Skip to content
Singahi

Compliance · guide

ISO 27001 A.5.19: Information Security in Supplier Relationships

82 min read

Share
On this page

Quick Reference (60 Seconds)

ISO 27001:2022 Annex A 5.19 asks organizations to define and run processes for managing information security in supplier relationships, ensuring that suppliers and their services, products, and personnel do not introduce unacceptable risk to the organization's information and systems.

ElementWhat You Need to Know
Standard ReferenceISO/IEC 27001:2022, Annex A, Control 5.19
27002 GuidanceISO/IEC 27002:2022, Clause 5.19, Information security in supplier relationships
ObjectiveEnsure information security is managed throughout the lifecycle of supplier relationships
Key RequirementRisk assessment, security requirements in contracts, monitoring, auditing, incident management, change control, termination
Who It Applies ToAll suppliers with access to information, systems, or premises: IT vendors, cloud providers, consultants, cleaners, security guards, managed services, outsourced development, SaaS
Audit FocusSupplier inventory, risk assessments, contractual security clauses, monitoring records, audit rights, incident history, change management
Typical FailuresNo supplier inventory, no security clauses, no risk assessment, no monitoring, no audit rights, no termination procedure
ISO 27002 attributesControl type: Preventive · Properties: Confidentiality, Integrity, Availability · Concepts: Identify · Capabilities: Supplier relationships security · Domains: Governance and ecosystem, Protection

The Bottom Line: You can have the strongest internal security in the world, but one vulnerable supplier can destroy it all. Supplier security is your security. If you don't manage it, you don't own your risk.


What the Control Asks For

The Control in Brief

In short:

ISO 27001:2022 Annex A 5.19 asks organizations to define and apply processes and controls to manage the security risks of using suppliers' products and services.

Do you need this control?

A.5.19 is not mandatory in itself: under clause 6.1.3 you include it if your risk assessment calls for it, and record the decision in your Statement of Applicability. Include it if suppliers handle your information or provide services you depend on, which is nearly everyone. Scale the effort by supplier risk: a tiering approach lets you treat a payroll processor very differently from a stationery vendor.

What ISO 27002:2022 Adds

ISO/IEC 27002 guidance for 5.19 (paraphrased). Set a topic-specific policy on supplier relationships, communicate it, and run processes, including what you require suppliers to do when you start and stop using them, that cover:

  • (a) the types of suppliers that can affect your information (ICT services, logistics, utilities, financial services, infrastructure components)
  • (b)–(c) how suppliers and their products are evaluated and selected according to sensitivity, including how well their controls protect integrity
  • (d)–(e) which of your information, services and facilities suppliers can access, monitor, control or use, and which supplier-provided components can affect you
  • (f) risks from suppliers' use of your information (including malicious supplier personnel) and from malfunctions or vulnerabilities in their products and software components
  • (g)–(h) monitoring suppliers' compliance (including third-party reviews and product validation) and dealing with non-compliance
  • (i) handling incidents and contingencies, with responsibilities on both sides
  • (j) resilience, recovery and contingency so that supplier problems do not take your information offline
  • (k) awareness and training for your own staff who deal with suppliers
  • (l) managing the transition of information and assets, keeping security intact throughout
  • (m) secure termination: removing access, handling information, intellectual property ownership, information portability if you change supplier or bring the work in-house, records, return of assets, secure disposal and ongoing confidentiality
  • (n) the personnel and physical security you expect at the supplier

27002 also asks you to plan how processing continues if a supplier can no longer deliver (for example by identifying alternatives in advance). Where you cannot impose requirements on a supplier, decide on the basis of risk and record the decision. Supplier agreements are covered by A.5.20, the ICT supply chain by A.5.21, monitoring and change of supplier services by A.5.22, and cloud services by A.5.23.

What Auditors Usually Look For

None of these is mandated by ISO; they are what auditors typically ask to see.

ComponentEvidence RequiredCommon Failure
1. Supplier inventoryComplete list of all suppliers with access to informationNo inventory; shadow suppliers
2. Supplier risk assessmentRisk assessment per supplier or supplier categoryNo assessment; generic template
3. Security requirements in contractsSecurity clauses in all supplier agreementsGeneric contracts; no security clauses
4. Supplier monitoringEvidence of ongoing monitoring and reviewNo monitoring after contract signing
5. Audit rightsContractual right to audit; audit execution recordsNo audit clause; never exercised
6. Termination procedureReturn/destruction of data; access revocationData left with supplier; access not revoked

Why Information Security in Supplier Relationships Matters

The Supplier Risk Reality

StatisticSourceImpact
30% of breaches involved a third party, double the previous yearVerizon DBIR 2025Supplier risk is a major and growing breach source
15% of breaches involved a third party (software supply chain, partner infrastructure, data custodians)Verizon DBIR 2024The baseline the 2025 figure doubled from

The Indian Context

India's digital economy is deeply intertwined with global and local suppliers. Key factors amplifying supplier risk in India:

  1. IT/ITES Hub: India hosts thousands of IT service providers, BPOs, and KPOs handling global customer data. A breach at one Indian supplier can expose data from 50+ international clients.
  2. DPDP Act 2023: The Act makes the "data fiduciary" (your organization) liable for breaches, even if caused by a supplier. Section 8(1) keeps you responsible for processing done by your processors, s.8(2) lets you use a processor only under a valid contract, and s.8(5)'s "reasonable security safeguards" extend to your supply chain.
  3. RBI, SEBI, IRDAI mandates: Financial regulators explicitly require vendor risk management. RBI's Master Direction on Outsourcing of Information Technology Services (2023) requires due diligence, contractual controls, monitoring, incident reporting and exit plans for IT outsourcing by regulated entities.
  4. Offshoring and outsourcing: Many Indian companies are suppliers to global enterprises, subject to stringent client audits (SOC 2, ISO 27001, PCI DSS). Failing supplier security means losing contracts.
  5. SMB supplier ecosystem: Indian SMEs often rely on small local IT vendors, website developers, and accountants who lack security awareness. These are the weakest links.

Scope and Applicability

What Suppliers Are Covered

A.5.19 applies to any external party that has access to the organization's information, systems, or premises. This includes:

Supplier CategoryExamplesSecurity Risk LevelTypical Access
IT service providersManaged IT services, system integrators, IT consultants, MSPsHighSystems, networks, admin credentials
Cloud and SaaS providersAWS, Azure, Google Cloud, Salesforce, Zoho, FreshworksHighData, infrastructure, APIs
Software development vendorsOffshore development centers, custom software shops, app developersHighSource code, databases, customer data
Data processorsPayroll processors, CRM managers, analytics providers, data cleansing servicesHighPersonal data, financial data, employee records
Professional servicesAuditors, legal firms, management consultants, marketing agenciesMedium-HighConfidential reports, strategy documents, customer data
Facilities and physical servicesSecurity guards, cleaning staff, facility management, maintenanceMediumPremises, devices, physical documents
Logistics and courierDocument couriers, warehouse operators, delivery servicesMediumPhysical documents, devices, media
Recruitment and staffingTemp agencies, background check providers, headhuntersMediumEmployee data, candidate PII
Outsourced business functionsBPO, KPO, customer support, accounting, HR administrationHighCustomer data, financial data, employee data
SubcontractorsYour supplier's suppliers, often invisibleHigh (indirect)Data passed through primary supplier
Hardware and software vendorsOEMs, resellers, implementation partnersMediumSystems, licenses, support access
Research and academic partnersUniversities, research institutes, joint venture partnersMedium-HighResearch data, IP, confidential findings
Government and regulatoryTax consultants, compliance auditors, regulatory filersMediumFinancial data, regulatory submissions
Freelancers and individual contractorsIndividual developers, designers, content creatorsMedium-HighSystems, content, customer data

Supplier Access Types

Access TypeDescriptionExamplesRisk Implications
Logical accessRemote or on-premise access to systems, networks, applicationsVPN, RDP, SSH, cloud console, admin portalHigh risk of data breach, lateral movement
Physical accessAccess to buildings, data centers, offices, secure areasID card, biometric, visitor passRisk of theft, espionage, unauthorized device access
Data accessAccess to data stored in supplier systems or transferred to supplierCloud storage, email, file transfer, database replicationRisk of data leakage, unauthorized processing, DPDP violation
Personnel accessSupplier personnel working on your premises or as part of your teamEmbedded developers, consultants, managed service staffInsider threat, credential sharing, knowledge leakage
Subcontractor accessAccess granted to your supplier's subcontractorsOffshore development partner of your main vendorInvisible risk; often no direct contract
Integration accessAPI, webhook, or system-to-system integration accessPayment gateway, CRM integration, logistics APIRisk of API abuse, data interception, supply chain attack

Organizational Scope

Entity TypeApplicabilitySpecial Considerations
Startups and SMEsAll vendors with data access: cloud, dev, accounting, payrollLightweight process; focus on high-risk suppliers; use standardized contract clauses
Growing companies (250-5000 employees)All IT, professional services, facilities, and outsourced functionsFormal TPRM program; risk tiers; quarterly reviews; annual audits for Critical suppliers
Large enterprises (5000+ employees)All suppliers including indirect/subcontractors; global supply chainEnterprise TPRM platform; automated risk scoring; continuous monitoring; on-site audits
Government and PSUsAll vendors for e-governance, citizen data, and infrastructureCERT-In compliance; additional security clearances; make-in-India preferences
BFSI sectorAll vendors handling financial data, payment systems, customer dataRBI/SEBI/IRDAI mandates; PCI DSS for payment suppliers; data location rules (e.g. RBI payment data storage)
HealthcareAll vendors handling patient data, clinical records, insurance claimsDPDP Act (health data is personal data; no separate sensitive category); ABDM and Clinical Establishments rules; HIPAA alignment for US partnerships
IT/ITES and SaaSAll client-facing suppliers; development partners; cloud providersClient audits; SOC 2 alignment; ISO 27001 certification of suppliers
ManufacturingERP vendors, OT system integrators, IoT device suppliers, logisticsIEC 62443 for OT; supply chain integrity; counterfeiting risk
Retail and E-commercePayment gateways, logistics, marketplace vendors, marketing techPCI DSS for all payment touchpoints; DPDP for customer data

Key Definitions and Terminology

TermDefinitionSource/Context
SupplierAn external organization or individual that provides a product, service, or information to the organizationISO 27001:2022, adapted
Third-Party Risk Management (TPRM)The process of identifying, assessing, and controlling risks arising from relationships with external partiesIndustry standard term
Vendor Risk Management (VRM)Synonym for TPRM; often used in IT procurement contextsIndustry standard term
Supplier Risk AssessmentThe evaluation of a supplier's potential to introduce information security risk based on access, data, criticality, and controlsISO 27002:2022 guidance
Security Clause / Security AddendumContractual provisions that specify information security requirements, obligations, and remediesContract law / ISO 27001 practice
Data Processing Agreement (DPA)A contract or clause that governs how a supplier processes personal data on behalf of the organizationGDPR Art. 28 / DPDP Act 2023
Right to AuditA contractual provision allowing the organization to audit the supplier's security controlsISO 27002:2022, Clause 5.19
Subcontractor / Sub-supplierA supplier engaged by your primary supplier to deliver part of the contracted serviceISO 27001:2022 context
Supplier Security Questionnaire (SSQ)A standardized set of questions used to assess a supplier's security postureTPRM best practice
Security Rating / ScoreA numerical or categorical assessment of a supplier's security posture, often based on external telemetrySecurityScorecard, BitSight, etc.
Due DiligenceThe investigation and verification of a supplier's security capabilities before engagementISO 27002:2022 guidance
Continuous MonitoringOngoing assessment of supplier security posture through automated tools, alerts, and periodic reviewsTPRM best practice
Offboarding / TerminationThe process of ending a supplier relationship, including data return/destruction and access revocationISO 27002:2022, Clause 5.19
Supply Chain AttackA cyberattack that targets a less-secure supplier to gain access to the primary target organizationIndustry threat terminology
Fourth-Party RiskRisk introduced by your supplier's suppliers (subcontractors), indirect supply chain riskTPRM advanced concept
Data ResidencyThe requirement that data must be stored and processed within a specific geographic boundarySector rules (RBI payment data, SEBI cloud framework), CERT-In logs, contracts; the DPDP Act has no general residency rule
Service Level Agreement (SLA)A contract that defines the expected level of service, including security-related metricsIT service management
Business Associate Agreement (BAA)A HIPAA-specific contract for healthcare suppliers handling protected health informationUSA healthcare regulation
Incident Notification ClauseA contractual requirement for the supplier to notify the organization of security incidents within a defined timeframeISO 27002:2022, Clause 5.19

Relationship to Other Controls

Figure · Matrix

Comparison: A.6.1 Screening to A.6.8 Information

RelationshipHow They Work
A.6.1 ScreeningSupplier personnelSupplier personnel
A.6.3 InformationSupplier trainingSupplier personnel must
A.6.4 DisciplinarySupplier enforcementSupplier contract must
A.6.7 Remote workingSupplier remote accessSupplier personnel working
A.6.8 InformationSupplier incidentSupplier must report
Condensed from the table below, which carries the full detail for each cell.

Control A.5.19 is a central organizational control that intersects with nearly every other control in ISO 27001:2022. Supplier relationships are conduits for risk, and their management must be coordinated across the entire standard.

