Abstract network diagram representing a supplier and third party ecosystem
Third Party Risk Assessments

A third party risk programme sized to your actual supplier population.

We build the tiering model, the questionnaire sets and the reassessment cycle that turns a spreadsheet of suppliers into a programme someone can actually run — and defend when an auditor or a customer asks how you know your suppliers are safe.

Supplier tiers
3-4
Typical build time
4-8
Reassessment cadence
12
Illustrative figures
The challenge

One questionnaire sent to every supplier gets ignored by all of them.

Most organisations have a supplier register somewhere, and most of it is out of date. New SaaS tools get added by individual teams without procurement ever being told, contracts renew automatically, and the person who originally assessed a supplier three years ago has since left. By the time anyone tries to answer 'do we know our suppliers are secure', the honest answer is usually a partial list and a folder of unread questionnaire responses.

The instinct is often to send everyone the same long questionnaire. That approach fails twice over: low-risk suppliers with no data or system access resent the effort and either ignore it or fill it in carelessly, while genuinely high-risk suppliers get exactly the same generic questions as everyone else, missing the specific access and data-handling detail that actually matters for that relationship.

Without a tiering model behind the process, assessment effort tends to follow contract value or how loudly a supplier's account manager pushes back, rather than following actual risk. A cheap file-sharing tool with access to client data can carry more exposure than an expensive facilities contract, but the facilities contract is the one that gets scrutinised because it's the bigger line item.

Reassessment is usually the first thing to lapse. A supplier passes an initial review, the relationship continues for years, and nobody revisits whether their access, their sub-processors or their own security posture has changed in the meantime. Boards and customers asking for supply chain assurance increasingly want evidence of an ongoing cycle, not a one-off tick from several years ago.

Underneath all of this is a resourcing problem: someone in procurement, IT or a risk function is usually asked to run this alongside their day job, without a structure that tells them where to focus limited time. The result is effort spread thinly and unevenly, rather than concentrated where the actual exposure sits.

  • No consistent tiering — assessment effort follows contract size, not risk
  • One questionnaire for every supplier regardless of access or data held
  • Response tracking scattered across email and spreadsheets
  • Reassessment dates missed or never set in the first place
Our approach

We build the model, the question sets and the cadence together.

We start by agreeing tiering criteria with you — typically data sensitivity, system or network access, and how disruptive losing the supplier would be operationally. Every supplier on your register gets classified against these criteria, which usually surfaces a handful of high-access suppliers nobody had previously flagged as significant, and a larger group of low-risk suppliers that can be handled with a lighter touch.

For each tier we build a proportionate question set rather than reusing one document everywhere. Critical suppliers with data or system access get detailed questions covering access control, encryption, incident history and sub-processor use; lower tiers get a shorter set focused on the basics that matter for their level of exposure. Shorter, relevant questionnaires get answered — long generic ones tend not to.

We then set the onboarding gate and the reassessment cadence for each tier, agreed against what your team can realistically sustain rather than an ideal that lapses within a year. This includes an escalation path for suppliers who don't respond or who disclose gaps, so decisions about acceptable risk get made by someone accountable rather than defaulting by inaction.

Where useful, we set the whole structure up in Secure Chain Horizon, so the supplier register, tier, questionnaire status, evidence and next review date sit in one place your team can see without chasing emails. We're equally comfortable configuring the same structure in a spreadsheet or an existing GRC tool if that's what you already run.

Throughout, we review evidence rather than just logging that a questionnaire came back. A supplier claiming ISO 27001 certification, encryption at rest, or multi-factor authentication gets that claim checked against the certificate, the policy or the configuration where it's reasonable to ask for it, so the programme produces assurance rather than paperwork.

  • Tiering criteria agreed and applied across the whole supplier register
  • Question sets sized to each tier, not a single document for everyone
  • Onboarding gate and reassessment cadence set per tier, not assumed
  • Escalation path for non-response or disclosed gaps agreed up front
What's included

Everything in the engagement, set out up front.

A structured engagement to design and stand up the programme, or to review and tighten one you already have.

Supplier tiering model

Criteria and classification covering data access, system access and business criticality, applied to your current supplier list.

Tier-based question sets

Proportionate questionnaires for each tier, focused on what actually matters at that level of access.

Onboarding gate design

A defined point in your procurement or onboarding process where assessment must be completed before a supplier goes live.

Reassessment cadence

A realistic review schedule per tier, with clear ownership for chasing and evidencing renewal.

Escalation and exception process

An agreed path for handling non-response, partial answers or disclosed gaps, with sign-off sitting where accountability actually lives.

Horizon setup support

Configuration of the supplier register and assurance tracking within Secure Chain Horizon, where you want a platform behind the programme.

Deliverables

What you receive.

  • Documented tiering model and criteria
  • Question sets for each supplier tier
  • Supplier register classified by tier
  • Onboarding gate process document
  • Reassessment schedule by tier
  • Escalation and exception handling procedure
  • Evidence review checklist per tier
  • Horizon configuration (where applicable)
  • Handover briefing for the team running the programme day to day
Who it suits

Built for organisations that need the work done properly.

