Third-party risk management works when you stop treating every vendor the same. Sort vendors into tiers based on what data they touch and how much you depend on them, then match the depth of each assessment to the tier. Reuse evidence vendors already have, such as SOC 2 reports and ISO 27001 certificates, instead of sending a 300-question questionnaire to everyone. Put the important protections in the contract, keep watch over the vendors that matter most, and close accounts properly when a relationship ends.
The rest of this post shows how to run that with a small team.
Why does vendor risk management turn into a spreadsheet nightmare?
Most programs start with a master spreadsheet and the same long questionnaire for every vendor. Within a year the sheet is stale, half the questionnaires are unanswered, and the vendors holding your customer data got the same attention as the company that services the coffee machine.
The real problem is a lack of prioritization. A team of two can't assess 300 vendors in depth. It needs to find the few dozen that could hurt the business badly and spend its time there.
How should you tier your vendors?
Tiering makes everything else manageable. Ask two questions about each vendor:
- What data or access do they have? Customer personal data, payment data, health records, credentials, source code, administrative access to your systems, or nothing sensitive at all.
- How critical are they to operations? If this vendor went down for a day, or a week, what would stop working?
A vendor that scores high on either question deserves attention. One that scores high on both goes to the top of the list.
| Tier | Typical profile | Examples |
|---|---|---|
| Tier 1 (critical) | Sensitive data at scale, privileged access, or operations stop without them | Cloud hosting, payroll, managed IT provider with admin rights |
| Tier 2 (moderate) | Limited sensitive data or moderate operational impact | Marketing automation, HR survey tool, logistics partner |
| Tier 3 (low) | No sensitive data, no system access, easy to replace | Office supplies, catering, design tool used with public assets |
Most small and mid-sized organizations end up with a short Tier 1 list, a larger middle tier and a long tail of Tier 3. That shape is the point.
Start with an honest inventory
You can't tier vendors you don't know about. Build the list from accounts payable, corporate card statements, your single sign-on provider and the OAuth app grants in your email and collaboration platforms. The last two often surface tools that teams adopted without going through procurement.
Give each vendor a business owner, the person who chases answers and handles renewals. And tier on potential impact, not only on stored data. A managed service provider with remote admin rights may never hold a customer record, yet a compromise of its tooling could reach every system you run.
What should a vendor assessment look like for each tier?
Right-sizing means the effort matches the risk. This pattern works for most teams:
- Tier 1: Collect independent evidence (a current SOC 2 Type II report or an ISO 27001 certificate with its scope), ask targeted follow-up questions about the gaps, review the contract in detail and talk to the vendor's security contact. Reassess annually.
- Tier 2: Collect whatever independent evidence exists, plus a short questionnaire of 20 to 30 questions on access control, encryption, incident response and data handling. Reassess every two years or when the relationship changes.
- Tier 3: A few intake questions at purchase time to confirm no sensitive data is involved. Revisit only if the use changes.
The biggest time saver is asking only questions you'll act on. If an answer can't change your decision or your contract terms, drop the question.
How do you reuse SOC 2 reports and ISO 27001 certificates?
Independent assurance saves vendors from answering the same questions for every customer. Using it well means reading the reports, not just filing them.
Reading a SOC 2 report
A SOC 2 report is an auditor's opinion on a service organization's controls, measured against the AICPA's Trust Services Criteria. Check these points:
- Type I or Type II. Type I covers control design at a single point in time. Type II tests whether controls operated effectively over a period, typically three to twelve months. Ask Tier 1 vendors for Type II.
- Period and scope. Confirm the report covers the service you're buying and that the period ended recently. If there's a gap since the period end, ask for a bridge letter.
- Exceptions. A few are normal. What matters is whether they touch controls you care about and how management responded.
- Complementary user entity controls. These are controls the vendor expects you to run, such as reviewing user access. Give each one an owner on your side.
- Subservice organizations. The report says whether the vendor's own providers are included or carved out. Carved-out providers are your fourth parties.
Checking an ISO 27001 certificate
An ISO/IEC 27001 certificate shows the vendor runs a certified information security management system. On its own it says little, so check:
- Scope. Does it cover the business unit, locations and service you use? A certificate scoped to one office tells you nothing about a product built elsewhere.
- Issuer. Look for a certification body accredited by a recognized accreditation body.
- Validity. Certificates run on a three-year cycle with annual surveillance audits.
- Edition. Organizations certified to the 2013 edition have until October 31, 2025 to transition to ISO/IEC 27001:2022.
Ask for the Statement of Applicability too. It lists which Annex A controls are in place and which were excluded.
When there's no report
Smaller vendors often have neither. Instead of writing your own questionnaire, ask for a standard one such as the Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ), which many cloud vendors have already completed.
