Third-Party Risk Management: Build a Programme That Scales
Third-party risk management (TPRM) is how an organisation identifies, assesses, contracts for and monitors the security risk that suppliers bring, from cloud platforms and payroll bureaux to the IT support firm with admin access. The practical next step is simple: build a single supplier inventory, tier it by criticality and data access, and match the depth of your checks to the tier.
TL;DR
- Start with an inventory: pull suppliers from finance, procurement and SSO logs, then tier them by criticality and data access within the first 2 to 4 weeks.
- Scale vendor due diligence to the tier: critical suppliers get evidence review (SOC 2 Type 2, ISO/IEC 27001 scope) and contract clauses; low-tier suppliers get a short questionnaire or none.
- Read the scope, not the badge: check that a certificate or report actually covers the service, locations and period you rely on.
- Put security, breach notification, right to audit and sub-processor terms into contracts before signature – procurement owns the gate, security owns the requirements.
- Review critical suppliers at least annually and on trigger events (breach, acquisition, new data flows), and plan offboarding before you need it.
What is third-party risk management and why does it matter?
Every supplier that touches your systems, data or operations extends your attack surface. A managed service provider with remote access, a SaaS tool holding customer records, or a logistics partner your revenue depends on can each cause a breach or outage that your own controls never see. Third-party risk management is the structured way of deciding which of those relationships matter most and what assurance you need for each.
The terms overlap, so it helps to be precise:
- Third-party risk management is the overall programme: governance, inventory, tiering, assessment, contracts, monitoring and exit. A documented TPRM framework sets out who does what at each stage.
- Vendor risk management is often used interchangeably, though some organisations reserve it for commercial suppliers and use TPRM for the wider set (partners, resellers, outsourcers).
- A third-party risk assessment or supplier security assessment is a single point-in-time check of one supplier – a questionnaire, evidence review or audit.
- Supply chain security is the broader discipline, including the security of software and hardware you buy.
- Fourth-party risk is the risk from your suppliers’ suppliers: the hosting provider behind your SaaS vendor, or the sub-processor handling your data.
Security is only one lens. A complete programme also considers resilience, financial stability and concentration risk, but security and data protection are usually where regulators and customers ask the hardest questions.
How do you tier suppliers by criticality and data access?
Tiering is what stops TPRM collapsing under its own weight. Two questions do most of the work: how badly would the business be hurt if this supplier failed or was compromised, and what access does it have to your data and systems? Score both, then take the higher result.
| Tier | Typical profile | Examples | Review cadence |
|---|---|---|---|
| Tier 1 – Critical | Supports a critical service, holds sensitive or large volumes of personal data, or has privileged access to your network | Core cloud platform, managed IT/security provider, payroll bureau, payment processor | Annual full review plus trigger events |
| Tier 2 – High | Holds confidential or personal data, or an outage would cause notable disruption with workarounds | CRM, HR system, marketing platform with customer lists | Every 1 to 2 years |
| Tier 3 – Moderate | Limited internal data, no privileged access, replaceable within weeks | Project management tools, design agencies | At onboarding and renewal |
| Tier 4 – Low | No access to data or systems | Office supplies, facilities with no network access | Basic checks only |
Build the inventory from more than one source. Accounts payable shows who you pay; single sign-on and expense data reveal SaaS tools bought on a credit card; IT knows who has remote access. Record an internal owner for every supplier – without one, nobody answers the questions when something goes wrong.
Vendor due diligence: what evidence should you ask for by tier?
Security questionnaires are useful for gathering facts, but self-reported answers are not assurance. For higher tiers, ask for independent evidence and read it properly.
| Tier | Questionnaire | Independent evidence | Contract and follow-up |
|---|---|---|---|
| Tier 1 | Full questionnaire tailored to the service | SOC 2 Type 2 report or ISO/IEC 27001 certificate with Statement of Applicability; recent penetration test summary; business continuity test evidence | Full security schedule, right to audit, breach notification, exit plan; remediation tracked to closure |
| Tier 2 | Standard questionnaire | SOC 2 or ISO/IEC 27001 evidence where available; Cyber Essentials as a baseline | Security and data protection clauses; key findings tracked |
| Tier 3 | Short questionnaire (10 to 20 questions) | Cyber Essentials or published security information | Standard terms, including data processing terms if personal data is involved |
| Tier 4 | None or a declaration | None | Standard terms |
Reading an ISO/IEC 27001 certificate. Check the scope statement: does it cover the service, sites and teams you actually use, or only a head office? Confirm the certification body, the issue and expiry dates, and whether the body is accredited (in the UK, by UKAS). Ask for the Statement of Applicability to see which controls are included. Remember that Anvay, like any consultancy, does not certify anyone – certification is carried out by independent certification bodies.
