A supplier risk assessment is the process of evaluating the security, compliance and operational risks associated with engaging a third-party supplier before and during the business relationship. It typically involves reviewing the supplier's security certifications, policies, incident history, financial stability and data processing practices, often supported by questionnaires, audits or independent assessment reports such as SOC 2.
The supplier risk assessment process:
- Build a supplier inventory: Record every third party that processes your data, connects to your systems or supports a critical process. You cannot assess what you have not written down, and an incomplete register is the most common audit finding here.
- Tier by criticality: Rank suppliers by the sensitivity of the data they touch and the impact of them failing. Tiering decides how deep each assessment goes: a payroll processor warrants far more scrutiny than an office supplier.
- Send a proportionate questionnaire: Ask about security controls, subprocessors, data location, breach notification and continuity. Match the depth to the tier; a 200-question form sent to every supplier gets rushed answers and tells you little.
- Review independent evidence: Certifications such as ISO 27001, audit reports such as SOC 2 Type II, and penetration test summaries carry more weight than self-declaration, because someone external has tested the claim.
- Decide and record: Accept, accept with conditions, or reject. Document the residual risk and who approved it. This decision trail is what an auditor asks for, not the questionnaire itself.
- Monitor and reassess: Set a review cadence per tier, and re-run the assessment on contract renewal, after an incident, or when the service materially changes.
ISO 27001:2022 covers this in Annex A controls A.5.19 to A.5.23, spanning supplier relationships, security within supplier agreements, the ICT supply chain, monitoring of supplier services, and cloud services. NIS2 makes supply chain security an explicit obligation under Article 21(2)(d), and DORA sets detailed third-party ICT risk requirements for financial entities. In practice most auditors look for three things: a maintained supplier register, evidence that assessments happened before onboarding rather than retrospectively, and a review cycle you can demonstrate.
Looking for a tool rather than a definition? See how Tidal Control automates supplier risk assessment: a supplier database that pre-fills certifications and policies, then scores and re-checks the risk for you.