Tiered Supplier Security Questionnaire
Provides four proportionate questionnaire sets matched to supplier tier, so low-risk vendors are not sent a 200-question audit.
Available soon
- Format
- Excel
- Size
- 136 KB
- Length
- 14 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Question Bank
- Set A
- Set B
- Set C
- Set D
- Results
- Export
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Tier first. Every supplier is screened and tiered before it is assessed (TP-01, TP-02), using the Supplier Criticality & Tiering Model. The tier decides the set: Tier 1 (Critical) gets Set A; Tier 2 (Important) gets Set B; Tier 3 (Standard) gets Set C; Tier 4 (Minimal) gets Set D. Each supplier must be sent the questionnaire set and evidence request for its tier, and never a set above it. (TP-03) |
| 2 | Question Bank sheet: read the questions and adapt them before first use. Change wording, add service-specific questions in the empty rows at the bottom (give each an ID, a domain and the smallest set it belongs in), or move a question to a different set by changing 'Smallest set'. The set sheets update themselves. |
| 3 | Set D is the intake screening of the Supplier Criticality & Tiering Model, asked word for word: the business owner answers it at intake, with the supplier's help where needed. A Tier 4 supplier is sent nothing more. |
| 4 | To send a set: right-click its tab, choose Move or Copy, tick 'Create a copy' and copy it to a new workbook. In the copy, select all, Copy, then Paste Special → Values, so it no longer depends on the bank. Delete the verdict, note, severity, finding and check columns (L to R) and send it. The supplier fills Answer (column J) and Evidence supplied (column K) and returns the evidence named in column I. |
| 5 | When the answers come back, paste the Answer and Evidence supplied columns (values only) into the same rows of the set sheet in this workbook. Check the question IDs line up. |
| 6 | Validate the evidence with the Supplier Due Diligence Evidence Checklist: scope, dates and the supplier's legal name are checked against the service we buy (TP-04). An answer the evidence does not support is not Meets. |
| 7 | For each question choose a verdict (column L): Meets, Partly, Does not meet or Not applicable. Write a note (column M) for anything other than Meets: what falls short, or why it does not apply. |
| 8 | For each Partly or Does not meet, propose a severity (column N) using the definitions on this sheet. High: a gap that could directly cause a significant incident or data loss at this supplier. Give the finding its reference (column O) when it is entered in the Supplier Security Risk Register. |
| 9 | Clear every Check (column P) that does not say Complete or Finding proposed. |
| 10 | Results sheet: enter the supplier, its tier, the set answered and the assessment date. Read the counts, the domain results and the proposed findings, with their deadlines. Take them into the Supplier Security Review Report Template, where the residual risk is scored on the P05 scale and the decision is made and signed by the business owner (TP-05, TP-06). |
| 11 | Export sheet: the answered set in one table. Copy it and paste as values into your records or attach it to the Supplier Security Review Report Template. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The sets. Set A: 60 questions for Tier 1 — about 60. Set B: 35 questions for Tier 2 — about 35. Set C: 15 questions for Tier 3 — about 15. Set D: 5 questions for Tier 4 — about 5 (intake screening only). Sets nest: every question in Set D is also in Set C, every Set C question is in Set B, and every Set B question is in Set A. 'Smallest set' on the Question Bank says where a question first appears.
Answer scale. There is no score. Each question has an acceptable answer (its scoring anchor), and the assessor's verdict says whether the answer and evidence meet it: Meets — the answer, and the evidence where asked for, meets the acceptable answer. Partly — some of the acceptable answer is met; a gap remains. Propose a finding. Does not meet — the acceptable answer is not met, or the supplier could not show it. Propose a finding. Not applicable — the question does not apply to this service; the note says why.
Weights. Questions are not weighted and verdicts are not added up: one missing control can matter more than fifty good answers. Instead, each shortfall becomes a proposed finding with a severity, and the severity sets the remediation deadline, counted in calendar days from the assessment date: High 90 calendar days; Medium 180 calendar days; Low tracked to the next assessment (TP-08).
High: A gap that could directly cause a significant incident or data loss at this supplier.
Medium: A gap that weakens a control but has other protection around it.
Low: An improvement; tracked to the next assessment.
The EXAMPLE. Set A is filled in with the answers of SUP-004, the ERP software provider (hosted) used by the example organisation (a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders), assessed on 2026-04-21. Column A of the Set A sheet says EXAMPLE on each answered row. Two answers fall short: ACC-03 (support staff without multi-factor authentication) becomes F-01, High, due 2026-07-20; DAT-05 (no evidence of deletion at contract end) becomes F-02, Medium, due 2026-10-18. The supplier was approved with conditions: those two findings fixed by their deadlines.
To clear the example: on the Set A sheet delete the contents of columns A and J to O (not the rows). On the Results sheet replace the yellow assessment details. Nothing else needs changing.
Tailoring — small organisation: most suppliers will be Tier 3 or 4, so Set C and the intake are what you will use most. Keep Set A for the few suppliers that run a critical service. Where a supplier's certification or report (EV-02, EV-03) covers a question and its scope matches the service, write 'Covered by EV-02' in Evidence supplied rather than asking for more.
Tailoring — regulated entity: NIS2 Article 21(2)(d) and 21(3) expect supply-chain security that takes account of each direct supplier's vulnerabilities, the quality of its products and cybersecurity practices, and its secure development: keep the Vulnerabilities and Secure development domains in Sets A and B. Under DORA (Articles 28 to 30), an ICT provider supporting a critical or important function is Tier 1 whatever the criteria say; add questions on audit and access rights, participation in your testing and exit strategies (Article 30(3)), and keep the answered set with the contract record. Under GDPR Article 28(1), the Data protection and Subcontractors answers are the processor's 'sufficient guarantees': have the Data Protection Officer review them.
Tailoring — IT run by a service provider: a managed IT provider is almost always Tier 1 (like the example's SUP-001). Send it Set A, and ask it to answer the Subcontractors questions for every provider it uses on your behalf. If the provider manages other suppliers for you, the business owner still makes and signs the decision (TP-05).
Limitations: see the foot of the Results sheet.
Question Bank
60 questions in 10 domains. 'Smallest set' decides which sets include a question (D = every set). Columns I to P are calculated. Add your own questions in the empty rows below.
| ID | Domain | Question | Answered by | Why we ask | Acceptable answer | Evidence to request (Evidence Checklist item) | Smallest set it is in | In Set A | In Set B | In Set C | In Set D | Set A no. | Set B no. | Set C no. | Set D no. |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GOV-01 | Governance | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Business owner, at intake | An override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02). | A clear yes or no to each part. | EV-01 Completed questionnaire for the supplier's tier | D | Yes | Yes | Yes | Yes | 1 | 1 | 1 | 1 |
| GOV-02 | Governance | Do you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers. | Supplier | Shows how much of your security someone independent has checked, and whether that check covers our service. | A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy. | EV-02 Security certification with its scope statement; EV-03 Independent assurance report | C | Yes | Yes | Yes | — | 2 | 2 | 2 | |
| GOV-03 | Governance | Do you have an information security policy approved by your senior management and reviewed in the last 12 months? | Supplier | Shows that security has an owner at the top of your organisation and is kept current. | Yes: approved by a named senior role and reviewed within the last 12 months. | EV-05 Key security policies with evidence they operate | B | Yes | Yes | — | — | 3 | 3 | ||
| GOV-04 | Governance | Who is accountable for information security in your organisation, and how do we reach them? | Supplier | We need a named person who can answer for security decisions that affect our service. | A named role with the authority to act, and contact details. | EV-01 Completed questionnaire for the supplier's tier | B | Yes | Yes | — | — | 4 | 4 | ||
| GOV-05 | Governance | How do you assess and treat the information security risks to the service you provide to us? | Supplier | A supplier that manages its own risks is less likely to pass them on to its customers. | A documented method, a risk register reviewed at least once a year, and named owners for treatment. | EV-05 Key security policies with evidence they operate; EV-02 Security certification with its scope statement | A | Yes | — | — | — | 5 | |||
| GOV-06 | Governance | Has an internal audit or independent review of your security controls been done in the last 12 months? What did it find, and what is still open? | Supplier | What an audit found, and how quickly it was fixed, tells us more than a certificate alone. | Yes; the findings summarised; any open finding has an owner and a date. | EV-02 Security certification with its scope statement; EV-03 Independent assurance report | A | Yes | — | — | — | 6 | |||
| GOV-07 | Governance | How do you tell customers about a material change to the service, such as a new hosting location, a new sub-processor or a change of ownership? | Supplier | A material change can change our risk, and it triggers a reassessment (TP-09). | Written notice in advance, with a stated notice period and a way for us to object. | EV-10 Data processing terms | A | Yes | — | — | — | 7 | |||
| ACC-01 | Access and identity | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | Business owner, at intake | Places the supplier on tiering criterion TC-3 (Access). | A clear answer: none, supervised on site, remote user, or privileged or network-level. | EV-01 Completed questionnaire for the supplier's tier | D | Yes | Yes | Yes | Yes | 8 | 5 | 3 | 2 |
| ACC-02 | Access and identity | Does every person who can reach our data or systems have their own named account, with no shared log-ins? | Supplier | With shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave. | Yes: named accounts only; any service accounts listed with an owner. | EV-09 Access control evidence for people who reach our data or systems | C | Yes | Yes | Yes | — | 9 | 6 | 4 | |
| ACC-03 | Access and identity | Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff? | Supplier | Stolen passwords are the most common way in; multi-factor authentication stops most attacks that use them. | Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited. | EV-09 Access control evidence for people who reach our data or systems | C | Yes | Yes | Yes | — | 10 | 7 | 5 | |
| ACC-04 | Access and identity | How quickly is a person's access to our data or systems removed when they leave or change role? | Supplier | Access left behind by leavers is a common route for misuse. | Within one working day of leaving, through a joiner, mover and leaver process that leaves a record. | EV-09 Access control evidence for people who reach our data or systems | B | Yes | Yes | — | — | 11 | 8 | ||
| ACC-05 | Access and identity | How often is access to our data or systems reviewed, and by whom? | Supplier | Reviews catch access that is no longer needed. | At least every [[6]] months, by a manager who does not hold the access, with the removals recorded. | EV-09 Access control evidence for people who reach our data or systems | B | Yes | Yes | — | — | 12 | 9 | ||
| ACC-06 | Access and identity | How is administrator (privileged) access controlled: who has it, is it separate from everyday accounts, and is its use logged? | Supplier | Administrator accounts can do the most damage if misused or taken over. | Few named people; separate administrator accounts; use logged and reviewed. | EV-09 Access control evidence for people who reach our data or systems | A | Yes | — | — | — | 13 | |||
| ACC-07 | Access and identity | How does your remote access to our systems work: by what route, can we see who connected, and can we suspend it? | Supplier | Remote support routes are a common way attackers reach a supplier's customers. | One secured route; every session logged; we can see who connected and suspend access. | EV-09 Access control evidence for people who reach our data or systems | A | Yes | — | — | — | 14 | |||
| ACC-08 | Access and identity | Are access logs for our data and systems kept, for how long, and can we have them for an investigation? | Supplier | Without logs an incident cannot be investigated. | Kept at least [[12 months]]; given to us on request within an agreed time. | EV-09 Access control evidence for people who reach our data or systems | A | Yes | — | — | — | 15 | |||
| DAT-01 | Data protection | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | Business owner, at intake | Places the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28. | A clear list of the kinds of data, or 'none'. | EV-01 Completed questionnaire for the supplier's tier | D | Yes | Yes | Yes | Yes | 16 | 10 | 6 | 3 |
| DAT-02 | Data protection | Is our data encrypted when it travels over networks and when it is stored, including in backups? | Supplier | Encryption keeps data safe if a network, disk or backup is exposed. | Yes: current encryption in transit on every network, and at rest including backups. | EV-05 Key security policies with evidence they operate | C | Yes | Yes | Yes | — | 17 | 11 | 7 | |
| DAT-03 | Data protection | In which countries is our data stored, processed and supported, including backups? | Supplier | Location affects legal duties, such as rules on transferring personal data, and who could demand access to it. | Every location named, including backups and support, matching the contract. | EV-11 Data location and hosting statement | B | Yes | Yes | — | — | 18 | 12 | ||
| DAT-04 | Data protection | If you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)? | Supplier | The law requires a binding contract with every processor (GDPR Article 28(3)). | Yes: covering documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits. | EV-10 Data processing terms | B | Yes | Yes | — | — | 19 | 13 | ||