Organizational Controls (5.x)

ControlRelationshipHow They Work Together
A.5.1 Policies for information securityParent policyThe supplier security policy is a topic-specific policy under the overall information security policy
A.5.4 Management responsibilitiesGovernanceSenior management ensures resources and authority for TPRM
A.5.2 Information security roles and responsibilitiesRole definitionSupplier security roles (Vendor Risk Manager, Supplier Security Officer) are defined
A.8.29 Security testing in development and acceptanceSupplier acceptanceNew systems/services from suppliers must pass security acceptance before production use
A.5.20 Addressing information security within supplier agreementsContractual basisA.5.20 sets what goes in each supplier agreement; A.5.19 runs the overall supplier process
A.5.21 Managing information security in the ICT supply chainICT supply chainExtra requirements for ICT products and services and their sub-suppliers
A.5.22 Monitoring, review and change management of supplier servicesOngoing assuranceMonitoring supplier performance and managing changes to their services
A.5.23 Information security for use of cloud servicesCloud suppliersSpecific rules for acquiring, using and exiting cloud services
A.5.14 Information transferData exchangeHow information moves to and from suppliers
A.5.8 Information security in project managementProject suppliersProjects involving suppliers apply both A.5.8 (project security) and A.5.19 (supplier security)
A.5.30 ICT readiness for business continuitySupplier resilienceSupplier business continuity must be verified to ensure organizational resilience
A.5.37 Documented operating proceduresOperational handoverSupplier-delivered systems must have documented operating procedures

People Controls (6.x)

ControlRelationshipHow They Work Together
A.6.1 ScreeningSupplier personnel screeningSupplier personnel with access may need background verification
A.6.3 Information security awareness, education and trainingSupplier trainingSupplier personnel must be trained on the organization's security requirements
A.6.4 Disciplinary processSupplier enforcementSupplier contract must allow for consequences of security breaches
A.6.7 Remote workingSupplier remote accessSupplier personnel working remotely must comply with the organization's remote work policy
A.6.8 Information security event reportingSupplier incident reportingSupplier must report security events to the organization per contract

Physical Controls (7.x)

ControlRelationshipHow They Work Together
A.7.1 Physical security perimetersSupplier physical accessSupplier personnel accessing premises must comply with physical security controls
A.7.4 Physical security monitoringSupplier activity monitoringSupplier personnel on premises are subject to physical monitoring
A.7.8 Equipment siting and protectionSupplier equipmentSupplier equipment on premises must be secured and accounted for
A.7.9 Security of assets off-premisesSupplier off-site assetsAssets provided to suppliers (laptops, documents) must be secured off-premises

Technological Controls (8.x)

ControlRelationshipHow They Work Together
A.8.1 User endpoint devicesSupplier devicesSupplier devices connecting to your network must meet endpoint security standards
A.8.5 Secure authenticationSupplier accessSupplier accounts must use strong authentication (MFA)
A.8.8 Management of technical vulnerabilitiesSupplier patchingSupplier must maintain vulnerability management for their systems touching your data
A.8.9 Configuration managementSupplier systemsSupplier systems must be configured securely
A.5.15 Access controlSupplier access rightsSupplier access must be controlled, minimized, and reviewed
A.8.6 Capacity managementSupplier capacitySupplier must maintain capacity for security operations (logging, monitoring)
A.8.2 Privileged access rightsSupplier admin accessSupplier admin access must be controlled and monitored
A.8.24 Use of cryptographySupplier encryptionSupplier must encrypt data in transit and at rest per your requirements
A.8.25 Secure development lifecycleSupplier developmentSoftware development suppliers must follow secure development practices
A.8.28 Secure codingSupplier codeCode from suppliers must meet your secure coding standards
A.8.29 Security testing in development and acceptanceSupplier testingSupplier must conduct security testing before delivery
A.8.31 Separation of development, test and production environmentsSupplier environmentsSupplier must maintain environment separation
A.8.32 Change managementSupplier changesSupplier changes affecting your systems must be controlled and approved
A.8.33 Test dataSupplier test dataSupplier must not use your production data for testing without anonymization

The Supplier Control Family (A.5.19 to A.5.23)

In ISO 27001:2013, supplier security sat in A.15.1 (information security in supplier relationships) and A.15.2 (supplier service delivery management). In 2022 the topic became a family of five controls:

  • A.5.19 (Information security in supplier relationships): the supplier policy and the end-to-end process
  • A.5.20 (Addressing information security within supplier agreements): what each agreement must contain
  • A.5.21 (Managing information security in the ICT supply chain): ICT products, services and their sub-suppliers
  • A.5.22 (Monitoring, review and change management of supplier services): ongoing assurance and change
  • A.5.23 (Information security for use of cloud services): cloud acquisition, use and exit

Implement them together: A.5.19 is the process, the other four apply it to agreements, the ICT supply chain, ongoing operation and cloud.

Implementation Roadmap (Week-by-Week)

Figure · Timeline

Rollout in order

  1. Week 1Inventory + Risk Framework
  2. Week 2Assess Critical + Policy
  3. Week 3Contract Remediation + High Assessment
  4. Week 4Monitoring + Offboarding + Training
  5. Week 5Audit + Harden
Milestones in delivery order. Owners and the evidence each produces are in the table below.

Standard Implementation: 10 Weeks

The following roadmap is designed for growing companies (250-5000 employees) with 50-200 active suppliers. Adjust for smaller or larger organizations.

WeekPhaseActivitiesDeliverablesOwner
Week 1Discovery & InventoryInventory all suppliers; categorize by access type and data handled; identify shadow suppliers; assess current contractsSupplier inventory (initial); shadow supplier report; contract gap analysisProcurement / IT / Security
Week 2Risk Framework DesignDefine supplier risk tiers; design risk assessment methodology; create risk scoring matrix; define risk treatment optionsSupplier risk framework; risk scoring matrix; tier definitionsVendor Risk Manager / CISO
Week 3Policy & Template DevelopmentDraft Supplier Security Policy; create Security Questionnaire; design contract security clauses; build monitoring checklistPolicy draft; SSQ template; contract clause library; monitoring checklistLegal / Security / Procurement
Week 4Assessment Execution (Critical)Send SSQ to all Critical suppliers; review responses; conduct follow-up calls; rate each supplierCritical supplier risk assessments; risk register entriesVendor Risk Manager
Week 5Assessment Execution (High/Medium)Send SSQ to High and Medium suppliers; review responses; rate suppliers; identify gapsHigh/Medium supplier risk assessments; consolidated risk registerVendor Risk Manager
Week 6Contract RemediationReview all supplier contracts; identify missing security clauses; negotiate amendments with Critical/High suppliers; execute new contracts for new suppliersAmended contracts; new contract templates; contract tracking reportLegal / Procurement
Week 7Monitoring & Audit SetupDefine monitoring frequency per tier; schedule annual audits for Critical suppliers; set up security rating service (if budget allows); configure alert thresholdsMonitoring schedule; audit calendar; security rating baselineVendor Risk Manager / Security Operations
Week 8Termination & OffboardingDocument termination procedures; create data return/destruction checklist; design access revocation workflow; test with 1-2 departing suppliersTermination procedure; offboarding checklist; access revocation workflowIT / Security / Vendor Risk Manager
Week 9Training & CommunicationTrain procurement on security clauses; train IT on supplier access provisioning; train security on TPRM process; communicate policy to all suppliersTraining records; communication log; policy acknowledgmentHR / Security / Procurement
Week 10Audit & RefinementConduct internal audit of TPRM implementation; verify supplier inventory completeness; sample contract reviews; test offboarding workflow; refine templatesInternal audit report; refined templates; continuous improvement planInternal Auditor / CISO

Accelerated Implementation: 5 Weeks

For organizations with urgent certification deadlines or fewer than 50 suppliers:

WeekFocusKey Actions
Week 1Inventory + Risk FrameworkComplete supplier inventory; define 3 risk tiers; create SSQ
Week 2Assess Critical + PolicyAssess all Critical suppliers; draft policy; create contract clauses
Week 3Contract Remediation + High AssessmentAmend Critical contracts; assess High suppliers
Week 4Monitoring + Offboarding + TrainingSet up monitoring; document offboarding; train key staff
Week 5Audit + HardenInternal audit; fix gaps; finalize documentation

Enterprise Implementation: 16 Weeks

For large organizations with 500+ suppliers, global operations, multiple procurement teams, and complex subcontractor chains:

PhaseWeeksFocus
Phase 1: Foundation1-4Multi-region supplier inventory; enterprise risk framework; tool selection (TPRM platform); governance structure
Phase 2: Policy & Standards5-6Global policy; regional addenda (India DPDP, EU GDPR, US state laws); contract clause library; standard operating procedures
Phase 3: Assessment at Scale7-10Automated SSQ distribution; external security ratings integration; risk scoring automation; Critical supplier deep-dive assessments
Phase 4: Contract Remediation11-12Bulk contract review; negotiation with Critical/High; new contract template rollout; procurement system integration
Phase 5: Monitoring & Audit13-14Continuous monitoring setup; annual audit program; quarterly business reviews with Critical suppliers; automated alert configuration
Phase 6: Optimization15-16Fourth-party risk visibility; AI-assisted risk prediction; integration with ERM and GRC; external pre-certification audit

Detailed Implementation Guidance

Figure · Tiers

Maturity levels for in supplier relationships

Maturity levels for ISO 27001 A.5.19, in supplier relationships, from most to least mature: Low, 0-5; Medium, 6-11; High, 12-17; Critical, 18-25.
Where most organisations sit, and what the next level asks for. Full characteristics per level are in the table below.

Step 1: Supplier Inventory, Know Your Suppliers

You cannot manage what you do not know. The first step is a complete inventory of all suppliers with access to your information, systems, or premises.

Inventory Sources:

  • Accounts payable / finance records (all paid vendors)
  • Procurement system / contract database
  • IT system access logs (who has VPN, RDP, admin accounts?)
  • Cloud admin consoles (who has IAM access?)
  • Physical access logs (visitor management, security passes)
  • Email domain analysis (who is on your distribution lists?)
  • Department interviews (ask each department who they share data with)
  • SaaS subscription discovery (use tools like Productiv, Torii, or manual survey)

Inventory Attributes:

AttributePurposeExample Values
Supplier NameUnique identificationAccenture India Pvt. Ltd.
Supplier IDInternal trackingSUP-2024-0147
CategoryRisk groupingIT Services, Cloud, Professional Services, Facilities
Data AccessedRisk determinationCustomer PII, Financial Data, Employee Records, Public Data
System AccessTechnical risk scopeVPN, Cloud Console, API, Email, Physical Only
Access TypeControl designAdmin, User, Read-Only, Physical
Personnel CountScale of exposure5 developers, 2 admins, 10 support staff
LocationRegulatory/geographic riskIndia, USA, Philippines, EU
SubcontractorsFourth-party riskYes, 2 offshore dev vendors
Contract Start/EndLifecycle management2024-01-15 to 2026-01-14
Annual SpendBusiness criticality
Risk TierManagement priorityCritical
Last Assessment DateMonitoring frequency2024-06-10
Security CertificationsEvidence of controlsISO 27001, SOC 2 Type II, PCI DSS
Key ContactEscalationVendor Security Officer

Shadow Supplier Discovery:

Shadow suppliers are vendors engaged by individual departments without procurement or security knowledge. Common examples:

  • Marketing team using a freelance designer with Google Drive access to brand assets
  • Sales team using a personal CRM subscription with customer data
  • Developer using a personal GitHub account for company code
  • HR using a free survey tool for employee feedback with PII

Discovery techniques:

  1. Expense report analysis (look for SaaS subscriptions, freelance payments)
  2. Email domain analysis (which external domains appear in internal distribution lists?)
  3. Cloud access logs (which external IPs access your cloud?)
  4. Department surveys ("List all external parties with access to your data")
  5. Network traffic analysis (which SaaS APIs are your systems calling?)

Step 2: Supplier Risk Classification, Tier Your Suppliers

Not all suppliers are equal. Risk-based tiering ensures you focus your limited resources on the suppliers that matter most.

Tiering Criteria:

FactorWeightScoring
Data sensitivity30%Secret/Confidential = 5; Internal = 3; Public = 1
System access level25%Admin/root = 5; User/write = 4; Read-only = 2; None = 0
Business criticality20%Business cannot operate without = 5; Major disruption = 3; Minor inconvenience = 1
Supplier security maturity15%No certifications/unknown = 5; ISO 27001/SOC 2 = 2; Enterprise-grade + audit = 1
Subcontractor complexity10%Multiple unknown subcontractors = 5; Known subcontractors = 3; No subcontractors = 1

Risk Tier Definitions:

TierRisk ScoreProportion of SuppliersManagement IntensityExample
Critical18-25Top 5-10%Deep due diligence before contract; annual on-site audit; quarterly business reviews; continuous monitoring; dedicated relationship managerCore banking system integrator; cloud provider with all customer data; payment processor
High12-17Next 15-20%Standard due diligence; annual SSQ review; semi-annual review; monitoring for security newsCRM vendor; payroll processor; major IT consultant
Medium6-11Next 30-40%Lightweight SSQ; biennial review; ad-hoc monitoring for incidentsMarketing agency; cleaning service; hardware vendor
Low0-5Remaining 30-50%Minimal assessment; triennial review; incident-driven monitoringCourier service; office supplies; training provider

Step 3: Supplier Security Assessment, Evaluate Before You Trust

The Security Questionnaire (SSQ):

A well-designed SSQ covers 8 domains:

DomainKey QuestionsEvidence Requested
1. Governance and PolicyDo you have an information security policy? Is it approved by management? How often is it reviewed?Policy document, review records
2. Risk ManagementDo you conduct risk assessments? How often? What methodology?Risk assessment report, methodology document
3. Access ControlHow do you manage user access? Is MFA enforced? How often are access reviews conducted?Access control policy, MFA configuration evidence, review records
4. Data ProtectionHow do you classify data? Is encryption used? What are your data retention and destruction policies?Data classification policy, encryption configuration, retention policy
5. Incident ManagementDo you have an incident response plan? What is your notification timeframe? Do you conduct post-incident reviews?IR plan, incident records (sanitized), notification SLA
6. Business ContinuityWhat is your RTO/RPO? Do you conduct DR drills? Are backups tested?BCP/DR plan, test records, RTO/RPO documentation
7. Compliance and AuditWhat certifications do you hold? When was your last audit? Are audit reports available?Certificates, SOC 2 report, pen test report, audit reports
8. Subcontractor ManagementDo you use subcontractors? How do you manage their security? Do you disclose all subcontractors?Subcontractor list, their security assessments, contractual clauses

SSQ Response Evaluation:

ScoreRatingMeaningAction
90-100%ExcellentMature security program; enterprise-gradeProceed with standard monitoring
70-89%GoodAdequate security; some gapsProceed with gap remediation plan; monitor closely
50-69%FairSignificant gaps; immature programConditional approval with mandatory remediation; increased monitoring
30-49%PoorMajor gaps; high riskDo not proceed unless critical and no alternatives; require major investment in controls; consider risk transfer (insurance, liability caps)
<30%UnacceptableNo meaningful security programDo not engage; find alternative supplier

Alternative Assessment Methods:

MethodWhen to UseCostDepth
Security Questionnaire (SSQ)All suppliersLowMedium
External Security RatingAll suppliers for baseline; Critical for continuous monitoringMediumMedium (external telemetry)
On-site AuditCritical suppliers; high-risk suppliers with poor SSQHighHigh
Virtual Audit / Video WalkthroughHigh suppliers; remote suppliers; pandemic/travel constraintsMediumMedium-High
Third-Party Certification ReviewAll certified suppliersLow (request report)Medium (trust but verify)
Penetration Test of SupplierCritical suppliers handling highly sensitive dataVery HighVery High
Financial and Background CheckCritical suppliers; suppliers with physical accessMediumLow-Medium (business risk)

Step 4: Contractual Security Requirements, Put It in Writing

Security requirements that are not in the contract are not enforceable. Every supplier contract must include a security addendum or embedded security clauses.

