Home / Services / Vendor Risk Management
Third-Party Risk

Vendor risk management that catches problems before renewal, not after an incident.

A tiered vendor inventory, proportionate due diligence, and an ongoing review cadence, aligned to ISO 27001's supplier controls and SOC 2's vendor management criteria.

Annex A.5.19 to A.5.23Tiered due diligence
Contract gap review
UK · US · EU consultants
Who it's for

Who this is for

Companies whose vendor list has grown faster than any process for reviewing it, which is most companies. The trigger is usually an auditor sampling vendor files and finding gaps, a customer asking how you assess your own suppliers, or a security incident at a vendor that prompts an uncomfortable question about how many others have similar access. If you can not currently produce a list of every third party with access to customer data, this is the service that fixes that.

What's included

Scope, in plain terms.

VR-01 Scope

Vendor Inventory & Tiering

A full third-party inventory, tiered by data access and business criticality, so review effort goes where the actual risk is.

VR-02 Scope

Due Diligence Questionnaires

Tailored due diligence questionnaires and evidence requests (SOC 2 reports, pentest summaries, security policies) matched to each vendor's tier.

VR-03 Scope

Contract & SLA Review

We check the security and data protection clauses in your vendor contracts, flagging gaps before renewal rather than after an incident.

VR-04 Deliverable

Vendor Risk Register

A living register your team can maintain, with review cadence built in for high-risk vendors.

VR-05 Deliverable

Onboarding Workflow

A repeatable process for assessing new vendors before contracts are signed, not retrofitted after the fact.

VR-06 Fit

Annex A.5.19-A.5.23 Aligned

Structured to satisfy ISO 27001's supplier relationship controls and SOC 2's vendor management criteria.

Why third party risk gets missed

Vendor risk is diffuse in a way most other security domains are not. Nobody owns it by default. Procurement signs contracts, engineering adopts tools, finance pays invoices, and each sees a fragment of the picture. The result is that a company can genuinely not know how many services hold its customer data.

The problem compounds because adoption is easy and removal is rare. A tool trialled by one team two years ago may still hold an export of production data, still have an active integration, and still be billed monthly without anyone treating it as a supplier.

Both ISO 27001 and SOC 2 address this directly. ISO 27001:2022 covers supplier relationships across Annex A.5.19 to A.5.23, including information security in supplier agreements and managing change in supplier services. SOC 2 addresses vendor management under its common criteria. In both cases auditors sample vendor files, and a register that omits the vendors that matter is quickly exposed.

Tiering, and why it is the whole game

Reviewing every vendor to the same depth is neither possible nor sensible. A payroll processor holding employee financial data and a design tool holding nothing but mockups do not warrant equal scrutiny, and treating them equally guarantees the important reviews get diluted.

Tiering sorts vendors by what they can actually reach: the sensitivity of data they hold, whether they have access into your production environment, and how badly their failure would disrupt your service. High tier vendors warrant evidence review, contract scrutiny and periodic reassessment. Low tier vendors warrant a record and a light touch check.

Done properly, tiering reduces total effort while increasing the quality of the reviews that matter. It is also the part auditors examine, because it demonstrates that your process is risk driven rather than mechanical.

What to actually ask for, and how to read it

For higher tier vendors, the most useful evidence is what they have already been assessed against by somebody independent: a SOC 2 Type II report, an ISO 27001 certificate with its Statement of Applicability, or a recent penetration test summary. A completed questionnaire is weaker evidence because it is self attested, though it remains useful where nothing else exists.

Reading these properly matters. An ISO 27001 certificate has a scope statement, and the scope may not include the service you are buying. A SOC 2 report has a period, which may have ended a year ago, and it has exceptions, which are the most informative part and the part most often skipped. Certificates get filed unread far more often than anyone admits.

We review what vendors provide rather than testing their systems directly, since that would require their authorisation. Where the evidence does not actually cover the service you rely on, we say so, because a filed certificate that does not cover the relevant scope offers no assurance at all.

Engagement process

How the work actually happens.

01

Vendor inventory

We work with procurement, engineering and finance to build a complete picture of vendors with access to your systems or data.

02

Risk tiering

Vendors are tiered by data sensitivity and business criticality, so a payroll processor gets more scrutiny than a design tool.

03

Due diligence review

We collect and assess evidence: SOC 2 reports, ISO 27001 certificates, pentest summaries, proportionate to each vendor's tier.

04

Contract gap review

Security and data protection clauses are checked against your requirements, with gaps flagged ahead of renewal.

05

Remediation round and re-review

You get one round to close the gaps we identified, whether that is missing vendor evidence, contract terms or re-tiering. We re-review those items and issue the final register.