| DAT-05 | Data protection | At the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give? | Supplier | Exit is where data is most often forgotten; every Tier 1 and Tier 2 contract needs an exit plan (TP-11). | Returned in a usable format; deleted from live systems and backups within a stated time; a written certificate of deletion. | EV-12 Data return and deletion procedure | B | Yes | Yes | — | — | 20 | 14 | ||
| DAT-06 | Data protection | How is our data kept apart from other customers' data? | Supplier | In a shared service a weakness in separation exposes every customer. | Separation described, and tested, for example in the penetration test. | EV-06 Penetration test summary | A | Yes | — | — | — | 21 | |||
| DAT-07 | Data protection | Is our data used for anything other than providing the service to us, such as testing, analytics or training software? | Supplier | Other uses multiply the places our data can leak from and may be unlawful for personal data. | No; or only as the contract allows, with personal data removed first. | EV-10 Data processing terms | A | Yes | — | — | — | 22 | |||
| VUL-01 | Vulnerabilities and patching | How quickly do you apply security updates to the systems that deliver our service? | Supplier | Most attacks use weaknesses for which an update already exists. | Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded. | EV-07 Vulnerability and patch status report | C | Yes | Yes | Yes | — | 23 | 15 | 8 | |
| VUL-02 | Vulnerabilities and patching | Do you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed? | Supplier | Scanning finds what patching missed. | At least monthly; findings tracked with an owner and a deadline. | EV-07 Vulnerability and patch status report | B | Yes | Yes | — | — | 24 | 16 | ||
| VUL-03 | Vulnerabilities and patching | Does the service run on any system or software its maker no longer supports (end of life)? | Supplier | Unsupported software no longer gets security updates. | No; or each one listed with extra protection and a replacement date. | EV-07 Vulnerability and patch status report | A | Yes | — | — | — | 25 | |||
| VUL-04 | Vulnerabilities and patching | When was the service last penetration tested by an independent tester, what was in scope, and are the serious findings fixed? | Supplier | A test shows how an attacker would actually get in. | Within the last 12 months; the service we use in scope; High and Critical findings fixed or on a dated plan. | EV-06 Penetration test summary | A | Yes | — | — | — | 26 | |||
| VUL-05 | Vulnerabilities and patching | How do you protect the service against malware, and how do you detect an attack on it? | Supplier | Prevention fails sometimes; detection limits the damage. | Malware protection on servers and staff devices, and security monitoring with alerts that are acted on at any hour. | EV-05 Key security policies with evidence they operate | A | Yes | — | — | — | 27 | |||
| DEV-01 | Secure development | If you write the software we use, do you follow a documented secure development process? | Supplier | Security built in during development costs less than fixing weaknesses after release (NIS2 Article 21(3) names secure development). | Yes: documented, covering security requirements, peer review and security testing before release. Or Not applicable: you do not write it. | EV-08 Secure development evidence | B | Yes | Yes | — | — | 28 | 17 | ||
| DEV-02 | Secure development | Are changes to the service tested and approved before they go live, and can they be rolled back? | Supplier | Untested changes cause outages and open security gaps. | Yes: a separate test environment, approval recorded, and a rollback plan. | EV-08 Secure development evidence | B | Yes | Yes | — | — | 29 | 18 | ||
| DEV-03 | Secure development | Do you check your code, and the open-source components it uses, for known vulnerabilities before release? | Supplier | Most applications are largely made of open-source components, each with its own weaknesses. | Automated checks on every build; release stopped on a Critical finding. | EV-08 Secure development evidence | A | Yes | — | — | — | 30 | |||
| DEV-04 | Secure development | Who can change the live code or data of the service, and are they different from the people who write the code? | Supplier | Separating those who write code from those who release it stops one person making an unchecked change. | Releases through an approved pipeline only; developers cannot change live systems directly. | EV-08 Secure development evidence; EV-09 Access control evidence for people who reach our data or systems | A | Yes | — | — | — | 31 | |||
| DEV-05 | Secure development | How do you tell customers about security vulnerabilities in your product, and about their fixes? | Supplier | We need to know when we are exposed and what to do. | Security notices to customers' administrators, with the fix and any action we must take. | EV-08 Secure development evidence | A | Yes | — | — | — | 32 | |||
| INC-01 | Incident management | Who do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service? | Supplier | Critical suppliers are part of our incident response, with named contacts and notification duties (TP-10). | A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time. | EV-13 Incident contacts and notification commitment | C | Yes | Yes | Yes | — | 33 | 19 | 9 | |
| INC-02 | Incident management | Do you have a documented incident response plan, and when was it last tested? | Supplier | An untested plan usually fails at the first real incident. | Yes: tested within the last 12 months. | EV-13 Incident contacts and notification commitment | C | Yes | Yes | Yes | — | 34 | 20 | 10 | |
| INC-03 | Incident management | What will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2? | Supplier | We may have to report within fixed times, and we cannot do it without your facts. | Initial facts quickly, regular updates and a final report; help with our reporting written into the contract. | EV-13 Incident contacts and notification commitment; EV-10 Data processing terms | B | Yes | Yes | — | — | 35 | 21 | ||
| INC-04 | Incident management | Have you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards? | Supplier | How a supplier learnt from an incident says more than a clean record. | An open answer; any lessons and changes described. | EV-13 Incident contacts and notification commitment | B | Yes | Yes | — | — | 36 | 22 | ||
| INC-05 | Incident management | Will you take part in our incident exercises, or share the results of your own for the service we use? | Supplier | Exercising together finds the gaps between our plans and yours (TP-10). | Yes, on reasonable notice, at least once a year for a critical service. | EV-14 Continuity and recovery test results | A | Yes | — | — | — | 37 | |||
| INC-06 | Incident management | How would you preserve evidence and support an investigation of an incident affecting our data? | Supplier | Evidence lost in the first hours cannot be recovered. | Logs and system images preserved; we or our investigator can have them. | EV-13 Incident contacts and notification commitment | A | Yes | — | — | — | 38 | |||
| CON-01 | Continuity and exit | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | Business owner, at intake | Places the supplier on tiering criterion TC-1 (Service). | The services named, and what would stop or degrade. | EV-01 Completed questionnaire for the supplier's tier | D | Yes | Yes | Yes | Yes | 39 | 23 | 11 | 4 |
| CON-02 | Continuity and exit | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | Business owner, at intake | Places the supplier on tiering criterion TC-4 (Substitutability). | An estimate of the time to replace it, and the effect meanwhile. | EV-01 Completed questionnaire for the supplier's tier | D | Yes | Yes | Yes | Yes | 40 | 24 | 12 | 5 |
| CON-03 | Continuity and exit | If your service stopped, how quickly would it be restored, and how much of our data could be lost? | Supplier | We need to know whether your recovery meets what our services need. | A recovery time and a maximum data loss, both within [[what our service needs]]. | EV-14 Continuity and recovery test results | C | Yes | Yes | Yes | — | 41 | 25 | 13 | |
| CON-04 | Continuity and exit | Are backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored? | Supplier | Backups on the same system are lost with it. | Yes: separate, protected against deletion or change, and restores tested at least every [[3 months]]. | EV-14 Continuity and recovery test results | B | Yes | Yes | — | — | 42 | 26 | ||
| CON-05 | Continuity and exit | Do you have a continuity plan for the service, and when was it last tested? | Supplier | A plan that has not been tested may not work when it is needed. | Yes: tested within the last 12 months, with the results and fixes available to us. | EV-14 Continuity and recovery test results | B | Yes | Yes | — | — | 43 | 27 | ||
| CON-06 | Continuity and exit | If our contract ends, or you stop trading, how would we get our data back and move the service elsewhere? | Supplier | Every Tier 1 and Tier 2 contract needs an exit plan: data return or deletion, access removal and a transition period (TP-11). | Export in a usable format, help with the move, and a transition period, all written into the contract. | EV-12 Data return and deletion procedure | B | Yes | Yes | — | — | 44 | 28 | ||
| CON-07 | Continuity and exit | What happens to our service if one of your own key suppliers, such as your hosting provider, fails? | Supplier | Your suppliers' failures become ours. | The dependency named, with a tested alternative or recovery plan. | EV-14 Continuity and recovery test results; EV-15 Subcontractor and sub-processor list | A | Yes | — | — | — | 45 | |||
| SUB-01 | Subcontractors and sub-processors | Will any other company handle our data or deliver part of the service to us? If so, which companies, and for what? | Supplier | Each such company is part of our supply chain, and for personal data it is a sub-processor. | A list, or 'none'. | EV-15 Subcontractor and sub-processor list | C | Yes | Yes | Yes | — | 46 | 29 | 14 | |
| SUB-02 | Subcontractors and sub-processors | Do your contracts hold those companies to security requirements at least as strict as ours? | Supplier | Our requirements mean little if they stop at your door. | Yes: in their contracts, with their assurance checked. | EV-15 Subcontractor and sub-processor list | B | Yes | Yes | — | — | 47 | 30 | ||
| SUB-03 | Subcontractors and sub-processors | Will you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data? | Supplier | A processor may not use another processor without the controller's prior written authorisation (GDPR Article 28(2)). | Yes: advance notice with the right to object, written into the contract. | EV-10 Data processing terms; EV-15 Subcontractor and sub-processor list | B | Yes | Yes | — | — | 48 | 31 | ||
| SUB-04 | Subcontractors and sub-processors | How do you assess and monitor the security of your own critical suppliers? | Supplier | Shows whether you manage your supply chain as we manage ours. | Suppliers ranked by risk, assessed before contract and reviewed at least once a year. | EV-15 Subcontractor and sub-processor list | A | Yes | — | — | — | 49 | |||
| SUB-05 | Subcontractors and sub-processors | Is any part of the service delivered from outside [[our country or region]]? Which, and with what safeguards? | Supplier | Delivery from other countries can bring legal duties and access risks. | None; or each one named, with the safeguards for any transfer of personal data. | EV-11 Data location and hosting statement; EV-15 Subcontractor and sub-processor list | A | Yes | — | — | — | 50 | |||
| SUB-06 | Subcontractors and sub-processors | Please name the providers the service depends on (for example cloud, network and software providers) so that we can check them against our other critical suppliers. | Supplier | Several critical services relying on one provider is concentration risk (TPM-04). | The providers named. | EV-15 Subcontractor and sub-processor list | A | Yes | — | — | — | 51 | |||
| PPL-01 | People | Are the staff who can reach our data screened before they start, as far as the law allows? | Supplier | Screening reduces the risk from people in trusted roles. | Yes: identity, right to work and references at least; more for administrators. | EV-16 Staff screening and training summary | C | Yes | Yes | Yes | — | 52 | 32 | 15 | |
| PPL-02 | People | Do staff receive security awareness training when they join and at least once a year? | Supplier | Most incidents involve a human mistake. | Yes: at joining and at least once a year, with completion tracked. | EV-16 Staff screening and training summary | B | Yes | Yes | — | — | 53 | 33 | ||
| PPL-03 | People | Are staff bound by confidentiality duties that continue after they leave? | Supplier | Confidentiality should outlast employment. | Yes: in employment and contractor agreements. | EV-16 Staff screening and training summary | A | Yes | — | — | — | 54 | |||
| PPL-04 | People | Do staff with administrator access receive extra security training, for example on social engineering and safe administration? | Supplier | Attackers target the people with the most access. | Yes: at least once a year, for every administrator. | EV-16 Staff screening and training summary | A | Yes | — | — | — | 55 | |||
| PHY-01 | Physical security and hosting | Where is the service hosted: your own premises, a data centre or a cloud provider? Please name them. | Supplier | Tells us who else holds our data, and whose physical security we rely on. | The hosting named. | EV-11 Data location and hosting statement | B | Yes | Yes | — | — | 56 | 34 | ||
| PHY-02 | Physical security and hosting | How are the premises or data centres that hold our data protected against unauthorised entry? | Supplier | Physical access can bypass every other control. | Entry control, visitor records and monitoring; or the hosting provider's certification or report covering them. | EV-02 Security certification with its scope statement; EV-11 Data location and hosting statement | B | Yes | Yes | — | — | 57 | 35 | ||
| PHY-03 | Physical security and hosting | Are those facilities protected against fire, flood and power loss, and is the protection tested? | Supplier | Environmental failures stop services as surely as attacks do. | Yes: covered by an independent report or certification, or by test records. | EV-03 Independent assurance report; EV-11 Data location and hosting statement | A | Yes | — | — | — | 58 | |||
| PHY-04 | Physical security and hosting | How are equipment and storage media that held our data disposed of? | Supplier | Discarded disks are a common source of data leaks. | Secure erasure or destruction, with a record. | EV-12 Data return and deletion procedure | A | Yes | — | — | — | 59 | |||
| PHY-05 | Physical security and hosting | Will your staff visit our premises or connect equipment to our network? If so, under what supervision? | Supplier | Visits and connected equipment bring access inside our defences. | No; or visits supervised and equipment approved before connection. | EV-01 Completed questionnaire for the supplier's tier | A | Yes | — | — | — | 60 |
Set A
Set A, for Tier 1 (Critical) suppliers: 60 questions. EXAMPLE: answered by SUP-004 (ERP software provider (hosted)), assessed 2026-04-21. Clear columns A and J to O to use it.
