
A supplier register that tells you who's actually assured.
Horizon holds your third-party population in one register — tiered by risk, checked at onboarding, tracked for reassessment — so supplier assurance is a managed schedule rather than a folder of expired questionnaires.
Most organisations know their suppliers. Few know their current risk.
A supplier list is easy to produce. A supplier register that tells you which of those suppliers are still assured, which have drifted out of scope since onboarding, and which represent a genuine concentration of risk if one of them fails, is a different and much rarer thing. Most organisations we meet have the former and assume it does the job of the latter.
The pattern is familiar: a due diligence questionnaire is completed at onboarding, filed, and never revisited. Twelve or eighteen months later, the supplier's certifications may have lapsed, their sub-processors may have changed, or their access to your systems may have expanded well beyond what was originally agreed — and none of that is visible because nothing prompted anyone to look again.
Tiering, where it exists at all, is often based on contract value rather than actual exposure. A low-cost supplier with privileged access to a core system can represent more risk than a large contract that never touches sensitive data, but spreadsheet-based registers rarely distinguish the two with any discipline, so reassessment effort ends up misallocated.
Concentration risk is the part that tends to surprise boards the most. Organisations frequently don't have a clear answer to how many critical functions run through a single supplier, or a single hosting region, until someone is forced to work it out during an incident or a client's due diligence request — at which point the answer arrives too late to be useful.
Exit risk sits alongside all of this, largely unmanaged. Contract notice periods, transition arrangements and what actually happens if a critical supplier fails or is terminated abruptly are typically held in procurement or legal files that the security or risk function rarely sees, disconnected from the assurance picture entirely.
- Onboarding checks completed once and never refreshed
- Tiering based on spend rather than access or dependency
- No visibility of concentration in a single supplier or region
- Exit and notice-period information held separately from assurance status
One register, tiered properly, reassessed on a schedule you set.
Horizon's supplier and third-party register starts with tiering based on the criteria that actually matter to your business — data access, system dependency, and the operational impact if the supplier fails — rather than defaulting to contract value. Each tier carries its own reassessment frequency, so critical suppliers are checked more often than low-impact ones without anyone having to remember to schedule it manually.
Onboarding checks are recorded against the supplier record from the start, with the assurance status and supporting evidence attached directly rather than filed elsewhere. When that assurance is due for review, Horizon flags it ahead of the date, so reassessment is planned work rather than a discovery made months after it should have happened.
Concentration reporting pulls the register together at a level a board or client can actually use — how much of your critical function sits with a single supplier, and where sub-processors or hosting locations cluster, where that information has been declared. It turns a question that used to take a week of digging through contracts into something the register can answer directly.
Exit risk is tracked alongside assurance rather than kept apart from it. Contract and notice-period detail sits on the same record as the supplier's current risk tier and assurance status, so the two pictures — how assured is this supplier, and how exposed are we if they fail or leave — are read together rather than reconstructed separately when it matters.
Where independent supplier due diligence or assessment work is needed, we carry that out as a separate engagement and record the outcome directly against the relevant supplier in Horizon, so the register stays the single source of truth rather than one of several places the information lives.
- Tiering criteria set by your business, not defaulted to contract value
- Assurance status and evidence attached at onboarding and refreshed on schedule
- Concentration reporting by supplier, sub-processor and hosting location
- Exit and notice-period information visible alongside assurance status
Everything in the engagement, set out up front.
Everything needed to run supplier assurance as a managed programme rather than a filing exercise.
Supplier and third-party register
A single record per supplier holding tier, assurance status, evidence, contract dates and reassessment schedule.
Risk-based tiering
Suppliers tiered against criteria you define, driving how often each is reassessed.
Onboarding assurance capture
Due diligence outcomes and evidence recorded against the supplier from the point of onboarding.
Reassessment scheduling
Automatic flags ahead of each supplier's reassessment date, by tier, so nothing is picked up late.
Concentration and exit reporting
Exportable reports showing supplier, sub-processor and hosting concentration alongside exit and notice-period exposure.
Role-based access
Procurement, IT and compliance work from the same record with access scoped to what each team needs.
What you receive.
- Populated supplier and third-party register
- Agreed tiering criteria and applied tier assignments
- Onboarding assurance evidence attached per supplier
- Reassessment schedule by tier with automated reminders
- Concentration report by supplier and hosting location
- Exit and notice-period exposure summary
- Executive dashboard of overall assurance status
- Exportable supplier assurance reports for client or board use
Built for organisations that need the work done properly.
Organisations with a growing supplier base
Businesses whose supplier count has outgrown a spreadsheet, where nobody's confident the list is complete or current.
Regulated or client-driven due diligence
Firms facing regular supplier assurance questions from clients, regulators or insurers, and needing an answer they can produce quickly.
Organisations reliant on a small number of critical suppliers
Businesses where a handful of suppliers carry disproportionate risk and need closer, more frequent reassessment.
