GRC / GRC-08
Third-party and supply-chain risk management
Assessing risks introduced by external providers, software and services according to their access and business importance.

WHEN IT HELPS
A focused response
to a defined need.
Procurement, legal or CISO; critical outsourcing, many suppliers or dependence on a SaaS platform.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Classify third parties
- proportionate questionnaires and evidence review
- access, incident, continuity, subcontracting and exit requirements
Deliverables
- Critical-provider register
- risk profiles
- contractual and operational measures for negotiation
Acceptance evidence
Priority providers have an evidence-based risk rating, an owner and a treatment or acceptance decision.
DELIVERY
How the work is structured.
Approach
Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.
Prerequisites & responsibilities
Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.
Scope factors
Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.
Questions to clarify
What access does the provider have? What happens if it stops operating? What evidence and exit options exist?
IMPORTANT BOUNDARIES
Supplier statements and certifications do not prove every practice; legal review is required for contract clauses.
The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company’s managed-service provider has broad permanent access. Project: review permissions, practices and incident commitments. Target outcome: bounded access, control evidence and clarified commitments before renewal.
Scenario 02
Procurement uses the same 200-question form for every supplier. Project: classify providers by criticality. Target outcome: deeper review of critical providers and lighter review of others, without equating completed forms with demonstrated security.
Technology and reference context
Provider register, contextual questionnaires and evidence pack; optional GRC tooling.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