| Row | No. | ID | Domain | Question | Answered by | Why we ask | Acceptable answer | Evidence to attach | Answer | Evidence supplied | Assessor verdict | Assessor note | Proposed severity | Finding ref | Check | Bank row (calc) | Finding key (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | 1 | GOV-01 | Governance | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Business owner, at intake | An override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02). | A clear yes or no to each part. | EV-01 Completed questionnaire for the supplier's tier | Yes: it processes staff and supplier personal data for us. We are not a regulated financial entity. | Intake record | Meets | Processor override: at least Tier 2. The criteria already reach Tier 1. | Complete | 1 | |||
| EXAMPLE | 2 | GOV-02 | Governance | Do you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers. | Supplier | Shows how much of your security someone independent has checked, and whether that check covers our service. | A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy. | EV-02 Security certification with its scope statement; EV-03 Independent assurance report | ISO/IEC 27001 certification; scope: development, hosting and support of the hosted ERP service. Valid to 2027-02. | EV-02 | Meets | Certificate and scope statement checked: scope covers the service we use. | Complete | 2 | |||
| EXAMPLE | 3 | GOV-03 | Governance | Do you have an information security policy approved by your senior management and reviewed in the last 12 months? | Supplier | Shows that security has an owner at the top of your organisation and is kept current. | Yes: approved by a named senior role and reviewed within the last 12 months. | EV-05 Key security policies with evidence they operate | Yes: approved by the Chief Executive, last reviewed January 2026. | Covered by EV-02 | Meets | Complete | 3 | ||||
| EXAMPLE | 4 | GOV-04 | Governance | Who is accountable for information security in your organisation, and how do we reach them? | Supplier | We need a named person who can answer for security decisions that affect our service. | A named role with the authority to act, and contact details. | EV-01 Completed questionnaire for the supplier's tier | Head of Information Security, named, with a direct email address and phone number. | Meets | Complete | 4 | |||||
| EXAMPLE | 5 | GOV-05 | Governance | How do you assess and treat the information security risks to the service you provide to us? | Supplier | A supplier that manages its own risks is less likely to pass them on to its customers. | A documented method, a risk register reviewed at least once a year, and named owners for treatment. | EV-05 Key security policies with evidence they operate; EV-02 Security certification with its scope statement | Annual risk assessment under our certified management system; risk register reviewed every quarter by the security committee. | Covered by EV-02 | Meets | Complete | 5 | ||||
| EXAMPLE | 6 | GOV-06 | Governance | Has an internal audit or independent review of your security controls been done in the last 12 months? What did it find, and what is still open? | Supplier | What an audit found, and how quickly it was fixed, tells us more than a certificate alone. | Yes; the findings summarised; any open finding has an owner and a date. | EV-02 Security certification with its scope statement; EV-03 Independent assurance report | Certification surveillance audit, March 2026: two minor nonconformities, both closed by May 2026. | Audit summary letter | Meets | Complete | 6 | ||||
| EXAMPLE | 7 | GOV-07 | Governance | How do you tell customers about a material change to the service, such as a new hosting location, a new sub-processor or a change of ownership? | Supplier | A material change can change our risk, and it triggers a reassessment (TP-09). | Written notice in advance, with a stated notice period and a way for us to object. | EV-10 Data processing terms | Customers are told by email 30 days in advance; the contract lets customers object to a new sub-processor. | EV-10 | Meets | Complete | 7 | ||||
| EXAMPLE | 8 | ACC-01 | Access and identity | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | Business owner, at intake | Places the supplier on tiering criterion TC-3 (Access). | A clear answer: none, supervised on site, remote user, or privileged or network-level. | EV-01 Completed questionnaire for the supplier's tier | Remote support access to our ERP application for the provider's support staff; no access to our network. | Intake record | Meets | TC-3 at Tier 2 (remote user access). | Complete | 8 | |||
| EXAMPLE | 9 | ACC-02 | Access and identity | Does every person who can reach our data or systems have their own named account, with no shared log-ins? | Supplier | With shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave. | Yes: named accounts only; any service accounts listed with an owner. | EV-09 Access control evidence for people who reach our data or systems | Yes: named accounts only. Two service accounts run integrations; the support lead owns both. | EV-09 | Meets | User list checked: named accounts only. | Complete | 9 | |||
| EXAMPLE | 10 | ACC-03 | Access and identity | Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff? | Supplier | Stolen passwords are the most common way in; multi-factor authentication stops most attacks that use them. | Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited. | EV-09 Access control evidence for people who reach our data or systems | Customer users must use multi-factor authentication. Our support staff reach customer environments through the support console with a password; multi-factor authentication for the console is planned. | EV-09 | Does not meet | Support staff reach our ERP without multi-factor authentication. A stolen support password could directly expose our finance and payroll data. | High | F-01 | Finding proposed | 10 | 1010 |
| EXAMPLE | 11 | ACC-04 | Access and identity | How quickly is a person's access to our data or systems removed when they leave or change role? | Supplier | Access left behind by leavers is a common route for misuse. | Within one working day of leaving, through a joiner, mover and leaver process that leaves a record. | EV-09 Access control evidence for people who reach our data or systems | The same day, triggered from our HR system; checked every month. | EV-09 | Meets | Complete | 11 | ||||
| EXAMPLE | 12 | ACC-05 | Access and identity | How often is access to our data or systems reviewed, and by whom? | Supplier | Reviews catch access that is no longer needed. | At least every [[6]] months, by a manager who does not hold the access, with the removals recorded. | EV-09 Access control evidence for people who reach our data or systems | Every quarter by the support manager; the last review, March 2026, removed three accounts. | EV-09 | Meets | Complete | 12 | ||||
| EXAMPLE | 13 | ACC-06 | Access and identity | How is administrator (privileged) access controlled: who has it, is it separate from everyday accounts, and is its use logged? | Supplier | Administrator accounts can do the most damage if misused or taken over. | Few named people; separate administrator accounts; use logged and reviewed. | EV-09 Access control evidence for people who reach our data or systems | Six engineers hold separate administrator accounts, raised to administrator only for a task; every session is logged centrally. | EV-09 | Meets | Complete | 13 | ||||
| EXAMPLE | 14 | ACC-07 | Access and identity | How does your remote access to our systems work: by what route, can we see who connected, and can we suspend it? | Supplier | Remote support routes are a common way attackers reach a supplier's customers. | One secured route; every session logged; we can see who connected and suspend access. | EV-09 Access control evidence for people who reach our data or systems | Through the support console only; each session is logged with its ticket number; customers can see the log and suspend support access from their administration screen. | Meets | Complete | 14 | |||||
| EXAMPLE | 15 | ACC-08 | Access and identity | Are access logs for our data and systems kept, for how long, and can we have them for an investigation? | Supplier | Without logs an incident cannot be investigated. | Kept at least [[12 months]]; given to us on request within an agreed time. | EV-09 Access control evidence for people who reach our data or systems | Kept 13 months; exported on request within two working days. | Meets | Complete | 15 | |||||
| EXAMPLE | 16 | DAT-01 | Data protection | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | Business owner, at intake | Places the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28. | A clear list of the kinds of data, or 'none'. | EV-01 Completed questionnaire for the supplier's tier | Personal data: staff pay and bank details and supplier contacts, with our order and stock records. | Intake record | Meets | TC-2 at Tier 2 (personal data). | Complete | 16 | |||
| EXAMPLE | 17 | DAT-02 | Data protection | Is our data encrypted when it travels over networks and when it is stored, including in backups? | Supplier | Encryption keeps data safe if a network, disk or backup is exposed. | Yes: current encryption in transit on every network, and at rest including backups. | EV-05 Key security policies with evidence they operate | Yes: TLS 1.2 or later for every connection; databases and backups encrypted. | Covered by EV-02 | Meets | Complete | 17 | ||||
| EXAMPLE | 18 | DAT-03 | Data protection | In which countries is our data stored, processed and supported, including backups? | Supplier | Location affects legal duties, such as rules on transferring personal data, and who could demand access to it. | Every location named, including backups and support, matching the contract. | EV-11 Data location and hosting statement | Two data centres of our hosting provider, both in the same country as your head office; support staff in that country only. | EV-11 | Meets | Complete | 18 | ||||
| EXAMPLE | 19 | DAT-04 | Data protection | If you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)? | Supplier | The law requires a binding contract with every processor (GDPR Article 28(3)). | Yes: covering documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits. | EV-10 Data processing terms | Yes: our data processing agreement is part of the contract. | EV-10 | Meets | Complete | 19 | ||||
| EXAMPLE | 20 | DAT-05 | Data protection | At the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give? | Supplier | Exit is where data is most often forgotten; every Tier 1 and Tier 2 contract needs an exit plan (TP-11). | Returned in a usable format; deleted from live systems and backups within a stated time; a written certificate of deletion. | EV-12 Data return and deletion procedure | Data is exported on request and deleted from live systems within 30 days. Backups expire on their normal cycle. We do not issue deletion certificates. | Partly | No evidence that our data is deleted at contract end: backups are left to expire and no confirmation is given. Other protection remains (contract clause, encrypted backups). | Medium | F-02 | Finding proposed | 20 | 2020 | |
| EXAMPLE | 21 | DAT-06 | Data protection | How is our data kept apart from other customers' data? | Supplier | In a shared service a weakness in separation exposes every customer. | Separation described, and tested, for example in the penetration test. | EV-06 Penetration test summary | A separate database for each customer; separation tested in the annual penetration test. | Penetration test summary | Meets | Complete | 21 | ||||
| EXAMPLE | 22 | DAT-07 | Data protection | Is our data used for anything other than providing the service to us, such as testing, analytics or training software? | Supplier | Other uses multiply the places our data can leak from and may be unlawful for personal data. | No; or only as the contract allows, with personal data removed first. | EV-10 Data processing terms | No. Test systems use made-up data. | EV-10 | Meets | Complete | 22 | ||||
| EXAMPLE | 23 | VUL-01 | Vulnerabilities and patching | How quickly do you apply security updates to the systems that deliver our service? | Supplier | Most attacks use weaknesses for which an update already exists. | Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded. | EV-07 Vulnerability and patch status report | Critical updates within 7 calendar days; others in the monthly cycle. | EV-07 | Meets | Complete | 23 | ||||
| EXAMPLE | 24 | VUL-02 | Vulnerabilities and patching | Do you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed? | Supplier | Scanning finds what patching missed. | At least monthly; findings tracked with an owner and a deadline. | EV-07 Vulnerability and patch status report | Weekly authenticated scans; findings tracked as tickets with deadlines. | EV-07 | Meets | Complete | 24 | ||||
| EXAMPLE | 25 | VUL-03 | Vulnerabilities and patching | Does the service run on any system or software its maker no longer supports (end of life)? | Supplier | Unsupported software no longer gets security updates. | No; or each one listed with extra protection and a replacement date. | EV-07 Vulnerability and patch status report | None. | EV-07 | Meets | Complete | 25 | ||||
| EXAMPLE | 26 | VUL-04 | Vulnerabilities and patching | When was the service last penetration tested by an independent tester, what was in scope, and are the serious findings fixed? | Supplier | A test shows how an attacker would actually get in. | Within the last 12 months; the service we use in scope; High and Critical findings fixed or on a dated plan. | EV-06 Penetration test summary | February 2026, application and hosting in scope; every High finding fixed by March 2026 and retested. | Penetration test summary | Meets | Complete | 26 | ||||
