor authentication. Our support staff reach customer environments through the support console with a password; multi-factor authentication for the console is planned.EV-09Does not meetSupport staff reach our ERP without multi-factor authentication. A stolen support password could directly expose our finance and payroll data.HighF-01Finding proposed101010
EXAMPLE11ACC-04Access and identityHow quickly is a person's access to our data or systems removed when they leave or change role?SupplierAccess left behind by leavers is a common route for misuse.Within one working day of leaving, through a joiner, mover and leaver process that leaves a record.EV-09 Access control evidence for people who reach our data or systemsThe same day, triggered from our HR system; checked every month.EV-09MeetsComplete11
EXAMPLE12ACC-05Access and identityHow often is access to our data or systems reviewed, and by whom?SupplierReviews catch access that is no longer needed.At least every [[6]] months, by a manager who does not hold the access, with the removals recorded.EV-09 Access control evidence for people who reach our data or systemsEvery quarter by the support manager; the last review, March 2026, removed three accounts.EV-09MeetsComplete12
EXAMPLE13ACC-06Access and identityHow is administrator (privileged) access controlled: who has it, is it separate from everyday accounts, and is its use logged?SupplierAdministrator accounts can do the most damage if misused or taken over.Few named people; separate administrator accounts; use logged and reviewed.EV-09 Access control evidence for people who reach our data or systemsSix engineers hold separate administrator accounts, raised to administrator only for a task; every session is logged centrally.EV-09MeetsComplete13
EXAMPLE14ACC-07Access and identityHow does your remote access to our systems work: by what route, can we see who connected, and can we suspend it?SupplierRemote support routes are a common way attackers reach a supplier's customers.One secured route; every session logged; we can see who connected and suspend access.EV-09 Access control evidence for people who reach our data or systemsThrough the support console only; each session is logged with its ticket number; customers can see the log and suspend support access from their administration screen.MeetsComplete14
EXAMPLE15ACC-08Access and identityAre access logs for our data and systems kept, for how long, and can we have them for an investigation?SupplierWithout logs an incident cannot be investigated.Kept at least [[12 months]]; given to us on request within an agreed time.EV-09 Access control evidence for people who reach our data or systemsKept 13 months; exported on request within two working days.MeetsComplete15
EXAMPLE16DAT-01Data protectionWhat data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale?Business owner, at intakePlaces the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28.A clear list of the kinds of data, or 'none'.EV-01 Completed questionnaire for the supplier's tierPersonal data: staff pay and bank details and supplier contacts, with our order and stock records.Intake recordMeetsTC-2 at Tier 2 (personal data).Complete16
EXAMPLE17DAT-02Data protectionIs our data encrypted when it travels over networks and when it is stored, including in backups?SupplierEncryption keeps data safe if a network, disk or backup is exposed.Yes: current encryption in transit on every network, and at rest including backups.EV-05 Key security policies with evidence they operateYes: TLS 1.2 or later for every connection; databases and backups encrypted.Covered by EV-02MeetsComplete17
EXAMPLE18DAT-03Data protectionIn which countries is our data stored, processed and supported, including backups?SupplierLocation affects legal duties, such as rules on transferring personal data, and who could demand access to it.Every location named, including backups and support, matching the contract.EV-11 Data location and hosting statementTwo data centres of our hosting provider, both in the same country as your head office; support staff in that country only.EV-11MeetsComplete18
EXAMPLE19DAT-04Data protectionIf you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)?SupplierThe law requires a binding contract with every processor (GDPR Article 28(3)).Yes: covering documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits.EV-10 Data processing termsYes: our data processing agreement is part of the contract.EV-10MeetsComplete19
EXAMPLE20DAT-05Data protectionAt the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give?SupplierExit is where data is most often forgotten; every Tier 1 and Tier 2 contract needs an exit plan (TP-11).Returned in a usable format; deleted from live systems and backups within a stated time; a written certificate of deletion.EV-12 Data return and deletion procedureData is exported on request and deleted from live systems within 30 days. Backups expire on their normal cycle. We do not issue deletion certificates.PartlyNo evidence that our data is deleted at contract end: backups are left to expire and no confirmation is given. Other protection remains (contract clause, encrypted backups).MediumF-02Finding proposed202020
EXAMPLE21DAT-06Data protectionHow is our data kept apart from other customers' data?SupplierIn a shared service a weakness in separation exposes every customer.Separation described, and tested, for example in the penetration test.EV-06 Penetration test summaryA separate database for each customer; separation tested in the annual penetration test.Penetration test summaryMeetsComplete21
EXAMPLE22DAT-07Data protectionIs our data used for anything other than providing the service to us, such as testing, analytics or training software?SupplierOther uses multiply the places our data can leak from and may be unlawful for personal data.No; or only as the contract allows, with personal data removed first.EV-10 Data processing termsNo. Test systems use made-up data.EV-10MeetsComplete22
EXAMPLE23VUL-01Vulnerabilities and patchingHow quickly do you apply security updates to the systems that deliver our service?SupplierMost attacks use weaknesses for which an update already exists.Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded.EV-07 Vulnerability and patch status reportCritical updates within 7 calendar days; others in the monthly cycle.EV-07MeetsComplete23
EXAMPLE24VUL-02Vulnerabilities and patchingDo you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed?SupplierScanning finds what patching missed.At least monthly; findings tracked with an owner and a deadline.EV-07 Vulnerability and patch status reportWeekly authenticated scans; findings tracked as tickets with deadlines.EV-07MeetsComplete24
EXAMPLE25VUL-03Vulnerabilities and patchingDoes the service run on any system or software its maker no longer supports (end of life)?SupplierUnsupported software no longer gets security updates.No; or each one listed with extra protection and a replacement date.EV-07 Vulnerability and patch status reportNone.EV-07MeetsComplete25
EXAMPLE26VUL-04Vulnerabilities and patchingWhen was the service last penetration tested by an independent tester, what was in scope, and are the serious findings fixed?SupplierA test shows how an attacker would actually get in.Within the last 12 months; the service we use in scope; High and Critical findings fixed or on a dated plan.EV-06 Penetration test summaryFebruary 2026, application and hosting in scope; every High finding fixed by March 2026 and retested.Penetration test summaryMeetsComplete26
EXAMPLE27VUL-05Vulnerabilities and patchingHow do you protect the service against malware, and how do you detect an attack on it?SupplierPrevention fails sometimes; detection limits the damage.Malware protection on servers and staff devices, and security monitoring with alerts that are acted on at any hour.EV-05 Key security policies with evidence they operateEndpoint detection on every server and laptop; monitored around the clock by a security operations centre.Covered by EV-02MeetsComplete27
EXAMPLE28DEV-01Secure developmentIf you write the software we use, do you follow a documented secure development process?SupplierSecurity built in during development costs less than fixing weaknesses after release (NIS2 Article 21(3) names secure development).Yes: documented, covering security requirements, peer review and security testing before release. Or Not applicable: you do not write it.EV-08 Secure development evidenceYes: secure development policy; every change is peer reviewed.EV-08MeetsComplete28
EXAMPLE29DEV-02Secure developmentAre changes to the service tested and approved before they go live, and can they be rolled back?SupplierUntested changes cause outages and open security gaps.Yes: a separate test environment, approval recorded, and a rollback plan.EV-08 Secure development evidenceYes: releases pass through test and acceptance environments; rollback is scripted.EV-08MeetsComplete29
EXAMPLE30DEV-03Secure developmentDo you check your code, and the open-source components it uses, for known vulnerabilities before release?SupplierMost applications are largely made of open-source components, each with its own weaknesses.Automated checks on every build; release stopped on a Critical finding.EV-08 Secure development evidenceAutomated code and component scanning on every build; a Critical finding blocks the release.EV-08MeetsComplete30
EXAMPLE31DEV-04Secure developmentWho can change the live code or data of the service, and are they different from the people who write the code?SupplierSeparating those who write code from those who release it stops one person making an unchecked change.Releases through an approved pipeline only; developers cannot change live systems directly.EV-08 Secure development evidence; EV-09 Access control evidence for people who reach our data or systemsReleases go through the deployment pipeline only; developers have no write access to live systems.EV-08MeetsComplete31
EXAMPLE32DEV-05Secure developmentHow do you tell customers about security vulnerabilities in your product, and about their fixes?SupplierWe need to know when we are exposed and what to do.Security notices to customers' administrators, with the fix and any action we must take.EV-08 Secure development evidenceSecurity notices to customer administrators; fixes are applied to the hosted service without customer action.MeetsComplete32
EXAMPLE33INC-01Incident managementWho do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service?SupplierCritical suppliers are part of our incident response, with named contacts and notification duties (TP-10).A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time.EV-13 Incident contacts and notification commitmentA security incident line staffed around the clock and a named incident manager; the contract commits us to notify you within 24 hours.EV-13MeetsContact tested by a test call.Complete33
EXAMPLE34INC-02Incident managementDo you have a documented incident response plan, and when was it last tested?SupplierAn untested plan usually fails at the first real incident.Yes: tested within the last 12 months.EV-13 Incident contacts and notification commitmentYes; tested in a desk exercise in November 2025.EV-13MeetsComplete34
