Independent security assurance and editable documentation to keep organizations secure, compliant and resilient Questions? contact@rootguardsecurity.com

Supplier assurance · One off or on a cycle

What your suppliers can reach, and who checked

A supplier register tiered by what each one can actually touch, and an assessment of the ones that matter. A returned questionnaire is an assertion until something is examined, and we mark it as one.

Basis
Quoted by tier and count
Input
Contracts, questionnaires, reports
Ends with
Register and coverage position
Cycle
Annual or as agreed

Who this is for

Anybody whose worst incident will arrive through somebody else

Most third party programs assess whoever replies. That is how a stationery supplier gets assessed while the payroll provider with domain administrator rights does not.

A customer or regulator is asking about your supply chain

The question is no longer whether you have a policy. It is which suppliers were assessed this period and what was found.

You are the supplier being asked

Nearshore and shared services operations carry their clients' obligations downward. Knowing your own suppliers is part of answering for yourself.

Somebody has access nobody remembers granting

Every register surfaces at least one. They come from accounts payable and access records, not from the list the business maintains.

What it protects

Your contracts, and the incident that arrives through somebody else

Supplier assurance is bought for two reasons, and both are commercial before they are technical.

Contracts that require it

Customers increasingly ask what you do about your own suppliers, and a policy is no longer the answer. Count the revenue behind contracts carrying a supply chain clause. That is the number this protects.

The access nobody remembers granting

Every register surfaces a supplier with live access and no current contract. That is an open door with no owner, and finding it is usually the cheapest risk reduction available in the engagement.

Insurance and renewal questions

Underwriters and customers both ask which suppliers were assessed and when. A coverage position answers it. A list of suppliers does not.

The four stages

Tier, then ask, then check

1

Build the register from records, not memory

Contracts, accounts payable and access records, reconciled against each other. Suppliers with access and no contract surface here, and so do contracts nobody is paying for.

This is where the surprise usually is, and it is the cheapest stage.

2

Tier by what they can reach

Data held, systems accessed, and whether access ends when the contract does. That decides the tier, not the size of the invoice.

A supplier who can reach your identity provider outranks one who bills you more and holds nothing.

3

Ask, as a file

Questionnaires go out and come back as documents, tracked by who received them and when. No portal anybody has to log into, and no platform your suppliers have to be onboarded to.

Non response is recorded as non response. Treating silence as a pass is how a register becomes fiction.

4

Check where the tier warrants it

For tier one, the assertion is checked against something. An attestation report read rather than filed, a certificate with its scope actually examined, a configuration export, a contract clause.

  • A SOC 2 report covering a different service than the one you buy is a common and expensive discovery.
  • A certificate with a scope statement excluding the relevant system is the same problem wearing a badge.
  • Exceptions in an attestation report are the part worth reading, and they are at the back.

How tiers work

What changes with tier, and what does not

The register covers every supplier. How hard each is examined depends on what they can reach.

TierTypicallyWhat we do
OneHolds personal or regulated data, or can reach systems directlyQuestionnaire, then evidence examined against it, findings raised, reassessed on a stated cycle.
TwoHolds limited data, or access is mediated and time boundQuestionnaire reviewed, contract terms checked, evidence requested only where an answer is inconsistent.
ThreeNo access to data or systemsRecorded in the register with the basis for the tier. Not assessed, and the register says so rather than leaving a blank.

How we work with your team

Alongside your people, not over them

Procurement and IT both get findings they can act on

Some supplier findings are contractual and some are technical. They go to the team that can fix them, separated, rather than as one list neither owns.

We do not speak to your suppliers as you

The conversation with a supplier is yours. We give you the finding and the clause it rests on, which makes that conversation shorter and considerably less awkward.

The register is yours to run

Tiering rules, questionnaire and cycle dates handed over, so your team can add a supplier next month without calling us.

What you end up with

A register that outlives the engagement

What you keep

  • A supplier register tiered by access and criticality, with the next assessment date on each entry.
  • Assessments of the tier one suppliers, each with the method, the evidence examined and a conclusion.
  • A coverage position: assessed, outstanding, and never assessed. This is the number a board asks for.
  • Findings with owners, including the contractual ones your procurement team rather than your IT team has to fix.

What this is not

  • Continuous monitoring. We assess on a cycle. Nothing here watches a supplier between assessments, and a page claiming otherwise would be describing a platform rather than an engagement.
  • A security rating. Externally scraped scores measure what is visible from the internet, which is not what your supplier can reach inside your business.
  • Testing a supplier's systems. We read what they provide and what your contract entitles you to see.

What changes afterwards

What your organization can do that it could not before

Answer which suppliers were assessed, and when

For a customer, an underwriter or a board, from a register rather than an email search.

Close access nobody owns

Starting with the suppliers who still have it and should not.

Add a supplier without starting over

Tiering rules and a cycle your own team runs.

Boundaries

What is not included

Negotiating with your suppliers

We establish the position and write the finding. The conversation with the supplier is yours, and it goes better when it cites a clause rather than a worry.

Suppliers who will not respond

Recorded as non responsive, with the date and the attempts. That is a finding about your leverage, and it is often the most useful one in the report.

Onward suppliers

Your supplier's suppliers are in scope only where your contract gives you the right to ask. Where it does not, that absence is the finding.

Start with the register, not the questionnaires

Almost every organization can produce a supplier list from accounts payable in an afternoon. Comparing it against who holds an account in your systems costs nothing, and it is usually where the surprise is.