| EXAMPLE | 27 | VUL-05 | Vulnerabilities and patching | How do you protect the service against malware, and how do you detect an attack on it? | Supplier | Prevention fails sometimes; detection limits the damage. | Malware protection on servers and staff devices, and security monitoring with alerts that are acted on at any hour. | EV-05 Key security policies with evidence they operate | Endpoint detection on every server and laptop; monitored around the clock by a security operations centre. | Covered by EV-02 | Meets | Complete | 27 | ||||
| EXAMPLE | 28 | DEV-01 | Secure development | If you write the software we use, do you follow a documented secure development process? | Supplier | Security built in during development costs less than fixing weaknesses after release (NIS2 Article 21(3) names secure development). | Yes: documented, covering security requirements, peer review and security testing before release. Or Not applicable: you do not write it. | EV-08 Secure development evidence | Yes: secure development policy; every change is peer reviewed. | EV-08 | Meets | Complete | 28 | ||||
| EXAMPLE | 29 | DEV-02 | Secure development | Are changes to the service tested and approved before they go live, and can they be rolled back? | Supplier | Untested changes cause outages and open security gaps. | Yes: a separate test environment, approval recorded, and a rollback plan. | EV-08 Secure development evidence | Yes: releases pass through test and acceptance environments; rollback is scripted. | EV-08 | Meets | Complete | 29 | ||||
| EXAMPLE | 30 | DEV-03 | Secure development | Do you check your code, and the open-source components it uses, for known vulnerabilities before release? | Supplier | Most applications are largely made of open-source components, each with its own weaknesses. | Automated checks on every build; release stopped on a Critical finding. | EV-08 Secure development evidence | Automated code and component scanning on every build; a Critical finding blocks the release. | EV-08 | Meets | Complete | 30 | ||||
| EXAMPLE | 31 | DEV-04 | Secure development | Who can change the live code or data of the service, and are they different from the people who write the code? | Supplier | Separating those who write code from those who release it stops one person making an unchecked change. | Releases through an approved pipeline only; developers cannot change live systems directly. | EV-08 Secure development evidence; EV-09 Access control evidence for people who reach our data or systems | Releases go through the deployment pipeline only; developers have no write access to live systems. | EV-08 | Meets | Complete | 31 | ||||
| EXAMPLE | 32 | DEV-05 | Secure development | How do you tell customers about security vulnerabilities in your product, and about their fixes? | Supplier | We need to know when we are exposed and what to do. | Security notices to customers' administrators, with the fix and any action we must take. | EV-08 Secure development evidence | Security notices to customer administrators; fixes are applied to the hosted service without customer action. | Meets | Complete | 32 | |||||
| EXAMPLE | 33 | INC-01 | Incident management | Who do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service? | Supplier | Critical suppliers are part of our incident response, with named contacts and notification duties (TP-10). | A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time. | EV-13 Incident contacts and notification commitment | A security incident line staffed around the clock and a named incident manager; the contract commits us to notify you within 24 hours. | EV-13 | Meets | Contact tested by a test call. | Complete | 33 | |||
| EXAMPLE | 34 | INC-02 | Incident management | Do you have a documented incident response plan, and when was it last tested? | Supplier | An untested plan usually fails at the first real incident. | Yes: tested within the last 12 months. | EV-13 Incident contacts and notification commitment | Yes; tested in a desk exercise in November 2025. | EV-13 | Meets | Complete | 34 | ||||
| EXAMPLE | 35 | INC-03 | Incident management | What will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2? | Supplier | We may have to report within fixed times, and we cannot do it without your facts. | Initial facts quickly, regular updates and a final report; help with our reporting written into the contract. | EV-13 Incident contacts and notification commitment; EV-10 Data processing terms | An initial notice, updates every 24 hours and a root-cause report within 10 working days; the data processing agreement commits us to help. | EV-10 | Meets | Complete | 35 | ||||
| EXAMPLE | 36 | INC-04 | Incident management | Have you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards? | Supplier | How a supplier learnt from an incident says more than a clean record. | An open answer; any lessons and changes described. | EV-13 Incident contacts and notification commitment | None that affected customers. In 2025 a staff laptop was stolen; it was encrypted and held no customer data. | Meets | Complete | 36 | |||||
| EXAMPLE | 37 | INC-05 | Incident management | Will you take part in our incident exercises, or share the results of your own for the service we use? | Supplier | Exercising together finds the gaps between our plans and yours (TP-10). | Yes, on reasonable notice, at least once a year for a critical service. | EV-14 Continuity and recovery test results | Yes, once a year on request. | Meets | Complete | 37 | |||||
| EXAMPLE | 38 | INC-06 | Incident management | How would you preserve evidence and support an investigation of an incident affecting our data? | Supplier | Evidence lost in the first hours cannot be recovered. | Logs and system images preserved; we or our investigator can have them. | EV-13 Incident contacts and notification commitment | Logs are kept 13 months and preserved on request; forensic support through our incident response retainer. | Meets | Complete | 38 | |||||
| EXAMPLE | 39 | CON-01 | Continuity and exit | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | Business owner, at intake | Places the supplier on tiering criterion TC-1 (Service). | The services named, and what would stop or degrade. | EV-01 Completed questionnaire for the supplier's tier | Finance and payroll, and warehouse dispatch (stock and orders). Both would degrade within a day if the ERP stopped. | Intake record | Meets | TC-1 at Tier 1 (runs critical services). | Complete | 39 | |||
| EXAMPLE | 40 | CON-02 | Continuity and exit | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | Business owner, at intake | Places the supplier on tiering criterion TC-4 (Substitutability). | An estimate of the time to replace it, and the effect meanwhile. | EV-01 Completed questionnaire for the supplier's tier | Not within 3 months: moving to another ERP would take about a year, and finance and payroll would depend on it throughout. | Intake record | Meets | TC-4 at Tier 1. | Complete | 40 | |||
| EXAMPLE | 41 | CON-03 | Continuity and exit | If your service stopped, how quickly would it be restored, and how much of our data could be lost? | Supplier | We need to know whether your recovery meets what our services need. | A recovery time and a maximum data loss, both within [[what our service needs]]. | EV-14 Continuity and recovery test results | Restored within 8 hours, with at most 15 minutes of data lost. | EV-14 | Meets | Meets the finance service's recovery needs. | Complete | 41 | |||
| EXAMPLE | 42 | CON-04 | Continuity and exit | Are backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored? | Supplier | Backups on the same system are lost with it. | Yes: separate, protected against deletion or change, and restores tested at least every [[3 months]]. | EV-14 Continuity and recovery test results | Daily backups to a separate account that cannot be changed for 35 days; a restore is tested every month. | EV-14 | Meets | Complete | 42 | ||||
| EXAMPLE | 43 | CON-05 | Continuity and exit | Do you have a continuity plan for the service, and when was it last tested? | Supplier | A plan that has not been tested may not work when it is needed. | Yes: tested within the last 12 months, with the results and fixes available to us. | EV-14 Continuity and recovery test results | Yes; failover between data centres tested in January 2026, results shared. | EV-14 | Meets | Complete | 43 | ||||
| EXAMPLE | 44 | CON-06 | Continuity and exit | If our contract ends, or you stop trading, how would we get our data back and move the service elsewhere? | Supplier | Every Tier 1 and Tier 2 contract needs an exit plan: data return or deletion, access removal and a transition period (TP-11). | Export in a usable format, help with the move, and a transition period, all written into the contract. | EV-12 Data return and deletion procedure | Full export in standard formats; a 90-day transition period in the contract. | Contract, exit schedule | Meets | Complete | 44 | ||||
| EXAMPLE | 45 | CON-07 | Continuity and exit | What happens to our service if one of your own key suppliers, such as your hosting provider, fails? | Supplier | Your suppliers' failures become ours. | The dependency named, with a tested alternative or recovery plan. | EV-14 Continuity and recovery test results; EV-15 Subcontractor and sub-processor list | Hosted across two data centres of one provider; a plan to move to a second provider, tested as a desk exercise in 2025. | EV-14 | Meets | Complete | 45 | ||||
| EXAMPLE | 46 | SUB-01 | Subcontractors and sub-processors | Will any other company handle our data or deliver part of the service to us? If so, which companies, and for what? | Supplier | Each such company is part of our supply chain, and for personal data it is a sub-processor. | A list, or 'none'. | EV-15 Subcontractor and sub-processor list | Yes: our cloud hosting provider (hosting and backups) and an email delivery service (system notifications). | EV-15 | Meets | Complete | 46 | ||||
| EXAMPLE | 47 | SUB-02 | Subcontractors and sub-processors | Do your contracts hold those companies to security requirements at least as strict as ours? | Supplier | Our requirements mean little if they stop at your door. | Yes: in their contracts, with their assurance checked. | EV-15 Subcontractor and sub-processor list | Yes: a security schedule in each contract; the hosting provider's certification is checked every year. | EV-15 | Meets | Complete | 47 | ||||
| EXAMPLE | 48 | SUB-03 | Subcontractors and sub-processors | Will you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data? | Supplier | A processor may not use another processor without the controller's prior written authorisation (GDPR Article 28(2)). | Yes: advance notice with the right to object, written into the contract. | EV-10 Data processing terms; EV-15 Subcontractor and sub-processor list | Yes: 30 days' notice with the right to object. | EV-10 | Meets | Complete | 48 | ||||
| EXAMPLE | 49 | SUB-04 | Subcontractors and sub-processors | How do you assess and monitor the security of your own critical suppliers? | Supplier | Shows whether you manage your supply chain as we manage ours. | Suppliers ranked by risk, assessed before contract and reviewed at least once a year. | EV-15 Subcontractor and sub-processor list | Every year we review each critical supplier's certificates and reports, using a list ranked by risk. | Meets | Complete | 49 | |||||
| EXAMPLE | 50 | SUB-05 | Subcontractors and sub-processors | Is any part of the service delivered from outside [[our country or region]]? Which, and with what safeguards? | Supplier | Delivery from other countries can bring legal duties and access risks. | None; or each one named, with the safeguards for any transfer of personal data. | EV-11 Data location and hosting statement; EV-15 Subcontractor and sub-processor list | No: every subcontractor delivers from the same country. | EV-15 | Meets | Complete | 50 | ||||
| EXAMPLE | 51 | SUB-06 | Subcontractors and sub-processors | Please name the providers the service depends on (for example cloud, network and software providers) so that we can check them against our other critical suppliers. | Supplier | Several critical services relying on one provider is concentration risk (TPM-04). | The providers named. | EV-15 Subcontractor and sub-processor list | Named in our sub-processor list: one public cloud provider and one email delivery service. | EV-15 | Meets | Checked against our supplier list for concentration (TPM-04). | Complete | 51 | |||
| EXAMPLE | 52 | PPL-01 | People | Are the staff who can reach our data screened before they start, as far as the law allows? | Supplier | Screening reduces the risk from people in trusted roles. | Yes: identity, right to work and references at least; more for administrators. | EV-16 Staff screening and training summary | Identity, right to work and references for everyone; criminal record checks for administrators. | EV-16 | Meets | Complete | 52 | ||||
| EXAMPLE | 53 | PPL-02 | People | Do staff receive security awareness training when they join and at least once a year? | Supplier | Most incidents involve a human mistake. | Yes: at joining and at least once a year, with completion tracked. | EV-16 Staff screening and training summary | Yes: at joining and every year; 98% completed in the last 12 months. | EV-16 | Meets | Complete | 53 | ||||