Organisations with a growing supplier base

Businesses whose SaaS and vendor count has outgrown informal tracking and now needs a structure someone can actually run.

Firms responding to customer assurance requests

Organisations increasingly asked by their own customers how they manage supplier risk, needing a defensible answer beyond 'we have a spreadsheet'.

Teams inheriting an unmanaged supplier register

New risk, procurement or IT leads finding a supplier list with no tiering, no cadence and no clear ownership.

Businesses working towards ISO 27001

Organisations needing supplier controls under A.5.19 to A.5.22 evidenced as an ongoing process, not a single assessment.

Outcomes & benefits

What changes once the work is done.

What changes once the programme is running rather than aspirational.

Effort concentrated where risk sits

High-access suppliers get proper scrutiny; low-risk suppliers stop consuming disproportionate time and goodwill.

Higher response rates

Right-sized questionnaires get completed properly instead of ignored or rushed.

A defensible answer to assurance requests

A documented tiering model and cadence you can show a customer, auditor or insurer without hedging.

No more forgotten reassessments

A cadence with clear ownership means renewal reviews happen on schedule rather than by chance.

Faster, cleaner onboarding

A defined gate means new suppliers are assessed consistently rather than assessed inconsistently or not at all.

Visibility for the board

A single view of supplier risk exposure that can be reported on without reconstructing it from scratch each time.

Proportionality is the whole point.

The single biggest reason supplier assessment programmes fail isn't lack of ambition — it's that they're designed for an ideal supplier population rather than the messy, mixed one every organisation actually has. A programme that demands the same depth of scrutiny from a stationery supplier as from a payroll processor either burns out the team running it or gets quietly abandoned within a year.

Tiering solves this by making the effort match the exposure. It also makes the programme explainable — when a customer or an auditor asks why one supplier was assessed in depth and another wasn't, the answer is a documented criterion, not a judgement call made under time pressure. That distinction matters more than most organisations expect the first time they're asked to justify it.

We see this work across organisations in Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London, and the businesses that sustain the programme longest are the ones that built the cadence around what their team can realistically maintain, not around what looks most thorough on a policy document. A modest programme that actually runs beats an ambitious one that lapses after the first busy quarter.

This is a programme-level engagement — the structure, tiering and cadence across your whole supplier population. Where a single relationship needs a detailed, evidence-tested look before a renewal or onboarding decision, our supplier security review service covers that in depth, and the two work well run alongside each other rather than as substitutes.

Frequently asked questions

Questions we are asked most often.

How is this different from a single supplier security review?

A supplier security review looks at one relationship in depth, usually ahead of onboarding or renewal. A third party risk assessment programme is the structure that sits above that — tiering your whole supplier population, deciding which suppliers warrant which level of scrutiny, and running the assessment and reassessment cycle across dozens or hundreds of relationships rather than one.

How do you decide which suppliers get the most scrutiny?

Tiering is based on data access, system access and business criticality rather than contract value. A low-cost supplier holding personal data or connected to your network sits in a higher tier than an expensive supplier with no access to anything sensitive. We agree the tiering criteria with you early, because it drives everything else in the programme.

Do we need a questionnaire for every supplier?

No. A single, lengthy questionnaire sent to every supplier regardless of tier is exactly what produces poor response rates and unread answers. We build shorter, tier-appropriate question sets so low-risk suppliers get a proportionate ask and high-risk suppliers get the depth of questioning their access actually warrants.

What happens when a supplier doesn't respond or gives poor answers?

The programme needs an escalation path agreed before it starts, not invented case by case. That typically means a follow-up window, an internal risk owner sign-off for accepted gaps, and a defined point at which non-response affects onboarding, renewal or contract continuation. We help set thresholds that are realistic for your organisation to actually enforce.

How often should suppliers be reassessed?

Reassessment frequency should follow the tier, not a blanket annual cycle. Critical suppliers with system or data access are usually reviewed annually or on material change; lower-tier suppliers can go longer between full reassessments with lighter interim checks. We help set a cadence your team can sustain rather than one that looks good on paper and lapses within a year.

Can this work with our existing procurement process?

Yes, and it should. Third party risk assessment works best when it's built into onboarding gates and renewal points that already exist, rather than run as a separate parallel process procurement doesn't know about. We map the assessment steps onto your current supplier lifecycle so they get followed rather than skipped under deadline pressure.

Do you use a platform to track all this?

We can set the programme up in Secure Chain Horizon, our supplier register and assurance tracking platform, so tiers, questionnaire status, evidence and reassessment dates are visible in one place rather than scattered across spreadsheets and inboxes. It's not compulsory — some clients run the same structure in their existing tools.

How long does it take to stand up a programme from scratch?

Building the tiering model, question sets and escalation process typically takes four to eight weeks, depending on how many suppliers need classifying and how much existing data you hold. Running the first full assessment cycle across your supplier population takes longer and depends heavily on how promptly suppliers respond.

Want an honest view of how your supplier list would tier?

We'll run a short review of your current supplier register against a proportionate tiering model and tell you where the gaps actually are, no obligation attached.

Talk to a consultant