Englishالعربية Soon
Under attack?
Third-party due diligence

You can outsource the service. You cannot outsource the liability.

Structured assessment of the suppliers, agents, resellers and partners you have given access to, who owns them, what they can reach, whether they can evidence their controls, and what happens when they change.

Who counts as a third party
Technology and cloud service providers
Outsourced operations and BPO
Agents, resellers and distributors
Consultants with system access
Joint venture and channel partners
Anyone holding your customer data

Regulators, courts and customers increasingly hold the contracting organisation responsible for what its third parties do. Diligence is the record that you looked, and what you found when you did.

Lifecycle

Six stages, and the programme fails at whichever one you skip

Due diligence is usually treated as an onboarding gate. It is a lifecycle, and the risk in a supplier relationship is rarely highest on the day it starts.

Stage 01

Identify

Build the population. Most organisations cannot produce a complete third-party list, because procurement, IT and business units each hold part of it.

Stage 02

Tier

Classify each relationship by the access it holds and the impact of its failure, so effort follows risk rather than contract value.

Stage 03

Assess

Run the checks appropriate to the tier. Evidence requested and verified, not accepted as a self-attestation and filed.

Stage 04

Contract

Security, data protection, audit rights, subcontracting limits, notification obligations and exit terms written in before signature, when you still have leverage.

Stage 05

Monitor

Continuous screening for sanctions, ownership and adverse media changes, plus periodic reassessment. Risk is a moving position, not an onboarding snapshot.

Stage 06

Exit

Access revoked, data returned or destroyed with evidence, and the dependency unwound. The step almost universally forgotten until an auditor asks.

Tiering

Three tiers, because you cannot assess everyone the same way

Tier by access and impact, not by spend. The cheapest contract in the estate is frequently the one with production credentials.

Critical
Access to production systems, customer data or funds; or a service whose failure stops your business.
Full assessment before contract: evidence reviewed, security terms negotiated, right to audit secured. Reassessed annually with continuous screening between.
Significant
Handles personal data, or supports an important but recoverable process.
Documentary assessment with targeted evidence requests and security schedule. Reassessed every two years, screened continuously.
Standard
No sensitive data, no system access, readily replaceable.
Screening and basic checks at onboarding, refreshed on renewal. Proportionate effort rather than a questionnaire nobody reads.
Checks

Ten checks, applied in depth proportionate to tier

A critical supplier gets all ten with evidence verified. A standard one gets screening and the essentials. Neither gets a form nobody reads.

01

Corporate and legal standing

Registration, ownership structure, trading history, licences held, litigation and insolvency records. Establishing that the entity is what the contract says it is.

02

Ultimate beneficial ownership

Who actually owns and controls the company behind the holding structure, the check most often skipped and most often the one that matters.

03

Sanctions and watch lists

Screening of the entity, its owners and its directors against sanctions regimes, enforcement lists and politically exposed person records, with the lists kept current rather than checked once.

04

Financial health

Accounts, credit standing and concentration exposure. A supplier that fails commercially disrupts you as effectively as one that is breached.

05

Adverse media

Reported bribery, corruption, fraud, labour or environmental issues, in local language sources as well as international ones.

06

Anti-bribery and corruption

Policies, training, gift and hospitality controls, and whether the counterparty can evidence them rather than assert them.

07

Information security posture

Certifications held and their scope, control maturity, testing history, incident record, and the security terms they will actually accept in a contract.

08

Data protection

What personal data they will hold or access, where it will be processed, on what lawful basis, and the contractual safeguards attached to it.

09

Operational resilience

Continuity and recovery capability for the service you depend on, and their own dependence on fourth parties you have never assessed.

10

Regulatory standing

Authorisations, supervisory history and whether outsourcing to them satisfies the requirements your own regulator places on you.

Failure modes

Six ways the programme quietly stops working

We find at least three of these in almost every review. They are process failures, not effort failures.

Assessed once, at onboarding

A supplier vetted three years ago has since changed owners, lost staff and been breached. Nobody looked again.

A questionnaire nobody verifies

Self-attested answers accepted without a single piece of supporting evidence, then filed as assurance.

No fourth-party view

Your critical supplier depends on a provider you have never heard of. Their outage is your outage.

Effort spread evenly

The same 200-question form sent to a cleaning contractor and a core platform vendor, so neither gets proper attention.

Security involved after signature

Terms negotiated by procurement, security consulted once the contract cannot be changed.

No exit process

Former suppliers retaining credentials and data years after the relationship ended.

Engagement model

One-off assessment

A defined review of your existing third-party population: the register built, relationships tiered, critical suppliers assessed in depth, and a rated finding per supplier with the contractual gaps named.

Risk assessment →

Engagement model

Ongoing programme

We own the process: onboarding assessments, continuous screening, periodic reassessment on the tier cadence, and a quarterly report on where concentration and exposure are building.

vCISO and DPO services →

Related

Where supplier risk shows up elsewhere

Privileged access management

Give a contractor access to a system, not to your network, and record every session.

Personal data protection

Data you sent to a processor is still your obligation, and the contract has to say so.

Internal audit & readiness

Third-party and outsourcing risk is a named domain in any credible IT audit.

Start by finding out how many there are.

We build the register and tier it first. The count is almost always higher than the finance system suggests.