Patterns that recur across hundreds of supplier assessments — and the controls that actually reduce exposure.
After risk assessments across more than 200 third-party organisations, the failures repeat with uncomfortable consistency. Very few are exotic.
The recurring five
- Unknown fourth parties. The supplier is assessed; the sub-processor holding the data is not.
- Certificates used as answers. A certificate proves a scope was audited, not that your data sits inside that scope.
- Access that outlives the contract. Offboarding rarely revokes integration credentials and API keys.
- Undefined incident duties. No notification window, no contact, no evidence obligation in the contract.
- Point-in-time assurance. One questionnaire a year against a threat landscape that moves weekly.
Tier by impact, not by spend
A low-cost supplier with production data access outranks an expensive supplier with none. Tier on data sensitivity, business criticality and access depth.
Ask questions evidence can answer
Replace "do you have a policy?" with "provide the last access review for our environment". Evidence-led questions shorten assessments and surface real gaps.
Monitor the critical tier continuously
For your highest tier, track certificate validity, breach disclosures, key personnel changes and attestation renewals between formal reviews.
Close the loop contractually
Security schedules, audit rights, sub-processor approval, notification windows and exit obligations. Assurance without contractual teeth is advice.
Supplier assurance is a monitoring discipline, not an annual document exchange.
- third-party risk
- supply chain
- due diligence