| EXAMPLE | 54 | PPL-03 | People | Are staff bound by confidentiality duties that continue after they leave? | Supplier | Confidentiality should outlast employment. | Yes: in employment and contractor agreements. | EV-16 Staff screening and training summary | Yes: in every employment and contractor agreement. | Meets | Complete | 54 | |||||
| EXAMPLE | 55 | PPL-04 | People | Do staff with administrator access receive extra security training, for example on social engineering and safe administration? | Supplier | Attackers target the people with the most access. | Yes: at least once a year, for every administrator. | EV-16 Staff screening and training summary | Yes: once a year for engineers and support staff. | EV-16 | Meets | Complete | 55 | ||||
| EXAMPLE | 56 | PHY-01 | Physical security and hosting | Where is the service hosted: your own premises, a data centre or a cloud provider? Please name them. | Supplier | Tells us who else holds our data, and whose physical security we rely on. | The hosting named. | EV-11 Data location and hosting statement | A public cloud provider, named in our sub-processor list; two data centres. | EV-11 | Meets | Complete | 56 | ||||
| EXAMPLE | 57 | PHY-02 | Physical security and hosting | How are the premises or data centres that hold our data protected against unauthorised entry? | Supplier | Physical access can bypass every other control. | Entry control, visitor records and monitoring; or the hosting provider's certification or report covering them. | EV-02 Security certification with its scope statement; EV-11 Data location and hosting statement | Covered by the hosting provider's certification; no customer data is held at our offices. | Hosting provider's certificate | Meets | Complete | 57 | ||||
| EXAMPLE | 58 | PHY-03 | Physical security and hosting | Are those facilities protected against fire, flood and power loss, and is the protection tested? | Supplier | Environmental failures stop services as surely as attacks do. | Yes: covered by an independent report or certification, or by test records. | EV-03 Independent assurance report; EV-11 Data location and hosting statement | Yes: covered by the hosting provider's independent report, which we review every year. | Meets | Complete | 58 | |||||
| EXAMPLE | 59 | PHY-04 | Physical security and hosting | How are equipment and storage media that held our data disposed of? | Supplier | Discarded disks are a common source of data leaks. | Secure erasure or destruction, with a record. | EV-12 Data return and deletion procedure | Disks are destroyed by the hosting provider under its certification; our laptops are wiped with a certificate. | Meets | Complete | 59 | |||||
| EXAMPLE | 60 | PHY-05 | Physical security and hosting | Will your staff visit our premises or connect equipment to our network? If so, under what supervision? | Supplier | Visits and connected equipment bring access inside our defences. | No; or visits supervised and equipment approved before connection. | EV-01 Completed questionnaire for the supplier's tier | No visits and no equipment connected. | Not applicable | Remote service only. | Complete | 60 |
Set B
Set B, for Tier 2 (Important) suppliers: 35 questions, drawn from the Question Bank. The supplier fills J and K; the assessor fills L to O.
| Row | No. | ID | Domain | Question | Answered by | Why we ask | Acceptable answer | Evidence to attach | Answer | Evidence supplied | Assessor verdict | Assessor note | Proposed severity | Finding ref | Check | Bank row (calc) | Finding key (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | GOV-01 | Governance | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Business owner, at intake | An override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02). | A clear yes or no to each part. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 1 | ||||||||
| 2 | GOV-02 | Governance | Do you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers. | Supplier | Shows how much of your security someone independent has checked, and whether that check covers our service. | A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy. | EV-02 Security certification with its scope statement; EV-03 Independent assurance report | Awaiting answer | 2 | ||||||||
| 3 | GOV-03 | Governance | Do you have an information security policy approved by your senior management and reviewed in the last 12 months? | Supplier | Shows that security has an owner at the top of your organisation and is kept current. | Yes: approved by a named senior role and reviewed within the last 12 months. | EV-05 Key security policies with evidence they operate | Awaiting answer | 3 | ||||||||
| 4 | GOV-04 | Governance | Who is accountable for information security in your organisation, and how do we reach them? | Supplier | We need a named person who can answer for security decisions that affect our service. | A named role with the authority to act, and contact details. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 4 | ||||||||
| 5 | ACC-01 | Access and identity | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | Business owner, at intake | Places the supplier on tiering criterion TC-3 (Access). | A clear answer: none, supervised on site, remote user, or privileged or network-level. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 8 | ||||||||
| 6 | ACC-02 | Access and identity | Does every person who can reach our data or systems have their own named account, with no shared log-ins? | Supplier | With shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave. | Yes: named accounts only; any service accounts listed with an owner. | EV-09 Access control evidence for people who reach our data or systems | Awaiting answer | 9 | ||||||||
| 7 | ACC-03 | Access and identity | Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff? | Supplier | Stolen passwords are the most common way in; multi-factor authentication stops most attacks that use them. | Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited. | EV-09 Access control evidence for people who reach our data or systems | Awaiting answer | 10 | ||||||||
| 8 | ACC-04 | Access and identity | How quickly is a person's access to our data or systems removed when they leave or change role? | Supplier | Access left behind by leavers is a common route for misuse. | Within one working day of leaving, through a joiner, mover and leaver process that leaves a record. | EV-09 Access control evidence for people who reach our data or systems | Awaiting answer | 11 | ||||||||
| 9 | ACC-05 | Access and identity | How often is access to our data or systems reviewed, and by whom? | Supplier | Reviews catch access that is no longer needed. | At least every [[6]] months, by a manager who does not hold the access, with the removals recorded. | EV-09 Access control evidence for people who reach our data or systems | Awaiting answer | 12 | ||||||||
| 10 | DAT-01 | Data protection | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | Business owner, at intake | Places the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28. | A clear list of the kinds of data, or 'none'. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 16 | ||||||||
| 11 | DAT-02 | Data protection | Is our data encrypted when it travels over networks and when it is stored, including in backups? | Supplier | Encryption keeps data safe if a network, disk or backup is exposed. | Yes: current encryption in transit on every network, and at rest including backups. | EV-05 Key security policies with evidence they operate | Awaiting answer | 17 | ||||||||
| 12 | DAT-03 | Data protection | In which countries is our data stored, processed and supported, including backups? | Supplier | Location affects legal duties, such as rules on transferring personal data, and who could demand access to it. | Every location named, including backups and support, matching the contract. | EV-11 Data location and hosting statement | Awaiting answer | 18 | ||||||||
| 13 | DAT-04 | Data protection | If you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)? | Supplier | The law requires a binding contract with every processor (GDPR Article 28(3)). | Yes: covering documented instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audits. | EV-10 Data processing terms | Awaiting answer | 19 | ||||||||
| 14 | DAT-05 | Data protection | At the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give? | Supplier | Exit is where data is most often forgotten; every Tier 1 and Tier 2 contract needs an exit plan (TP-11). | Returned in a usable format; deleted from live systems and backups within a stated time; a written certificate of deletion. | EV-12 Data return and deletion procedure | Awaiting answer | 20 | ||||||||
| 15 | VUL-01 | Vulnerabilities and patching | How quickly do you apply security updates to the systems that deliver our service? | Supplier | Most attacks use weaknesses for which an update already exists. | Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded. | EV-07 Vulnerability and patch status report | Awaiting answer | 23 | ||||||||
| 16 | VUL-02 | Vulnerabilities and patching | Do you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed? | Supplier | Scanning finds what patching missed. | At least monthly; findings tracked with an owner and a deadline. | EV-07 Vulnerability and patch status report | Awaiting answer | 24 | ||||||||
| 17 | DEV-01 | Secure development | If you write the software we use, do you follow a documented secure development process? | Supplier | Security built in during development costs less than fixing weaknesses after release (NIS2 Article 21(3) names secure development). | Yes: documented, covering security requirements, peer review and security testing before release. Or Not applicable: you do not write it. | EV-08 Secure development evidence | Awaiting answer | 28 | ||||||||
| 18 | DEV-02 | Secure development | Are changes to the service tested and approved before they go live, and can they be rolled back? | Supplier | Untested changes cause outages and open security gaps. | Yes: a separate test environment, approval recorded, and a rollback plan. | EV-08 Secure development evidence | Awaiting answer | 29 | ||||||||
| 19 | INC-01 | Incident management | Who do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service? | Supplier | Critical suppliers are part of our incident response, with named contacts and notification duties (TP-10). | A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time. | EV-13 Incident contacts and notification commitment | Awaiting answer | 33 | ||||||||
| 20 | INC-02 | Incident management | Do you have a documented incident response plan, and when was it last tested? | Supplier | An untested plan usually fails at the first real incident. | Yes: tested within the last 12 months. | EV-13 Incident contacts and notification commitment | Awaiting answer | 34 | ||||||||
| 21 | INC-03 | Incident management | What will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2? | Supplier | We may have to report within fixed times, and we cannot do it without your facts. | Initial facts quickly, regular updates and a final report; help with our reporting written into the contract. | EV-13 Incident contacts and notification commitment; EV-10 Data processing terms | Awaiting answer | 35 | ||||||||
| 22 | INC-04 | Incident management | Have you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards? | Supplier | How a supplier learnt from an incident says more than a clean record. | An open answer; any lessons and changes described. | EV-13 Incident contacts and notification commitment | Awaiting answer | 36 | ||||||||
| 23 | CON-01 | Continuity and exit | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | Business owner, at intake | Places the supplier on tiering criterion TC-1 (Service). | The services named, and what would stop or degrade. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 39 | ||||||||
| 24 | CON-02 | Continuity and exit | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | Business owner, at intake | Places the supplier on tiering criterion TC-4 (Substitutability). | An estimate of the time to replace it, and the effect meanwhile. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 40 | ||||||||
| 25 | CON-03 | Continuity and exit | If your service stopped, how quickly would it be restored, and how much of our data could be lost? | Supplier | We need to know whether your recovery meets what our services need. | A recovery time and a maximum data loss, both within [[what our service needs]]. | EV-14 Continuity and recovery test results | Awaiting answer | 41 | ||||||||
| 26 | CON-04 | Continuity and exit | Are backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored? | Supplier | Backups on the same system are lost with it. | Yes: separate, protected against deletion or change, and restores tested at least every [[3 months]]. | EV-14 Continuity and recovery test results | Awaiting answer | 42 | ||||||||
| 27 | CON-05 | Continuity and exit | Do you have a continuity plan for the service, and when was it last tested? | Supplier | A plan that has not been tested may not work when it is needed. | Yes: tested within the last 12 months, with the results and fixes available to us. | EV-14 Continuity and recovery test results | Awaiting answer | 43 | ||||||||
| 28 | CON-06 | Continuity and exit | If our contract ends, or you stop trading, how would we get our data back and move the service elsewhere? | Supplier | Every Tier 1 and Tier 2 contract needs an exit plan: data return or deletion, access removal and a transition period (TP-11). | Export in a usable format, help with the move, and a transition period, all written into the contract. | EV-12 Data return and deletion procedure | Awaiting answer | 44 | ||||||||