EXAMPLE35INC-03Incident managementWhat will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2?SupplierWe may have to report within fixed times, and we cannot do it without your facts.Initial facts quickly, regular updates and a final report; help with our reporting written into the contract.EV-13 Incident contacts and notification commitment; EV-10 Data processing termsAn initial notice, updates every 24 hours and a root-cause report within 10 working days; the data processing agreement commits us to help.EV-10MeetsComplete35
EXAMPLE36INC-04Incident managementHave you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards?SupplierHow a supplier learnt from an incident says more than a clean record.An open answer; any lessons and changes described.EV-13 Incident contacts and notification commitmentNone that affected customers. In 2025 a staff laptop was stolen; it was encrypted and held no customer data.MeetsComplete36
EXAMPLE37INC-05Incident managementWill you take part in our incident exercises, or share the results of your own for the service we use?SupplierExercising together finds the gaps between our plans and yours (TP-10).Yes, on reasonable notice, at least once a year for a critical service.EV-14 Continuity and recovery test resultsYes, once a year on request.MeetsComplete37
EXAMPLE38INC-06Incident managementHow would you preserve evidence and support an investigation of an incident affecting our data?SupplierEvidence lost in the first hours cannot be recovered.Logs and system images preserved; we or our investigator can have them.EV-13 Incident contacts and notification commitmentLogs are kept 13 months and preserved on request; forensic support through our incident response retainer.MeetsComplete38
EXAMPLE39CON-01Continuity and exitWhich of our services does it run or support, and would any critical service stop or degrade if it failed?Business owner, at intakePlaces the supplier on tiering criterion TC-1 (Service).The services named, and what would stop or degrade.EV-01 Completed questionnaire for the supplier's tierFinance and payroll, and warehouse dispatch (stock and orders). Both would degrade within a day if the ERP stopped.Intake recordMeetsTC-1 at Tier 1 (runs critical services).Complete39
EXAMPLE40CON-02Continuity and exitIf it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime?Business owner, at intakePlaces the supplier on tiering criterion TC-4 (Substitutability).An estimate of the time to replace it, and the effect meanwhile.EV-01 Completed questionnaire for the supplier's tierNot within 3 months: moving to another ERP would take about a year, and finance and payroll would depend on it throughout.Intake recordMeetsTC-4 at Tier 1.Complete40
EXAMPLE41CON-03Continuity and exitIf your service stopped, how quickly would it be restored, and how much of our data could be lost?SupplierWe need to know whether your recovery meets what our services need.A recovery time and a maximum data loss, both within [[what our service needs]].EV-14 Continuity and recovery test resultsRestored within 8 hours, with at most 15 minutes of data lost.EV-14MeetsMeets the finance service's recovery needs.Complete41
EXAMPLE42CON-04Continuity and exitAre backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored?SupplierBackups on the same system are lost with it.Yes: separate, protected against deletion or change, and restores tested at least every [[3 months]].EV-14 Continuity and recovery test resultsDaily backups to a separate account that cannot be changed for 35 days; a restore is tested every month.EV-14MeetsComplete42
EXAMPLE43CON-05Continuity and exitDo you have a continuity plan for the service, and when was it last tested?SupplierA plan that has not been tested may not work when it is needed.Yes: tested within the last 12 months, with the results and fixes available to us.EV-14 Continuity and recovery test resultsYes; failover between data centres tested in January 2026, results shared.EV-14MeetsComplete43
EXAMPLE44CON-06Continuity and exitIf our contract ends, or you stop trading, how would we get our data back and move the service elsewhere?SupplierEvery Tier 1 and Tier 2 contract needs an exit plan: data return or deletion, access removal and a transition period (TP-11).Export in a usable format, help with the move, and a transition period, all written into the contract.EV-12 Data return and deletion procedureFull export in standard formats; a 90-day transition period in the contract.Contract, exit scheduleMeetsComplete44
EXAMPLE45CON-07Continuity and exitWhat happens to our service if one of your own key suppliers, such as your hosting provider, fails?SupplierYour suppliers' failures become ours.The dependency named, with a tested alternative or recovery plan.EV-14 Continuity and recovery test results; EV-15 Subcontractor and sub-processor listHosted across two data centres of one provider; a plan to move to a second provider, tested as a desk exercise in 2025.EV-14MeetsComplete45
EXAMPLE46SUB-01Subcontractors and sub-processorsWill any other company handle our data or deliver part of the service to us? If so, which companies, and for what?SupplierEach such company is part of our supply chain, and for personal data it is a sub-processor.A list, or 'none'.EV-15 Subcontractor and sub-processor listYes: our cloud hosting provider (hosting and backups) and an email delivery service (system notifications).EV-15MeetsComplete46
EXAMPLE47SUB-02Subcontractors and sub-processorsDo your contracts hold those companies to security requirements at least as strict as ours?SupplierOur requirements mean little if they stop at your door.Yes: in their contracts, with their assurance checked.EV-15 Subcontractor and sub-processor listYes: a security schedule in each contract; the hosting provider's certification is checked every year.EV-15MeetsComplete47
EXAMPLE48SUB-03Subcontractors and sub-processorsWill you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data?SupplierA processor may not use another processor without the controller's prior written authorisation (GDPR Article 28(2)).Yes: advance notice with the right to object, written into the contract.EV-10 Data processing terms; EV-15 Subcontractor and sub-processor listYes: 30 days' notice with the right to object.EV-10MeetsComplete48
EXAMPLE49SUB-04Subcontractors and sub-processorsHow do you assess and monitor the security of your own critical suppliers?SupplierShows whether you manage your supply chain as we manage ours.Suppliers ranked by risk, assessed before contract and reviewed at least once a year.EV-15 Subcontractor and sub-processor listEvery year we review each critical supplier's certificates and reports, using a list ranked by risk.MeetsComplete49
EXAMPLE50SUB-05Subcontractors and sub-processorsIs any part of the service delivered from outside [[our country or region]]? Which, and with what safeguards?SupplierDelivery from other countries can bring legal duties and access risks.None; or each one named, with the safeguards for any transfer of personal data.EV-11 Data location and hosting statement; EV-15 Subcontractor and sub-processor listNo: every subcontractor delivers from the same country.EV-15MeetsComplete50
EXAMPLE51SUB-06Subcontractors and sub-processorsPlease name the providers the service depends on (for example cloud, network and software providers) so that we can check them against our other critical suppliers.SupplierSeveral critical services relying on one provider is concentration risk (TPM-04).The providers named.EV-15 Subcontractor and sub-processor listNamed in our sub-processor list: one public cloud provider and one email delivery service.EV-15MeetsChecked against our supplier list for concentration (TPM-04).Complete51
EXAMPLE52PPL-01PeopleAre the staff who can reach our data screened before they start, as far as the law allows?SupplierScreening reduces the risk from people in trusted roles.Yes: identity, right to work and references at least; more for administrators.EV-16 Staff screening and training summaryIdentity, right to work and references for everyone; criminal record checks for administrators.EV-16MeetsComplete52
EXAMPLE53PPL-02PeopleDo staff receive security awareness training when they join and at least once a year?SupplierMost incidents involve a human mistake.Yes: at joining and at least once a year, with completion tracked.EV-16 Staff screening and training summaryYes: at joining and every year; 98% completed in the last 12 months.EV-16MeetsComplete53
EXAMPLE54PPL-03PeopleAre staff bound by confidentiality duties that continue after they leave?SupplierConfidentiality should outlast employment.Yes: in employment and contractor agreements.EV-16 Staff screening and training summaryYes: in every employment and contractor agreement.MeetsComplete54
EXAMPLE55PPL-04PeopleDo staff with administrator access receive extra security training, for example on social engineering and safe administration?SupplierAttackers target the people with the most access.Yes: at least once a year, for every administrator.EV-16 Staff screening and training summaryYes: once a year for engineers and support staff.EV-16MeetsComplete55
EXAMPLE56PHY-01Physical security and hostingWhere is the service hosted: your own premises, a data centre or a cloud provider? Please name them.SupplierTells us who else holds our data, and whose physical security we rely on.The hosting named.EV-11 Data location and hosting statementA public cloud provider, named in our sub-processor list; two data centres.EV-11MeetsComplete56
EXAMPLE57PHY-02Physical security and hostingHow are the premises or data centres that hold our data protected against unauthorised entry?SupplierPhysical access can bypass every other control.Entry control, visitor records and monitoring; or the hosting provider's certification or report covering them.EV-02 Security certification with its scope statement; EV-11 Data location and hosting statementCovered by the hosting provider's certification; no customer data is held at our offices.Hosting provider's certificateMeetsComplete57
EXAMPLE58PHY-03Physical security and hostingAre those facilities protected against fire, flood and power loss, and is the protection tested?SupplierEnvironmental failures stop services as surely as attacks do.Yes: covered by an independent report or certification, or by test records.EV-03 Independent assurance report; EV-11 Data location and hosting statementYes: covered by the hosting provider's independent report, which we review every year.MeetsComplete58
EXAMPLE59PHY-04Physical security and hostingHow are equipment and storage media that held our data disposed of?SupplierDiscarded disks are a common source of data leaks.Secure erasure or destruction, with a record.EV-12 Data return and deletion procedureDisks are destroyed by the hosting provider under its certification; our laptops are wiped with a certificate.MeetsComplete59
EXAMPLE60PHY-05Physical security and hostingWill your staff visit our premises or connect equipment to our network? If so, under what supervision?SupplierVisits and connected equipment bring access inside our defences.No; or visits supervised and equipment approved before connection.EV-01 Completed questionnaire for the supplier's tierNo visits and no equipment connected.Not applicableRemote service only.Complete60

