RaptorGRC — Offline GRC

BLOG

How to Run a Supplier Security Assessment That Is Not Just a Questionnaire

Published 7 August 2026 ยท By P Larner

Security in Practice#supplier assurance#ISO 27001#third-party risk#due diligence

How to Run a Supplier Security Assessment That Is Not Just a Questionnaire

Illustration for: How to Run a Supplier Security Assessment That Is Not Just a Questionnaire

Illustration for: How to Run a Supplier Security Assessment That Is Not Just a Questionnaire

Most supplier security assessment is theatre, in the form of a 300-question spreadsheet sent to every vendor, answered optimistically by someone in sales, and filed unread. Meanwhile the breaches that actually hurt, from managed service providers to payroll software, come through suppliers whose questionnaires were returned on time and looked fine. There is a better way, and it starts with admitting that you cannot deeply assess everyone.

Tier suppliers before you assess anything

Effort must follow risk, and supplier risk is driven by two things, how critical the supplier is to your operations and what access they have to your data and systems. Score both before sending anyone anything.

A workable model has three tiers.

  • Tier 1 covers suppliers whose failure stops your business, or who hold large volumes of personal or confidential data, or who have privileged access into your environment. Managed service providers, payroll, core SaaS platforms, anyone with a VPN connection or admin credentials. Typically 5 to 15 suppliers even in a large organisation.
  • Tier 2 covers suppliers with meaningful but bounded data access or operational importance. A marketing platform holding customer email addresses, a facilities system, a niche development contractor.
  • Tier 3 is everyone else. The stationery supplier, the training provider with nothing but your PO number.

Three-tier supplier pyramid with assessment effort rising towards the top

Three-tier supplier pyramid with assessment effort rising towards the top

Three tiers sized by consequence. Assessment effort and evidence depth climb with the tier.

The tiering questions belong in procurementโ€™s onboarding flow, not in a security backwater. Five questions answered by the business owner at purchase time, covering what data, how much, what access, how critical and what alternative exists, will tier a supplier in two minutes. If security only hears about suppliers after contracts are signed, fix that first, because it matters more than any assessment technique.

Proportionate due diligence per tier

Once tiered, apply different treatments.

  • Tier 1 gets an evidence-based review, covered below, plus contractual security clauses, a named relationship owner, annual reassessment, and inclusion in your incident response and exit planning. For suppliers with network access, add technical controls on your side too, meaning dedicated accounts, MFA, session logging and least privilege.
  • Tier 2 gets a short questionnaire of 20 questions rather than 300, a certification check, standard contract clauses, and reassessment every two years or on significant change.
  • Tier 3 gets self-attestation of a few basics at onboarding, or nothing beyond standard terms. Spending analyst time here is spending it away from Tier 1.

The uncomfortable discipline is the last one. Every hour spent chasing a Tier 3 questionnaire is an hour not spent reading a Tier 1 supplierโ€™s penetration test summary. Proportionality means consciously doing less in some places.

Questionnaire fatigue and what to do instead

Questionnaires have three structural problems. They record claims, not facts. They are answered by people incentivised to say yes. And they are a snapshot that starts ageing the day it is returned. The industryโ€™s answer to a low-value artefact has been to make it longer, which helps nobody, because suppliers now employ teams whose job is answering questionnaires, and the answers are templated.

Side by side comparison of a 300 question questionnaire, marked as claims that age from day one, against an evidence based review built on certifications, test results, metrics, conversation and contract clauses

Side by side comparison of a 300 question questionnaire, marked as claims that age from day one, against an evidence based review built on certifications, test results, metrics, conversation and contract clauses

Evidence based review replaces bulk claims with a short list of verifiable artefacts.

For Tier 1 suppliers, replace bulk questions with evidence.