Mandatory Contract Clauses for Critical/High Suppliers:

ClauseMinimum RequirementPurpose
1. Security Standard ComplianceSupplier must comply with ISO 27001 or equivalent; maintain certification; notify of certification lapsesBaseline security assurance
2. Data ProtectionEncryption at rest and in transit (TLS 1.2 or later; 1.3 preferred); data minimization; purpose limitation; no unauthorized processingData confidentiality and integrity
3. Data LocationData stored and processed only in agreed locations; changes notified in advance; no transfer to countries restricted under DPDP s.16Client contracts, sector rules (e.g. RBI payment data storage in India), DPDP s.16
4. Access ControlMFA for all admin access; principle of least privilege; quarterly access reviews; no shared accountsPrevent unauthorized access
5. Incident NotificationNotify without delay and within 24 hours at most (sooner where your own deadlines are shorter, e.g. CERT-In's 6 hours); provide detailed incident report within 72 hours; cooperate with investigationTimely incident response
6. Right to AuditOrganization may audit supplier's security controls annually with 30 days' notice; supplier must cooperate and provide evidenceVerification of compliance
7. Subcontractor Disclosure and ControlSupplier must disclose all subcontractors; subcontractor must meet same security standards; supplier remains liable for subcontractor breachesFourth-party risk management
8. Change ManagementSupplier must notify of material changes (location, personnel, technology, subcontractors) 30 days in advance; organization may reassessRisk control during relationship
9. Vulnerability ManagementSupplier must patch Critical vulnerabilities within 7 days; High within 30 days; annual penetration testingTechnical security maintenance
10. Business ContinuitySupplier must maintain BCP/DR plan with RTO and RPO agreed for the risk tier; annual DR test; evidence of backup restorationOperational resilience
11. Personnel SecurityBackground checks for personnel with access to organization data; security awareness training; confidentiality agreementsHuman risk mitigation
12. Data Return and DestructionReturn all data within 30 days of termination; certify destruction; allow verificationData lifecycle control
13. Access RevocationRevoke all access within 24 hours of termination; return all credentials, devices, and materialsImmediate risk removal
14. Liability and InsuranceSupplier must maintain cyber insurance (amount set by risk tier); liability for breaches caused by supplier negligence; indemnificationFinancial risk transfer
15. Termination for Security CauseOrganization may terminate immediately for material security breach; pro-rata refund if applicableEnforcement mechanism

Clause Library by Supplier Type:

Supplier TypeAdditional Clauses
Cloud/SaaSSOC 2 Type II report; data portability; API security; multi-tenant isolation; customer data segregation
Software DevelopmentSecure development lifecycle (SDL); source code escrow; IP ownership; no open-source with viral licenses; security testing before delivery
Data ProcessorDPIA cooperation (where required); Data Principal rights support; breach notification to you without delay (you notify the Data Protection Board); processing records
Professional ServicesConfidentiality of client data; no use of data for AI training; return of all work product; conflict of interest disclosure
Facilities/PhysicalBackground checks; no photography in secure areas; visitor escort; incident reporting; key/card return
Logistics/CourierChain of custody; tamper-evident packaging; GPS tracking; no subcontracting without approval; incident reporting
Managed Security ServicesSOC 2 Type II; 24/7 monitoring; SLA for detection and response; dedicated CISO contact; threat intelligence sharing

Step 5: Supplier Monitoring, Trust but Verify

Signing a contract with security clauses is not enough. You must monitor the supplier's ongoing compliance.

Monitoring Methods by Tier:

TierFrequencyMethodsEvidence
CriticalMonthlySecurity metrics review; vulnerability scan of supplier-facing assets; log review; quarterly business review (QBR) with security agenda; annual on-site auditQBR minutes; scan reports; audit reports; metrics dashboard
HighQuarterlySSQ refresh; security news alert monitoring; certificate validity check; semi-annual review meetingUpdated SSQ; news alerts; certificate checks; meeting minutes
MediumBi-annuallySSQ refresh; incident inquiry; ad-hoc monitoring for major security newsSSQ; incident records; news alerts
LowAnnuallyLight SSQ or attestation; incident-driven inquiryAttestation letter; incident records

Continuous Monitoring Techniques:

  1. Security Rating Services: BitSight, SecurityScorecard, UpGuard, or Panorays provide daily security ratings based on external telemetry (open ports, malware, SSL certificates, breach history). Use for all Critical and High suppliers.

  2. Certificate Monitoring: Track ISO 27001, SOC 2, PCI DSS certification expiry dates. Set alerts 90 days before expiry.

  3. Security News Monitoring: Google Alerts, Feedly, or vendor-specific threat intelligence for supplier breach news. A supplier breach may expose your data even if they don't notify you proactively.

  4. Log Monitoring: If suppliers have VPN or system access, monitor their access logs for anomalies: unusual hours, geolocation changes, excessive data download, privilege escalation.

  5. Vulnerability Scanning: Scan supplier-facing assets (APIs, portals, integrations) for vulnerabilities. If their infrastructure is weak, your connection is at risk.

  6. Dark Web Monitoring: Monitor for leaked credentials, data, or intellectual property related to your supplier relationships.

  7. Quarterly Business Reviews (QBR): For Critical suppliers, include a standing security agenda: incident review, patch status, access review, certification status, subcontractor changes.

Step 6: Supplier Audit, See for Yourself

Audit Planning:

ElementCritical SupplierHigh Supplier
FrequencyAnnualEvery 2 years
Notice30 days30 days
Duration2-3 days1 day
ScopeFull ISMS review; technical controls; personnel; physical; subcontractorsKey controls; data protection; access control; incident management
TeamInternal auditor + security architect + compliance officerInternal auditor + security analyst
Follow-upCAP for findings; re-audit in 6 months if major findingsCAP for findings; evidence review in 3 months

Audit Checklist (Critical Supplier):

#AreaAudit QuestionsEvidence
1GovernanceIs there a documented security policy? Approved by management?Policy document, approval record
2GovernanceIs there a security organization chart? Roles defined?Org chart, job descriptions
3RiskIs there a risk register? Last updated? Methodology?Risk register, methodology doc
4AccessIs MFA enforced for all admin access?Configuration screenshot, policy
5AccessWhen was the last access review? Findings?Access review report, minutes
6DataIs data encrypted at rest? Algorithm? Key management?Configuration, encryption policy
7DataIs data encrypted in transit? TLS version?SSL Labs scan, configuration
8IncidentIs there an incident response plan? Tested?IR plan, test records
9IncidentWhat incidents occurred in the last 12 months?Incident log (sanitized)
10BC/DRWhat is the RTO/RPO? Last DR test?BCP, DR test report
11SubcontractorsList all subcontractors. Assessments available?Subcontractor list, assessments
12PersonnelBackground checks for staff with access?Sample background check records
13PhysicalSecure area for our data? Access control?Site walkthrough, photos
14TechnicalVulnerability scan results? Pen test results?Scan report, pen test report
15ComplianceISO 27001 certificate? SOC 2 report? Audit findings?Certificates, reports, CARs

Step 7: Incident Management with Suppliers

Supplier Incident Response Protocol:

  1. Detection: Your SOC detects anomalous activity from a supplier account, or you receive a supplier breach notification, or you read about a supplier breach in the news.

  2. Notification Verification: Contact the supplier's security team immediately. Verify the scope: what data, what systems, what timeframe, what is the root cause.

  3. Impact Assessment: Determine if your data, systems, or customers are affected. Classify the incident internally per your incident response plan.

  4. Containment:

    • Disable supplier accounts if compromise is confirmed
    • Revoke API keys, certificates, or VPN access
    • Isolate supplier-connected systems if necessary
    • Engage the supplier's incident response team for joint containment
  5. Eradication: Work with the supplier to ensure the root cause is fixed. Require evidence of remediation before re-enabling access.

  6. Recovery: Re-enable access under heightened monitoring. Conduct a security review of the supplier's improved controls.

  7. Post-Incident:

    • Update the supplier risk assessment
    • Consider contract termination if the breach was due to gross negligence
    • Update your incident response playbook with lessons learned
    • Notify authorities where required: CERT-In within 6 hours of noticing a reportable incident; RBI-regulated entities report cyber incidents to RBI within 2 to 6 hours; under the DPDP Rules, intimate the Data Protection Board and affected people without delay, with a detailed report within 72 hours
    • Notify affected customers if personal data was compromised

Step 8: Change Management, When Suppliers Change

Supplier changes that must trigger a reassessment:

Change TypeRisk ImplicationAction Required
New subcontractorUnknown fourth-party riskRequire disclosure; conduct assessment; update contract
Change in data processing locationPossible breach of contract or sector location rules; DPDP s.16 if the new country is restrictedVerify new location compliance; update DPA; reassess
Change in key personnelLoss of institutional knowledge; new insider riskVerify background checks; update access; conduct handover
Change in technology stackNew vulnerabilities; integration risksArchitecture review; security testing; update monitoring
Merger or acquisitionNew entity; unknown security postureFull reassessment; contract novation; integration review
Certification lapseUnverified security claimsDemand immediate recertification or enhanced monitoring
Service scope expansionMore data, more access, more riskUpdate risk assessment; amend contract; additional controls

Step 9: Termination and Offboarding, Close Securely

Termination Triggers:

  • Contract natural expiry
  • Early termination for convenience
  • Termination for breach (including security breach)
  • Supplier insolvency or business closure
  • Service consolidation or replacement

Offboarding Checklist:

#TaskOwnerTimelineEvidence
1Notify supplier of termination (official)ProcurementDay 0Termination letter/email
2Revoke all system access (VPN, RDP, cloud, API, email)IT / SecurityDay 0Access revocation log
3Disable supplier accounts in all systemsIT / SecurityDay 0Account disablement log
4Change shared passwords/credentials if anyIT / SecurityDay 0Password change log
5Revoke physical access (ID cards, biometrics, keys)Facilities / SecurityDay 0Access revocation record
6Collect all company assets (laptops, devices, documents)IT / FacilitiesDay 1-7Asset return receipt
7Request return of all dataProcurement / Data OwnerDay 1-7Data transfer log
8Request certificate of data destructionProcurement / SecurityDay 14-30Destruction certificate
9Verify data destruction (sample audit if possible)Security / Internal AuditDay 30-45Verification report
10Remove supplier from monitoring and alert systemsSecurity OperationsDay 0Configuration change
11Update supplier inventory status to "Terminated"Vendor Risk ManagerDay 0Updated inventory
12Retain termination records for audit/evidenceVendor Risk ManagerPermanentArchive record
13Conduct post-termination review (lessons learned)Vendor Risk ManagerDay 30-45Lessons learned log
14Notify relevant stakeholders (legal, compliance, audit)ProcurementDay 0Communication log
15Update incident response plan (remove supplier references)Security OperationsDay 7Updated IR plan

Data Destruction Verification:

For Critical suppliers handling sensitive data, do not trust a self-signed certificate of destruction. Require:

  • Detailed destruction methodology (NIST 800-88 Clear, Purge, or Destroy)
  • Third-party attestation or audit of destruction
  • Sample verification (if contract allows, request proof for a sample of records)
  • Chain of custody documentation for data transfer before destruction

Tools, Technologies, and Solutions

Third-Party Risk Management (TPRM) Platforms

PlatformKey FeaturesBest For
Spreadsheet + shared mailboxSimple register, SSQs by email, review calendarFewer than about 30 suppliers
Archer (RSA)Enterprise GRC with TPRM module; deep customisationLarge enterprise; existing Archer GRC
MetricStreamGRC + TPRM; integrated risk management; regulatory mappingLarge enterprise; integrated GRC
OneTrust Third-Party RiskQuestionnaires, risk scoring, privacy integrationPrivacy-led programmes
ProcessUnity / Mitratech PrevalentVendor lifecycle workflow, assessments, monitoringMid-market to enterprise
ServiceNow Vendor Risk ManagementTPRM on the ServiceNow platformServiceNow customers
SecurityScorecard / BitSight / UpGuardExternal security ratingsContinuous outside-in monitoring

Contract and Procurement Tools

ToolPurposeIntegration with TPRM
IroncladContract lifecycle management; clause library; approval workflowsAPI integrations with TPRM platforms
DocuSign CLMContract management; e-signature; template managementIntegrations with Salesforce, GRC tools
IcertisEnterprise contract management; AI-powered clause extractionTPRM module available
Conga ContractsContract automation; template management; compliance trackingCRM and ERP integrations
Zoho Contracts (India)Affordable CLM for Indian SMEs; India-specific templatesZoho ecosystem integration

Discovery and Monitoring Tools

ToolPurpose
ProductivSaaS application discovery; usage analytics; renewal management
ToriiSaaS management; shadow IT discovery; spend optimization
NetskopeCloud access security broker (CASB); shadow IT discovery; DLP
Obsidian SecuritySaaS security; identity threat detection; configuration monitoring
Google Alerts / FeedlyFree security news monitoring for suppliers
Recorded Future / FlashpointThreat intelligence; supplier risk monitoring; dark web

