Consultant reviewing supplier evidence and contract documents
Supplier Security Reviews

A proper look at one supplier, before you sign or renew.

We test what a specific supplier tells you against what's actually true — evidence, technical checks where permitted, and the contract terms behind the relationship — and give you a plain recommendation before the decision is made.

Typical duration
2-4
Evidence items checked
12+
Recommendation types
3
Illustrative figures
The challenge

A confident sales call is not evidence of security.

By the time a supplier reaches contract stage, they've usually been through procurement, legal and a technical demo, and everyone in the room wants the deal to close. A questionnaire response claiming 'ISO 27001 certified, MFA enforced, data encrypted' tends to get accepted at face value, because checking it properly feels like it slows things down and nobody wants to be the person raising awkward questions late in the process.

The gap between what a supplier states and what's actually configured is common and rarely malicious — it's frequently a sales or account team answering from memory rather than from a technical audit. A certificate might have lapsed, might not cover the service you're actually buying, or might apply to a different part of the business entirely. None of that surfaces unless someone asks for the certificate itself and checks its scope.

Contracts often lag behind the technical conversation too. A security schedule copied from a template three years ago may not reflect the supplier's actual sub-processor list, breach notification practice, or what happens to your data if the contract ends. Exit and offboarding terms in particular are frequently vague or absent, which becomes a serious problem only once you're trying to leave.

Renewal is often where the least scrutiny happens, precisely because the relationship already exists. A supplier's security posture can change materially over a contract term — new sub-processors, a change of ownership, a previous incident that was never disclosed — and none of that gets revisited if renewal is treated as administrative rather than as a decision point in its own right.

The organisations that get caught out are rarely careless. They're busy, the supplier sounds credible, and there's commercial pressure to move quickly. A structured review exists precisely to slow that specific decision down by a week or two, without holding up everything else.

  • Certification and control claims accepted without checking scope or validity
  • Security schedules copied from templates that don't match the actual service
  • Sub-processors and data flows not disclosed or not questioned
  • Renewal treated as administrative, missing changes since the original agreement
Our approach

We test the claims, check what's permitted technically, and read the contract properly.

We start by agreeing the scope of the review with you — what the supplier actually has access to, what data they hold or process, and what decision the review needs to support, whether that's onboarding, renewal or a specific concern raised internally. This shapes how deep the review needs to go rather than applying the same checklist to every supplier regardless of stakes.

We then request evidence directly from the supplier rather than relying on their account team's summary: certificates and their scope, security policies, penetration test summaries, sub-processor lists, and configuration detail for the specific controls that matter to your relationship. Where a claim can't be evidenced, we say so in the report rather than letting it pass quietly.

Where appropriate and with the supplier's consent, we carry out non-intrusive technical checks — external attack surface review, TLS and email security configuration, exposed services and known vulnerability indicators. This isn't a substitute for a full penetration test, but it often reveals a meaningful gap between what's claimed and what's actually internet-facing.

In parallel, we review the contract's security schedule against the access being granted: data protection and sub-processor terms, breach notification obligations, audit rights, and — often the most neglected area — exit and offboarding provisions covering data return and deletion. Gaps here get flagged clearly enough for legal or procurement to act on before signature.

The review concludes with a plain-language recommendation, not a score out of ten: proceed, proceed with specific conditions attached, or do not proceed without remediation. We set out exactly what was checked, what was and wasn't provided, and what the residual risk looks like, so whoever makes the final call is doing so with a complete picture.

  • Scope agreed against the actual decision the review needs to support
  • Evidence requested and checked directly, not summarised secondhand
  • Non-intrusive technical checks where the supplier consents
  • Contract security schedule reviewed against the access actually granted
What's included

Everything in the engagement, set out up front.

A fixed-scope review of a single supplier, sized to the decision it needs to support.

Evidence request and review

Certificates, policies, penetration test summaries and configuration evidence requested and checked against the supplier's actual claims.

Sub-processor and data flow check

Confirmation of where data actually goes, including any sub-processors not previously disclosed.

External technical review

Non-intrusive checks of internet-facing services, TLS configuration and email security, where the supplier consents.

Contract and security schedule review

Assessment of data protection, breach notification, audit and exit provisions against the level of access granted.

Findings and gap report

A clear written account of what was reviewed, what was evidenced, and what remains outstanding.

Recommendation and rationale

A plain proceed, proceed-with-conditions, or do-not-proceed recommendation, with the reasoning behind it set out.

Deliverables

What you receive.

  • Evidence request log and supplier responses
  • Certificate and claim verification summary
  • Sub-processor and data flow map
  • External technical review summary (where applicable)
  • Contract and security schedule gap findings
  • Exit and offboarding provision assessment
  • Overall findings report
  • Clear proceed / conditional / do-not-proceed recommendation
  • Recommended conditions or remediation, where relevant
Who it suits

Built for organisations that need the work done properly.

Organisations onboarding a critical supplier

Businesses granting a new supplier meaningful access to systems or data and wanting a checked view before contracts are signed.