Set B

Set B, for Tier 2 (Important) suppliers: 35 questions, drawn from the Question Bank. The supplier fills J and K; the assessor fills L to O.

RowNo.IDDomainQuestionAnswered byWhy we askAcceptable answerEvidence to attachAnswerEvidence suppliedAssessor verdictAssessor noteProposed severityFinding refCheckBank row (calc)Finding key (calc)
1GOV-01GovernanceWill it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)?Business owner, at intakeAn override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02).A clear yes or no to each part.EV-01 Completed questionnaire for the supplier's tierAwaiting answer1
2GOV-02GovernanceDo you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers.SupplierShows how much of your security someone independent has checked, and whether that check covers our service.A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy.EV-02 Security certification with its scope statement; EV-03 Independent assurance reportAwaiting answer2
3GOV-03GovernanceDo you have an information security policy approved by your senior management and reviewed in the last 12 months?SupplierShows that security has an owner at the top of your organisation and is kept current.Yes: approved by a named senior role and reviewed within the last 12 months.EV-05 Key security policies with evidence they operateAwaiting answer3
4GOV-04GovernanceWho is accountable for information security in your organisation, and how do we reach them?SupplierWe need a named person who can answer for security decisions that affect our service.A named role with the authority to act, and contact details.EV-01 Completed questionnaire for the supplier's tierAwaiting answer4
5ACC-01Access and identityWhat access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level?Business owner, at intakePlaces the supplier on tiering criterion TC-3 (Access).A clear answer: none, supervised on site, remote user, or privileged or network-level.EV-01 Completed questionnaire for the supplier's tierAwaiting answer8
6ACC-02Access and identityDoes every person who can reach our data or systems have their own named account, with no shared log-ins?SupplierWith shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave.Yes: named accounts only; any service accounts listed with an owner.EV-09 Access control evidence for people who reach our data or systemsAwaiting answer9
7ACC-03Access and identityIs multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff?SupplierStolen passwords are the most common way in; multi-factor authentication stops most attacks that use them.Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited.EV-09 Access control evidence for people who reach our data or systemsAwaiting answer10
8ACC-04Access and identityHow quickly is a person's access to our data or systems removed when they leave or change role?SupplierAccess left behind by leavers is a common route for misuse.Within one working day of leaving, through a joiner, mover and leaver process that leaves a record.EV-09 Access control evidence for people who reach our data or systemsAwaiting answer11
9ACC-05Access and identityHow often is access to our data or systems reviewed, and by whom?SupplierReviews catch access that is no longer needed.At least every [[6]] months, by a manager who does not hold the access, with the removals recorded.EV-09 Access control evidence for people who reach our data or systemsAwaiting answer12
10DAT-01Data protectionWhat data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale?Business owner, at intakePlaces the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28.A clear list of the kinds of data, or 'none'.EV-01 Completed questionnaire for the supplier's tierAwaiting answer16
11DAT-02Data protectionIs our data encrypted when it travels over networks and when it is stored, including in backups?SupplierEncryption keeps data safe if a network, disk or backup is exposed.Yes: current encryption in transit on every network, and at rest including backups.EV-05 Key security policies with evidence they operateAwaiting answer17
12DAT-03Data protectionIn which countries is our data stored, processed and supported, including backups?SupplierLocation affects legal duties, such as rules on transferring personal data, and who could demand access to it.Every location named, including backups and support, matching the contract.EV-11 Data location and hosting statementAwaiting answer18
13DAT-04Data protectionIf you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)?SupplierThe law requires a binding contract with every processor (GDPR Article 28(3)).Yes: covering documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits.EV-10 Data processing termsAwaiting answer19
14DAT-05Data protectionAt the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give?SupplierExit is where data is most often forgotten; every Tier 1 and Tier 2 contract needs an exit plan (TP-11).Returned in a usable format; deleted from live systems and backups within a stated time; a written certificate of deletion.EV-12 Data return and deletion procedureAwaiting answer20
15VUL-01Vulnerabilities and patchingHow quickly do you apply security updates to the systems that deliver our service?SupplierMost attacks use weaknesses for which an update already exists.Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded.EV-07 Vulnerability and patch status reportAwaiting answer23
16VUL-02Vulnerabilities and patchingDo you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed?SupplierScanning finds what patching missed.At least monthly; findings tracked with an owner and a deadline.EV-07 Vulnerability and patch status reportAwaiting answer24
17DEV-01Secure developmentIf you write the software we use, do you follow a documented secure development process?SupplierSecurity built in during development costs less than fixing weaknesses after release (NIS2 Article 21(3) names secure development).Yes: documented, covering security requirements, peer review and security testing before release. Or Not applicable: you do not write it.EV-08 Secure development evidenceAwaiting answer28
18DEV-02Secure developmentAre changes to the service tested and approved before they go live, and can they be rolled back?SupplierUntested changes cause outages and open security gaps.Yes: a separate test environment, approval recorded, and a rollback plan.EV-08 Secure development evidenceAwaiting answer29
19INC-01Incident managementWho do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service?SupplierCritical suppliers are part of our incident response, with named contacts and notification duties (TP-10).A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time.EV-13 Incident contacts and notification commitmentAwaiting answer33
20INC-02Incident managementDo you have a documented incident response plan, and when was it last tested?SupplierAn untested plan usually fails at the first real incident.Yes: tested within the last 12 months.EV-13 Incident contacts and notification commitmentAwaiting answer34
21INC-03Incident managementWhat will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2?SupplierWe may have to report within fixed times, and we cannot do it without your facts.Initial facts quickly, regular updates and a final report; help with our reporting written into the contract.EV-13 Incident contacts and notification commitment; EV-10 Data processing termsAwaiting answer35
22INC-04Incident managementHave you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards?SupplierHow a supplier learnt from an incident says more than a clean record.An open answer; any lessons and changes described.EV-13 Incident contacts and notification commitmentAwaiting answer36
23CON-01Continuity and exitWhich of our services does it run or support, and would any critical service stop or degrade if it failed?Business owner, at intakePlaces the supplier on tiering criterion TC-1 (Service).The services named, and what would stop or degrade.EV-01 Completed questionnaire for the supplier's tierAwaiting answer39
24CON-02Continuity and exitIf it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime?Business owner, at intakePlaces the supplier on tiering criterion TC-4 (Substitutability).An estimate of the time to replace it, and the effect meanwhile.EV-01 Completed questionnaire for the supplier's tierAwaiting answer40
25CON-03Continuity and exitIf your service stopped, how quickly would it be restored, and how much of our data could be lost?SupplierWe need to know whether your recovery meets what our services need.A recovery time and a maximum data loss, both within [[what our service needs]].EV-14 Continuity and recovery test resultsAwaiting answer41
26CON-04Continuity and exitAre backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored?SupplierBackups on the same system are lost with it.Yes: separate, protected against deletion or change, and restores tested at least every [[3 months]].EV-14 Continuity and recovery test resultsAwaiting answer42
27CON-05Continuity and exitDo you have a continuity plan for the service, and when was it last tested?SupplierA plan that has not been tested may not work when it is needed.Yes: tested within the last 12 months, with the results and fixes available to us.EV-14 Continuity and recovery test resultsAwaiting answer43
28CON-06Continuity and exitIf our contract ends, or you stop trading, how would we get our data back and move the service elsewhere?SupplierEvery Tier 1 and Tier 2 contract needs an exit plan: data return or deletion, access removal and a transition period (TP-11).Export in a usable format, help with the move, and a transition period, all written into the contract.EV-12 Data return and deletion procedureAwaiting answer44
29SUB-01Subcontractors and sub-processorsWill any other company handle our data or deliver part of the service to us? If so, which companies, and for what?SupplierEach such company is part of our supply chain, and for personal data it is a sub-processor.A list, or 'none'.EV-15 Subcontractor and sub-processor listAwaiting answer46
30SUB-02Subcontractors and sub-processorsDo your contracts hold those companies to security requirements at least as strict as ours?SupplierOur requirements mean little if they stop at your door.Yes: in their contracts, with their assurance checked.EV-15 Subcontractor and sub-processor listAwaiting answer47
31SUB-03Subcontractors and sub-processorsWill you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data?SupplierA processor may not use another processor without the controller's prior written authorisation (GDPR Article 28(2)).Yes: advance notice with the right to object, written into the contract.EV-10 Data processing terms; EV-15 Subcontractor and sub-processor listAwaiting answer48
32PPL-01PeopleAre the staff who can reach our data screened before they start, as far as the law allows?SupplierScreening reduces the risk from people in trusted roles.Yes: identity, right to work and references at least; more for administrators.EV-16 Staff screening and training summaryAwaiting answer52
33PPL-02PeopleDo staff receive security awareness training when they join and at least once a year?SupplierMost incidents involve a human mistake.Yes: at joining and at least once a year, with completion tracked.EV-16 Staff screening and training summaryAwaiting answer53
34PHY-01Physical security and hostingWhere is the service hosted: your own premises, a data centre or a cloud provider? Please name them.SupplierTells us who else holds our data, and whose physical security we rely on.The hosting named.EV-11 Data location and hosting statementAwaiting answer56
35PHY-02Physical security and hostingHow are the premises or data centres that hold our data protected against unauthorised entry?SupplierPhysical access can bypass every other control.Entry control, visitor records and monitoring; or the hosting provider's certification or report covering them.EV-02 Security certification with its scope statement; EV-11 Data location and hosting statementAwaiting answer57