Indian Market Considerations

ConsiderationGuidance
Data locationCheck where the TPRM platform stores supplier data and whether a client or sector rule restricts it
Local supportIndia-based support teams provide faster response and understand local regulatory context
Regional complianceIndian TPRM platforms often include RBI, SEBI, IRDAI, and DPDP compliance templates
LanguageSome platforms offer Hindi or regional language support for supplier communication

Policy and Procedure Templates

Supplier Security Policy (Template Outline)

1. Purpose and Scope
   1.1 Purpose: Define requirements for managing information security in all supplier relationships
   1.2 Scope: All suppliers with access to information, systems, or premises
   1.3 Applicability: All procurement, IT, security, facilities, and business teams

2. Roles and Responsibilities
   2.1 CISO: Accountable for supplier security framework; approves Critical supplier engagements
   2.2 Vendor Risk Manager: Responsible for TPRM program execution; assessments; monitoring; audits
   2.3 Procurement: Responsible for including security clauses in contracts; enforcing procurement process
   2.4 Legal: Responsible for contract security clause drafting; enforcement; termination
   2.5 IT / Security Operations: Responsible for supplier access provisioning; monitoring; revocation
   2.6 Data Owners: Responsible for defining data protection requirements for suppliers
   2.7 Business Units: Responsible for identifying and registering all suppliers

3. Supplier Classification and Risk Tiering
   3.1 Classification criteria (data, access, criticality, maturity, subcontractors)
   3.2 Four-tier system: Critical, High, Medium, Low
   3.3 Classification authority and review frequency

4. Supplier Security Assessment
   4.1 Timing: Before contract signing; periodic reassessment
   4.2 Methodology: SSQ + external ratings + audits
   4.3 Evaluation criteria and scoring
   4.4 Exception handling and risk acceptance

5. Contractual Security Requirements
   5.1 Mandatory clauses for each tier
   5.2 Data protection addendum requirements
   5.3 Subcontractor control clauses
   5.4 Right to audit and inspection
   5.5 Incident notification and response
   5.6 Termination and data return

6. Supplier Monitoring and Review
   6.1 Monitoring frequency by tier
   6.2 Continuous monitoring techniques
   6.3 Quarterly business review requirements
   6.4 Security news and alert monitoring

7. Supplier Audit Program
   7.1 Audit frequency by tier
   7.2 Audit planning and notification
   7.3 Audit scope and checklist
   7.4 Finding remediation and follow-up

8. Supplier Change Management
   8.1 Changes requiring notification
   8.2 Reassessment triggers
   8.3 Contract amendment process

9. Supplier Incident Management
   9.1 Incident notification requirements
   9.2 Joint response protocol
   9.3 Root cause analysis and remediation
   9.4 Contract termination for security cause

10. Supplier Termination and Offboarding
    10.1 Termination triggers
    10.2 Offboarding checklist and timeline
    10.3 Data return and destruction verification
    10.4 Access revocation procedures
    10.5 Post-termination review

11. Subcontractor and Fourth-Party Risk
    11.1 Disclosure requirements
    11.2 Assessment obligations
    11.3 Liability and control

12. Training and Awareness
    12.1 Procurement training on security clauses
    12.2 Business unit training on supplier registration
    12.3 Security team training on TPRM

13. Compliance and Audit
    13.1 Internal audit requirements
    13.2 Evidence retention
    13.3 Non-conformance handling

14. Policy Review
    14.1 Annual review cycle
    14.2 Trigger-based review (incident, regulation, breach)

Supplier Security Procedure (Template Outline)

Procedure: SUP-SEC-001 Supplier Security Management Lifecycle

1. Supplier Identification and Registration
   Step 1: Business unit identifies supplier need
   Step 2: Procurement requests supplier registration
   Step 3: Supplier completes registration form with access and data details
   Step 4: Supplier added to inventory with unique ID
   Step 5: Initial classification (Low default until assessment)

2. Pre-Engagement Assessment
   Step 6: Vendor Risk Manager classifies supplier based on registration data
   Step 7: For Critical/High: Full SSQ + external rating + certification review
   Step 8: For Medium: Standard SSQ + certification review
   Step 9: For Low: Light attestation or certification check
   Step 10: Risk assessment completed and scored
   Step 11: Risk treatment plan defined if gaps exist
   Step 12: Security approval obtained before contract

3. Contracting
   Step 13: Legal includes security clauses based on tier
   Step 14: Data Owner confirms data protection requirements
   Step 15: CISO approves Critical/High supplier contracts
   Step 16: Contract signed and archived with security addendum

4. Onboarding and Access Provisioning
   Step 17: IT provisions access per least privilege principle
   Step 18: MFA enforced for all logical access
   Step 19: Physical access provisioned (if applicable) with escort/area restrictions
   Step 20: Supplier personnel complete security awareness training
   Step 21: Supplier added to monitoring and alert systems

5. Ongoing Monitoring
   Step 22: Monthly QBR for Critical suppliers (security agenda)
   Step 23: Quarterly review for High suppliers
   Step 24: Bi-annual review for Medium suppliers
   Step 25: Annual light review for Low suppliers
   Step 26: Continuous monitoring via security ratings and news alerts
   Step 27: Access reviews quarterly for Critical/High suppliers

6. Audit
   Step 28: Annual on-site audit for Critical suppliers
   Step 29: Bi-annual virtual audit for High suppliers
   Step 30: Audit findings documented; CAP issued; follow-up scheduled

7. Change Management
   Step 31: Supplier notifies of material change
   Step 32: Vendor Risk Manager evaluates change impact
   Step 33: Reassessment conducted if required
   Step 34: Contract amended if required
   Step 35: Updated monitoring scope applied

8. Incident Response
   Step 36: Incident detected or reported by supplier
   Step 37: Impact assessment conducted
   Step 38: Containment actions executed (access revocation if needed)
   Step 39: Joint investigation with supplier
   Step 40: Root cause analysis and remediation verification
   Step 41: Risk assessment updated; contract termination considered if negligence

9. Termination and Offboarding
   Step 42: Termination triggered (expiry, convenience, breach)
   Step 43: Termination notice issued
   Step 44: All access revoked within 24 hours
   Step 45: Data return requested and verified
   Step 46: Destruction certificate obtained and verified
   Step 47: Assets collected and accounted for
   Step 48: Supplier removed from inventory and monitoring
   Step 49: Lessons learned captured

Supplier Security Questionnaire (SSQ) Template (Excerpt)

SUPPLIER SECURITY QUESTIONNAIRE
Supplier Name: _________________________
Assessment Date: _________________________
Assessed By: _________________________
Risk Tier: _________________________

SECTION A: GOVERNANCE AND POLICY (10 points)
A1. Do you have a documented information security policy?
    □ Yes, approved by management, reviewed annually
    □ Yes, but not reviewed recently
    □ No
A2. Do you have a dedicated security function or CISO?
    □ Yes, full-time CISO or security team
    □ Yes, part-time or outsourced
    □ No
A3. Have you achieved any of the following certifications?
    □ ISO 27001 (current) — provide certificate
    □ SOC 2 Type II (current) — provide report
    □ PCI DSS (if applicable) — provide AOC
    □ None

SECTION B: ACCESS CONTROL (15 points)
B1. Do you enforce Multi-Factor Authentication (MFA) for all administrative access?
    □ Yes, for all admin accounts
    □ Yes, for some admin accounts
    □ No
B2. How frequently do you review user access rights?
    □ Quarterly or more frequently
    □ Annually
    □ Ad-hoc or never
B3. Do you maintain a principle of least privilege for all users?
    □ Yes, enforced and audited
    □ Yes, but not formally audited
    □ No

SECTION C: DATA PROTECTION (20 points)
C1. Is our data encrypted at rest? Algorithm?
    □ AES-256 or equivalent
    □ AES-128 or equivalent
    □ No encryption
C2. Is our data encrypted in transit? Protocol?
    □ TLS 1.3 or equivalent
    □ TLS 1.2
    □ Unencrypted or TLS 1.0/1.1
C3. Do you have a data retention and destruction policy?
    □ Yes, documented and enforced
    □ Yes, but not enforced
    □ No

SECTION D: INCIDENT MANAGEMENT (15 points)
D1. Do you have an incident response plan?
    □ Yes, documented, tested, and maintained
    □ Yes, but not tested
    □ No
D2. What is your incident notification timeframe to customers?
    □ Within 24 hours
    □ Within 72 hours
    □ Within 1 week
    □ No defined timeframe
D3. How many security incidents did you experience in the last 12 months?
    □ 0
    □ 1-2
    □ 3-5
    □ More than 5

SECTION E: BUSINESS CONTINUITY (10 points)
E1. What is your Recovery Time Objective (RTO)?
    □ < 4 hours
    □ < 24 hours
    □ < 72 hours
    □ > 72 hours or no RTO
E2. When was your last disaster recovery test?
    □ Within 6 months
    □ Within 12 months
    □ > 12 months ago
    □ Never

SECTION F: SUBCONTRACTORS (10 points)
F1. Do you use subcontractors for services related to our data?
    □ No
    □ Yes — list attached
    □ Yes — but not disclosed
F2. Do you assess your subcontractors' security?
    □ Yes, same standard as our own
    □ Yes, but less rigorously
    □ No

SECTION G: COMPLIANCE AND AUDIT (10 points)
G1. When was your last external security audit?
    □ Within 12 months
    □ Within 24 months
    □ > 24 months ago
    □ Never
G2. Are you willing to provide audit reports or undergo our audit?
    □ Yes, fully cooperative
    □ Yes, with restrictions
    □ No

SECTION H: REGULATORY (10 points)
H1. Are you familiar with the Digital Personal Data Protection Act 2023 (India)?
    □ Yes, and we comply
    □ Yes, but not fully compliant
    □ No
H2. Can you store and process all our data within India?
    □ Yes
    □ Yes, with some exceptions (specify)
    □ No

SCORING:
Total Score: ___ / 100
Rating: □ Excellent (90-100) □ Good (70-89) □ Fair (50-69) □ Poor (30-49) □ Unacceptable (<30)

Risk Assessment and Treatment

Supplier Risk Assessment Methodology

Step 1: Inherent Risk Assessment

Inherent risk is the risk before considering the supplier's controls. It is determined by what the supplier does, not how well they do it.

FactorScoreRationale
Data sensitivity1-5What data will the supplier access?
System access1-5What level of access to your systems?
Business criticality1-5How important is the service to operations?
Supplier location1-5Geographic risk (sanctions, data residency, cybercrime rate)
Subcontractor complexity1-5How many layers of subcontractors?
Inherent Risk ScoreSum of above5-25 scale

Step 2: Control Effectiveness Assessment

Evaluate the supplier's security controls based on SSQ, certifications, and external ratings.

Control AreaWeightSupplier Score (1-5)Weighted Score
Governance and policy15%______
Access control20%______
Data protection25%______
Incident management10%______
Business continuity10%______
Subcontractor management10%______
Compliance and audit10%______
Control Effectiveness Score100%___ / 5

Step 3: Residual Risk Calculation

Residual Risk = Inherent Risk × (1 - Control Effectiveness/5)
Residual Risk ScoreRisk LevelAction
>15CriticalDo not engage unless no alternative; board-level risk acceptance; enhanced monitoring; contract termination clause
10-15HighConditional engagement with mandatory remediation; quarterly monitoring; annual audit
5-9MediumStandard engagement with standard monitoring; biennial review
<5LowStandard engagement with lightweight monitoring; triennial review

Sample Supplier Risk Register

Supplier IDSupplier NameCategoryInherent RiskControl ScoreResidual RiskTierTreatmentStatus
SUP-001CloudServe IndiaCloud Hosting204.23.2CriticalStandard + enhanced monitoringActive
SUP-002DevTech SolutionsSoftware Dev183.07.2HighConditional + remediation planActive
SUP-003PaySecure GatewayPayment Processing224.52.4CriticalStandard + PCI DSS validationActive
SUP-004CleanPro ServicesFacilities82.54.0MediumStandardActive
SUP-005MarketBoost AgencyMarketing123.54.2MediumStandardActive
SUP-006GlobalLogisticsCourier102.06.0HighConditional + access restrictionActive
SUP-007OffshoreDev LtdDevelopment201.514.0CriticalTermination plannedTerminating
SUP-008BackupVaultData Backup164.03.2HighStandard + encryption verificationActive
SUP-009TaxConsult PartnersProfessional Services103.04.0MediumStandardActive
SUP-010TempStaff AgencyStaffing122.56.0HighConditional + background checksActive

Risk Treatment Options

TreatmentWhen to UseExampleCost
AvoidHigh inherent risk with no compensating valueDo not engage OffshoreDev Ltd due to unacceptable securityOpportunity cost
MitigateSupplier has potential but gaps existRequire DevTech to implement MFA, SAST, and annual pen testSupplier effort; follow-up
AcceptLow residual risk; cost of treatment exceeds benefitAccept CleanPro's medium risk with standard monitoringMonitoring cost only
ShareRisk cannot be fully mitigated, or is jointly heldCyber insurance; liability caps and indemnities; co-developed controls in partnershipsInsurance premium; legal cost

Audit and Compliance Checklist

Use this checklist during internal audits, certification audits, and customer audits. Each question should be answered with evidence.

