A tiered vendor inventory, proportionate due diligence, and an ongoing review cadence, aligned to ISO 27001's supplier controls and SOC 2's vendor management criteria.
Companies whose vendor list has grown faster than any process for reviewing it, which is most companies. The trigger is usually an auditor sampling vendor files and finding gaps, a customer asking how you assess your own suppliers, or a security incident at a vendor that prompts an uncomfortable question about how many others have similar access. If you can not currently produce a list of every third party with access to customer data, this is the service that fixes that.
A full third-party inventory, tiered by data access and business criticality, so review effort goes where the actual risk is.
Tailored due diligence questionnaires and evidence requests (SOC 2 reports, pentest summaries, security policies) matched to each vendor's tier.
We check the security and data protection clauses in your vendor contracts, flagging gaps before renewal rather than after an incident.
A living register your team can maintain, with review cadence built in for high-risk vendors.
A repeatable process for assessing new vendors before contracts are signed, not retrofitted after the fact.
Structured to satisfy ISO 27001's supplier relationship controls and SOC 2's vendor management criteria.
Vendor risk is diffuse in a way most other security domains are not. Nobody owns it by default. Procurement signs contracts, engineering adopts tools, finance pays invoices, and each sees a fragment of the picture. The result is that a company can genuinely not know how many services hold its customer data.
The problem compounds because adoption is easy and removal is rare. A tool trialled by one team two years ago may still hold an export of production data, still have an active integration, and still be billed monthly without anyone treating it as a supplier.
Both ISO 27001 and SOC 2 address this directly. ISO 27001:2022 covers supplier relationships across Annex A.5.19 to A.5.23, including information security in supplier agreements and managing change in supplier services. SOC 2 addresses vendor management under its common criteria. In both cases auditors sample vendor files, and a register that omits the vendors that matter is quickly exposed.
Reviewing every vendor to the same depth is neither possible nor sensible. A payroll processor holding employee financial data and a design tool holding nothing but mockups do not warrant equal scrutiny, and treating them equally guarantees the important reviews get diluted.
Tiering sorts vendors by what they can actually reach: the sensitivity of data they hold, whether they have access into your production environment, and how badly their failure would disrupt your service. High tier vendors warrant evidence review, contract scrutiny and periodic reassessment. Low tier vendors warrant a record and a light touch check.
Done properly, tiering reduces total effort while increasing the quality of the reviews that matter. It is also the part auditors examine, because it demonstrates that your process is risk driven rather than mechanical.
For higher tier vendors, the most useful evidence is what they have already been assessed against by somebody independent: a SOC 2 Type II report, an ISO 27001 certificate with its Statement of Applicability, or a recent penetration test summary. A completed questionnaire is weaker evidence because it is self attested, though it remains useful where nothing else exists.
Reading these properly matters. An ISO 27001 certificate has a scope statement, and the scope may not include the service you are buying. A SOC 2 report has a period, which may have ended a year ago, and it has exceptions, which are the most informative part and the part most often skipped. Certificates get filed unread far more often than anyone admits.
We review what vendors provide rather than testing their systems directly, since that would require their authorisation. Where the evidence does not actually cover the service you rely on, we say so, because a filed certificate that does not cover the relevant scope offers no assurance at all.
We work with procurement, engineering and finance to build a complete picture of vendors with access to your systems or data.
Vendors are tiered by data sensitivity and business criticality, so a payroll processor gets more scrutiny than a design tool.
We collect and assess evidence: SOC 2 reports, ISO 27001 certificates, pentest summaries, proportionate to each vendor's tier.
Security and data protection clauses are checked against your requirements, with gaps flagged ahead of renewal.
You get one round to close the gaps we identified, whether that is missing vendor evidence, contract terms or re-tiering. We re-review those items and issue the final register.
A review cadence and onboarding workflow handed to your team, so vendor risk doesn't quietly drift between formal audits.
After the initial review, you get one round to close the gaps we identified, whether that means obtaining missing evidence from a vendor, correcting contract terms, or re-tiering a vendor whose access has changed. We then re-review those specific items and issue the final vendor risk register.
If procurement, engineering and finance each hold part of the list, nobody can answer the question an auditor or customer is asking.
Uniform review depth means the vendors that matter receive the same shallow attention as the ones that do not.
Scope statements and report periods frequently reveal that the evidence does not cover the service you actually use.
Once committed, your leverage to negotiate security terms is gone. Assessment belongs inside procurement, before signature.
An initial inventory and tiering exercise typically takes two to three weeks for a company with a few dozen vendors, longer where the estate is larger or genuinely unknown at the outset. Due diligence review of the higher tiers follows over the subsequent weeks, prioritised so the vendors with production access or sensitive data are completed first. After that the work becomes a cadence rather than a project: onboarding checks as new vendors are proposed, and periodic reassessment of high tier vendors, usually annually.
We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.
Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →
Both frameworks explicitly require supplier and vendor risk management: ISO 27001 Annex A.5.19 through A.5.23, and SOC 2's vendor management criteria under CC9. Auditors routinely sample vendor files.
It depends entirely on your business. We start with a full inventory and tiering exercise so effort is proportionate, not a flat review of every subscription you use.
We review the evidence vendors provide (SOC 2 reports, certificates, questionnaire responses, pentest summaries) and flag where it's insufficient. We don't perform security testing of third-party vendors' systems directly, as that would require their authorisation.
Yes. The onboarding workflow is designed to sit inside procurement so new vendors are assessed before contracts are signed, not after.
A baseline version is often included in those programmes; a full standalone vendor risk management build-out is available for organisations with a larger or more complex vendor footprint.
Annex A.5.19 through A.5.23 address supplier relationships, including information security within supplier agreements, managing the ICT supply chain, monitoring supplier service delivery, and managing changes to supplier services.
Every vendor should appear in your inventory. The depth of assessment should be proportionate to the tier, which is precisely what a tiering model exists to determine.
That is itself a finding worth recording. Options include requesting evidence under NDA, accepting the risk formally with a documented decision at the right level of authority, adding compensating controls, or reconsidering the vendor. What matters to an auditor is that a deliberate decision was made and recorded.
Annually is the common cadence, plus reassessment on a trigger such as a breach at the vendor, a material change to the service, or a contract renewal.
No. We review the evidence they provide and flag where it is insufficient or where its scope does not cover the service you use. Testing a third party's systems would require their authorisation and is a separate engagement with them.
One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.
Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.
Book a discovery call