What belongs in the analysis
A practical scenario
Consider a simple scenario: a billing provider outage prevents invoices from being issued and exposes customer records even though the organization’s own network remains intact.
Use the scenario to answer two concrete questions: What business process depends on this vendor? What access, data, or concentration does the relationship create? The record becomes useful when those answers are supported by evidence and tied to a named decision owner.
Evidence worth gathering
Evidence should be proportionate to the importance of the decision. The following records commonly make the discussion more reliable:
- Risk-tiering criteria tied to business impact
- Completed due diligence with documented gaps
- Contract terms aligned to identified exposure
- Periodic review and issue tracking
- Offboarding confirmation for access and data
A practical review sequence
- Clarify service criticality: How the vendor supports essential work and the effect of interruption.
- Describe access and data: Accounts, integrations, administrative privileges, data handling, and storage locations.
- Evaluate assurance: Evidence about governance, safeguards, testing, incidents, and subcontractors.
- Test contract and notification: Security obligations, incident notice, audit rights, recovery commitments, and data return.
- Confirm ongoing oversight: Performance, changes, exceptions, incidents, concentration, and offboarding.
- Close the review by answering: How will the relationship be monitored and ended safely?
Common failure modes
- Approving a vendor based only on a certificate
- Collecting questionnaires without reviewing answers
- Failing to reassess after service or ownership change
- Leaving accounts and data active after termination
Questions for management
- What business process depends on this vendor?
- What access, data, or concentration does the relationship create?
- Which gaps require treatment before or after onboarding?
- How will the relationship be monitored and ended safely?
Frequently asked questions
What should be documented first for third-party cyber risk?
Start with service criticality: How the vendor supports essential work and the effect of interruption.
Which evidence should receive early attention?
Begin with risk-tiering criteria tied to business impact and completed due diligence with documented gaps. The right evidence is the evidence capable of changing confidence or the treatment decision.
What commonly weakens this analysis?
One frequent problem is approving a vendor based only on a certificate. The review should make that weakness visible instead of hiding it behind a score or dashboard.
When should it be revisited?
Review it on the scheduled date and whenever the conditions behind this question change: What business process depends on this vendor?