Policy and Governance (5 questions)

#Audit QuestionEvidence RequiredPass Criteria
1Is there a documented policy for managing information security in supplier relationships?Policy document, version controlled, approvedPolicy exists; covers all supplier types; approved within 12 months
2Does the policy define roles and responsibilities for supplier security management?Policy section or RACI matrixRoles defined for procurement, security, legal, IT, business units
3Is there a complete inventory of all suppliers with access to information/systems/premises?Supplier inventory; procurement records; access logsInventory complete; no shadow suppliers; includes subcontractors
4Are suppliers classified by risk tier (Critical, High, Medium, Low)?Classification records; risk scoring methodologyAll suppliers classified; methodology documented; review frequency defined
5Does senior management review supplier security performance?Meeting minutes; dashboard reports; management review recordsAt least quarterly review for Critical suppliers; actions documented

Risk Assessment and Contracting (6 questions)

#Audit QuestionEvidence RequiredPass Criteria
6Is a security risk assessment conducted before engaging new suppliers?Risk assessment records for new suppliers100% of sampled new suppliers have pre-engagement assessment
7Are security requirements included in all supplier contracts?Contract samples; clause library; redlined contractsSecurity clauses in 100% of sampled contracts; clause library exists
8Do contracts include data protection requirements (encryption, residency, DPA)?Contract addenda; DPA templatesDPA for all personal data processors; encryption requirements present
9Do contracts include incident notification requirements (timeframe, contact, cooperation)?Contract clauses; incident response recordsNotification clause in 100% of contracts; SLA defined (≤24 hours for Critical)
10Do contracts include right to audit and inspect supplier controls?Audit clause in contracts; audit recordsAudit clause in Critical/High contracts; audits conducted per schedule
11Do contracts include termination and data return/destruction clauses?Termination clauses; offboarding recordsData return clause in 100% of contracts; destruction verification evidenced

Monitoring and Audit (6 questions)

#Audit QuestionEvidence RequiredPass Criteria
12Is there a defined monitoring frequency for each supplier tier?Monitoring schedule; calendar recordsSchedule exists; aligns with tier definitions; executed as planned
13Are Critical suppliers monitored at least quarterly?QBR minutes; monitoring reports; metric reviewsEvidence of quarterly reviews for all Critical suppliers
14Are security ratings or external assessments used for continuous monitoring?Security rating platform subscription; rating reportsPlatform in use for Critical/High; ratings reviewed; alerts acted upon
15Are supplier security incidents monitored and tracked?Incident log; supplier incident records; tracking systemSupplier incidents logged; impact assessed; corrective actions tracked
16Are on-site or virtual audits conducted for Critical/High suppliers?Audit plan; audit reports; CAPs; follow-up recordsCritical: annual audit; High: biennial audit; evidence of execution
17Are supplier access rights reviewed periodically?Access review records; IAM logsQuarterly for Critical/High; evidence of review and remediation

Change and Incident Management (5 questions)

#Audit QuestionEvidence RequiredPass Criteria
18Are suppliers required to notify of material changes (subcontractors, location, technology)?Change notification records; contract clausesNotification clause exists; changes tracked; reassessments triggered
19Is there a joint incident response protocol with Critical suppliers?IR plan; joint response records; contact listsProtocol documented; tested at least annually; contacts current
20Are supplier-caused incidents investigated and root cause analyzed?Incident reports; RCA documents; supplier CARsInvestigations conducted; supplier accountability enforced; CAPs tracked
21Can the organization terminate supplier relationships for security cause?Contract clauses; termination recordsTermination for security cause clause exists; executed if needed
22Are supplier incidents reported to regulators when required?Regulatory filings; incident notification recordsDPDP 72-hour notification; RBI 6-hour for payment; evidence of compliance

Termination and Offboarding (5 questions)

#Audit QuestionEvidence RequiredPass Criteria
23Is there a documented offboarding procedure for suppliers?Offboarding procedure; checklists; workflowProcedure documented; covers access, data, assets, monitoring
24Is all supplier access revoked within 24 hours of termination?Access revocation logs; IAM records100% of sampled terminations: access revoked within 24 hours
25Is data returned or destroyed upon termination, with verification?Data return log; destruction certificate; verification evidenceReturn/destruction evidenced; certificate obtained; verification conducted for Critical
26Are supplier termination records retained for audit purposes?Archive records; retention policyRetained per the retention schedule; accessible for audit
27Are lessons learned from supplier incidents and terminations captured?Lessons learned log; knowledge base updatesCaptured within 30 days; fed into policy/template updates

Subcontractor and Fourth-Party Risk (3 questions)

#Audit QuestionEvidence RequiredPass Criteria
28Are all subcontractors disclosed by primary suppliers?Subcontractor lists; contract clauses; disclosure recordsDisclosure clause in contracts; lists obtained for Critical/High
29Are subcontractors assessed for security risk?Subcontractor assessments; risk registersAssessments conducted for subcontractors of Critical suppliers
30Does the primary supplier remain liable for subcontractor security breaches?Contractual liability clauses; incident recordsLiability clause in 100% of contracts; enforced in incidents

Metrics and KPIs

Supplier Security KPIs

KPI IDKPI NameFormulaTargetMeasurement FrequencyData Source
KPI-01Supplier Inventory Coverage(Suppliers in inventory / Total known suppliers) × 100100%MonthlyInventory vs. finance/AP records
KPI-02Risk Assessment Completion(Suppliers with completed risk assessment / Total active suppliers) × 100100%MonthlyRisk register
KPI-03Critical Supplier Assessment Rate(Critical suppliers with current assessment / Total Critical suppliers) × 100100%MonthlyRisk register
KPI-04Security Clause Coverage(Contracts with security clauses / Total active contracts) × 100100%QuarterlyContract review sample
KPI-05Audit Execution Rate(Audits completed per plan / Audits planned) × 100100%QuarterlyAudit calendar
KPI-06Supplier Incident CountNumber of security incidents caused by or involving suppliers0 for Critical; trend downwardMonthlyIncident management system
KPI-07Incident Notification Compliance(Supplier incidents notified within SLA / Total supplier incidents) × 100100%Per incidentIncident records
KPI-08Access Review Completion(Supplier access reviews completed on schedule / Total scheduled reviews) × 100100%QuarterlyAccess review records
KPI-09Termination Offboarding Compliance(Terminations with complete offboarding / Total terminations) × 100100%Per terminationOffboarding records
KPI-10Security Rating TrendAverage security rating of Critical suppliers (month-over-month)Improving or stableMonthlySecurity rating platform
KPI-11Shadow Supplier DiscoveryNumber of unregistered suppliers discovered per month0MonthlyDiscovery process
KPI-12DPA Coverage for Data Processors(Data processors with signed DPA / Total data processors) × 100100%QuarterlyContract review
KPI-13Supplier Change Notification Compliance(Supplier changes notified per contract / Total observed changes) × 100>90%QuarterlyChange records
KPI-14Subcontractor Disclosure Rate(Critical suppliers with disclosed subcontractors / Total Critical suppliers) × 100100%QuarterlySubcontractor lists
KPI-15Supplier Security Training Completion(Procurement staff completing supplier security training / Total procurement staff) × 100100%AnnualTraining records

KPI Dashboard Layout

SUPPLIER SECURITY DASHBOARD — June 2026
========================================

Active Suppliers: 187
Critical: 12 | High: 34 | Medium: 78 | Low: 63
New This Month: 5 | Terminated This Month: 2

COVERAGE METRICS
- Inventory Coverage: 100% (187/187) ✓
- Risk Assessment Completion: 98% (183/187) ⚠️
- Security Clause Coverage: 97% (181/187) ⚠️
- DPA Coverage: 100% (45/45) ✓

QUALITY METRICS
- Audit Execution Rate: 100% (8/8) ✓
- Access Review Completion: 100% (46/46) ✓
- Offboarding Compliance: 100% (2/2) ✓

RISK METRICS
- Supplier Incidents (MTD): 1 (Medium severity, contained) ⚠️
- Security Rating Trend: Stable (avg 78/100)
- Shadow Suppliers Discovered: 0 ✓

ACTIONS
1. Complete risk assessment for 4 pending Medium suppliers (SUP-184 to SUP-187)
2. Renegotiate security clauses with 6 suppliers missing data residency terms
3. Schedule Q3 audit for SUP-012 (CloudServe India) — certificate expiry approaching

Common Pitfalls and How to Avoid Them

The 15 Most Common Pitfalls

#PitfallWhy It HappensImpactHow to Avoid
1No supplier inventoryProcurement and IT do not coordinate; shadow IT proliferatesUnknown risk exposure; audit failureMandatory registration process; finance cross-check; SaaS discovery tools
2Generic security clauses in all contractsLegal uses one template for all vendorsInadequate protection for Critical suppliers; unenforceable termsTiered clause library; Critical/High get full clauses; Low gets lightweight
3No pre-engagement assessmentBusiness urgency; "we need them now"Engaging high-risk suppliers without knowing itSecurity approval gate before contract signature; no exceptions for Critical
4Assessment never revisited after initial engagement"We assessed them last year; they must be fine"Supplier security degrades; certifications lapse; incidents missedCalendar-driven reassessment; expiry alerts; continuous monitoring
5No monitoring of supplier security newsNo process to track supplier breachesBreach discovered months late; customer data already leakedGoogle Alerts; security rating platform; threat intelligence feed
6Subcontractors ignoredPrimary supplier does not disclose; organization does not askFourth-party risk is invisible; major breach vectorMandatory disclosure clause; request subcontractor lists; assessment for Critical
7Access not revoked promptly on terminationHR/procurement delays; IT not informed; "we might need them again"Former supplier retains access; data exposure; audit failureAutomated offboarding workflow; 24-hour SLA; checklist with sign-offs
8Data left with supplier after terminationNo data return requirement; no verificationSupplier retains your data indefinitely; DPDP violationData return clause; destruction certificate; sample verification
9Supplier incidents not investigated"It's their problem, not ours"Recurrence; liability; regulatory penaltyJoint investigation protocol; root cause analysis; contract enforcement
10No right to audit exercisedAudit clause exists but never used; "we trust them"Unverified security claims; false assuranceAnnual audit calendar; budget for audits; treat as non-negotiable
11Over-reliance on certifications"They have ISO 27001, so they're secure"Certification does not mean perfect security; scope may not cover your dataTrust but verify; certification + SSQ + monitoring + audit
12Small suppliers exempted"They're too small to matter"Small vendors are often the weakest link; used as attack vectorAll suppliers assessed; lightweight process for Low tier; no exemptions
13Physical security suppliers ignoredFocus on IT; cleaning/security guards "not technical"Physical theft; dumpster diving; tailgating; device accessInclude facilities suppliers in inventory; background checks; physical access controls
14No integration between procurement and securityProcurement buys; security finds out laterSecurity as afterthought; renegotiation cost; delaysSecurity approval workflow in procurement system; security checkpoint before PO
15DPDP Act requirements ignored in supplier contractsLegal unaware of DPDP; "we'll add it later"Regulatory violation; fine exposure; customer trust lossDPDP clause library; legal training; mandatory DPA for all personal data processors

Illustrative Scenarios

Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.

Illustrative Scenario 1: Indian Growing SaaS Company, Building TPRM from Scratch

Organization: CloudCraft Solutions Pvt. Ltd., a Hyderabad-based SaaS company with 320 employees, providing project management software to 4,000+ SMB customers in India and Southeast Asia.

Challenge:

  • 85 active suppliers, but no formal inventory; estimated 30+ shadow suppliers
  • Preparing for first SOC 2 Type II audit and ISO 27001 certification
  • No security clauses in 60% of contracts
  • Customer audit from a large enterprise client identified supplier security gaps
  • Budget: for TPRM program setup

Implementation Steps:

Step 1, Supplier Discovery (Week 1): The consultant conducted a complete discovery:

  • Finance record analysis: 87 paid vendors in last 12 months
  • IT access log analysis: 23 external accounts with system access
  • Cloud IAM analysis: 12 external IAM users in AWS
  • Department survey: 15 additional suppliers not in finance records
  • Total discovered: 107 suppliers (22 more than initially known)

Step 2, Classification and Tiering (Week 2): Using the risk framework:

  • Critical: 8 (cloud hosting, payment gateway, core development vendor, customer support BPO)
  • High: 18 (CRM, email, backup, legal, accounting, major IT consultants)
  • Medium: 35 (marketing tools, recruitment, training, minor consultants)
  • Low: 46 (office supplies, couriers, travel, minor services)

Step 3, Policy and Templates (Week 3): The consultant delivered:

  • Supplier Security Policy (aligned with DPDP Act 2023, SOC 2, and ISO 27001)
  • Tiered contract clause library (Critical: 15 clauses; High: 12 clauses; Medium: 8 clauses; Low: 4 clauses)
  • Standard Supplier Security Questionnaire (SSQ) with 80 questions across 8 domains
  • Offboarding checklist with 15 tasks and evidence requirements

Step 4, Critical Supplier Assessment (Weeks 4-5): All 8 Critical suppliers assessed:

  • Cloud hosting provider (Provider A): ISO 27001 + SOC 2; score 94/100, Excellent
  • Payment gateway (Provider B): PCI DSS Level 1; score 91/100, Excellent
  • Core development vendor (Bengaluru ODC): No ISO 27001; score 58/100, Fair
  • Customer support BPO (Chennai): No certifications; score 45/100, Poor
  • Backup provider: ISO 27001; score 88/100, Good
  • Email/SaaS provider (Provider C): SOC 2; score 95/100, Excellent
  • CDN/WAF provider (Provider D): SOC 2; score 92/100, Excellent
  • Penetration testing vendor (Provider E): ISO 27001; score 89/100, Good

Step 5, Remediation and Contract Amendments (Weeks 6-8):

  • Core development vendor: Required to achieve ISO 27001 within 12 months; interim: enhanced monitoring, quarterly SSQ, mandatory SAST/DAST on all deliverables, secure coding training for 20 developers. Contract amended with security addendum and a higher liability cap cap.
  • Customer support BPO: Required to implement MFA, quarterly access reviews, incident notification within 24 hours, and annual pen test. Contract amended with security milestones and right to audit. Score improved to 68/100 within 6 months.
  • All 8 Critical suppliers: Contract amendments signed with new security clauses.
  • High suppliers: Batch contract review; 14 of 18 amended successfully; 4 in negotiation.

