Traditional vendor risk programmes assess suppliers one at a time. That approach misses a growing risk: many different suppliers may depend on the same underlying cloud region, identity provider or software component.
Map dependencies, not just vendors
For critical services, record the fourth parties your suppliers rely on. Patterns quickly emerge — several 'independent' vendors may share a single hosting provider.
Plan exits that could actually work
Exit plans are often written to satisfy a requirement rather than to be executed. Test them: could you retrieve your data in a usable format within the notice period? Who would run the service in the meantime?
- Tier suppliers by the criticality of the service they support
- Record fourth-party dependencies for top-tier suppliers
- Test data return and exit assumptions annually
- Report concentration to the board as a distinct risk
Need this applied to your organisation?
Our team can turn this guidance into an action plan for your regulators, systems and timelines.
Book a consultationRelated reading
1 min read
A practical roadmap for Sri Lanka's Personal Data Protection Act
Where to start, what to prioritise and how to show progress to your board — a phased approach to the PDPA for organisations that can't do everything at once.
1 min read
Why compliance programmes fail at evidence, not intent
Most organisations do the right things. Far fewer can prove it on demand. The difference is designing controls around the evidence they produce.
1 min read
AI governance for regulated organisations: five first principles
Most AI risk in regulated firms comes from tools they buy, not models they build. A short set of principles to govern both.
Regulatory notes, monthly
New rules, enforcement themes and practical guidance. One email a month, no promotions.