Set C

Set C, for Tier 3 (Standard) suppliers: 15 questions, drawn from the Question Bank. The supplier fills J and K; the assessor fills L to O.

RowNo.IDDomainQuestionAnswered byWhy we askAcceptable answerEvidence to attachAnswerEvidence suppliedAssessor verdictAssessor noteProposed severityFinding refCheckBank row (calc)Finding key (calc)
1GOV-01GovernanceWill it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)?Business owner, at intakeAn override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02).A clear yes or no to each part.EV-01 Completed questionnaire for the supplier's tierAwaiting answer1
2GOV-02GovernanceDo you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers.SupplierShows how much of your security someone independent has checked, and whether that check covers our service.A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy.EV-02 Security certification with its scope statement; EV-03 Independent assurance reportAwaiting answer2
3ACC-01Access and identityWhat access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level?Business owner, at intakePlaces the supplier on tiering criterion TC-3 (Access).A clear answer: none, supervised on site, remote user, or privileged or network-level.EV-01 Completed questionnaire for the supplier's tierAwaiting answer8
4ACC-02Access and identityDoes every person who can reach our data or systems have their own named account, with no shared log-ins?SupplierWith shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave.Yes: named accounts only; any service accounts listed with an owner.EV-09 Access control evidence for people who reach our data or systemsAwaiting answer9
5ACC-03Access and identityIs multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff?SupplierStolen passwords are the most common way in; multi-factor authentication stops most attacks that use them.Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited.EV-09 Access control evidence for people who reach our data or systemsAwaiting answer10
6DAT-01Data protectionWhat data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale?Business owner, at intakePlaces the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28.A clear list of the kinds of data, or 'none'.EV-01 Completed questionnaire for the supplier's tierAwaiting answer16
7DAT-02Data protectionIs our data encrypted when it travels over networks and when it is stored, including in backups?SupplierEncryption keeps data safe if a network, disk or backup is exposed.Yes: current encryption in transit on every network, and at rest including backups.EV-05 Key security policies with evidence they operateAwaiting answer17
8VUL-01Vulnerabilities and patchingHow quickly do you apply security updates to the systems that deliver our service?SupplierMost attacks use weaknesses for which an update already exists.Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded.EV-07 Vulnerability and patch status reportAwaiting answer23
9INC-01Incident managementWho do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service?SupplierCritical suppliers are part of our incident response, with named contacts and notification duties (TP-10).A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time.EV-13 Incident contacts and notification commitmentAwaiting answer33
10INC-02Incident managementDo you have a documented incident response plan, and when was it last tested?SupplierAn untested plan usually fails at the first real incident.Yes: tested within the last 12 months.EV-13 Incident contacts and notification commitmentAwaiting answer34
11CON-01Continuity and exitWhich of our services does it run or support, and would any critical service stop or degrade if it failed?Business owner, at intakePlaces the supplier on tiering criterion TC-1 (Service).The services named, and what would stop or degrade.EV-01 Completed questionnaire for the supplier's tierAwaiting answer39
12CON-02Continuity and exitIf it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime?Business owner, at intakePlaces the supplier on tiering criterion TC-4 (Substitutability).An estimate of the time to replace it, and the effect meanwhile.EV-01 Completed questionnaire for the supplier's tierAwaiting answer40
13CON-03Continuity and exitIf your service stopped, how quickly would it be restored, and how much of our data could be lost?SupplierWe need to know whether your recovery meets what our services need.A recovery time and a maximum data loss, both within [[what our service needs]].EV-14 Continuity and recovery test resultsAwaiting answer41
14SUB-01Subcontractors and sub-processorsWill any other company handle our data or deliver part of the service to us? If so, which companies, and for what?SupplierEach such company is part of our supply chain, and for personal data it is a sub-processor.A list, or 'none'.EV-15 Subcontractor and sub-processor listAwaiting answer46
15PPL-01PeopleAre the staff who can reach our data screened before they start, as far as the law allows?SupplierScreening reduces the risk from people in trusted roles.Yes: identity, right to work and references at least; more for administrators.EV-16 Staff screening and training summaryAwaiting answer52

Set D

Set D, for Tier 4 (Minimal) suppliers: 5 questions, the intake screening, drawn from the Question Bank. The supplier fills J and K; the assessor fills L to O.

RowNo.IDDomainQuestionAnswered byWhy we askAcceptable answerEvidence to attachAnswerEvidence suppliedAssessor verdictAssessor noteProposed severityFinding refCheckBank row (calc)Finding key (calc)
1GOV-01GovernanceWill it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)?Business owner, at intakeAn override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02).A clear yes or no to each part.EV-01 Completed questionnaire for the supplier's tierAwaiting answer1
2ACC-01Access and identityWhat access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level?Business owner, at intakePlaces the supplier on tiering criterion TC-3 (Access).A clear answer: none, supervised on site, remote user, or privileged or network-level.EV-01 Completed questionnaire for the supplier's tierAwaiting answer8
3DAT-01Data protectionWhat data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale?Business owner, at intakePlaces the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28.A clear list of the kinds of data, or 'none'.EV-01 Completed questionnaire for the supplier's tierAwaiting answer16
4CON-01Continuity and exitWhich of our services does it run or support, and would any critical service stop or degrade if it failed?Business owner, at intakePlaces the supplier on tiering criterion TC-1 (Service).The services named, and what would stop or degrade.EV-01 Completed questionnaire for the supplier's tierAwaiting answer39
5CON-02Continuity and exitIf it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime?Business owner, at intakePlaces the supplier on tiering criterion TC-4 (Substitutability).An estimate of the time to replace it, and the effect meanwhile.EV-01 Completed questionnaire for the supplier's tierAwaiting answer40

Results

Results

Calculated from the set sheet you choose. There is no score: the counts show how complete the assessment is and where the gaps are, and the proposed findings, High first, are what the review report and the decision work from.