Reading a SOC 2 report. A Type 1 report describes controls at a point in time; a Type 2 report tests whether they operated over a period, usually 6 to 12 months. Check the period end date (and ask for a bridge letter if it is stale), the system description, any exceptions noted by the auditor, and whether the opinion is qualified. Look for carve-outs, where subservice organisations such as the hosting provider are excluded – that is fourth-party risk you need to assess separately. Finally, list the complementary user entity controls: these are the controls you are expected to operate, such as managing your own user access.
Third-party risk management checklist: step by step
A workable TPRM framework follows the supplier lifecycle. Use this checklist to build or review yours:
- Set governance. Agree a short policy, risk appetite and RACI: procurement runs the process, security and privacy set requirements, the business owner accepts residual risk.
- Build the inventory. Consolidate suppliers from finance, procurement, SSO and IT records; assign an owner to each.
- Tier suppliers. Score criticality and data access; record the rationale.
- Assess before onboarding. Run the third-party risk assessment for the tier: questionnaire, evidence review, and targeted follow-up questions.
- Contract for security. Include security requirements, breach notification timelines, right to audit, sub-processor controls, data location, and return or deletion of data at exit. Where the supplier processes personal data on your behalf, UK GDPR Article 28 requires a written contract with specific terms, including sub-processor authorisation.
- Remediate or accept. Track gaps with owners and dates; where you accept a risk, record who accepted it and why.
- Monitor continuously. Review on the tier’s cadence and on triggers: a supplier breach, acquisition, new service, or change in data shared.
- Plan incident handling. Know which contact to call, what the supplier must tell you and when, and how supplier incidents feed your own response plan. Rehearse a supplier-breach scenario in a tabletop exercise.
- Map fourth parties. For Tier 1 suppliers, list their critical sub-processors and hosting providers, and check whether any single provider sits behind several of your suppliers.
- Offboard cleanly. Revoke access and accounts, retrieve or confirm deletion of data, and update the inventory.
Which regulations drive supply chain security requirements?
The following is guidance, not legal advice; take specialist advice on how the rules apply to your organisation.
- NCSC supply chain security guidance sets out 12 principles grouped into four stages: understand the risks, establish control, check your arrangements and continuously improve. It is a sensible baseline for any UK organisation.
- NIS2 Article 21 requires in-scope EU entities to include supply chain security in their cybersecurity risk-management measures, covering relationships with direct suppliers and service providers and taking account of their vulnerabilities and security practices. National transposition varies, so check the current position in each member state where you operate; our NIS2 implementation guide covers this in more depth.
- DORA applies to EU financial entities from 17 January 2025. It requires ICT third-party risk management, including a register of information on all contractual arrangements for ICT services, pre-contract assessment, specified contractual provisions and exit strategies for services supporting critical or important functions.
- UK GDPR Article 28 requires controllers to use only processors that provide sufficient guarantees, with a written contract covering instructions, confidentiality, security, sub-processors, assistance, deletion or return of data, and audits. The ICO publishes guidance on these terms.
- UK Cyber Security and Resilience Bill is expected to extend regulation to some managed service providers and to strengthen supply chain duties; check the current position before relying on any specific requirement.
For a standards-based approach, ISO/IEC 27036 is the supplier relationship security series: Part 1 gives the overview and concepts, Part 2 the requirements, and later parts cover ICT supply chain and cloud services. ISO/IEC 27001:2022 Annex A also includes supplier controls (5.19 to 5.23), so a supplier programme supports certification too – see our comparison of NIST CSF and ISO 27001.
TPRM timeline and effort drivers
For a small or mid-sized organisation, standing up a first programme typically takes 6 to 12 weeks: 2 to 4 weeks for inventory and tiering, 2 to 4 weeks to assess the Tier 1 suppliers, and further time to update contracts, which depends on renewal dates and supplier negotiation. The main effort drivers are:
- the number of suppliers and how scattered the records are across finance, IT and the business;
- the number of Tier 1 suppliers and whether they can provide independent evidence;
- regulatory scope – a DORA register of information or NIS2 obligations add structure and documentation;
- contract leverage: large SaaS providers rarely accept bespoke clauses, so you assess their standard terms instead;
- tooling: a spreadsheet works for dozens of suppliers; hundreds usually justify a GRC platform.
Common third-party risk management mistakes
- Questionnaire fatigue. Sending the same 300-question form to every supplier wastes everyone’s time and produces answers nobody reads. Tier first, then scale.
