Services /  GRC

Third-Party Risk Management

Know what your vendors can reach, and prove you checked.

The problem

Engineering signs up for a SaaS tool with a corporate card, connects it to production data, and nobody finds out until an auditor asks for the supplier list. Meanwhile your own enterprise customers demand evidence that you assess your vendors, and you cannot even enumerate them.

The method.

01

Discover the actual vendor estate

Reconcile three sources that never agree: accounts payable and card statements, the identity provider's OAuth and SSO application list, and the DNS and email records. The gap between the vendors finance knows about and the OAuth grants in your IdP is where the risk lives.

02

Tier by access, not by spend

Classify each supplier by what it can reach: production personal data, source code, admin credentials, customer environments. A $40/month tool with an OAuth grant to your entire mailbox is a higher tier than a $200k platform that never touches your data.

03

Assess proportionally

Tier 1 suppliers: review the SOC 2 report or ISO certificate (including scope and exceptions, which is the part everyone skips) plus penetration test summary, subprocessor list, breach history, and the DPA. Lower tiers: a short questionnaire and evidence of certification. We do not send a 300-question spreadsheet to a font provider.

04

Fix the contract before the risk

Ensure the agreement carries what you will need later: GDPR Article 28 processor terms, breach notification windows, subprocessor change notice, audit rights, data return and deletion on exit, and, where in scope, DORA subcontracting and exit provisions.

05

Re-assess on cadence and on event

Annual re-assessment for critical suppliers, and event-driven re-assessment on breach disclosure, an expiring certificate, a change of subprocessor, or an acquisition. Offboarding is a control too: tokens revoked, OAuth grants removed, data return confirmed in writing.

Vendor estates change weekly. The ROC continuously watches the IdP for new OAuth grants and new SSO applications, and flags a supplier that was onboarded without assessment in the week it happens, which is the only way a supplier inventory stays true.

What is third-party risk management?

Third-party risk management is the process of identifying every supplier that can reach your systems or data, tiering them by the access they hold, assessing their security before and during the relationship, ensuring the contract carries the necessary security and data-protection terms, and revoking access cleanly when the relationship ends.

How should vendors be tiered for a security assessment?

Tier by access, not by contract value. The determining questions are: can this vendor reach production personal data, source code, or administrative credentials; is it in the path of a critical business process; and would its outage stop us serving customers. A low-cost tool with a broad OAuth grant to corporate mail routinely outranks an expensive platform that never touches customer data.

What evidence should you request from a critical supplier?

A current SOC 2 Type II report or ISO 27001 certificate (read the scope statement and the exceptions, not just the cover page), a penetration test summary, the subprocessor list, the Data Processing Agreement, and their breach notification commitment. A certificate whose scope excludes the service you actually buy is common and is worth nothing to you.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.