Third-Party Risk Management
Assess, monitor and govern vendor and supply-chain risk.
What it is
Suppliers process your data and connect to your systems — and regulators increasingly hold you accountable for them, from ICT supply-chain expectations to supply-chain risk management in NIST CSF 2.0’s Govern function. We build proportionate vendor risk processes: tiering, assessments, contracts and monitoring.
Coverage
- Vendor inventory and criticality tiering
- Security assessment questionnaires and reviews
- Contractual security requirements
- Concentration and fourth-party awareness
- Ongoing monitoring approach
How we deliver
- Inventory — know all suppliers touching data/systems.
- Tier — proportionate scrutiny by criticality.
- Assess — evaluate and gap-report.
- Contract — embed security requirements.
- Monitor — periodic reassessment.
Outcomes
- Risk-tiered supplier register
- Assessment evidence for auditors
- Stronger supplier contracts
- Proportionate, sustainable process