Resources · 07
Third-party digital risk: assess a critical supplier
Connect evidence, dependencies, subcontractors, continuity and reversibility before entrusting a sensitive service or dataset.
· 16 min
What this guide helps achieve
- Separate useful suppliers from genuinely critical third parties
- Verify beyond self-assessment
- See dependency chains
- Prepare a workable exit
Quick check
- Which service stops if this supplier fails?
- Which data can it read, transform or export?
- Which subcontractors are essential?
- Has restoration been demonstrated?
- Can data be recovered in a usable format?
Step-by-step method
- 01
Classify criticality
Connect each supplier to processes, data, users, obligations and recovery deadlines. High spend is not always critical; a small API may be.
Deliverable: service, impact and owner profile.
- 02
Request proportionate evidence
Target architecture, access, incidents, backups, tests, relevant certifications and exceptions. An attestation does not replace understanding its scope.
Deliverable: evidence file and clarification points.
- 03
Map the chain
Identify hosting, data processors, SaaS components and geographic dependencies. Look for common concentration across several suppliers.
Deliverable: dependency and concentration map.
- 04
Test scenarios
Assess outage, compromise, data loss, ownership change and contract termination. Give each scenario a signal, decision and fallback.
Deliverable: failure scenarios and compensating measures.
- 05
Align contract and operation
Check that notification deadlines, evidence access, subcontracting, return, deletion and exit support can work in practice.
Deliverable: contractual and operational controls.
- 06
Decide and monitor
State acceptance, remediation or rejection with an owner, deadline and closure evidence. Reassess after major change or incident.
Deliverable: conditional decision and monitoring plan.
Management indicators
| Indicator | What it measures | First action |
|---|---|---|
| Coverage | Critical suppliers with an owner and current file | Address services with no fallback |
| Valid evidence | Important controls supported by recent proof | Request items that can change the decision |
| Concentration | Services dependent on the same actor or region | Prepare a realistic alternative |
| Reversibility | Measured time and quality for recovering service and data | Test an export before it is urgently needed |
Common pitfalls
- Sending every supplier the same questionnaire
- Treating certification as absence of risk
- Ignoring supplier subcontractors
- Negotiating exit without testing it
Frequently asked questions
Must every supplier be audited?
No. Start with those whose failure affects an essential service, sensitive data, an obligation or an existing concentration.
Is certification enough?
No. It can be useful evidence, but its scope, date, exclusions and relationship to your use must be checked.
How often should a supplier be reviewed?
According to criticality and pace of change, and after an incident, acquisition, major service change or material subcontracting change.






