Skip to content
Service

Third-party & Supply Chain Risk

Your risk increasingly sits in systems you do not run, under contracts you may not have read since signing.

You contract with the first tier and inherit everything behind it. The marked node is a concentration: two suppliers you chose independently sitting on the same underlying provider, so one failure takes out both. That dependency appears in no contract you have signed.

Outsourcing moves the work and leaves the accountability behind. The payroll platform, the managed service provider with domain administrator rights, the analytics tool quietly receiving customer records: each one holds a piece of your risk, and a regulator or a customer will still hold you responsible for it. The uncomfortable part is that your exposure does not stop at the companies you contracted with. It runs through whoever they depend on, and you have no relationship with any of them.

The common response is questionnaire theatre. A long spreadsheet goes out annually, comes back self-attested, and is filed unread. It creates a record that due diligence occurred without producing any knowledge of whether the supplier is actually safe to rely on. The alternative is not more questionnaires, it is fewer and better: tier suppliers by the harm their failure would cause, then spend real assurance effort on the handful at the top and accept a light touch for the rest.

Two things get missed almost universally. The first is concentration: a dozen suppliers can look like diversification while all of them sit on the same cloud region or the same underlying provider, so one outage takes out what looked like independent services. The second is exit. Contracts are signed with attention on onboarding and none on leaving, and organisations discover mid-crisis that they cannot retrieve their data in a usable form or move without an outage they cannot afford.

You might need this if

  • A supplier breach would reach your data and you are not certain which suppliers those are
  • Vendor questionnaires are collected annually, self-attested, and never verified
  • Nobody can say which of your suppliers depend on the same underlying provider
  • Contracts carry no assurance rights, no breach-notification clause, and no exit provisions
  • A customer or insurer asked about your fourth-party exposure and the answer was a guess

Who it's for

Heads of risk, procurement, and executives who have outsourced delivery but cannot outsource the accountability that came with it.

How the engagement runs

  1. 01

    Inventory and tiering

    Establish who your suppliers actually are, including the ones procured on a card outside the formal process, and tier them by the harm a compromise or failure would cause rather than by what they cost.

  2. 02

    Proportionate assurance

    Real assurance on the critical few, including reading the certifications and attestation reports properly rather than noting that they exist. Light-touch treatment for the long tail, so the effort lands where it changes a decision.

  3. 03

    Contractual and concentration review

    Assurance rights, breach notification, subcontractor flow-down, and exit provisions checked against what you would actually need. Alongside that, an analysis of where apparently independent suppliers share a dependency.

  4. 04

    Monitoring and exit readiness

    Reassessment triggered by change rather than by the calendar, supplier incidents wired into your own response plan, and exit plans for the critical few that have been tested rather than assumed.

What's delivered

  • Supplier inventory tiered by the harm a failure would cause, not by invoice value
  • Proportionate assurance: deep review where it matters, light touch where it does not
  • Concentration and fourth-party analysis, exposing the shared dependencies nobody contracted for
  • Contractual control review covering assurance rights, breach notification, and exit
  • Ongoing monitoring and an exit plan that has been thought through before it is needed

Proof point

Assessed service-provider and third-party obligations as part of PCI-DSS programmes in financial services and media, and reviewed AI supply-chain exposure across models, datasets, and third-party dependencies.

Common questions

We have hundreds of suppliers. We cannot assess them all.
You should not try. Assessing everyone equally is how the critical ones end up receiving the same cursory treatment as the stationery supplier. Tiering is the whole point: most organisations find that a small number of suppliers carry the overwhelming majority of the exposure, and those are the ones worth real effort.
Isn't a SOC 2 report or an ISO certificate enough?
It is evidence, not an answer. What matters is the scope, the period covered, and the exceptions, and those are precisely the parts nobody reads. A certificate whose scope excludes the very service you consume is common and tells you almost nothing.
How can we assess fourth parties we have no relationship with?
Not directly, and anyone promising otherwise is overselling. What works is contractual flow-down so your suppliers carry their own obligations, requiring disclosure of critical subcontractors, and analysing concentration so you at least know where the shared dependencies are.
Do we need a third-party risk platform?
Not at the start. Tooling helps once you have a tiering model and a defined process, and simply automates confusion if you do not. Establish what good looks like for your organisation first, then judge whether a product fits it.
Get in touch

Let's talk about your security programme

Considering a vCISO, a security strategy and architecture, a SOC uplift, an AI assurance review, or a secure web build? Tell me where you are and where you need to get to.