Firms approaching a contract renewal

Organisations treating renewal as a genuine checkpoint rather than an administrative formality, particularly for long-standing suppliers.

Teams responding to a specific concern

Businesses reacting to a supplier incident, a change of ownership, or an undisclosed sub-processor that's raised internal questions.

Organisations needing to evidence due diligence

Firms that need to show a customer, auditor or insurer that a specific high-risk supplier relationship was properly checked, not assumed.

Outcomes & benefits

What changes once the work is done.

What you get once the review is complete.

A decision based on evidence, not assurance

A recommendation grounded in what was actually checked, rather than what the supplier's account team stated.

Contract gaps closed before signature

Security schedule and exit provisions tightened while there's still leverage to negotiate them.

Undisclosed exposure surfaced early

Sub-processors, lapsed certificates or unpatched services identified before they become your problem.

A clear paper trail for due diligence

A written record showing exactly what was reviewed and why the decision was made, ready to produce if challenged later.

A defensible renewal decision

Confidence that a long-standing supplier relationship still matches what was originally agreed, or a clear list of what's changed.

Confidence to walk away where warranted

A plain do-not-proceed recommendation, backed by evidence, when a supplier genuinely isn't ready for the access being requested.

The point of a review is to give you a real answer, not a reassuring one.

It would be easy to run reviews that mostly confirm what the supplier already told you, because that's the path of least friction and nobody enjoys being the reason a deal slows down. We don't work that way. If a supplier can't evidence a claim, the report says so plainly, and if a contract's exit terms leave you without a clear route to get your data back, we flag it regardless of how far along the negotiation already is.

This is deliberately a single-relationship service. Where you need the structure to manage assessment across your entire supplier population — tiering, proportionate question sets, an ongoing reassessment cycle — that's a different piece of work, and our third party risk assessments service covers it. The two are complementary: a programme's tiering often tells you which suppliers warrant this level of individual scrutiny in the first place.

We carry out these reviews for organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, most commonly ahead of a renewal date or a new supplier onboarding with meaningful data or system access. Timing matters — reviews commissioned with a week left before a renewal deadline leave little room to negotiate anything a finding actually turns up.

Findings and evidence can be logged in Secure Chain Horizon against the relevant supplier record, so the review isn't a one-off document that gets filed and forgotten, but sits alongside the ongoing assurance history for that relationship. That's optional — we're equally happy to hand over a standalone report if that's what suits your process.

Frequently asked questions

Questions we are asked most often.

How is this different from a third party risk assessment programme?

A programme is the structure covering your whole supplier population — tiering, question sets, cadence. A supplier security review is a single, in-depth look at one supplier, usually ahead of onboarding, contract renewal or a specific concern. Reviews are often the deep-dive step your programme's tiering triggers for a critical supplier, rather than a replacement for it.

What evidence do you actually check, rather than just ask for?

Where a supplier claims a certification, we ask for the certificate and check its scope and validity. Where they describe controls like encryption, MFA or patching, we ask for policy documents, configuration screenshots or, with permission, a technical check such as an external scan of internet-facing services. The point is testing claims, not collecting reassuring-sounding statements.

Can you carry out technical checks on our supplier?

Only with the supplier's consent, and typically limited to non-intrusive checks such as external attack surface review, TLS configuration and DNS security records. Anything more invasive, such as a penetration test, requires the supplier's own authorisation and is usually arranged directly with them rather than as a hidden or unannounced activity.

What if the supplier won't provide evidence or answer questions?

That's a finding in itself and we say so plainly. A supplier unwilling to evidence basic controls before a contract is signed, or before a renewal, is telling you something about the relationship regardless of what their sales team says. Our report sets out exactly what was requested, what was provided, and what remains unanswered, so the decision is yours to make with full visibility.

Do you look at the contract as well as the technical controls?

Yes, where it's in scope. We review the security schedule, data protection clauses, sub-processor arrangements, breach notification terms and exit or offboarding provisions, and flag anything missing or vague against what the supplier's access actually warrants. Contract gaps are often as significant as technical gaps and are far cheaper to fix before signature than after.

How long does a single supplier review take?

A standard review, from initial information request to final report, typically takes two to four weeks, depending on how quickly the supplier responds. Reviews involving external technical checks or a larger set of sub-processors can take longer. We agree realistic timescales up front against your onboarding or renewal deadline.

What does the final output look like?

A written report setting out what was reviewed, what evidence was and wasn't provided, any gaps identified, and a clear recommendation — proceed, proceed with conditions, or do not proceed without specific remediation. We avoid vague scoring systems in favour of a plain recommendation your decision-makers can actually act on.

Do you review suppliers we already work with, not just new ones?

Yes. Reviews are commonly requested ahead of a contract renewal, after a security incident affecting the supplier, or after a change such as new sub-processors or a change of ownership. An existing relationship with years of history is not a reason to skip scrutiny — it's often the reason a fresh look is overdue.

Got a supplier decision coming up that needs a proper look?

Tell us which supplier and what's at stake, and we'll scope a review sized to the decision you actually need to make, with no pressure to buy more than that.

Discuss a supplier review