06

Ongoing monitoring

A review cadence and onboarding workflow handed to your team, so vendor risk doesn't quietly drift between formal audits.

Included as standard

One remediation cycle is built into every engagement

After the initial review, you get one round to close the gaps we identified, whether that means obtaining missing evidence from a vendor, correcting contract terms, or re-tiering a vendor whose access has changed. We then re-review those specific items and issue the final vendor risk register.

What goes wrong

Common mistakes we are asked to fix.

No single inventory

If procurement, engineering and finance each hold part of the list, nobody can answer the question an auditor or customer is asking.

Treating all vendors identically

Uniform review depth means the vendors that matter receive the same shallow attention as the ones that do not.

Filing certificates without reading them

Scope statements and report periods frequently reveal that the evidence does not cover the service you actually use.

Assessing vendors after contracts are signed

Once committed, your leverage to negotiate security terms is gone. Assessment belongs inside procurement, before signature.

Timelines

Timing and what to expect

An initial inventory and tiering exercise typically takes two to three weeks for a company with a few dozen vendors, longer where the estate is larger or genuinely unknown at the outset. Due diligence review of the higher tiers follows over the subsequent weeks, prioritised so the vendors with production access or sensitive data are completed first. After that the work becomes a cadence rather than a project: onboarding checks as new vendors are proposed, and periodic reassessment of high tier vendors, usually annually.

One thing worth being clear about

We're consultants. We'll get your controls in shape and get you ready for the audit, but we don't hand out ISO 27001 certificates or sign SOC 2 reports, because the rules quite rightly don't let the firm that prepared you be the firm that passes you. That job goes to an independent certification body or CPA firm, and we'll help you find a good one. More on where exactly that line sits in our independence statement.

Offer

Your first year of service is free

Sign a 2-year agreement with pricing locked in upfront, and your first year of any one service is completely free. Adding more than one service in year one? We give you the highest-value one free and a bundle discount on the rest. See how the offer works →

Common questions

Frequently asked questions

Why does vendor risk matter for ISO 27001 or SOC 2?

Both frameworks explicitly require supplier and vendor risk management: ISO 27001 Annex A.5.19 through A.5.23, and SOC 2's vendor management criteria under CC9. Auditors routinely sample vendor files.

How many vendors does a typical review cover?

It depends entirely on your business. We start with a full inventory and tiering exercise so effort is proportionate, not a flat review of every subscription you use.

Do you assess our vendors' security directly?

We review the evidence vendors provide (SOC 2 reports, certificates, questionnaire responses, pentest summaries) and flag where it's insufficient. We don't perform security testing of third-party vendors' systems directly, as that would require their authorisation.

Can this integrate with our procurement process?

Yes. The onboarding workflow is designed to sit inside procurement so new vendors are assessed before contracts are signed, not after.

Is this included in ISO 27001 or SOC 2 preparation?

A baseline version is often included in those programmes; a full standalone vendor risk management build-out is available for organisations with a larger or more complex vendor footprint.

Which ISO 27001 controls cover vendor management?

Annex A.5.19 through A.5.23 address supplier relationships, including information security within supplier agreements, managing the ICT supply chain, monitoring supplier service delivery, and managing changes to supplier services.

Do we need to assess every vendor?

Every vendor should appear in your inventory. The depth of assessment should be proportionate to the tier, which is precisely what a tiering model exists to determine.

What if a critical vendor refuses to provide evidence?

That is itself a finding worth recording. Options include requesting evidence under NDA, accepting the risk formally with a documented decision at the right level of authority, adding compensating controls, or reconsidering the vendor. What matters to an auditor is that a deliberate decision was made and recorded.

How often should high tier vendors be reassessed?

Annually is the common cadence, plus reassessment on a trigger such as a breach at the vendor, a material change to the service, or a contract renewal.

Do you test our vendors' security directly?

No. We review the evidence they provide and flag where it is insufficient or where its scope does not cover the service you use. Testing a third party's systems would require their authorisation and is a separate engagement with them.

Is remediation included, or is that charged separately?

One remediation cycle is included as standard in every engagement. You get one round to apply fixes to what we raised, we re-check those specific findings, and the final report reflects your corrected state rather than the position we found at the start. What sits outside that is our engineers implementing the fixes on your behalf, rather than verifying yours, and any further rounds beyond the first. Both are quoted separately and transparently before any work starts.

Related services

Often scoped alongside this.

Ready to scope this?

Tell us your target date and current state. We'll come back with a fixed-scope proposal within two business days.

Book a discovery call