Six stages, and the programme fails at whichever one you skip
Due diligence is usually treated as an onboarding gate. It is a lifecycle, and the risk in a supplier relationship is rarely highest on the day it starts.
Three tiers, because you cannot assess everyone the same way
Tier by access and impact, not by spend. The cheapest contract in the estate is frequently the one with production credentials.
Six ways the programme quietly stops working
We find at least three of these in almost every review. They are process failures, not effort failures.
Assessed once, at onboarding
A supplier vetted three years ago has since changed owners, lost staff and been breached. Nobody looked again.
A questionnaire nobody verifies
Self-attested answers accepted without a single piece of supporting evidence, then filed as assurance.
No fourth-party view
Your critical supplier depends on a provider you have never heard of. Their outage is your outage.
Effort spread evenly
The same 200-question form sent to a cleaning contractor and a core platform vendor, so neither gets proper attention.
Security involved after signature
Terms negotiated by procurement, security consulted once the contract cannot be changed.
No exit process
Former suppliers retaining credentials and data years after the relationship ended.
One-off assessment
A defined review of your existing third-party population: the register built, relationships tiered, critical suppliers assessed in depth, and a rated finding per supplier with the contractual gaps named.
Ongoing programme
We own the process: onboarding assessments, continuous screening, periodic reassessment on the tier cadence, and a quarterly report on where concentration and exposure are building.
Where supplier risk shows up elsewhere
Privileged access management
Give a contractor access to a system, not to your network, and record every session.
Personal data protection
Data you sent to a processor is still your obligation, and the contract has to say so.
Internal audit & readiness
Third-party and outsourcing risk is a named domain in any credible IT audit.