| 29 | SUB-01 | Subcontractors and sub-processors | Will any other company handle our data or deliver part of the service to us? If so, which companies, and for what? | Supplier | Each such company is part of our supply chain, and for personal data it is a sub-processor. | A list, or 'none'. | EV-15 Subcontractor and sub-processor list | Awaiting answer | 46 | ||||||||
| 30 | SUB-02 | Subcontractors and sub-processors | Do your contracts hold those companies to security requirements at least as strict as ours? | Supplier | Our requirements mean little if they stop at your door. | Yes: in their contracts, with their assurance checked. | EV-15 Subcontractor and sub-processor list | Awaiting answer | 47 | ||||||||
| 31 | SUB-03 | Subcontractors and sub-processors | Will you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data? | Supplier | A processor may not use another processor without the controller's prior written authorisation (GDPR Article 28(2)). | Yes: advance notice with the right to object, written into the contract. | EV-10 Data processing terms; EV-15 Subcontractor and sub-processor list | Awaiting answer | 48 | ||||||||
| 32 | PPL-01 | People | Are the staff who can reach our data screened before they start, as far as the law allows? | Supplier | Screening reduces the risk from people in trusted roles. | Yes: identity, right to work and references at least; more for administrators. | EV-16 Staff screening and training summary | Awaiting answer | 52 | ||||||||
| 33 | PPL-02 | People | Do staff receive security awareness training when they join and at least once a year? | Supplier | Most incidents involve a human mistake. | Yes: at joining and at least once a year, with completion tracked. | EV-16 Staff screening and training summary | Awaiting answer | 53 | ||||||||
| 34 | PHY-01 | Physical security and hosting | Where is the service hosted: your own premises, a data centre or a cloud provider? Please name them. | Supplier | Tells us who else holds our data, and whose physical security we rely on. | The hosting named. | EV-11 Data location and hosting statement | Awaiting answer | 56 | ||||||||
| 35 | PHY-02 | Physical security and hosting | How are the premises or data centres that hold our data protected against unauthorised entry? | Supplier | Physical access can bypass every other control. | Entry control, visitor records and monitoring; or the hosting provider's certification or report covering them. | EV-02 Security certification with its scope statement; EV-11 Data location and hosting statement | Awaiting answer | 57 |
Set C
Set C, for Tier 3 (Standard) suppliers: 15 questions, drawn from the Question Bank. The supplier fills J and K; the assessor fills L to O.
| Row | No. | ID | Domain | Question | Answered by | Why we ask | Acceptable answer | Evidence to attach | Answer | Evidence supplied | Assessor verdict | Assessor note | Proposed severity | Finding ref | Check | Bank row (calc) | Finding key (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | GOV-01 | Governance | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Business owner, at intake | An override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02). | A clear yes or no to each part. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 1 | ||||||||
| 2 | GOV-02 | Governance | Do you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers. | Supplier | Shows how much of your security someone independent has checked, and whether that check covers our service. | A clear yes or no. If yes: named, in date, issued to the company we contract with, and its scope covers the service we buy. | EV-02 Security certification with its scope statement; EV-03 Independent assurance report | Awaiting answer | 2 | ||||||||
| 3 | ACC-01 | Access and identity | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | Business owner, at intake | Places the supplier on tiering criterion TC-3 (Access). | A clear answer: none, supervised on site, remote user, or privileged or network-level. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 8 | ||||||||
| 4 | ACC-02 | Access and identity | Does every person who can reach our data or systems have their own named account, with no shared log-ins? | Supplier | With shared accounts nobody can tell who did what, and one person's access cannot be removed when they leave. | Yes: named accounts only; any service accounts listed with an owner. | EV-09 Access control evidence for people who reach our data or systems | Awaiting answer | 9 | ||||||||
| 5 | ACC-03 | Access and identity | Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff? | Supplier | Stolen passwords are the most common way in; multi-factor authentication stops most attacks that use them. | Yes: enforced by a technical setting for every such person, with no exceptions, or with exceptions listed and time-limited. | EV-09 Access control evidence for people who reach our data or systems | Awaiting answer | 10 | ||||||||
| 6 | DAT-01 | Data protection | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | Business owner, at intake | Places the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28. | A clear list of the kinds of data, or 'none'. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 16 | ||||||||
| 7 | DAT-02 | Data protection | Is our data encrypted when it travels over networks and when it is stored, including in backups? | Supplier | Encryption keeps data safe if a network, disk or backup is exposed. | Yes: current encryption in transit on every network, and at rest including backups. | EV-05 Key security policies with evidence they operate | Awaiting answer | 17 | ||||||||
| 8 | VUL-01 | Vulnerabilities and patching | How quickly do you apply security updates to the systems that deliver our service? | Supplier | Most attacks use weaknesses for which an update already exists. | Critical updates within [[14]] calendar days and others within [[30]] calendar days, with exceptions recorded. | EV-07 Vulnerability and patch status report | Awaiting answer | 23 | ||||||||
| 9 | INC-01 | Incident management | Who do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service? | Supplier | Critical suppliers are part of our incident response, with named contacts and notification duties (TP-10). | A named contact or team, reachable at all times for a critical service, and a commitment to notify us within a stated time. | EV-13 Incident contacts and notification commitment | Awaiting answer | 33 | ||||||||
| 10 | INC-02 | Incident management | Do you have a documented incident response plan, and when was it last tested? | Supplier | An untested plan usually fails at the first real incident. | Yes: tested within the last 12 months. | EV-13 Incident contacts and notification commitment | Awaiting answer | 34 | ||||||||
| 11 | CON-01 | Continuity and exit | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | Business owner, at intake | Places the supplier on tiering criterion TC-1 (Service). | The services named, and what would stop or degrade. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 39 | ||||||||
| 12 | CON-02 | Continuity and exit | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | Business owner, at intake | Places the supplier on tiering criterion TC-4 (Substitutability). | An estimate of the time to replace it, and the effect meanwhile. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 40 | ||||||||
| 13 | CON-03 | Continuity and exit | If your service stopped, how quickly would it be restored, and how much of our data could be lost? | Supplier | We need to know whether your recovery meets what our services need. | A recovery time and a maximum data loss, both within [[what our service needs]]. | EV-14 Continuity and recovery test results | Awaiting answer | 41 | ||||||||
| 14 | SUB-01 | Subcontractors and sub-processors | Will any other company handle our data or deliver part of the service to us? If so, which companies, and for what? | Supplier | Each such company is part of our supply chain, and for personal data it is a sub-processor. | A list, or 'none'. | EV-15 Subcontractor and sub-processor list | Awaiting answer | 46 | ||||||||
| 15 | PPL-01 | People | Are the staff who can reach our data screened before they start, as far as the law allows? | Supplier | Screening reduces the risk from people in trusted roles. | Yes: identity, right to work and references at least; more for administrators. | EV-16 Staff screening and training summary | Awaiting answer | 52 |
Set D
Set D, for Tier 4 (Minimal) suppliers: 5 questions, the intake screening, drawn from the Question Bank. The supplier fills J and K; the assessor fills L to O.
| Row | No. | ID | Domain | Question | Answered by | Why we ask | Acceptable answer | Evidence to attach | Answer | Evidence supplied | Assessor verdict | Assessor note | Proposed severity | Finding ref | Check | Bank row (calc) | Finding key (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | GOV-01 | Governance | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Business owner, at intake | An override sets a minimum tier whatever the criteria say: a GDPR processor is at least Tier 2; an ICT service supporting a critical or important function of a DORA financial entity is Tier 1 (TP-02). | A clear yes or no to each part. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 1 | ||||||||
| 2 | ACC-01 | Access and identity | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | Business owner, at intake | Places the supplier on tiering criterion TC-3 (Access). | A clear answer: none, supervised on site, remote user, or privileged or network-level. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 8 | ||||||||
| 3 | DAT-01 | Data protection | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | Business owner, at intake | Places the supplier on tiering criterion TC-2 (Data), and shows whether it is a processor under GDPR Article 28. | A clear list of the kinds of data, or 'none'. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 16 | ||||||||
| 4 | CON-01 | Continuity and exit | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | Business owner, at intake | Places the supplier on tiering criterion TC-1 (Service). | The services named, and what would stop or degrade. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 39 | ||||||||
| 5 | CON-02 | Continuity and exit | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | Business owner, at intake | Places the supplier on tiering criterion TC-4 (Substitutability). | An estimate of the time to replace it, and the effect meanwhile. | EV-01 Completed questionnaire for the supplier's tier | Awaiting answer | 40 |
Results
Results
Calculated from the set sheet you choose. There is no score: the counts show how complete the assessment is and where the gaps are, and the proposed findings, High first, are what the review report and the decision work from.
| Assessment details | Set no. (calc) | ||||||||
| Field | Value | Note | 1 | ||||||
| Supplier reference | SUP-004 | EXAMPLE — replace with your supplier's reference. | |||||||
| Supplier name | ERP software provider (hosted) | EXAMPLE. | |||||||
| Supplier tier | Tier 1 | EXAMPLE. From the Supplier Criticality & Tiering Model. | |||||||
| Set answered | Set A | Everything below is calculated from this set sheet. | |||||||
| Assessment date | 21 Apr 2026 | EXAMPLE date (SUP-004's assessment). Replace it with the date of your assessment: finding deadlines count from it. | |||||||
| Assessor | [[Name, role]] | ||||||||
| Set for this tier | Set A | Calculated from the tier (TIERS). | |||||||
| Set check | Set A is the set for Tier 1. | Calculated (TP-03). | |||||||
Overall
| Measure | Count | What the results mean | ||||||
|---|---|---|---|---|---|---|---|---|
| Questions in the set | 60 | 1 High finding(s) proposed, and 1 other finding(s). 'Approve' is not available while a High finding is open. Score the residual risk on the P05 scale in the Supplier Security Review Report Template, then choose Approve with conditions, Escalate or Reject. | ||||||
| Meets | 57 | |||||||
| Partly | 1 | |||||||
| Does not meet | 1 | |||||||
| Not applicable | 1 | Decisions (TP-05). Approve: Residual risk within appetite; no High finding open. Approve with conditions: Proceed; named findings fixed by their deadlines, recorded as conditions in the contract or the register. Escalate: Residual risk outside appetite: the risk goes to the risk register (P05) and its owner decides treatment (RM-06). Reject: Do not contract, or plan exit (TP-11). | ||||||
| Not yet assessed | 0 | |||||||
| Findings proposed: High | 1 | |||||||
| Findings proposed: Medium | 1 | |||||||
| Findings proposed: Low | 0 | |||||||
Result by domain
| Domain | Questions | Meets | Partly | Does not meet | Not applicable | Not yet assessed |
|---|---|---|---|---|---|---|
| Governance | 7 | 7 | 0 | 0 | 0 | 0 |
| Access and identity | 8 | 7 | 0 | 1 | 0 | 0 |
| Data protection | 7 | 6 | 1 | 0 | 0 | 0 |
| Vulnerabilities and patching | 5 | 5 | 0 | 0 | 0 | 0 |
| Secure development | 5 | 5 | 0 | 0 | 0 | 0 |
| Incident management | 6 | 6 | 0 | 0 | 0 | 0 |
| Continuity and exit | 7 | 7 | 0 | 0 | 0 | 0 |
| Subcontractors and sub-processors | 6 | 6 | 0 | 0 | 0 | 0 |
| People | 4 | 4 | 0 | 0 | 0 | 0 |
| Physical security and hosting | 5 | 4 | 0 | 0 | 1 | 0 |
Shaded cells are counts of Partly (amber) and Does not meet (red): read them with the column heading.