Assessment detailsSet no. (calc)
FieldValueNote1
Supplier referenceSUP-004EXAMPLE — replace with your supplier's reference.
Supplier nameERP software provider (hosted)EXAMPLE.
Supplier tierTier 1EXAMPLE. From the Supplier Criticality & Tiering Model.
Set answeredSet AEverything below is calculated from this set sheet.
Assessment date21 Apr 2026EXAMPLE date (SUP-004's assessment). Replace it with the date of your assessment: finding deadlines count from it.
Assessor[[Name, role]]
Set for this tierSet ACalculated from the tier (TIERS).
Set checkSet A is the set for Tier 1.Calculated (TP-03).

Overall

MeasureCountWhat the results mean
Questions in the set601 High finding(s) proposed, and 1 other finding(s). 'Approve' is not available while a High finding is open. Score the residual risk on the P05 scale in the Supplier Security Review Report Template, then choose Approve with conditions, Escalate or Reject.
Meets57
Partly1
Does not meet1
Not applicable1Decisions (TP-05). Approve: Residual risk within appetite; no High finding open. Approve with conditions: Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. Escalate: Residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06). Reject: Do not contract, or plan exit (TP-11).
Not yet assessed0
Findings proposed: High1
Findings proposed: Medium1
Findings proposed: Low0

Result by domain

DomainQuestionsMeetsPartlyDoes not meetNot applicableNot yet assessed
Governance770000
Access and identity870100
Data protection761000
Vulnerabilities and patching550000
Secure development550000
Incident management660000
Continuity and exit770000
Subcontractors and sub-processors660000
People440000
Physical security and hosting540010

Shaded cells are counts of Partly (amber) and Does not meet (red): read them with the column heading.

Proposed findings, High first

QuestionVerdictSeverityDeadlineProposed due dateFinding refDomainAssessor noteQuestion textKey (calc)
ACC-03Does not meetHigh90 calendar days20 Jul 2026F-01Access and identitySupport staff reach our ERP without multi-factor authentication. A stolen support password could directly expose our finance and payroll data.Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff?1010
DAT-05PartlyMedium180 calendar days18 Oct 2026F-02Data protectionNo evidence that our data is deleted at contract end: backups are left to expire and no confirmation is given. Other protection remains (contract clause, encrypted backups).At the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give?2020

Deadlines are calendar days from the assessment date (TP-08). Enter each finding in the Supplier Security Risk Register and put its reference in the set sheet's Finding ref column. The first 12 findings are listed; the set sheet's Check column shows every one.

Limitations

The answers are the supplier's own. A verdict of Meets is only as good as the evidence behind it: validate the evidence with the Supplier Due Diligence Evidence Checklist (TP-04), and do not count an answer the evidence does not support.

The results are not a risk score. The supplier's residual risk is scored on the P05 impact × likelihood scale in the Supplier Security Review Report Template, and the decision follows from it (TP-05, TP-06).

The questions are generic. A service with unusual risks (for example payment card data, operational technology or artificial intelligence) needs questions of its own: add them to the bank.

A questionnaire describes one moment. Changes, incidents and certificate expiry between assessments are caught by monitoring and reassessment (TP-09), not by this workbook.

Export

The set chosen on the Results sheet, one row per question. Everything here is calculated: select the table, copy, and paste as values into your records or the review report.

