Resources · 07

Third-party digital risk: assess a critical supplier

Connect evidence, dependencies, subcontractors, continuity and reversibility before entrusting a sensitive service or dataset.

· 16 min

Risk team validating a technology vendor and its critical dependencies

What this guide helps achieve

  • Separate useful suppliers from genuinely critical third parties
  • Verify beyond self-assessment
  • See dependency chains
  • Prepare a workable exit

Quick check

  • Which service stops if this supplier fails?
  • Which data can it read, transform or export?
  • Which subcontractors are essential?
  • Has restoration been demonstrated?
  • Can data be recovered in a usable format?

Step-by-step method

  1. 01

    Classify criticality

    Connect each supplier to processes, data, users, obligations and recovery deadlines. High spend is not always critical; a small API may be.

    Deliverable: service, impact and owner profile.

  2. 02

    Request proportionate evidence

    Target architecture, access, incidents, backups, tests, relevant certifications and exceptions. An attestation does not replace understanding its scope.

    Deliverable: evidence file and clarification points.

  3. 03

    Map the chain

    Identify hosting, data processors, SaaS components and geographic dependencies. Look for common concentration across several suppliers.

    Deliverable: dependency and concentration map.

  4. 04

    Test scenarios

    Assess outage, compromise, data loss, ownership change and contract termination. Give each scenario a signal, decision and fallback.

    Deliverable: failure scenarios and compensating measures.

  5. 05

    Align contract and operation

    Check that notification deadlines, evidence access, subcontracting, return, deletion and exit support can work in practice.

    Deliverable: contractual and operational controls.

  6. 06

    Decide and monitor

    State acceptance, remediation or rejection with an owner, deadline and closure evidence. Reassess after major change or incident.

    Deliverable: conditional decision and monitoring plan.

Management indicators

IndicatorWhat it measuresFirst action
CoverageCritical suppliers with an owner and current fileAddress services with no fallback
Valid evidenceImportant controls supported by recent proofRequest items that can change the decision
ConcentrationServices dependent on the same actor or regionPrepare a realistic alternative
ReversibilityMeasured time and quality for recovering service and dataTest an export before it is urgently needed

Common pitfalls

  • Sending every supplier the same questionnaire
  • Treating certification as absence of risk
  • Ignoring supplier subcontractors
  • Negotiating exit without testing it

Frequently asked questions

Must every supplier be audited?

No. Start with those whose failure affects an essential service, sensitive data, an obligation or an existing concentration.

Is certification enough?

No. It can be useful evidence, but its scope, date, exclusions and relationship to your use must be checked.

How often should a supplier be reviewed?

According to criticality and pace of change, and after an incident, acquisition, major service change or material subcontracting change.