Proposed findings, High first
| Question | Verdict | Severity | Deadline | Proposed due date | Finding ref | Domain | Assessor note | Question text | Key (calc) |
|---|---|---|---|---|---|---|---|---|---|
| ACC-03 | Does not meet | High | 90 calendar days | 20 Jul 2026 | F-01 | Access and identity | Support staff reach our ERP without multi-factor authentication. A stolen support password could directly expose our finance and payroll data. | Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff? | 1010 |
| DAT-05 | Partly | Medium | 180 calendar days | 18 Oct 2026 | F-02 | Data protection | No evidence that our data is deleted at contract end: backups are left to expire and no confirmation is given. Other protection remains (contract clause, encrypted backups). | At the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give? | 2020 |
Deadlines are calendar days from the assessment date (TP-08). Enter each finding in the Supplier Security Risk Register and put its reference in the set sheet's Finding ref column. The first 12 findings are listed; the set sheet's Check column shows every one.
Limitations
The answers are the supplier's own. A verdict of Meets is only as good as the evidence behind it: validate the evidence with the Supplier Due Diligence Evidence Checklist (TP-04), and do not count an answer the evidence does not support.
The results are not a risk score. The supplier's residual risk is scored on the P05 impact × likelihood scale in the Supplier Security Review Report Template, and the decision follows from it (TP-05, TP-06).
The questions are generic. A service with unusual risks (for example payment card data, operational technology or artificial intelligence) needs questions of its own: add them to the bank.
A questionnaire describes one moment. Changes, incidents and certificate expiry between assessments are caught by monitoring and reassessment (TP-09), not by this workbook.
Export
The set chosen on the Results sheet, one row per question. Everything here is calculated: select the table, copy, and paste as values into your records or the review report.
| Supplier | Set | No. | ID | Domain | Question | Answer | Evidence supplied | Verdict | Assessor note | Proposed severity | Finding ref |
|---|---|---|---|---|---|---|---|---|---|---|---|
| SUP-004 | Set A | 1 | GOV-01 | Governance | Will it process personal data on our behalf, and does it support a critical or important function of a regulated financial entity (DORA)? | Yes: it processes staff and supplier personal data for us. We are not a regulated financial entity. | Intake record | Meets | Processor override: at least Tier 2. The criteria already reach Tier 1. | ||
| SUP-004 | Set A | 2 | GOV-02 | Governance | Do you hold a current independent security certification or assurance report for the service you would provide to us? If so, name it and say what it covers. | ISO/IEC 27001 certification; scope: development, hosting and support of the hosted ERP service. Valid to 2027-02. | EV-02 | Meets | Certificate and scope statement checked: scope covers the service we use. | ||
| SUP-004 | Set A | 3 | GOV-03 | Governance | Do you have an information security policy approved by your senior management and reviewed in the last 12 months? | Yes: approved by the Chief Executive, last reviewed January 2026. | Covered by EV-02 | Meets | |||
| SUP-004 | Set A | 4 | GOV-04 | Governance | Who is accountable for information security in your organisation, and how do we reach them? | Head of Information Security, named, with a direct email address and phone number. | Meets | ||||
| SUP-004 | Set A | 5 | GOV-05 | Governance | How do you assess and treat the information security risks to the service you provide to us? | Annual risk assessment under our certified management system; risk register reviewed every quarter by the security committee. | Covered by EV-02 | Meets | |||
| SUP-004 | Set A | 6 | GOV-06 | Governance | Has an internal audit or independent review of your security controls been done in the last 12 months? What did it find, and what is still open? | Certification surveillance audit, March 2026: two minor nonconformities, both closed by May 2026. | Audit summary letter | Meets | |||
| SUP-004 | Set A | 7 | GOV-07 | Governance | How do you tell customers about a material change to the service, such as a new hosting location, a new sub-processor or a change of ownership? | Customers are told by email 30 days in advance; the contract lets customers object to a new sub-processor. | EV-10 | Meets | |||
| SUP-004 | Set A | 8 | ACC-01 | Access and identity | What access will its people or systems have to ours: none, supervised on site, remote user, or privileged or network-level? | Remote support access to our ERP application for the provider's support staff; no access to our network. | Intake record | Meets | TC-3 at Tier 2 (remote user access). | ||
| SUP-004 | Set A | 9 | ACC-02 | Access and identity | Does every person who can reach our data or systems have their own named account, with no shared log-ins? | Yes: named accounts only. Two service accounts run integrations; the support lead owns both. | EV-09 | Meets | User list checked: named accounts only. | ||
| SUP-004 | Set A | 10 | ACC-03 | Access and identity | Is multi-factor authentication required for every person who can reach our data or systems, including your support and administrator staff? | Customer users must use multi-factor authentication. Our support staff reach customer environments through the support console with a password; multi-factor authentication for the console is planned. | EV-09 | Does not meet | Support staff reach our ERP without multi-factor authentication. A stolen support password could directly expose our finance and payroll data. | High | F-01 |
| SUP-004 | Set A | 11 | ACC-04 | Access and identity | How quickly is a person's access to our data or systems removed when they leave or change role? | The same day, triggered from our HR system; checked every month. | EV-09 | Meets | |||
| SUP-004 | Set A | 12 | ACC-05 | Access and identity | How often is access to our data or systems reviewed, and by whom? | Every quarter by the support manager; the last review, March 2026, removed three accounts. | EV-09 | Meets | |||
| SUP-004 | Set A | 13 | ACC-06 | Access and identity | How is administrator (privileged) access controlled: who has it, is it separate from everyday accounts, and is its use logged? | Six engineers hold separate administrator accounts, raised to administrator only for a task; every session is logged centrally. | EV-09 | Meets | |||
| SUP-004 | Set A | 14 | ACC-07 | Access and identity | How does your remote access to our systems work: by what route, can we see who connected, and can we suspend it? | Through the support console only; each session is logged with its ticket number; customers can see the log and suspend support access from their administration screen. | Meets | ||||
| SUP-004 | Set A | 15 | ACC-08 | Access and identity | Are access logs for our data and systems kept, for how long, and can we have them for an investigation? | Kept 13 months; exported on request within two working days. | Meets | ||||
| SUP-004 | Set A | 16 | DAT-01 | Data protection | What data of ours will it hold, see or process: none or public, internal, personal, or customer, sensitive or personal data at scale? | Personal data: staff pay and bank details and supplier contacts, with our order and stock records. | Intake record | Meets | TC-2 at Tier 2 (personal data). | ||
| SUP-004 | Set A | 17 | DAT-02 | Data protection | Is our data encrypted when it travels over networks and when it is stored, including in backups? | Yes: TLS 1.2 or later for every connection; databases and backups encrypted. | Covered by EV-02 | Meets | |||
| SUP-004 | Set A | 18 | DAT-03 | Data protection | In which countries is our data stored, processed and supported, including backups? | Two data centres of our hosting provider, both in the same country as your head office; support staff in that country only. | EV-11 | Meets | |||
| SUP-004 | Set A | 19 | DAT-04 | Data protection | If you process personal data for us, will you sign data processing terms that meet GDPR Article 28(3)? | Yes: our data processing agreement is part of the contract. | EV-10 | Meets | |||
| SUP-004 | Set A | 20 | DAT-05 | Data protection | At the end of the contract, how is our data returned and deleted, including from backups, and what evidence of deletion do you give? | Data is exported on request and deleted from live systems within 30 days. Backups expire on their normal cycle. We do not issue deletion certificates. | Partly | No evidence that our data is deleted at contract end: backups are left to expire and no confirmation is given. Other protection remains (contract clause, encrypted backups). | Medium | F-02 | |
| SUP-004 | Set A | 21 | DAT-06 | Data protection | How is our data kept apart from other customers' data? | A separate database for each customer; separation tested in the annual penetration test. | Penetration test summary | Meets | |||
| SUP-004 | Set A | 22 | DAT-07 | Data protection | Is our data used for anything other than providing the service to us, such as testing, analytics or training software? | No. Test systems use made-up data. | EV-10 | Meets | |||
| SUP-004 | Set A | 23 | VUL-01 | Vulnerabilities and patching | How quickly do you apply security updates to the systems that deliver our service? | Critical updates within 7 calendar days; others in the monthly cycle. | EV-07 | Meets | |||
| SUP-004 | Set A | 24 | VUL-02 | Vulnerabilities and patching | Do you scan the systems that deliver our service for vulnerabilities? How often, and how are the findings tracked until fixed? | Weekly authenticated scans; findings tracked as tickets with deadlines. | EV-07 | Meets | |||
| SUP-004 | Set A | 25 | VUL-03 | Vulnerabilities and patching | Does the service run on any system or software its maker no longer supports (end of life)? | None. | EV-07 | Meets | |||
| SUP-004 | Set A | 26 | VUL-04 | Vulnerabilities and patching | When was the service last penetration tested by an independent tester, what was in scope, and are the serious findings fixed? | February 2026, application and hosting in scope; every High finding fixed by March 2026 and retested. | Penetration test summary | Meets | |||
| SUP-004 | Set A | 27 | VUL-05 | Vulnerabilities and patching | How do you protect the service against malware, and how do you detect an attack on it? | Endpoint detection on every server and laptop; monitored around the clock by a security operations centre. | Covered by EV-02 | Meets | |||
| SUP-004 | Set A | 28 | DEV-01 | Secure development | If you write the software we use, do you follow a documented secure development process? | Yes: secure development policy; every change is peer reviewed. | EV-08 | Meets | |||
| SUP-004 | Set A | 29 | DEV-02 | Secure development | Are changes to the service tested and approved before they go live, and can they be rolled back? | Yes: releases pass through test and acceptance environments; rollback is scripted. | EV-08 | Meets | |||
| SUP-004 | Set A | 30 | DEV-03 | Secure development | Do you check your code, and the open-source components it uses, for known vulnerabilities before release? | Automated code and component scanning on every build; a Critical finding blocks the release. | EV-08 | Meets | |||
| SUP-004 | Set A | 31 | DEV-04 | Secure development | Who can change the live code or data of the service, and are they different from the people who write the code? | Releases go through the deployment pipeline only; developers have no write access to live systems. | EV-08 | Meets | |||
| SUP-004 | Set A | 32 | DEV-05 | Secure development | How do you tell customers about security vulnerabilities in your product, and about their fixes? | Security notices to customer administrators; fixes are applied to the hosted service without customer action. | Meets | ||||
| SUP-004 | Set A | 33 | INC-01 | Incident management | Who do we contact about a security incident, and will you tell us promptly if an incident affects our data or our service? | A security incident line staffed around the clock and a named incident manager; the contract commits us to notify you within 24 hours. | EV-13 | Meets | Contact tested by a test call. | ||
| SUP-004 | Set A | 34 | INC-02 | Incident management | Do you have a documented incident response plan, and when was it last tested? | Yes; tested in a desk exercise in November 2025. | EV-13 | Meets | |||