SupplierSetNo.IDDomainQuestionAnswerEvidence suppliedVerdictAssessor noteProposed severityFinding ref
SUP-004Set A1GOV-01GovernanceWill it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)?Yes: it processes staff and supplier personal data for us. We are not a regulated financial entity.Intake recordMeetsProcessor override: at least Tier 2. The criteria already reach Tier 1.
SUP-004Set A2GOV-02GovernanceDo you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers.ISO/IEC 27001 certification; scope: development, hosting and support of the hosted ERP service. Valid to 2027-02.EV-02MeetsCertificate and scope statement checked: scope covers the service we use.
SUP-004Set A3GOV-03GovernanceDo you have an information security policy approved by your senior management and reviewed in the last 12 months?Yes: approved by the Chief Executive, last reviewed January 2026.Covered by EV-02Meets
SUP-004Set A4GOV-04GovernanceWho is accountable for information security in your organisation, and how do we reach them?Head of Information Security, named, with a direct email address and phone number.Meets
SUP-004Set A5GOV-05GovernanceHow do you assess and treat the information security risks to the service you provide to us?Annual risk assessment under our certified management system; risk register reviewed every quarter by the security committee.Covered by EV-02Meets
SUP-004Set A6GOV-06GovernanceHas an internal audit or independent review of your security controls been done in the last 12 months? What did it find, and what is still open?Certification surveillance audit, March 2026: two minor nonconformities, both closed by May 2026.Audit summary letterMeets
SUP-004Set A7GOV-07GovernanceHow do you tell customers about a material change to the service, such as a new hosting location, a new sub-processor or a change of ownership?Customers are told by email 30 days in advance; the contract lets customers object to a new sub-processor.EV-10Meets
SUP-004Set A8ACC-01Access and identityWhat access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level?Remote support access to our ERP application for the provider's support staff; no access to our network.Intake recordMeetsTC-3 at Tier 2 (remote user access).
SUP-004Set A9ACC-02Access and identityDoes every person who can reach our data or systems have their own named account, with no shared log-ins?Yes: named accounts only. Two service accounts run integrations; the support lead owns both.EV-09MeetsUser list checked: named accounts only.
SUP-004Set A10ACC-03Access and identityIs multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff?Customer users must use multi-factor authentication. Our support staff reach customer environments through the support console with a password; multi-factor authentication for the console is planned.EV-09Does not meetSupport staff reach our ERP without multi-factor authentication. A stolen support password could directly expose our finance and payroll data.HighF-01
SUP-004Set A11ACC-04Access and identityHow quickly is a person's access to our data or systems removed when they leave or change role?The same day, triggered from our HR system; checked every month.EV-09Meets
SUP-004Set A12ACC-05Access and identityHow often is access to our data or systems reviewed, and by whom?Every quarter by the support manager; the last review, March 2026, removed three accounts.EV-09Meets
SUP-004Set A13ACC-06Access and identityHow is administrator (privileged) access controlled: who has it, is it separate from everyday accounts, and is its use logged?Six engineers hold separate administrator accounts, raised to administrator only for a task; every session is logged centrally.EV-09Meets
SUP-004Set A14ACC-07Access and identityHow does your remote access to our systems work: by what route, can we see who connected, and can we suspend it?Through the support console only; each session is logged with its ticket number; customers can see the log and suspend support access from their administration screen.Meets
SUP-004Set A15ACC-08Access and identityAre access logs for our data and systems kept, for how long, and can we have them for an investigation?Kept 13 months; exported on request within two working days.Meets
SUP-004Set A16DAT-01Data protectionWhat data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale?Personal data: staff pay and bank details and supplier contacts, with our order and stock records.Intake recordMeetsTC-2 at Tier 2 (personal data).
SUP-004Set A17DAT-02Data protectionIs our data encrypted when it travels over networks and when it is stored, including in backups?Yes: TLS 1.2 or later for every connection; databases and backups encrypted.Covered by EV-02Meets
SUP-004Set A18DAT-03Data protectionIn which countries is our data stored, processed and supported, including backups?Two data centres of our hosting provider, both in the same country as your head office; support staff in that country only.EV-11Meets
SUP-004Set A19DAT-04Data protectionIf you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)?Yes: our data processing agreement is part of the contract.EV-10Meets
SUP-004Set A20DAT-05Data protectionAt the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give?Data is exported on request and deleted from live systems within 30 days. Backups expire on their normal cycle. We do not issue deletion certificates.PartlyNo evidence that our data is deleted at contract end: backups are left to expire and no confirmation is given. Other protection remains (contract clause, encrypted backups).MediumF-02
SUP-004Set A21DAT-06Data protectionHow is our data kept apart from other customers' data?A separate database for each customer; separation tested in the annual penetration test.Penetration test summaryMeets
SUP-004Set A22DAT-07Data protectionIs our data used for anything other than providing the service to us, such as testing, analytics or training software?No. Test systems use made-up data.EV-10Meets
SUP-004Set A23VUL-01Vulnerabilities and patchingHow quickly do you apply security updates to the systems that deliver our service?Critical updates within 7 calendar days; others in the monthly cycle.EV-07Meets
SUP-004Set A24VUL-02Vulnerabilities and patchingDo you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed?Weekly authenticated scans; findings tracked as tickets with deadlines.EV-07Meets
SUP-004Set A25VUL-03Vulnerabilities and patchingDoes the service run on any system or software its maker no longer supports (end of life)?None.EV-07Meets
SUP-004Set A26VUL-04Vulnerabilities and patchingWhen was the service last penetration tested by an independent tester, what was in scope, and are the serious findings fixed?February 2026, application and hosting in scope; every High finding fixed by March 2026 and retested.Penetration test summaryMeets
SUP-004Set A27VUL-05Vulnerabilities and patchingHow do you protect the service against malware, and how do you detect an attack on it?Endpoint detection on every server and laptop; monitored around the clock by a security operations centre.Covered by EV-02Meets
SUP-004Set A28DEV-01Secure developmentIf you write the software we use, do you follow a documented secure development process?Yes: secure development policy; every change is peer reviewed.EV-08Meets
SUP-004Set A29DEV-02Secure developmentAre changes to the service tested and approved before they go live, and can they be rolled back?Yes: releases pass through test and acceptance environments; rollback is scripted.EV-08Meets