- One-off checks. Assessing at onboarding and never again misses changes in ownership, services and data flows.
- Ignoring SaaS sprawl. Tools bought on expense cards or free tiers often hold real customer data and never pass procurement. Use SSO and expense data to find them.
- Trusting the badge. A certificate that covers a different service, or a SOC 2 report from two years ago, is not assurance.
- No owner, no exit. Suppliers without an internal owner drift, and suppliers without an exit plan become impossible to replace.
- Forgetting fourth parties. Several suppliers may share a single cloud provider, concentrating risk you cannot see in your own inventory.
How Anvay approaches third-party risk management
We start by understanding your own security baseline, often through a free GAPZe assessment, because supplier requirements only make sense against your own controls and risk appetite. GAPZe gives an indicative readiness screening based on self-reported answers, not a certification or audit opinion. From there we work through four steps:
- Inventory and tier suppliers – consolidate records, assign owners and apply a tiering model you can defend.
- Assess – questionnaires and evidence – right-sized questionnaires and a structured review of SOC 2 reports, ISO/IEC 27001 scopes and other evidence.
- Contract and remediate – security schedules and data processing terms, with supplier gaps tracked to closure or formally accepted.
- Monitor and review – review cadences, trigger events, fourth-party mapping and reporting to leadership.
Each engagement is scoped before work starts, with deliverables and timescales agreed up front.
One practical takeaway for supplier security
This week, list your ten most important suppliers and answer two questions for each: what data or access do they have, and what independent evidence do you hold that covers the service you actually use? The gaps in that short list will tell you where your third-party risk management programme should start.
— Achal, Anvay
Anvay services for third-party risk management
Our GRC and risk work includes designing a TPRM framework, tiering models and supplier policies that fit your size. Through vendor assessment we carry out supplier security assessments and review evidence for critical suppliers before you sign or renew. If you need ongoing ownership of the programme without a full-time hire, our fractional CISO service can run supplier reviews and report to your board, and our compliance and assurance team can align it with ISO/IEC 27001, NIS2 or DORA. A good first step is the free GAPZe assessment, which includes a PDF report and a free 30-minute 1:1. Talk to us about your supplier risk.
FAQ
What is third-party risk management?
Third-party risk management is the programme an organisation uses to identify, assess, contract for and monitor the risks suppliers and partners introduce. It covers the full lifecycle, from inventory and tiering through due diligence and contract clauses to ongoing monitoring, incident handling and offboarding. Security and data protection are usually the core, alongside resilience and concentration risk.
What are the stages of a third-party risk assessment?
A typical third-party risk assessment has five stages: scope the service and data involved, tier the supplier, gather information through a questionnaire and independent evidence such as SOC 2 reports or ISO/IEC 27001 certificates, analyse gaps against your requirements, and agree remediation or formally accept the residual risk before contract signature or renewal.
What is fourth-party risk?
Fourth-party risk is the risk from your suppliers’ own suppliers, such as the cloud host behind a SaaS product or a sub-processor handling your personal data. You cannot usually assess them directly, so check carve-outs in SOC 2 reports, require sub-processor lists and change notifications in contracts, and look for single providers sitting behind several critical suppliers.
Is an ISO 27001 certificate enough for vendor due diligence?
Not on its own. An ISO/IEC 27001 certificate shows an accredited body has audited the supplier’s management system, but you need to check that the scope covers the service and locations you use, that it is current, and which controls the Statement of Applicability includes. For critical suppliers, combine it with targeted questions and contract terms.
How often should suppliers be reassessed?
Base frequency on tier. Critical suppliers are commonly reviewed annually, high-tier suppliers every one to two years, and lower tiers at renewal. Reassess immediately on trigger events: a supplier breach, change of ownership, a new service, or a significant change in the data or access you share. Light continuous monitoring between reviews helps catch problems early.
Sources
- Supply chain security guidance (NCSC)
- The principles of supply chain security (NCSC)
- Directive (EU) 2022/2555 (NIS2) (EUR-Lex)
- Regulation (EU) 2022/2554 on digital operational resilience (DORA) (EUR-Lex)
- Contracts and liabilities between controllers and processors (ICO)
- ISO/IEC 27036-1:2021 Cybersecurity – Supplier relationships – Part 1 (ISO)
- SOC 2 – System and Organization Controls (AICPA & CIMA)
Primary references and standards: this article draws on NCSC supply chain guidance, the NIS2 and DORA legal texts, ICO guidance on UK GDPR Article 28, ISO/IEC 27036 and the AICPA SOC suite.