| SUP-004 | Set A | 35 | INC-03 | Incident management | What will you tell us about an incident that affects us, and will you help us meet our own reporting duties, such as the 72-hour notification of a personal data breach under GDPR or incident reporting under NIS2? | An initial notice, updates every 24 hours and a root-cause report within 10 working days; the data processing agreement commits us to help. | EV-10 | Meets | |||
| SUP-004 | Set A | 36 | INC-04 | Incident management | Have you had a security incident or personal data breach in the last 24 months that affected customers? What did you change afterwards? | None that affected customers. In 2025 a staff laptop was stolen; it was encrypted and held no customer data. | Meets | ||||
| SUP-004 | Set A | 37 | INC-05 | Incident management | Will you take part in our incident exercises, or share the results of your own for the service we use? | Yes, once a year on request. | Meets | ||||
| SUP-004 | Set A | 38 | INC-06 | Incident management | How would you preserve evidence and support an investigation of an incident affecting our data? | Logs are kept 13 months and preserved on request; forensic support through our incident response retainer. | Meets | ||||
| SUP-004 | Set A | 39 | CON-01 | Continuity and exit | Which of our services does it run or support, and would any critical service stop or degrade if it failed? | Finance and payroll, and warehouse dispatch (stock and orders). Both would degrade within a day if the ERP stopped. | Intake record | Meets | TC-1 at Tier 1 (runs critical services). | ||
| SUP-004 | Set A | 40 | CON-02 | Continuity and exit | If it stopped tomorrow, how long would it take to replace it, and what would stop in the meantime? | Not within 3 months: moving to another ERP would take about a year, and finance and payroll would depend on it throughout. | Intake record | Meets | TC-4 at Tier 1. | ||
| SUP-004 | Set A | 41 | CON-03 | Continuity and exit | If your service stopped, how quickly would it be restored, and how much of our data could be lost? | Restored within 8 hours, with at most 15 minutes of data lost. | EV-14 | Meets | Meets the finance service's recovery needs. | ||
| SUP-004 | Set A | 42 | CON-04 | Continuity and exit | Are backups of our data kept apart from the live system, protected against deletion and ransomware, and test-restored? | Daily backups to a separate account that cannot be changed for 35 days; a restore is tested every month. | EV-14 | Meets | |||
| SUP-004 | Set A | 43 | CON-05 | Continuity and exit | Do you have a continuity plan for the service, and when was it last tested? | Yes; failover between data centres tested in January 2026, results shared. | EV-14 | Meets | |||
| SUP-004 | Set A | 44 | CON-06 | Continuity and exit | If our contract ends, or you stop trading, how would we get our data back and move the service elsewhere? | Full export in standard formats; a 90-day transition period in the contract. | Contract, exit schedule | Meets | |||
| SUP-004 | Set A | 45 | CON-07 | Continuity and exit | What happens to our service if one of your own key suppliers, such as your hosting provider, fails? | Hosted across two data centres of one provider; a plan to move to a second provider, tested as a desk exercise in 2025. | EV-14 | Meets | |||
| SUP-004 | Set A | 46 | SUB-01 | Subcontractors and sub-processors | Will any other company handle our data or deliver part of the service to us? If so, which companies, and for what? | Yes: our cloud hosting provider (hosting and backups) and an email delivery service (system notifications). | EV-15 | Meets | |||
| SUP-004 | Set A | 47 | SUB-02 | Subcontractors and sub-processors | Do your contracts hold those companies to security requirements at least as strict as ours? | Yes: a security schedule in each contract; the hosting provider's certification is checked every year. | EV-15 | Meets | |||
| SUP-004 | Set A | 48 | SUB-03 | Subcontractors and sub-processors | Will you ask our permission, or give us notice and the right to object, before adding or changing a sub-processor of our personal data? | Yes: 30 days' notice with the right to object. | EV-10 | Meets | |||
| SUP-004 | Set A | 49 | SUB-04 | Subcontractors and sub-processors | How do you assess and monitor the security of your own critical suppliers? | Every year we review each critical supplier's certificates and reports, using a list ranked by risk. | Meets | ||||
| SUP-004 | Set A | 50 | SUB-05 | Subcontractors and sub-processors | Is any part of the service delivered from outside [[our country or region]]? Which, and with what safeguards? | No: every subcontractor delivers from the same country. | EV-15 | Meets | |||
| SUP-004 | Set A | 51 | SUB-06 | Subcontractors and sub-processors | Please name the providers the service depends on (for example cloud, network and software providers) so that we can check them against our other critical suppliers. | Named in our sub-processor list: one public cloud provider and one email delivery service. | EV-15 | Meets | Checked against our supplier list for concentration (TPM-04). | ||
| SUP-004 | Set A | 52 | PPL-01 | People | Are the staff who can reach our data screened before they start, as far as the law allows? | Identity, right to work and references for everyone; criminal record checks for administrators. | EV-16 | Meets | |||
| SUP-004 | Set A | 53 | PPL-02 | People | Do staff receive security awareness training when they join and at least once a year? | Yes: at joining and every year; 98% completed in the last 12 months. | EV-16 | Meets | |||
| SUP-004 | Set A | 54 | PPL-03 | People | Are staff bound by confidentiality duties that continue after they leave? | Yes: in every employment and contractor agreement. | Meets | ||||
| SUP-004 | Set A | 55 | PPL-04 | People | Do staff with administrator access receive extra security training, for example on social engineering and safe administration? | Yes: once a year for engineers and support staff. | EV-16 | Meets | |||
| SUP-004 | Set A | 56 | PHY-01 | Physical security and hosting | Where is the service hosted: your own premises, a data centre or a cloud provider? Please name them. | A public cloud provider, named in our sub-processor list; two data centres. | EV-11 | Meets | |||
| SUP-004 | Set A | 57 | PHY-02 | Physical security and hosting | How are the premises or data centres that hold our data protected against unauthorised entry? | Covered by the hosting provider's certification; no customer data is held at our offices. | Hosting provider's certificate | Meets | |||
| SUP-004 | Set A | 58 | PHY-03 | Physical security and hosting | Are those facilities protected against fire, flood and power loss, and is the protection tested? | Yes: covered by the hosting provider's independent report, which we review every year. | Meets | ||||
| SUP-004 | Set A | 59 | PHY-04 | Physical security and hosting | How are equipment and storage media that held our data disposed of? | Disks are destroyed by the hosting provider under its certification; our laptops are wiped with a certificate. | Meets | ||||
| SUP-004 | Set A | 60 | PHY-05 | Physical security and hosting | Will your staff visit our premises or connect equipment to our network? If so, under what supervision? | No visits and no equipment connected. | Not applicable | Remote service only. |
Lists
| Domain | AnsweredBy | SmallestSet | Verdict | Severity | SeverityDays | SeverityDeadline | Tier | TierSet | SetName |
|---|---|---|---|---|---|---|---|---|---|
| Governance | Supplier | D | Meets | High | 90 | 90 calendar days | Tier 1 | Set A | Set A |
| Access and identity | Business owner, at intake | C | Partly | Medium | 180 | 180 calendar days | Tier 2 | Set B | Set B |
| Data protection | B | Does not meet | Low | None | Next assessment | Tier 3 | Set C | Set C | |
| Vulnerabilities and patching | A | Not applicable | Tier 4 | Set D | Set D |
Secure development
Incident management
Continuity and exit
Subcontractors and sub-processors
People
Physical security and hosting
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Question set | One of the four questionnaires, A to D, drawn from the Question Bank. The supplier's tier decides the set (TP-03): Tier 1 Set A, Tier 2 Set B, Tier 3 Set C, Tier 4 Set D. |
| Smallest set | The smallest set a question appears in. Sets nest, so a question whose smallest set is C is also in Sets B and A. |
| Intake screening | The five questions every supplier is screened with before it is engaged or renewed (TP-01), which place it on the tiering criteria TC-1, TC-2, TC-3, TC-4 and the overrides. They are Set D. |
| Tier | How critical a supplier is, from Tier 1 (Critical) to Tier 4 (Minimal), set with the Supplier Criticality & Tiering Model. |
| Acceptable answer | What an answer, with its evidence, must show for the verdict Meets. It is the scoring anchor for the question. |
| Meets | The answer, and the evidence where asked for, meets the acceptable answer. |
| Partly | Some of the acceptable answer is met; a gap remains. Propose a finding. |
| Does not meet | The acceptable answer is not met, or the supplier could not show it. Propose a finding. |
| Not applicable | The question does not apply to this service; the note says why. |
| Proposed severity | The assessor's proposal for a finding's severity, confirmed in the review report. It sets the remediation deadline (TP-08). |
| High finding | A gap that could directly cause a significant incident or data loss at this supplier. Deadline: 90 calendar days from the assessment date. |
| Medium finding | A gap that weakens a control but has other protection around it. Deadline: 180 calendar days from the assessment date. |
| Low finding | An improvement; tracked to the next assessment. Deadline: tracked to the next assessment. |
| Finding | A shortfall found in an assessment, with an owner and a deadline, recorded in the Supplier Security Risk Register as F-nn. |
| Evidence item (EV-nn) | A piece of evidence defined in the Supplier Due Diligence Evidence Checklist, with how to validate it. |
| Business owner | The manager who buys and relies on the service. Answers the intake questions and signs the decision (TP-05). |
| Assessor | The person who reviews the answers and evidence and proposes verdicts and findings. |
| Processor, sub-processor | Under GDPR, a company that processes personal data on our behalf; a sub-processor is a company the processor engages to do part of that processing. |
| Multi-factor authentication | A log-in that needs a second factor, such as an authenticator app or security key, as well as a password. |
| Penetration test | An authorised, simulated attack by an independent tester to find weaknesses an attacker could use. |
| EXAMPLE | The example organisation's answers from SUP-004 on the Set A sheet and the Results sheet's assessment details. Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.19 — Information security in supplier relationships | Whole workbook: supplier security requirements asked in proportion to the supplier's tier |
| ISO/IEC 27001:2022 | Annex A 5.21 — Managing information security in the ICT supply chain | Domains Secure development, Vulnerabilities and patching, and Subcontractors and sub-processors |
| NIST CSF 2.0 | GV.SC-06 — “Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships” | Question Bank and set sheets: due diligence before a supplier relationship |
| NIST CSF 2.0 | GV.SC-07 — “The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship” | Assessor verdicts and the Results sheet: supplier risks assessed, recorded and prioritised |
| NIS2 — Directive (EU) 2022/2555 | Article 21(3) — measures take into account each direct supplier's specific vulnerabilities and the overall quality of its products and cybersecurity practices, including secure development | Sets A and B: each supplier's vulnerabilities, cybersecurity practices and secure development |
| GDPR — Regulation (EU) 2016/679 | Article 28(1) — use only processors providing sufficient guarantees of appropriate technical and organisational measures | Data protection and Subcontractors domains: the processor's sufficient guarantees |
| GDPR — Regulation (EU) 2016/679 | Article 28(2) — no sub-processor without the controller's prior written authorisation | SUB-03 |
| GDPR — Regulation (EU) 2016/679 | Article 28(3) — a binding contract with the processor, covering documented instructions, confidentiality, security, sub-processors, assistance, return or deletion of data, and audits | DAT-04 |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2016/679 (GDPR)