practice

Third-Party Risk Assessment

also called Vendor Risk, Supplier Assurance

Evaluating the security, resilience and compliance posture of suppliers whose failure would become your incident.

riskvendorssupply-chain

Every integration imports the supplier's risk, and regulators are consistent on the point that outsourcing an activity does not outsource accountability for it. When a vendor is breached, it is your customers' data and your notification obligation.

The assessment that matters is proportionate to what the vendor actually touches, and most organisations get this backwards — applying the same lengthy questionnaire to a payroll processor handling every employee record and to a font provider. The triage should be driven by data sensitivity, integration depth, and whether the vendor sits on a critical path.

What to examine for anything material: independent assurance rather than self-attestation, the sub-processor chain because your vendor's vendors are your vendors, incident notification terms with a defined timeframe, data location and transfer mechanism, and exit terms including data return and deletion.

The architectural half is more useful than the paperwork and is usually neglected: design so that the vendor's failure is survivable. Scope credentials narrowly, isolate the integration, limit what data flows to them to what the function requires, apply timeouts and circuit breakers so their outage does not become yours, and know what your degraded mode looks like when they are unavailable.

The concrete question worth asking in review: what precisely can this vendor read, and what happens to us at 09:00 on a Monday if they are down for six hours?