Third party risk management

Supplier risk that gets remediated, not just recorded.

Getting an assessment back is one thing. We chase the suppliers who haven't replied, test whether the answers hold up, and work with them until the risk comes down — so a supplier's exposure doesn't become your incident, and you can evidence where you stand to your board and your regulator.

How third party risk grows

Every supplier you take on is a potential risk to your business.

You can hold your own security to a standard, but you can't control theirs. And the number of organisations holding your data, connecting to your systems or underpinning something you depend on only goes up. Due diligence at onboarding captures a supplier on one day; their security keeps changing after that, and so does the list.

Supplier records held across procurement, IT and individual business units

Questionnaires returned once and not revisited

Findings that need a conversation with the supplier, and no obvious owner for it

Assessment volume rising faster than the people available to do them

The same depth of review applied to a critical supplier and a low-risk one

No assembled evidence trail when an auditor or regulator asks

48%

of breaches now involve a third party — a share that has risen by 60% in a year.

Your suppliers' security decisions land on your balance sheet, your service availability and your regulatory position. You carry the consequence without holding the controls — which is why the assessment has to be followed by someone who can get something changed.

Verizon Data Breach Investigations Report, 2026

The service

Five stages, run continuously.

Supplier risk isn't a project with an end date, so the service doesn't have one either. Each stage runs on a schedule set by how critical the supplier is, not by when anyone last had capacity.

01

Identify

We work with your procurement, IT and business teams to establish who your suppliers actually are, what each one touches, and which tier they belong in. Criticality decides how much scrutiny a supplier gets and how often.

02

Assess

Each supplier is assessed against a risk-based framework covering data sensitivity, access levels, regulatory exposure and operational impact. Our assessors read what comes back and interpret the technical control gaps rather than scoring a form.

03

Remediate

We turn findings into prioritised actions, then take them to the supplier ourselves — chasing responses, testing whether the answers hold up, and staying with each finding until the risk is reduced or formally accepted by the business.

04

Monitor

We track changes to supplier status, risk posture and compliance obligations, with alerts and reporting that keep the risk owners informed. Supplier breach notifications are triaged alongside your own detection and response.

05

Revalidate

Assessments are revisited on a schedule tied to supplier criticality, contract renewals and changes in your business — so the position you report is current rather than historic.

What the service answers

The five questions a supplier estate has to answer.

Who are our suppliers, and which of them could stop us trading?

What data and what systems does each one actually touch?

Which of them have we assessed, and how long ago?

What did we find, and what has been done about it since?

Can we evidence all of that to an auditor this week?

Your business Critical suppliers Wider supply base

Solid markers are suppliers that have been assessed and had findings closed. The work is keeping that proportion moving as the estate changes.

Why a service, not a licence

The platform isn't the service.

A platform will tell you a supplier hasn't answered. It won't ring them.

It won't judge whether the answer they eventually give is good enough, push back when it isn't, or stay with a finding until it's closed. That's the work — and it's the part that goes undone when a tool is bought without the capacity to run it.

Our assessors read what comes back, interpret the technical control gaps, translate them into risks your business can act on, and go back to the supplier themselves until the risk is reduced. Your team keeps ownership of the decisions. We do the chasing.

On platforms

We can run the service on a platform you already own.

Buy the full package and it comes with Risk Ledger, including the licence. Supplier-side access is free, so you only pay as the consuming organisation — and many of your suppliers will already hold a profile.

What you get

Included in the managed service.

Supplier tiering and onboarding

Structured onboarding, a tiering policy your teams agree to, and a clear record of which supplier belongs in which tier and why. Criticality drives the depth and frequency of everything that follows.

Assessment and interpretation

Risk-based assessment covering data sensitivity, access, regulatory exposure and operational impact — read and interpreted by named assessors, not scored by a rules engine.

Supplier communications handled for you

We handle the back-and-forth: chasing non-responders, querying weak answers, requesting evidence, and taking remediation actions to the supplier on your behalf.

Reporting your risk owners can use

Business risk reporting and prioritised remediation recommendations, written so that the person who owns the supplier relationship can act on them without a security background.

For higher-risk suppliers we add enhanced reviews: a 30-day dark web scan for leaked credentials, a review of the technical access granted to that supplier, and evidence-based validation that tests supplier claims against what we actually find.

Proof

Two programmes, two use cases.

Financial services

A capital management and risk transfer provider

They already had a platform and a process. What they didn't have was the capacity to keep pace with a growing supplier base, and a backlog had built up behind it. We cleared the backlog, validated the assessments already on file, and helped embed risk ownership with the business rather than with IT.

Full compliance with internal policy, improved audit readiness, and assessment cycle times reduced by over 85%.

Blue light

A Fire and Rescue Authority

A compliance gap against the CAF triggered the programme, and there was nothing in place to build on. We launched it from scratch — supplier onboarding, risk reviews and remediation workflows — and set the review schedule against supplier criticality.

All critical suppliers assessed within three months, on a risk-based review schedule aligned to NCSC expectations.

Independently assessed

  • ISO 27001
  • ISO 9001
  • Cyber Essentials Plus
  • CREST Security Operations
  • FSQS registered
Questions we get asked

Before you talk to us.

Do we have to use Risk Ledger?

No. We can run the service on a platform you already own. If you buy the full package it comes with Risk Ledger, including the licence, and supplier-side access is free — you only pay as the consuming organisation.

What size of supplier base is this for?

It works from a few dozen suppliers upwards. Below that, the assessment work is usually manageable in-house; above it, the volume tends to outgrow the team before anyone notices.

What kinds of risk do you assess?

Security and resilience risk: how a supplier protects your data, what access they hold, how they'd detect and respond to an incident, and what happens to your service if they have one. We're not assessing their financial standing or their credit rating — that's a separate discipline, and a supplier can be financially sound and a poor security risk at the same time.

Where does this stop and procurement due diligence start?

Procurement due diligence answers whether to contract with a supplier at all — commercials, financial standing, references. This sits alongside it and answers a different question: what that supplier's security looks like now, what has changed since you signed, and what needs fixing. Neither replaces the other.

Who from our side needs to be involved?

Less than most people expect. We need someone who can tell us which suppliers matter and why, usually a mix of procurement and the business owners, and a security or risk contact to agree the tiering and receive the reporting. The supplier-facing work is ours.

Who owns the risk decisions — you or us?

You do. We assess, interpret, recommend and chase, but the decision to accept, mitigate or exit a supplier relationship stays with the risk owner in your business. Part of the work is making sure those decisions reach the right person.

How often are suppliers reassessed?

On a schedule set by supplier criticality, contract renewal dates and changes in your business, rather than on a fixed annual cycle for everyone.

What happens when you find something serious?

We come to you the same day with what we've found, what it exposes and what we'd recommend — before we go back to the supplier. If it warrants it, we'll take it to the supplier as an urgent remediation rather than through the normal cycle.

What happens if one of our suppliers is breached?

Where you're on our Managed Detection and Response, supplier breach notifications are triaged against your own environment directly, so the impact on you is assessed quickly. Where you have another provider, we pass the supplier-side intelligence to your team in a form they can act on.

Start with the suppliers that matter most.

Tell us how many suppliers you have and which of them are most critical to your organisation. That's enough for us to show you what the first ninety days would cover.

Talk to us about supplier risk