Step 6, Monitoring Setup (Week 9):

  • Subscribed to SecurityScorecard for 8 Critical + 10 High suppliers
  • Configured Google Alerts for all 107 suppliers
  • Quarterly Business Review (QBR) calendar established for Critical suppliers
  • Access review calendar: quarterly for Critical/High; bi-annual for Medium

Step 7, Offboarding Test (Week 10): Tested offboarding with 1 departing Low supplier:

  • Access revoked in 4 hours (exceeded 24-hour target)
  • Data return: 500 GB of backup logs transferred and verified
  • Destruction certificate obtained
  • Lessons learned: improve asset collection process for remote suppliers

Step 8, Training and Rollout (Week 11):

  • Procurement team trained on security clause library and approval workflow (4 hours)
  • IT team trained on access provisioning and revocation procedures (2 hours)
  • Business unit heads trained on supplier registration requirement (1 hour)
  • Policy communicated to all 107 suppliers via email with acknowledgment request

Outcome:

  • SOC 2 Type II audit (Month 6): zero exceptions in the vendor management trust services criteria
  • ISO 27001 Stage 2 audit (Month 8): zero major non-conformities in A.5.19; one minor (missing access review for 1 Medium supplier, fixed in 48 hours)
  • Customer audit from large enterprise client: passed with commendation for "mature TPRM for company size"
  • Supplier security incidents in first 12 months: 1 (supplier phishing attempt; contained within 2 hours due to monitoring)
  • Core development vendor achieved ISO 27001 certification in Month 10
  • CloudCraft's TPRM program became a reference model for 3 peer companies in their Hyderabad tech cluster

Key Lessons:

  1. Growing SaaS companies can build effective TPRM in 10-12 weeks with focused effort and templates
  2. Shadow supplier discovery is critical, 20% of suppliers were invisible before the program
  3. Tiered contract clauses are essential, one-size-fits-all contracts leave gaps or create unnecessary burden
  4. Security rating platforms provide continuous visibility at reasonable cost for growing companies
  5. Customer audits are powerful motivators, use them to justify TPRM investment to management

Illustrative Scenario 2: Large Indian Enterprise Bank, Enterprise TPRM Transformation

Regulated by RBI under the Banking Regulation Act.

Challenge:

  • 2,400+ active suppliers across IT, facilities, professional services, BPO, ATM maintenance, cash logistics, and consulting
  • RBI's Master Direction on Outsourcing of Information Technology Services (2023) requires complete IT vendor risk management
  • 200+ Critical suppliers with access to core banking systems, payment networks, and customer data
  • Legacy TPRM process was manual, spreadsheet-based, and conducted annually, inadequate for current threat landscape
  • Multiple audit findings: inconsistent supplier assessments, missing security clauses, no continuous monitoring, delayed incident notification
  • Budget: for TPRM transformation over 18 months

Implementation Steps:

Step 1, Program Establishment (Months 1-2): The consultant established a dedicated Vendor Risk Management (VRM) function:

  • Hired Vendor Risk Manager (reporting to CISO)
  • 4 Vendor Risk Analysts (2 for Critical, 2 for High)
  • Governance: Monthly VRM Committee with CISO, CIO, CRO, Head of Procurement, and Head of Legal
  • Policy: Complete rewrite of Supplier Security Policy with RBI-specific requirements

Step 2, Enterprise Inventory and Discovery (Months 2-4):

  • Migrated from spreadsheets to a TPRM platform
  • Integrated with SAP Ariba (procurement) for automatic supplier registration
  • Integrated with Active Directory and VPN logs for access-based supplier discovery
  • Integrated with AWS, Azure, and GCP IAM for cloud-based supplier discovery
  • Final inventory: 2,847 suppliers (447 more than previously known)
  • Shadow supplier reduction: 78% of newly discovered suppliers registered within 60 days

Step 3, Risk Classification at Scale (Months 3-5):

  • Automated risk scoring based on: data sensitivity, system access, annual spend, certification status, location
  • Critical: 247 (up from 200 due to better visibility)
  • High: 512
  • Medium: 1,034
  • Low: 1,054

Step 4, Assessment Automation (Months 4-8):

  • Automated SSQ distribution via OneTrust to all 2,847 suppliers
  • 78% response rate within 30 days; follow-up for non-responders
  • External security ratings (BitSight) integrated for all Critical and High suppliers
  • Automated risk score calculation: inherent risk × control effectiveness
  • 312 suppliers flagged for remediation; 18 flagged for potential termination

Step 5, Contract Remediation at Scale (Months 6-12):

  • Legal team engaged in largest contract remediation effort in bank history
  • 2,100 contracts reviewed; 1,680 required amendment
  • Critical suppliers: 100% amended with full security addendum (15 clauses + RBI-specific requirements)
  • High suppliers: 85% amended; 15% in negotiation or replacement
  • New contract template: Security addendum is mandatory; no PO issued without security sign-off from VRM
  • Data location clause: payment system data stored only in India (RBI 2018 directive); location of other customer data agreed per contract and RBI outsourcing rules

Step 6, Continuous Monitoring (Months 8-14):

  • BitSight ratings reviewed daily for Critical; weekly for High
  • Automated alerts for: certification expiry, rating drop >20 points, breach news, dark web mentions
  • Monthly QBRs for all 247 Critical suppliers with standard security agenda
  • Quarterly access reviews for all Critical/High supplier accounts
  • Penetration testing of supplier-facing APIs and portals: quarterly

Step 7, Audit Program (Months 10-16):

  • 50 on-site audits conducted for Critical suppliers (ATM maintenance, cash logistics, core banking integrators, cloud providers)
  • 120 virtual audits conducted for High suppliers
  • Total audit findings: 340; 98% closed within 90 days; 2% escalated to contract termination
  • Subcontractor audits: 15 audits of subcontractor facilities (primarily offshore development centers and BPOs)

Step 8, Incident Response Integration (Months 12-16):

  • Joint incident response protocol established with top 20 Critical suppliers
  • 24/7 security contact matrix with escalation paths
  • Supplier incident tabletop exercise: conducted quarterly with 3 suppliers rotating per quarter
  • Actual incident during Month 14: BPO supplier detected unauthorized access attempt; notified BNB within 4 hours; joint containment within 2 hours; no data exposure; supplier's access suspended for 48 hours pending investigation; root cause: supplier employee credential phishing; supplier enhanced MFA and training; relationship continued with enhanced monitoring

Step 9, Termination and Offboarding Hardening (Months 14-16):

  • Automated offboarding workflow in ServiceNow: termination trigger → access revocation tickets → data return tracking → certificate verification
  • 12 suppliers terminated during program (security cause: 3; business: 9)
  • Average offboarding time: 18 hours for access revocation; 14 days for data return/destruction
  • 100% of terminations completed with full evidence package

Step 10, Regulatory Compliance and Certification (Months 16-18):

  • RBI inspection (Month 17): VRM programme reviewed; no adverse findings on vendor risk management
  • ISO 27001 surveillance audit (Month 18): zero non-conformities in A.5.19 to A.5.22
  • Internal audit: VRM program maturity rated Level 4 (Managed) on the CMMI scale

Outcome:

  • Supplier security incidents: 3 in 18 months (all detected and contained within 4 hours due to monitoring)
  • Audit findings pre-program: 47 annually; post-program: 3 annually (93% reduction)
  • Customer trust: 2 major enterprise clients renewed contracts citing "strong supplier security governance" as a factor

Key Lessons:

  1. Enterprise TPRM requires dedicated technology, manual spreadsheets do not scale beyond 100 suppliers
  2. Procurement system integration is essential for preventing shadow suppliers and enforcing security gates
  3. RBI-regulated banks must go beyond ISO 27001 minimums; regulator expectations are higher than standard
  4. Subcontractor audits are non-negotiable for Critical suppliers in BFSI, 15% of audit findings were in subcontractor facilities
  5. Automated offboarding is critical at scale, manual processes fail under volume and time pressure
  6. The investment in TPRM is small compared with the cost of a single supplier-related breach in banking

Multi-Framework Mapping

ISO 27001:2022 ↔ SOC 2 ↔ PCI DSS ↔ NIST 800-53 ↔ CIS Controls ↔ COBIT 2019 ↔ GDPR/DPDP

FrameworkReferenceRelationship
SOC 2CC9.2 (vendor and business partner risk), CC3.2 (risk identification includes vendors)Vendor risk assessment and management
PCI DSS v4.0.112.8.1 (list of TPSPs), 12.8.2 (written agreements), 12.8.3 (due diligence before engagement), 12.8.4 (monitor TPSPs' PCI DSS status at least annually), 12.8.5 (which requirements each TPSP manages); 12.9.x applies to TPSPs themselvesThird-party service provider management
NIST SP 800-53 Rev 5SA-4, SA-9, SR-3, SR-5, SR-6, SR-8, PS-7Acquisition, external services, supply chain risk family
NIST CSF 2.0GV.SC-01 to GV.SC-10Cybersecurity supply chain risk management
CIS Controls v8Control 15 (15.1–15.7)Service provider management
COBIT 2019APO10 (Managed Vendors)Vendor selection, contracts, risk and performance
DPDP Act 2023s.8(1), s.8(2), s.8(5), s.8(6)Fiduciary stays responsible; processors only under a valid contract; safeguards; breach intimation
GDPRArt. 28Processor contracts and sub-processor control

Detailed Control Mapping

ISO 27001 A.5.19 → NIST 800-53 Rev 5:

A.5.19 RequirementNIST 800-53 ControlNIST Control Description
Supplier risk assessmentRA-3 Risk Assessment; SR-6 Supplier Assessments and ReviewsAssess risk from suppliers and the supply chain
Security requirements in contractsSA-4 Acquisition Process; SA-9 External System ServicesPut security requirements into acquisitions and external service agreements
Supplier monitoringSA-9; SR-6Monitor providers' control compliance
Right to auditSR-6 Supplier Assessments and ReviewsAssess and review suppliers, including by audit
Incident notificationSR-8 Notification Agreements; IR-7Agree how compromises are notified
Subcontractor managementSR-3 Supply Chain Controls and Processes (SA-12 was withdrawn in Rev 5)Control sub-supplier risk
Termination and data returnPS-7 External Personnel Security; SA-9Remove external personnel access; return or destroy data
Change managementSA-9(1) Risk Assessments and Organizational ApprovalsAssess and approve changes to external services

ISO 27001 A.5.19 → CIS Controls v8:

A.5.19 RequirementCIS ControlCIS Safeguard
Supplier inventory and risk assessmentCIS 15.1Establish and Maintain an Inventory of Service Providers
Supplier policyCIS 15.2Establish and Maintain a Service Provider Management Policy
Supplier classificationCIS 15.3Classify Service Providers
Security requirements in contractsCIS 15.4Ensure Service Provider Contracts Include Security Requirements
Risk-based assessmentCIS 15.5Assess Service Providers
Supplier monitoringCIS 15.6Monitor Service Providers
Data return on terminationCIS 15.7Securely Decommission Service Providers

ISO 27001 A.5.19 → COBIT 2019:

A.5.19 RequirementCOBIT DomainCOBIT Practice
Supplier relationship managementAPO10Managed Vendors
Supplier risk assessmentAPO10.04Manage vendor risk
Supplier security requirementsAPO13Managed Security
Supplier monitoringAPO10.05Monitor vendor performance and compliance
Supplier incident managementDSS05Managed Security Services
Supplier change managementBAI06Managed Change
Supplier terminationAPO10.03Manage vendor relationships and contracts

Regulatory and Industry Context

India-Specific Regulations

RegulationRelevance to A.5.19Key Supplier RequirementsPenalty for Non-Compliance
DPDP Act 2023CriticalData fiduciary remains liable for processor breaches; the fiduciary must engage processors under a valid contract (s.8(2)) and keep safeguards; transfers barred only to restricted countries (s.16); breach notification flows from processor to fiduciary by contractUp to ₹250 crore for the fiduciary (security safeguards); processor liability under contract
IT Act 2000 (Section 43A)HighBody corporate liable for negligence by "any person who has access to sensitive personal data", includes suppliersCompensation claims; no statutory cap
RBI Master Direction on Outsourcing of Information Technology Services (2023)Critical for banks, NBFCs and other REsBoard-approved IT outsourcing policy; due diligence; contracts with audit and RBI access rights; monitoring; incident reporting; exit planning; concentration riskSupervisory action
RBI Master Direction on Digital Payment Security Controls (2021)Payment channelsSecurity of digital payment channels, including vendor-supplied componentsSupervisory action
RBI Cyber Security Framework in Banks (2016) and IT Governance Master Direction (2023)Critical for banksVendor access controls; third-party risk in the cyber security policySupervisory action
SEBI CSCRF (Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities, 20 August 2024)Critical for market infrastructureVendor risk management for stock exchanges, depositories, clearing corporations; security clauses; audit rights; incident reportingSEBI enforcement; trading restrictions; penalties
IRDAI Information and Cyber Security Guidelines (2023)Critical for insuranceVendor security management; third-party risk assessments; contractual controls; incident reportingLicense conditions; business restrictions
CERT-In Directions 2022High for all6-hour reporting applies even when a supplier caused the incident (service providers must also report); ICT logs kept 180 days in IndiaService blocking; legal action; directions
MeitY Intermediary Rules 2021High for platformsSecurity measures must extend to vendors; data retention; traceability; grievance redressalSafe harbour loss; blocking; liability
Companies Act 2013, s.134(5)(e)Where supplier processes affect financial reportingDirectors' responsibility statement on internal financial controlsDirector liability

International Regulations

RegulationJurisdictionSupplier Security Relevance
GDPR (Regulation 2016/679)EU + EEAArt. 28: Processor must meet security requirements; written contract/DPA mandatory; processor liability; sub-processor consent and control; breach notification to the controller without undue delay (Art. 33(2))
CCPA/CPRACalifornia, USA"Service provider" and "contractor" definitions with security obligations; third-party data sales restrictions; breach notification
HIPAA Security RuleUSA healthcareBusiness Associate Agreement (BAA) mandatory; business associate liable for breaches; security safeguards; subcontractor control
NIS2 DirectiveEUSupply chain security; ICT product and service security; third-party risk management; incident reporting; security by design for critical entities
SOX Section 404USA public companiesThird-party service organizations in internal controls; SOC 1 Type II reports for financial process vendors; auditor reliance on vendor controls
PCI DSS v4.0.1GlobalReq 12.8: Third-party due diligence; contractual security requirements; third-party PCI DSS compliance; evidence of compliance; incident management
FedRAMPUSA federal cloudThird-party assessment organizations (3PAOs); continuous monitoring; security controls for cloud service providers; agency ATO dependencies
APPI (Japan)JapanThird-party supervision obligation; personal information protection in outsourcing; data transfer restrictions
PDPA (Singapore)SingaporeProtection obligation extends to data intermediaries; contractual security requirements; data breach notification; DPIA for high-risk processing
LGPD (Brazil)BrazilSecurity measures for processing; data processor obligations; contractual requirements; breach notification; DPIA
POPIA (South Africa)South AfricaInformation officer responsible for operator security; written contract with operators; breach notification; data subject rights

