Third-party & Supply Chain Risk
Your risk increasingly sits in systems you do not run, under contracts you may not have read since signing.
Outsourcing moves the work and leaves the accountability behind. The payroll platform, the managed service provider with domain administrator rights, the analytics tool quietly receiving customer records: each one holds a piece of your risk, and a regulator or a customer will still hold you responsible for it. The uncomfortable part is that your exposure does not stop at the companies you contracted with. It runs through whoever they depend on, and you have no relationship with any of them.
The common response is questionnaire theatre. A long spreadsheet goes out annually, comes back self-attested, and is filed unread. It creates a record that due diligence occurred without producing any knowledge of whether the supplier is actually safe to rely on. The alternative is not more questionnaires, it is fewer and better: tier suppliers by the harm their failure would cause, then spend real assurance effort on the handful at the top and accept a light touch for the rest.
Two things get missed almost universally. The first is concentration: a dozen suppliers can look like diversification while all of them sit on the same cloud region or the same underlying provider, so one outage takes out what looked like independent services. The second is exit. Contracts are signed with attention on onboarding and none on leaving, and organisations discover mid-crisis that they cannot retrieve their data in a usable form or move without an outage they cannot afford.
You might need this if
- A supplier breach would reach your data and you are not certain which suppliers those are
- Vendor questionnaires are collected annually, self-attested, and never verified
- Nobody can say which of your suppliers depend on the same underlying provider
- Contracts carry no assurance rights, no breach-notification clause, and no exit provisions
- A customer or insurer asked about your fourth-party exposure and the answer was a guess
Who it's for
Heads of risk, procurement, and executives who have outsourced delivery but cannot outsource the accountability that came with it.
How the engagement runs
- 01
Inventory and tiering
Establish who your suppliers actually are, including the ones procured on a card outside the formal process, and tier them by the harm a compromise or failure would cause rather than by what they cost.
- 02
Proportionate assurance
Real assurance on the critical few, including reading the certifications and attestation reports properly rather than noting that they exist. Light-touch treatment for the long tail, so the effort lands where it changes a decision.
- 03
Contractual and concentration review
Assurance rights, breach notification, subcontractor flow-down, and exit provisions checked against what you would actually need. Alongside that, an analysis of where apparently independent suppliers share a dependency.
- 04
Monitoring and exit readiness
Reassessment triggered by change rather than by the calendar, supplier incidents wired into your own response plan, and exit plans for the critical few that have been tested rather than assumed.
What's delivered
- Supplier inventory tiered by the harm a failure would cause, not by invoice value
- Proportionate assurance: deep review where it matters, light touch where it does not
- Concentration and fourth-party analysis, exposing the shared dependencies nobody contracted for
- Contractual control review covering assurance rights, breach notification, and exit
- Ongoing monitoring and an exit plan that has been thought through before it is needed
Proof point
Assessed service-provider and third-party obligations as part of PCI-DSS programmes in financial services and media, and reviewed AI supply-chain exposure across models, datasets, and third-party dependencies.
Common questions
- We have hundreds of suppliers. We cannot assess them all.
- You should not try. Assessing everyone equally is how the critical ones end up receiving the same cursory treatment as the stationery supplier. Tiering is the whole point: most organisations find that a small number of suppliers carry the overwhelming majority of the exposure, and those are the ones worth real effort.
- Isn't a SOC 2 report or an ISO certificate enough?
- It is evidence, not an answer. What matters is the scope, the period covered, and the exceptions, and those are precisely the parts nobody reads. A certificate whose scope excludes the very service you consume is common and tells you almost nothing.
- How can we assess fourth parties we have no relationship with?
- Not directly, and anyone promising otherwise is overselling. What works is contractual flow-down so your suppliers carry their own obligations, requiring disclosure of critical subcontractors, and analysing concentration so you at least know where the shared dependencies are.
- Do we need a third-party risk platform?
- Not at the start. Tooling helps once you have a tiering model and a defined process, and simply automates confusion if you do not. Establish what good looks like for your organisation first, then judge whether a product fits it.
Other services
- Risk Management & Quantitative Risk Analysis
- Digital, Cyber & Technology Risk
- AI Security, Risk & Governance
- Applied AI for Cyber
- Security Operations
- Governance, Risk & Compliance
- Data Governance & Privacy
- Secure Architecture & Zero Trust
- Secure Web Applications for SMEs
- Virtual CISO & Security Leadership
- Incident Response & Readiness
Let's talk about your security programme
Considering a vCISO, a security strategy and architecture, a SOC uplift, an AI assurance review, or a secure web build? Tell me where you are and where you need to get to.