Which contract clauses matter most?
An assessment tells you about a vendor today. The contract decides what you can require tomorrow. For Tier 1 and Tier 2 vendors, these clauses do the heavy lifting:
- Breach notification. Require notice of any security incident affecting your data within a defined window measured in hours or a few days, not just "without undue delay." Under GDPR, controllers generally have 72 hours from becoming aware of a qualifying breach to notify their supervisory authority, so your vendor's clock has to be shorter than yours.
- Right to audit. Keep it even if you'll rarely use it. A practical version accepts a current SOC 2 report or ISO 27001 certificate in place of an on-site audit, with the full right reserved for after an incident.
- Subprocessors. Require a published subprocessor list, advance notice of changes, the right to object and flow-down of equivalent security obligations. GDPR Article 28 sets similar expectations for processors handling personal data.
- Data location, return and deletion. State where data may be stored and how it will be returned or destroyed at the end of the contract, with written confirmation.
- Security baseline and continuity. Name the minimum controls you expect, such as encryption and multi-factor authentication for admin access. For operationally critical vendors, add recovery time commitments.
Get these terms into legal's templates so Tier 1 contracts aren't signed on the vendor's paper without review.
What does continuous vendor monitoring look like in practice?
For most organizations, "continuous monitoring" means a few lightweight habits between formal reviews:
- Track evidence expiry. Record SOC 2 period end dates and certificate expiry dates, and request new versions when due.
- Watch for material changes. An acquisition, new subprocessors or a new use of the service can move a vendor up a tier.
- Follow status and security pages. Subscribe to them for Tier 1 vendors so outages and disclosures reach you directly.
- Review your own connections. Once a year, check the integrations, API tokens and service accounts linked to Tier 1 vendors and remove what isn't used.
- Treat outside-in scores with care. External vendor ratings can flag expired certificates or exposed services. Use them as prompts for a question, not as a verdict.
Monitoring works when it lives on someone's calendar. A quarterly 30-minute review of Tier 1 vendors beats an ambitious dashboard nobody opens.
How do you manage fourth-party risk?
Your vendors have vendors. A SaaS provider may run on a large cloud platform and send email through a delivery service. An outage or compromise at either can affect you, even though you have no contract with them.
You can't assess every fourth party. Focus on visibility and concentration instead:
- Ask Tier 1 vendors for their subprocessor list and how they assess their own critical suppliers.
- Read the subservice organization section of each SOC 2 report.
- Look for concentration. If several critical vendors depend on the same hosting provider or region, one outage could hit all of them at once.
The NIST Cybersecurity Framework 2.0, released in February 2024, added a Govern function with a dedicated cybersecurity supply chain risk management category (GV.SC). It's a handy reference when you explain this work to leadership.
How do you offboard a vendor safely?
Offboarding is where many programs quietly fail. The contract ends, but accounts, integrations and data linger for years. Use a short checklist for every Tier 1 and Tier 2 exit:
- Disable SSO access and any local accounts on the vendor's platform.
- Revoke API keys, OAuth grants, service accounts and remote-access connections.
- Rotate any shared credentials or secrets the vendor could have seen.
- Export the data you need to keep, in a usable format.
- Request deletion or return of everything else and get written confirmation.
- Remove the vendor from firewall allowlists, DNS records and email sending authorizations such as SPF includes.
- Close the inventory record with a date and the owner's sign-off.
Step six is the one teams forget most. A DNS record still pointing at a service you no longer control can let someone else claim that hostname.
Frequently asked questions
How many vendors should be in Tier 1?
There's no fixed number. The top tier should be short enough that each vendor in it gets real attention every year. If it isn't, your criteria are probably too loose.
Do we need a dedicated third-party risk platform?
Not to start. An inventory with tiers, owners, evidence dates and contract links carries most small and mid-sized organizations a long way. Add tooling once the process is stable.
What if a vendor won't complete our questionnaire?
Large providers rarely complete custom questionnaires, but most share SOC 2 reports and certifications under NDA or through a trust portal. Accept those instead. If a small vendor offers nothing and handles sensitive data, the business owner should accept that risk in writing or choose another supplier.
Next steps
- Build the vendor inventory from finance, SSO and OAuth data, and give every vendor an owner.
- Tier each vendor on data access and operational criticality.
- Collect and read SOC 2 reports and ISO 27001 certificates for Tier 1 first.
- Add breach notification, right-to-audit, subprocessor and data-return clauses to your contract templates.
- Put a quarterly Tier 1 review and an offboarding checklist on someone's calendar.
A short list of well-understood vendors is worth more than a long spreadsheet of unread questionnaires.