Procurement and risk teams working separately today
Organisations where supplier contracts and supplier security assurance are managed in different places and need bringing together.
What changes once the work is done.
What changes once the supplier population is tiered, checked and tracked in one place.
A current answer to 'how assured are our suppliers'
Assurance status visible by tier at any point, not reconstructed under pressure for a client or auditor request.
Reassessment effort aimed at the right suppliers
Critical suppliers checked more often, based on actual exposure rather than contract size.
Concentration risk made visible
Clear reporting on where critical functions or data cluster with a single supplier or region.
Exit exposure understood ahead of time
Notice periods and transition risk visible next to assurance status, not discovered during an actual exit.
Fewer overdue reassessments
Scheduled reminders replace the reliance on someone remembering a supplier was due a refresh.
A register that stands up to scrutiny
One source of supplier assurance evidence that can be produced quickly for a client, insurer or board request.
Supplier assurance is a programme, not a one-off questionnaire.
It's worth being clear about what Horizon does here. It's a platform for tiering, tracking and scheduling supplier assurance — it doesn't itself carry out due diligence or make the judgement about whether a particular supplier's controls are good enough. Those decisions still sit with your procurement, risk and compliance teams; what Horizon changes is whether that judgement is applied consistently and revisited on schedule, rather than made once at onboarding and left.
The organisations that struggle most with third-party risk aren't usually the ones with the largest supplier lists — they're the ones with no consistent tiering, so a genuinely critical supplier and a peripheral one get the same light-touch review, or none at all. Getting the tiering criteria right at the start does more for risk reduction than almost any amount of subsequent questionnaire chasing.
Concentration and exit risk deserve more attention than they typically get, particularly for organisations that have consolidated onto fewer, larger suppliers for efficiency. That consolidation is often the right commercial decision, but it needs to be made with the concentration risk visible, not discovered afterwards when the supplier in question has an outage or a breach.
We support organisations across Chesterfield, Sheffield, Derby, Nottingham, Leeds, Manchester, Birmingham and London on third-party risk, and the register works the same way regardless of sector: tier the population honestly, check it on a schedule that matches the risk, and keep exit exposure in view alongside assurance status.
Questions we are asked most often.
What does Horizon's supplier register actually track?
Each supplier record holds a risk tier, assurance status, the evidence supporting that status, key contract or renewal dates and a scheduled reassessment date. It's built to answer a simple question at any point — which suppliers matter most, and are we current on checking them — rather than being a static contacts list.
How does supplier tiering work?
Tiering reflects the access and dependency a supplier represents — data handled, systems connected to, or how disruptive their failure would be — rather than contract value alone. Horizon lets you set your own tiering criteria and applies reassessment frequency accordingly, so a critical supplier is checked more often than a low-impact one.
Can Horizon show us where we're concentrated in one supplier or region?
Yes. Reporting can surface concentration by supplier, by sub-processor where declared, or by hosting location, which is useful when a board or a client asks how exposed you are to a single point of failure rather than just how many suppliers are on the register.
Does Horizon carry out the supplier due diligence for us?
Horizon is the platform that holds and tracks assurance status, evidence and reassessment dates; it isn't itself an assessment service. Where you need an independent supplier security assessment carried out, that sits alongside Horizon as a separate engagement, with the outcome recorded against the relevant supplier record.
What happens when a reassessment falls due?
Horizon flags the supplier ahead of the reassessment date so it's picked up as scheduled work rather than discovered months late. You decide what reassessment means for that tier — a refreshed questionnaire, updated certifications, or a fuller review — and the outcome and evidence are logged against the record.
How does this fit with our exit and offboarding process?
Supplier records carry contract and notice period information alongside assurance status, so exit risk — what happens if a critical supplier fails or is offboarded — is visible next to the assurance picture rather than held separately in procurement or legal files that the security team may not routinely see.
Is this only useful for large supplier populations?
No. Smaller organisations with a handful of critical suppliers benefit just as much, often more, because a single supplier failure or breach can be proportionally more disruptive. The register scales to whatever your supplier population actually is, without forcing a large-enterprise process onto a short list.
Who should own the supplier register day to day?
Typically procurement or IT own the operational relationship while a compliance or risk lead owns the assurance status and reassessment cycle. Horizon's role-based access lets both groups work from the same record without either needing full visibility of the other's areas.
Third-party risk assessments
Independent assessment of individual supplier security posture, feeding assurance status into the register.
ISO 27001 implementation support
Supplier controls under Annex A, built into a wider ISMS rather than managed in isolation.
Compliance support
Broader framework support across ISO 27001, Cyber Essentials, NHS DSPT and FCA-driven controls.
See your supplier population set out in Horizon.
We'll walk through the register structure against your own supplier list — a straightforward look at tiering, gaps and where reassessment is overdue, no pressure to commit.
Book a Horizon walkthrough