SUP-004Set A30DEV-03Secure developmentDo you check your code, and the open-source components it uses, for known vulnerabilities before release?Automated code and component scanning on every build; a Critical finding blocks the release.EV-08Meets
SUP-004Set A31DEV-04Secure developmentWho can change the live code or data of the service, and are they different from the people who write the code?Releases go through the deployment pipeline only; developers have no write access to live systems.EV-08Meets
SUP-004Set A32DEV-05Secure developmentHow do you tell customers about security vulnerabilities in your product, and about their fixes?Security notices to customer administrators; fixes are applied to the hosted service without customer action.Meets
SUP-004Set A33INC-01Incident managementWho do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service?A security incident line staffed around the clock and a named incident manager; the contract commits us to notify you within 24 hours.EV-13MeetsContact tested by a test call.
SUP-004Set A34INC-02Incident managementDo you have a documented incident response plan, and when was it last tested?Yes; tested in a desk exercise in November 2025.EV-13Meets
SUP-004Set A35INC-03Incident managementWhat will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2?An initial notice, updates every 24 hours and a root-cause report within 10 working days; the data processing agreement commits us to help.EV-10Meets
SUP-004Set A36INC-04Incident managementHave you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards?None that affected customers. In 2025 a staff laptop was stolen; it was encrypted and held no customer data.Meets
SUP-004Set A37INC-05Incident managementWill you take part in our incident exercises, or share the results of your own for the service we use?Yes, once a year on request.Meets
SUP-004Set A38INC-06Incident managementHow would you preserve evidence and support an investigation of an incident affecting our data?Logs are kept 13 months and preserved on request; forensic support through our incident response retainer.Meets
SUP-004Set A39CON-01Continuity and exitWhich of our services does it run or support, and would any critical service stop or degrade if it failed?Finance and payroll, and warehouse dispatch (stock and orders). Both would degrade within a day if the ERP stopped.Intake recordMeetsTC-1 at Tier 1 (runs critical services).
SUP-004Set A40CON-02Continuity and exitIf it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime?Not within 3 months: moving to another ERP would take about a year, and finance and payroll would depend on it throughout.Intake recordMeetsTC-4 at Tier 1.
SUP-004Set A41CON-03Continuity and exitIf your service stopped, how quickly would it be restored, and how much of our data could be lost?Restored within 8 hours, with at most 15 minutes of data lost.EV-14MeetsMeets the finance service's recovery needs.
SUP-004Set A42CON-04Continuity and exitAre backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored?Daily backups to a separate account that cannot be changed for 35 days; a restore is tested every month.EV-14Meets
SUP-004Set A43CON-05Continuity and exitDo you have a continuity plan for the service, and when was it last tested?Yes; failover between data centres tested in January 2026, results shared.EV-14Meets
SUP-004Set A44CON-06Continuity and exitIf our contract ends, or you stop trading, how would we get our data back and move the service elsewhere?Full export in standard formats; a 90-day transition period in the contract.Contract, exit scheduleMeets
SUP-004Set A45CON-07Continuity and exitWhat happens to our service if one of your own key suppliers, such as your hosting provider, fails?Hosted across two data centres of one provider; a plan to move to a second provider, tested as a desk exercise in 2025.EV-14Meets
SUP-004Set A46SUB-01Subcontractors and sub-processorsWill any other company handle our data or deliver part of the service to us? If so, which companies, and for what?Yes: our cloud hosting provider (hosting and backups) and an email delivery service (system notifications).EV-15Meets
SUP-004Set A47SUB-02Subcontractors and sub-processorsDo your contracts hold those companies to security requirements at least as strict as ours?Yes: a security schedule in each contract; the hosting provider's certification is checked every year.EV-15Meets
SUP-004Set A48SUB-03Subcontractors and sub-processorsWill you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data?Yes: 30 days' notice with the right to object.EV-10Meets
SUP-004Set A49SUB-04Subcontractors and sub-processorsHow do you assess and monitor the security of your own critical suppliers?Every year we review each critical supplier's certificates and reports, using a list ranked by risk.Meets
SUP-004Set A50SUB-05Subcontractors and sub-processorsIs any part of the service delivered from outside [[our country or region]]? Which, and with what safeguards?No: every subcontractor delivers from the same country.EV-15Meets
SUP-004Set A51SUB-06Subcontractors and sub-processorsPlease name the providers the service depends on (for example cloud, network and software providers) so that we can check them against our other critical suppliers.Named in our sub-processor list: one public cloud provider and one email delivery service.EV-15MeetsChecked against our supplier list for concentration (TPM-04).
SUP-004Set A52PPL-01PeopleAre the staff who can reach our data screened before they start, as far as the law allows?Identity, right to work and references for everyone; criminal record checks for administrators.EV-16Meets
SUP-004Set A53PPL-02PeopleDo staff receive security awareness training when they join and at least once a year?Yes: at joining and every year; 98% completed in the last 12 months.EV-16Meets
SUP-004Set A54PPL-03PeopleAre staff bound by confidentiality duties that continue after they leave?Yes: in every employment and contractor agreement.Meets
SUP-004Set A55PPL-04PeopleDo staff with administrator access receive extra security training, for example on social engineering and safe administration?Yes: once a year for engineers and support staff.EV-16Meets
SUP-004Set A56PHY-01Physical security and hostingWhere is the service hosted: your own premises, a data centre or a cloud provider? Please name them.A public cloud provider, named in our sub-processor list; two data centres.EV-11Meets
SUP-004Set A57PHY-02Physical security and hostingHow are the premises or data centres that hold our data protected against unauthorised entry?Covered by the hosting provider's certification; no customer data is held at our offices.Hosting provider's certificateMeets
SUP-004Set A58PHY-03Physical security and hostingAre those facilities protected against fire, flood and power loss, and is the protection tested?Yes: covered by the hosting provider's independent report, which we review every year.Meets
SUP-004Set A59PHY-04Physical security and hostingHow are equipment and storage media that held our data disposed of?Disks are destroyed by the hosting provider under its certification; our laptops are wiped with a certificate.Meets
SUP-004Set A60PHY-05Physical security and hostingWill your staff visit our premises or connect equipment to our network? If so, under what supervision?No visits and no equipment connected.Not applicableRemote service only.