Industry-Specific Context

IndustrySupplier Security ConsiderationsKey Standards/Best Practices
Banking and Financial ServicesRBI-mandated vendor management; payment processor PCI DSS; core banking vendor security; ATM/cash logistics physical security; fintech partnershipsRBI Master Directions, PCI DSS, ISO 27001, NIST CSF, COBIT
InsuranceIRDAI-mandated vendor controls; claim processing BPO security; policy data protection; agent/broker access managementIRDAI guidelines, ISO 27001, COBIT
Healthcare and PharmaPatient data protection (health data; SPDI Rules apply until DPDP s.44(2) commences); clinical trial vendor management; drug safety data; medical device security (MDR/IVDR)HIPAA, DPDP Act, GxP, ISO 27001, IEC 62304
IT/ITES and SaaSClient-mandated supplier audits; multi-tenant isolation; API security; development vendor security; cloud shared responsibilitySOC 2, ISO 27001, ISO 27017, CSA STAR, OWASP
ManufacturingOT/IT supplier security; ICS system integrators; IoT device supply chain integrity; counterfeit prevention; Industry 4.0IEC 62443, NIST SP 800-82, ISO 27001, supply chain integrity frameworks
Retail and E-commercePayment gateway security; marketplace vendor access; logistics partner data; customer data protection; loyalty program securityPCI DSS, DPDP Act, ISO 27001
Education (EdTech)Children's data protection (DPDP); student privacy; third-party content providers; online assessment security; international student dataDPDP Act, COPPA (USA), FERPA (USA), ISO 27001
Government and Public SectorCERT-In compliance; e-governance vendor security; citizen data protection; national security considerations; make-in-India preferencesCERT-In directions, ISO 27001, GIGW, additional security clearances
TelecomNetwork equipment from trusted sources under the DoT National Security Directive on the telecom sector (2021); subscriber data protection; lawful interception vendor controls; tower infrastructureDoT security requirements, 3GPP, ISO 27001, GSMA security guidelines
Energy and UtilitiesCritical infrastructure protection; SCADA/ICS vendor security; smart grid supply chain; renewable energy IoT; NERC CIP (USA equivalent)CERC guidelines, IEC 62351, NERC CIP, ISO 27001, NIST CSF

Roles and Responsibilities (RACI)

Supplier Security Activities RACI Matrix

#ActivityBoard / CEOCISOCIOHead of ProcurementLegal CounselVendor Risk ManagerVendor Risk AnalystIT / Security OperationsData OwnerBusiness Unit HeadCompliance Officer
1Approve Supplier Security PolicyARCCCCIIIIC
2Define Supplier Risk FrameworkIACCCRCIIIC
3Maintain Supplier InventoryICCRIRRCCCI
4Classify Supplier Risk TierIACCIRCICCI
5Conduct Supplier Security AssessmentICICIRRCCII
6Review Supplier Certifications/AuditsICIIIRRCIIC
7Draft Security Contract ClausesICICRCIICIC
8Negotiate Security Terms with SuppliersICIRRCIIIII
9Approve Critical Supplier ContractsARCCCCIIIIC
10Provision Supplier AccessICRIICIRCII
11Monitor Supplier Security PostureIAIIIRRRIIC
12Conduct Supplier Security AuditIAIIIRRCCIC
13Manage Supplier Security IncidentsIACIIRCRCIC
14Execute Supplier Change ReassessmentICICIRCCCCI
15Execute Supplier OffboardingICRCCRCRCII
16Verify Data Return/DestructionICIIIRCCCIC
17Update Supplier Risk RegisterICIIIRRCCII
18Report Supplier Security MetricsIRCCCRCIIIC
19Audit TPRM Program ComplianceIAIIICIIIIR
20Drive Continuous ImprovementIACCCRCCCCC
21Approve Subcontractor EngagementsIACCCRCIIIC
22Define Data Protection Requirements for SuppliersICIIICIIRCC
23Train Business Units on Supplier RegistrationICICIRCIICI
24Manage Supplier Security BudgetACCRICIIIII

Legend:

  • R = Responsible (does the work)
  • A = Accountable (ultimately answerable; approves)
  • C = Consulted (provides input)
  • I = Informed (kept updated)

Role Descriptions

RoleKey ResponsibilitiesTypical Designation in Indian Organizations
Board / CEOStrategic oversight; policy approval; budget for enterprise TPRM; risk acceptance for catastrophic supplier risksManaging Director, CEO, Chairman
CISOAccountable for all supplier security; approves Critical supplier engagements; signs off on audits; reports to boardChief Information Security Officer, Head of Security
CIOEnsures IT systems support TPRM; manages supplier access provisioning; technical architecture for supplier connectionsChief Information Officer
Head of ProcurementEnsures security clauses in all contracts; manages supplier onboarding/offboarding; procurement system enforcementChief Procurement Officer, VP Procurement, Purchase Head
Legal CounselDrafts and negotiates security clauses; enforces contract terms; manages termination; handles liability disputesGeneral Counsel, Legal Head, Company Secretary
Vendor Risk ManagerDay-to-day TPRM program management; risk assessments; monitoring; audits; incident coordination; metrics reportingVendor Risk Manager, Supplier Security Manager, Third-Party Risk Manager
Vendor Risk AnalystExecutes assessments; maintains inventory; analyzes ratings; prepares audit reports; tracks remediationVendor Risk Analyst, Supplier Security Analyst
IT / Security OperationsProvisions and revokes supplier access; monitors supplier activity; manages SIEM alerts for supplier accounts; executes technical offboardingIT Operations, Security Operations Center (SOC), IAM Team
Data OwnerDefines data protection requirements for suppliers; approves data sharing; verifies data return; assesses data breach impactData Owner, Business Unit Head, Function Head
Business Unit HeadIdentifies and registers all suppliers; ensures business team compliance with TPRM policy; alerts VRM to new supplier needsDepartment Head, Business Unit Head, Regional Manager
Compliance OfficerEnsures regulatory compliance in supplier contracts; audits TPRM program; manages regulatory reporting; DPDP complianceCompliance Head, Company Secretary, Regulatory Affairs

Documentation and Evidence Requirements

Suggested Evidence by TPRM Lifecycle Phase

ISO 27001 sets no retention periods; the periods below are examples. Set yours from legal, contractual and DPDP erasure obligations.

PhaseDocument / EvidenceRetention PeriodFormatOwner
InventorySupplier inventory registerPermanent (updated continuously)Spreadsheet / TPRM platform / DatabaseVendor Risk Manager
InventoryShadow supplier discovery records3 yearsEmail / Survey / Analysis reportVendor Risk Manager
AssessmentSupplier Security Questionnaire (SSQ) responses7 years from assessment datePDF / Platform exportVendor Risk Manager
AssessmentRisk assessment records per supplier7 years from assessment datePDF / Risk registerVendor Risk Manager
AssessmentExternal security rating reports3 yearsPlatform export / PDFVendor Risk Manager
ContractingSupplier contracts with security clausesDuration of relationship + 7 yearsPDF / Contract management systemLegal / Procurement
ContractingData Processing Agreements (DPAs)Duration of relationship + 7 yearsPDF / Contract management systemLegal / Compliance
ContractingRisk acceptance forms (for gaps)7 yearsPDF / Workflow recordCISO / Vendor Risk Manager
MonitoringQuarterly Business Review (QBR) minutes7 yearsPDF / Meeting notesVendor Risk Manager
MonitoringContinuous monitoring alerts and actions3 yearsPlatform export / Email / TicketSecurity Operations
MonitoringSupplier access review records7 yearsPDF / IAM system exportIT / Security Operations
AuditSupplier audit plans7 yearsPDF / WordInternal Audit / Vendor Risk Manager
AuditSupplier audit reports7 yearsPDFInternal Audit / Vendor Risk Manager
AuditCorrective Action Plans (CAPs) and closure evidence7 yearsPDF / ExcelVendor Risk Manager / Supplier
IncidentSupplier incident records7 yearsIncident management system / PDFSecurity Operations / Vendor Risk Manager
IncidentJoint investigation reports7 yearsPDF / WordCISO / Vendor Risk Manager
IncidentRegulatory notification records (DPDP, RBI, etc.)7 yearsPDF / Email / Regulatory portalCompliance Officer
ChangeSupplier change notifications7 yearsEmail / Platform recordVendor Risk Manager
ChangeReassessment records triggered by change7 yearsPDF / Risk registerVendor Risk Manager
TerminationTermination notice7 yearsPDF / Email / WorkflowProcurement / Legal
TerminationAccess revocation logs7 yearsIAM system export / Log filesIT / Security Operations
TerminationData return/destruction certificates7 yearsPDF / CertificateVendor Risk Manager / Data Owner
TerminationAsset collection receipts7 yearsPDF / Signed receiptIT / Facilities
TerminationPost-termination review records7 yearsPDF / Meeting notesVendor Risk Manager
GovernanceTPRM Committee meeting minutes7 yearsPDF / Meeting notesVendor Risk Manager
GovernanceManagement review records (supplier security)7 yearsPDF / Meeting notesCISO
GovernanceTPRM metrics and dashboards3 yearsBI tool / Excel / PDFVendor Risk Manager
TrainingProcurement team security training records7 yearsTraining system / AttendanceHR / Vendor Risk Manager
TrainingSupplier security awareness training records7 yearsTraining system / CertificatesHR / Vendor Risk Manager

Evidence Organization

For audit readiness, organize evidence in a structured repository:

/TPRM-Evidence/
  /YYYY/
    /Supplier-Assessments/
      /Critical/
        - [Supplier-ID]-[Name]-Assessment-YYYY-MM-DD.pdf
      /High/
      /Medium/
      /Low/
    /Contracts/
      /Critical/
        - [Supplier-ID]-[Name]-Contract-vX.pdf
      /High/
      /Medium/
      /Low/
    /Monitoring/
      /QBR-Minutes/
      /Security-Ratings/
      /Access-Reviews/
    /Audits/
      /On-Site/
      /Virtual/
      /CAPs/
    /Incidents/
      /YYYY-MM-Incident-[ID]-[Supplier-Name]/
    /Terminations/
      /YYYY-MM-[Supplier-Name]/
    /Governance/
      /Committee-Minutes/
      /Management-Reviews/
      /KPI-Dashboards/
    /Training/
      /Procurement-Training/
      /Supplier-Training/

Continuous Improvement

The Continuous Improvement Cycle for Supplier Security

Plan → Do → Check → Act

Plan:

  • Review TPRM metrics quarterly: incident trends, assessment coverage, audit findings, monitoring effectiveness
  • Benchmark against industry standards (Gartner TPRM maturity, Shared Assessments SIG, NIST CSF supply chain)
  • Identify regulatory changes (DPDP amendments, RBI circulars, new SEBI requirements)
  • Update risk framework based on new threat intelligence (supply chain attacks, new vulnerabilities)

Do:

  • Deploy updated templates, clauses, and procedures to procurement and security teams
  • Train new staff and refresh existing staff on TPRM practices
  • Implement new monitoring tools or automation
  • Pilot new assessment techniques (e.g., AI-assisted risk scoring, automated evidence collection)

Check:

  • Measure KPIs before and after changes
  • Conduct internal audit of TPRM program effectiveness
  • Gather feedback from suppliers on assessment process (friction vs. value)
  • Review post-incident data for supplier root causes

Act:

  • Standardize improvements that prove effective
  • Eliminate redundant assessments or processes that add no value
  • Update knowledge base and playbook
  • Report improvements to management and incorporate into governance

Supplier Security Maturity Model

LevelNameCharacteristicsEvidenceTypical Organization
1, InitialAd-hocNo supplier inventory; no security assessments; no security clauses; reactive incident management; shadow suppliers rampantNo policy; no inventory; contracts without security terms; incident-driven responseStartups; very small businesses; unregulated sectors
2, DevelopingBasic TPRMBasic supplier inventory exists; security clauses in some contracts; lightweight SSQ for some suppliers; no continuous monitoring; manual processesInventory (incomplete); some contracts with clauses; basic SSQ; spreadsheet-basedSMEs beginning ISO 27001; 1-2 procurement staff
3, DefinedStandardizedComplete inventory; security clauses in all contracts; risk tiering; scheduled assessments; quarterly monitoring for Critical; defined offboardingPolicy + procedure; 100% clause coverage; tiered assessments; monitoring schedule; documented offboardingGrowing companies; 250-5000 employees; pursuing certification
4, ManagedMeasuredAutomated inventory; continuous monitoring via security ratings; automated SSQ; risk scoring; annual audits; metrics-driven governance; integration with GRCTPRM platform; security ratings; automated workflows; KPI dashboard; integrated GRCLarge enterprises; 5000+ employees; mature risk management
5, OptimizingStrongPredictive risk analytics; AI-assisted threat intelligence; fourth-party risk visibility; real-time monitoring; automated offboarding; industry leadership; zero trust supply chainPredictive analytics; AI/ML risk models; real-time supply chain visibility; automated response; industry contributionsGlobal banks; top tech companies; defence organizations

Improvement Triggers and Actions

TriggerActionResponsibleTimeline
Supplier incident rate >2 per quarterRoot cause analysis; control enhancement; supplier retraining; potential contract amendmentsCISO + Vendor Risk Manager2 weeks
Audit finding in TPRM programCorrective action; process update; evidence enhancement; retrainingInternal Audit + Vendor Risk Manager4 weeks
New regulation (DPDP amendment, RBI circular)Policy review; contract clause update; regulatory mapping; trainingCompliance Officer + Legal + CISO6 weeks
Major supply chain breach in industryIndustry threat analysis; review of similar suppliers; control enhancementCISO + Threat Intelligence2 weeks
Certification lapse of Critical supplierImmediate escalation; enhanced monitoring; contract enforcement; alternative sourcing evaluationVendor Risk Manager + Procurement1 week
Customer audit finding on supplier securityImmediate corrective action; process update; supplier engagement evidence enhancementVendor Risk Manager + CISO1 week
TPRM platform upgrade or replacementProcess re-engineering; training; data migration; integration testingIT + Vendor Risk Manager8 weeks
Annual management reviewFull policy and framework review; KPI trend analysis; improvement plan; budget revisionCISO + Vendor Risk Manager + ProcurementAnnual
Significant business growth (>25% new suppliers)Scale TPRM resources; automation investment; process optimizationCISO + HR + Procurement3 months

FAQ

General Questions

Q1: Does A.5.19 apply to all suppliers, including small ones like office supply vendors? A: Yes, but with proportionate effort. A.5.19 applies to all suppliers with access to information, systems, or premises. However, a courier service or office supply vendor (Low tier) requires only a lightweight assessment (e.g., a 4-clause contract and basic security awareness). A cloud hosting provider (Critical tier) requires deep due diligence, continuous monitoring, and annual audits. The key is that no supplier is exempt from the inventory and some level of security consideration.