  • Certifications and audit reports first. ISO 27001 certificates, where you check the scope statement actually covers the service you buy, which is the most common gap. SOC 2 Type II reports, where you read the exceptions and the complementary user entity controls rather than just the cover page. Cyber Essentials Plus for UK suppliers.
  • Evidence sampling for what matters to you. Rather than โ€œdo you patch?โ€, ask for the patching policy plus a redacted metrics extract for the last quarter. Rather than โ€œdo you test?โ€, ask for the executive summary of the latest penetration test and confirmation the criticals were remediated.
  • A conversation. An hour with their security lead tells you more than 300 rows. You learn whether security is a function or a person, whether they know their own architecture, and how they responded to their last incident. Vague answers to specific questions are themselves evidence.
  • Contract clauses that create obligations. Breach notification within a defined window, aligned to your own regulatory clocks at 24 or 72 hours, a right to audit or to receive audit reports annually, data location and deletion terms, minimum control requirements, and flow-down of equivalent obligations to their subcontractors.

A short questionnaire still has a place for Tier 2 and for gaps the evidence does not cover. Keep it under 25 questions and make every question one whose answer would change your decision. If no answer would change anything, delete the question.

Point-in-time is not enough

An assessment done at onboarding describes the supplier as they were, once. Suppliers get acquired, lose key staff, change subcontractors and suffer incidents between your reviews. Continuous monitoring does not have to mean buying a ratings platform, though external attack surface ratings can be a useful weak signal for Tier 1 if you treat them as conversation starters rather than verdicts.

The practical core is cheaper than that.

  • Contractual notification duties for incidents, material subcontractor changes and loss of certifications, with a named contact on both sides.
  • A watch on public sources, including breach disclosures, ICO enforcement, and financial distress signals for suppliers whose failure would strand you.
  • Annual reconfirmation of certificates. An ISO certificate that quietly lapsed is a signal worth catching.
  • Reassessment triggers rather than just calendars. A supplier incident, a major change in the service, or your own use of them expanding, so that the CRM that held prospect names in year one and holds your full customer base in year three changes tier accordingly.

When a supplier fails the assessment

A failed assessment is a risk decision, not automatically a rejection. Here are the options, roughly in order of preference.

  • Remediate. Agree specific improvements with dates, written into the contract or a side letter, and verify completion. Most competent suppliers will engage, especially pre-signature while you still hold the negotiating power.
  • Contain. Reduce what you expose to them, whether through less data, tokenised identifiers, no standing network access, or your controls wrapped around their weakness.
  • Accept. Document the residual risk, get sign-off from the business owner at a level appropriate to the exposure, and set a review date. This is legitimate when the supplier is genuinely irreplaceable, provided it is written down and revisited.
  • Exit. Walk away, or start planning the exit for an incumbent. This is rare in practice, which is precisely why exit terms and data return clauses need agreeing at the start, when leaving is still thinkable.

What is not legitimate is the common fourth path, which is noting the failure, doing nothing, and renewing anyway with no record of the decision.

Decision flowchart for a failed supplier assessment moving through remediate, contain, accept and exit, with renewing without a record crossed out

Decision flowchart for a failed supplier assessment moving through remediate, contain, accept and exit, with renewing without a record crossed out

A failed assessment is a risk decision, so remediate, contain, accept or exit, but never renew without a record.

Making it stick

Put the tiering questions into procurement onboarding this quarter. List your current Tier 1 suppliers, and for each one check three things. Do you hold current certification evidence with the right scope, does the contract oblige them to tell you about a breach quickly, and do you have a security contact who would answer the phone during an incident? Those three checks, applied to a dozen suppliers, deliver more real assurance than a thousand questionnaire rows.

Supplier assurance register in RaptorGRC

Supplier assurance register in RaptorGRC

The supplier assurance register in RaptorGRC.

Run your GRC programme in your own network.

RaptorGRC Community Edition is free โ€” every module, offline licence activation, nothing phones home.

Register / Download Contact us
An unhandled error has occurred. Reload ๐Ÿ—™

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.