Skip to content

Home Expertise / Risk & governance

GRC / GRC-08

Third-party and supply-chain risk management

Assessing risks introduced by external providers, software and services according to their access and business importance.

WHEN IT HELPS

A focused response
to a defined need.

Procurement, legal or CISO; critical outsourcing, many suppliers or dependence on a SaaS platform.

AT A GLANCE

Family
Risk & governance

Engagement
Advisory

Reference
GRC-08

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Classify third parties
  • proportionate questionnaires and evidence review
  • access, incident, continuity, subcontracting and exit requirements

Deliverables

  • Critical-provider register
  • risk profiles
  • contractual and operational measures for negotiation

Acceptance evidence

Priority providers have an evidence-based risk rating, an owner and a treatment or acceptance decision.

DELIVERY

How the work is structured.

Approach

Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.

Prerequisites & responsibilities

Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.

Scope factors

Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.

Questions to clarify

What access does the provider have? What happens if it stops operating? What evidence and exit options exist?

IMPORTANT BOUNDARIES

Supplier statements and certifications do not prove every practice; legal review is required for contract clauses.

The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company’s managed-service provider has broad permanent access. Project: review permissions, practices and incident commitments. Target outcome: bounded access, control evidence and clarified commitments before renewal.

Scenario 02

Procurement uses the same 200-question form for every supplier. Project: classify providers by criticality. Target outcome: deeper review of critical providers and lighter review of others, without equating completed forms with demonstrated security.

Technology and reference context

Provider register, contextual questionnaires and evidence pack; optional GRC tooling.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.