Q2: What is the difference between A.5.19 and A.5.20? A: A.5.19 sets the overall supplier policy and process (identify, assess, select, monitor, exit). A.5.20 sets what goes into each supplier agreement. A.5.21 adds rules for the ICT supply chain, A.5.22 covers monitoring and changes to supplier services, and A.5.23 covers cloud services. A.5.14 (information transfer) applies to the data you exchange with suppliers.

Q3: Do we need to audit every supplier? A: No. Audits are resource-intensive and should be risk-based. We recommend: annual on-site audits for Critical suppliers, biennial virtual audits for High suppliers, and ad-hoc or incident-driven audits for Medium and Low suppliers. If a supplier holds a current ISO 27001 or SOC 2 Type II certification, you can rely on that (with spot checks) rather than conducting a full audit.

Q4: How do we manage fourth-party risk (our supplier's suppliers)? A: Fourth-party risk is managed through: (1) contractual disclosure requirements, your supplier must tell you who their subcontractors are; (2) contractual liability, your supplier remains liable for subcontractor breaches; (3) assessment of subcontractors for Critical suppliers; (4) security ratings that may capture fourth-party telemetry; (5) limiting the subcontractor chain, require approval for new subcontractors. Full fourth-party visibility is difficult but essential for Critical suppliers.

Q5: Can we accept a supplier without ISO 27001 or SOC 2? A: Yes, but with enhanced scrutiny. Certifications are evidence of a mature security program, but they are not mandatory for A.5.19 compliance. (SOC 2 is an attestation report, not a certification; for either, check that the scope covers the service you buy.) If a supplier lacks certifications, require: a detailed SSQ, evidence of equivalent controls, a remediation plan for gaps, increased monitoring, and potentially a shorter contract term with renewal contingent on improvement. For Critical suppliers, consider requiring certification within 12-24 months as a contract milestone.

Q6: How often should we reassess suppliers? A: Reassessment frequency should align with risk tier: Critical suppliers annually (or more frequently if incidents occur); High suppliers every 18-24 months; Medium suppliers every 2-3 years; Low suppliers every 3 years or on renewal. In addition, reassess whenever there is a material change (subcontractor, location, technology, certification lapse, or incident).

Q7: What is a "shadow supplier" and how do we find them? A: A shadow supplier is a vendor engaged by individual employees or departments without procurement or security knowledge. Examples: a marketing manager's personal Canva subscription with company logos, a developer's personal GitHub account with company code, a department's free survey tool with employee feedback. Find them through: expense report analysis, cloud IAM audits, email domain analysis, network traffic monitoring, and department surveys. Shadow suppliers are a major audit failure point because they bypass all security controls.

Q8: How do we handle supplier security for international vendors (e.g., AWS, Google, Salesforce)? A: Global hyperscalers (AWS, Azure, Google Cloud) typically have strong security programs (ISO 27001, SOC 2, PCI DSS). Your assessment should focus on: shared responsibility model clarity (what they secure vs. what you secure), data residency and region selection, IAM configuration, encryption key management, and their incident notification process. For smaller international vendors, apply the same risk-based assessment as domestic vendors, with additional attention to data residency and cross-border transfer compliance (DPDP Act 2023, GDPR).

Q9: Should we include physical security suppliers (guards, cleaning) in our TPRM program? A: Yes. Physical security suppliers have access to your premises, devices, and sometimes documents. They should be in your inventory, classified (typically Medium), and subject to background checks, physical access controls, and confidentiality agreements. A cleaning crew with after-hours access to executive offices can be a significant insider threat if not managed.

Q10: How does A.5.19 relate to DPDP Act 2023 compliance? A: The DPDP Act 2023 makes the "data fiduciary" (your organization) liable for breaches, even if caused by a supplier (data processor). Section 8(5) requires "reasonable security safeguards" that extend to your supply chain. For any supplier processing personal data on your behalf, you must have a Data Processing Agreement (DPA) with security clauses, verify their safeguards, and ensure they can meet breach notification requirements. Failing to take reasonable security safeguards, including over processors, can attract a penalty of up to ₹250 crore.

Q11: What is the minimum viable TPRM process for a 30-person startup? A: For startups, keep it lean: (1) List all suppliers with access to your data/systems (even the free ones), (2) Classify into Critical (cloud, payment, core dev) and Other, (3) Use standardized security clauses for Critical suppliers (use our clause library), (4) Require MFA and data residency for Critical, (5) Revoke access immediately when a supplier is no longer needed, (6) Monitor for breach news. As you grow, add formal assessments, monitoring tools, and audit programs.

Q12: How do we justify TPRM investment to management? A: Use the business case: (1) the Verizon 2025 DBIR found third-party involvement in 30% of breaches, double the previous year, (2) DPDP Act penalties of up to ₹250 crore for failing to take reasonable safeguards, regulatory liability is personal and organizational, (3) enterprise clients require supplier security evidence, revenue depends on it, (4) breach cost averages M for third-party breaches, prevention is cheaper, (5) TPRM program cost is typically 0.5-2% of IT spend, negligible compared to breach cost. Use illustrative scenarios (Section 15) to show peer examples.

Q13: Can we use a single security questionnaire for all suppliers? A: A single complete SSQ can be used, but the evaluation should be tiered. All suppliers answer the same questions, but the pass threshold and required evidence vary by tier. For Low suppliers, a score of 50/100 may be acceptable. For Critical suppliers, 80/100 is the minimum. Alternatively, use a lightweight SSQ for Low/Medium and a complete SSQ for Critical/High. The key is consistency and proportionality.

Q14: What should we do if a Critical supplier refuses to allow an audit? A: If a Critical supplier refuses an audit, you have three options: (1) Accept the risk with formal risk acceptance and enhanced monitoring (not recommended for highly sensitive data), (2) Require an alternative assurance (e.g., SOC 2 Type II report from a reputable auditor, ISO 27001 with scope covering your data), (3) Find an alternative supplier. Never allow a Critical supplier to operate without any form of security assurance. Document the refusal and your decision in the risk register.

Q15: How do we manage supplier security in a merger or acquisition? A: M&A introduces massive supplier risk: (1) Immediately inventory all suppliers of the acquired company, (2) Assess them against your security standards before integration, (3) Do not grant access to your systems until assessment is complete, (4) Harmonize contracts to your clause library, (5) Plan termination of redundant suppliers with secure offboarding, (6) Integrate monitoring and access controls. M&A is a high-risk period for supplier security, treat it as a security project (A.5.20 + A.5.19).

Q16: Should we include open-source software and public libraries as "suppliers"? A: Open-source libraries are not traditional suppliers but introduce similar supply chain risks. A.5.19 focuses on contractual relationships, but the broader supply chain risk concept (A.8.25, A.8.28) includes software dependencies. Best practice: use Software Composition Analysis (SCA) tools to track open-source dependencies; monitor for vulnerabilities (CVEs); maintain an SBOM (Software Bill of Materials); have a policy for approved open-source licenses. This is increasingly required by regulations (NIS2, EO 14028 in the USA).

Q17: How do we handle a supplier breach? A: Follow the joint incident response protocol: (1) Verify the breach scope with the supplier immediately, (2) Assess if your data/systems/customers are affected, (3) Contain (revoke access if needed), (4) Investigate jointly, (5) Require root cause analysis and remediation evidence, (6) Update the supplier risk assessment, (7) Consider contract termination if negligence is proven, (8) Notify regulators if required (DPDP: 72 hours; RBI: 6 hours for payment), (9) Notify affected customers if personal data is involved, (10) Update your incident response playbook. Speed and documentation are critical.

Q18: Is there a difference between "vendor," "supplier," and "third party"? A: In practice, these terms are often used interchangeably. ISO 27001:2022 uses "supplier" consistently. "Vendor" is common in procurement and IT. "Third party" is broader and includes non-contractual relationships (e.g., industry partners, regulators). For A.5.19, focus on "suppliers", entities with whom you have a contractual relationship for products or services. The control applies regardless of the term used internally.

Q19: How do we balance security requirements with supplier relationship management? A: Security requirements should not be adversarial. Frame them as "helping us both succeed", your enterprise clients require you to have secure suppliers, so your suppliers must meet those standards. Use tiered requirements (don't overburden a small vendor), provide clear guidance (use our clause library), offer assistance (help them understand DPDP requirements), and recognize good performance (positive reinforcement in QBRs). A supplier that improves its security for your benefit often wins more business from other clients too.

Q20: Can we automate supplier risk assessment? A: Yes, and you should at scale. Automated tools can: send SSQs, collect responses, calculate risk scores, monitor security ratings, alert on certification expiry, and track remediation. However, human judgment remains essential for: architecture reviews, complex risk scenarios, negotiation of security terms, incident investigation, and relationship management. The goal is "augmented TPRM", automation handles volume and consistency; humans handle nuance and decisions.


References and Further Reading

ISO Standards

  1. ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection, Information security management systems, Requirements
  2. ISO/IEC 27002:2022: Information security, cybersecurity and privacy protection, Information security controls, Clause 5.19
  3. ISO/IEC 27003:2017: Information security management system, Guidance
  4. ISO/IEC 27005:2022: Information security risk management
  5. ISO/IEC 27036: Information security for supplier relationships, Multiple parts (27036-1 to 27036-4)
  6. ISO/IEC 27037:2012: Guidelines for identification, collection, acquisition and preservation of digital evidence (relevant for incident investigation)

Indian Regulations and Guidelines

  1. Digital Personal Data Protection Act 2023: Government of India, Ministry of Electronics and Information Technology
  2. Information Technology Act 2000 (as amended in 2008): Government of India
  3. CERT-In Directions 2022: Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology
  4. RBI Master Direction on Outsourcing of Information Technology Services: Reserve Bank of India, 2023
  5. RBI Cyber Security Framework in Banks (2016) and Master Direction on Digital Payment Security Controls (2021): Reserve Bank of India
  6. SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, circular of 20 August 2024: consolidated and replaced the earlier frameworks for stock exchanges, depositories, clearing corporations and intermediaries
  7. SEBI CSCRF (2024): also applies to mutual funds and AMCs, replacing their 2019 framework
  8. IRDAI Information and Cyber Security Guidelines: Insurance Regulatory and Development Authority of India, 2023
  9. MeitY Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
  10. National Cyber Security Policy 2013: Ministry of Electronics and Information Technology

International Frameworks and Standards

  1. NIST SP 800-53 Rev 5: Security and Privacy Controls for Information Systems and Organizations
  2. NIST Cybersecurity Framework (CSF) 2.0: National Institute of Standards and Technology, 2024
  3. NIST SP 800-161 Rev 1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations
  4. CIS Controls v8: Center for Internet Security
  5. COBIT 2019: Control Objectives for Information and Related Technologies, ISACA
  6. PCI DSS v4.0.1: Payment Card Industry Data Security Standard
  7. Shared Assessments Standardized Information Gathering (SIG) Questionnaire: Shared Assessments Working Group
  8. AICPA SOC 2 Trust Services Criteria: TSP Section 100, 2017 Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy

Third-Party Risk Management Resources

  1. Gartner Research: Magic Quadrant for IT Vendor Risk Management Solutions: Annual
  2. Forrester Research: The Forrester Wave™: Third-Party Risk Management Platforms: Quarterly
  3. BitSight Security Ratings Methodology: bitsight.com
  4. SecurityScorecard Ratings Methodology: securityscorecard.com
  5. UpGuard Vendor Risk Management Guide: upguard.com

Industry Reports and Statistics

  1. Verizon Data Breach Investigations Reports (DBIR) 2024 and 2025: Verizon Business
  2. IBM Cost of a Data Breach Report 2024: IBM Security
  3. Ponemon Institute: Data Risk in the Third-Party Ecosystem: Annual
  4. CERT-In Annual Report 2023-2024: Indian Computer Emergency Response Team
  5. Reserve Bank of India Annual Report: RBI cyber security and payment system sections

Supply Chain Security

  1. NIST SP 800-161 Rev 1: Cybersecurity Supply Chain Risk Management Practices, National Institute of Standards and Technology
  2. CISA Supply Chain Risk Management: US Cybersecurity and Infrastructure Security Agency
  3. ENISA Supply Chain Security Guidance: European Union Agency for Cybersecurity

How Singahi can help

Singahi is one team for compliance, assessment and managed security. We help growing companies implement and certify ISO 27001:2022, and stay secure afterward.


Continue the toolkit

How we can help

Working toward this?

If a certification or a customer's security questionnaire is what brought you here, tell us where you are. We'll give you an honest read on the work and the timeline, with no obligation.

What happens next

  1. Tell us the trigger

    A questionnaire, an audit date or an investor ask. The short form or a call both work.

  2. A practitioner replies

    A senior practitioner, not a bot, within four business hours.

  3. You get a scoped next step

    An honest view of what the work involves. No pressure, no theatre.