Building a third-party risk management programme buyers trust
In the enterprise world, your security posture is only as strong as the weakest link in your supply chain. For founders and heads of security, third-party risk management (TPRM) is no longer a tick-box exercise; it is a competitive differentiator that can shorten sales cycles and placate even the most forensic procurement teams. This guide outlines how to build a TPRM programme that moves beyond the spreadsheet and into actionable governance.
Michael McCarroll— Founder · 20+ yrs GRC, ISO 27001 lead implementer 16 min read Updated June 2026
The Strategy of Tiering: Stop Treating Every Vendor Like Google.
Most firms fail at TPRM because they treat every vendor the same, leading to 'questionnaire fatigue' and bottlenecked procurement. A mature programme begins with a rigorous tiering methodology based on the data to be processed and the potential impact of a service outage. If a supplier is handling PII or intellectual property, they are Tier 1; if they provide office fruit, they are Tier 4 and should be ignored by the security team.
To satisfy an ISO 27001 auditor or a sophisticated buyer, you must demonstrate that you have evaluated the supplier before the contract is signed. This means your TPRM programme must be integrated into the procurement lifecycle. You cannot retroactively apply security controls to a SaaS platform that the marketing team has already integrated into your CRM without significant friction.
Define the 'Minimum Viable Security' requirements for each tier before procurement begins.
Assign a business owner for every supplier to ensure accountability for the relationship.
Align your assessment criteria with ISO 27001:2022 Annex A 5.21 (Managing Information Security in the Supplier Relationship).
Contractual Enforcement: Moving Beyond Good Intentions.
A security assessment is toothless if the findings cannot be enforced through the contract. Clause A 5.22 of ISO 27001:2022 specifically requires security requirements to be documented and agreed upon within supplier agreements. It is common for vendors to push back on these terms, and your ability to stand firm or negotiate a risk acceptance determines the true maturity of your GRC function.
Procurement and legal teams must work in lockstep with the security office. We often see 'Security Schedules' appended to contracts that provide a clear list of non-negotiable controls, such as MFA, encryption at rest, and annual penetration testing. This proactive legal stance proves to your customers that you take the security of their data—and the data of your sub-processors—seriously.
Right to Audit: Ensure you have the contractual right to review their security documentation or conduct an onsite audit.
Breach Notification: Demand a 24-48 hour window for notifications regarding security incidents.
Data Return/Deletion: Explicitly state what happens to your data when the contract terminates.
Sub-processor Transparency: Require the vendor to notify you if they move your data to a new fourth-party provider.
Evidence Validation: The 'Verify' Part of 'Trust but Verify'.
The most common failure I see in mid-market firms is the 'collect-and-forget' approach to SOC 2 and ISO 27001 reports. Receiving a PDF from a vendor is not an assessment; you must read the auditor's opinion and the listed exceptions. If a vendor’s SOC 2 report shows three failed controls in access management, you must record how those failures impact your data and what compensating controls you have in place.
For critical suppliers, you should be looking for a 'Bridge Letter' if the audit report is older than six months. This ensures there have been no material changes in their control environment since the last report. Buyers trust you more when they see that you haven't just checked a box, but have actually analysed the third party's residual risk and documented it in your risk register.
Furthermore, map your supplier reviews to the 'Complementary User Entity Controls' (CUECs) often listed in SOC 2 reports. These are the things the vendor expects YOU to do to keep their service secure. If you aren't doing them, the vendor’s security is essentially voided in your context. Demonstrating this level of oversight is Tier-1 GRC work.
Continuous Monitoring: Avoiding the 'Point-in-Time' Trap.
Risk is not static. A supplier that was secure two years ago may have undergone a merger, a change in leadership, or a significant staff turnover that has eroded their security culture. Clause 5.23 of the ISO 2022 update emphasises the need for monitoring, reviewing, and change management of supplier services. To an enterprise buyer, this continuous monitoring is the mark of a reliable partner.
Operationalising this requires a repeatable workflow. You shouldn't be reinventing the wheel every time a supplier comes up for renewal. By using a centralised GRC platform, you can keep a live history of every interaction, every questionnaire response, and every bit of evidence collected. This documentation is your primary defence during an ISO 27001 certification audit.
Maintain a centralised Supplier Inventory that includes the contract end date and last assessment date.
Implement an automated reminder system 90 days before an assessment expires.
Create a 'Risk Acceptance' workflow for vendors who fail certain criteria but are business-critical.
Perform annual reviews of 'High' risk vendors and biennial reviews for 'Medium' risk vendors.
Communicating TPRM Maturity to Win Business.
The ultimate goal of TPRM is to be able to show your own customers that you aren't the weak link. When a prospect sends you a security questionnaire, the ability to say 'Here is our Supplier Security Policy, here is how we tier our vendors, and here is our summary risk report for our sub-processors' is a massive trust signal. It shifts the conversation from defensive to proactive.
Founders often worry that being honest about third-party risks will scare off buyers. In reality, the opposite is true. Showing a buyer that you identified a risk in a sub-processor and implemented a compensating control (like additional IP whitelisting or more frequent backups) demonstrates that you are actually managing your business properly. It proves competence.
Automate your TPRM and close bigger deals.
Stop managing risks in spreadsheets. ISO-STANDARD.app provides the central hub for your supplier assessments, evidence collection, and risk treatment plans, helping you close enterprise deals faster.
ISO-STANDARD.app ships a ready-to-adopt TPRM workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.
Frequently asked questions
How do I prioritize which vendors to assess first?
Not all suppliers are equal. Tier your vendors based on the sensitivity of data they touch or their criticality to your operations. A cloud hosting provider requires a full ISO 27001 review; a stationary supplier likely needs nothing more than a basic business check.
Should I accept SOC 2 reports instead of ISO 27001 certificates?
While ISO 27001 is the gold standard for management systems, a SOC 2 Type II report provides specific point-in-time testing of controls. For high-risk vendors, ask for both. For lower-risk ones, a self-assessment questionnaire (SAQ) mapped to Annex A controls may suffice.
How often should I re-assess my existing suppliers?
A minimum of once per year for 'Critical' or 'High' risk vendors. However, triggered assessments should occur if the vendor has a significant breach or if the scope of the services they provide you changes significantly.
What is the biggest mistake firms make in TPRM?
Trust but verify. Do not take a 'Yes' at face value. Ask for specific evidence such as redacted penetration test summaries, certificates of insurance, or screenshots of their access control logs. If they refuse, it is a risk that must be logged and potentially escalated.
Action checklist PDF
Mirrors this guide with owners, artefacts & a 30/60/90-day plan.