Lists

DomainAnsweredBySmallestSetVerdictSeveritySeverityDaysSeverityDeadlineTierTierSetSetName
GovernanceSupplierDMeetsHigh9090 calendar daysTier 1Set ASet A
Access and identityBusiness owner, at intakeCPartlyMedium180180 calendar daysTier 2Set BSet B
Data protectionBDoes not meetLowNoneNext assessmentTier 3Set CSet C
Vulnerabilities and patchingANot applicableTier 4Set DSet D

Secure development

Incident management

Continuity and exit

Subcontractors and sub-processors

People

Physical security and hosting

Definitions

Definitions

TermMeaning in this workbook
Question setOne of the four questionnaires, A to D, drawn from the Question Bank. The supplier's tier decides the set (TP-03): Tier 1 Set A, Tier 2 Set B, Tier 3 Set C, Tier 4 Set D.
Smallest setThe smallest set a question appears in. Sets nest, so a question whose smallest set is C is also in Sets B and A.
Intake screeningThe five questions every supplier is screened with before it is engaged or renewed (TP-01), which place it on the tiering criteria TC-1, TC-2, TC-3, TC-4 and the overrides. They are Set D.
TierHow critical a supplier is, from Tier 1 (Critical) to Tier 4 (Minimal), set with the Supplier Criticality & Tiering Model.
Acceptable answerWhat an answer, with its evidence, must show for the verdict Meets. It is the scoring anchor for the question.
MeetsThe answer, and the evidence where asked for, meets the acceptable answer.
PartlySome of the acceptable answer is met; a gap remains. Propose a finding.
Does not meetThe acceptable answer is not met, or the supplier could not show it. Propose a finding.
Not applicableThe question does not apply to this service; the note says why.
Proposed severityThe assessor's proposal for a finding's severity, confirmed in the review report. It sets the remediation deadline (TP-08).
High findingA gap that could directly cause a significant incident or data loss at this supplier. Deadline: 90 calendar days from the assessment date.
Medium findingA gap that weakens a control but has other protection around it. Deadline: 180 calendar days from the assessment date.
Low findingAn improvement; tracked to the next assessment. Deadline: tracked to the next assessment.
FindingA shortfall found in an assessment, with an owner and a deadline, recorded in the Supplier Security Risk Register as F-nn.
Evidence item (EV-nn)A piece of evidence defined in the Supplier Due Diligence Evidence Checklist, with how to validate it.
Business ownerThe manager who buys and relies on the service. Answers the intake questions and signs the decision (TP-05).
AssessorThe person who reviews the answers and evidence and proposes verdicts and findings.
Processor, sub-processorUnder GDPR, a company that processes personal data on our behalf; a sub-processor is a company the processor engages to do part of that processing.
Multi-factor authenticationA log-in that needs a second factor, such as an authenticator app or security key, as well as a password.
Penetration testAn authorised, simulated attack by an independent tester to find weaknesses an attacker could use.
EXAMPLEThe example organisation's answers from SUP-004 on the Set A sheet and the Results sheet's assessment details. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.19 — Information security in supplier relationshipsWhole workbook: supplier security requirements asked in proportion to the supplier's tier
ISO/IEC 27001:2022Annex A 5.21 — Managing information security in the ICT supply chainDomains Secure development, Vulnerabilities and patching, and Subcontractors and sub-processors
NIST CSF 2.0GV.SC-06 — “Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships”Question Bank and set sheets: due diligence before a supplier relationship
NIST CSF 2.0GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship”Assessor verdicts and the Results sheet: supplier risks assessed, recorded and prioritised
NIS2 — Directive (EU) 2022/2555Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure developmentSets A and B: each supplier's vulnerabilities, cybersecurity practices and secure development
GDPR — Regulation (EU) 2016/679Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measuresData protection and Subcontractors domains: the processor's sufficient guarantees
GDPR — Regulation (EU) 2016/679Article 28(2) — no sub-processor without the controller's prior written authorisationSUB-03
GDPR — Regulation (EU) 2016/679Article 28(3) — a binding contract with the processor, covering documented instructions, confidentiality, security, sub-processors, assistance, return or deletion of data, and auditsDAT-04

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)