Suppliers

Supplier and third-party risk management

Many incidents arrive through a supplier: IT support, a cloud service, finance software. NIS2 and DORA require you to manage that risk, and the responsibility stays with you. We tier your suppliers by criticality, check their contracts and leave a working process for new suppliers.

Scope and price are confirmed in writing before work starts.

Discuss your case

The benefit for your organisation

  • You know which suppliers are critical and what happens if one of them stops.
  • You know which requirements are missing from critical suppliers’ contracts and what to renegotiate.
  • New suppliers go through a clear check before they get access.

Supplier risk package

Up to 20 suppliers: a register and criticality tiers, a questionnaire matched to criticality, contract checks for up to 5 critical suppliers and an onboarding procedure.

from €3 900usually 3–4 weeks

Ongoing review

An annual review of critical suppliers, new suppliers and contract changes as part of an external expert role.

from €1 400 / monthwithin an external role

What the rules require

  • NIS2 requires supply-chain security measures, taking into account each direct supplier’s vulnerabilities, the overall quality of its products and its security practices, including secure development (Art. 21(2)(d) and 21(3)).
  • DORA requires an ICT third-party risk policy, a register of information covering all contracts, pre-contract assessment and documented exit strategies (Art. 28), plus mandatory contract provisions (Art. 30). Responsibility does not transfer to the provider.
  • The GDPR requires a contract with every processor acting on your behalf (Art. 28).

How it works

  • A supplier inventory from contracts, finance and IT: who provides what and which data and systems they can reach.
  • Criticality tiers: which services stop if the supplier stops, and what access it has.
  • A questionnaire matched to criticality and a review of answers and evidence for critical suppliers.
  • Contract checks for critical suppliers: security obligations, incident notification, audit rights, subcontractors, data location and exit.

What you receive

  • A supplier register with criticality tiers.
  • An assessment of critical suppliers and a list of risks.
  • A list of missing contract requirements to renegotiate. Legal wording and negotiation are a separate next step.
  • A procedure for new suppliers and annual review. For financial entities: guidance on exit strategies.

After the review we can implement the agreed measures or coordinate your team or a suitable partner. Implementation is quoted separately.

We also know the other side: we prepare ICT providers for banks’ reviews. See the bank supplier pack.

Boundaries

  • This is not a legal contract review.
  • On-site checks at a supplier are agreed separately.
  • Responsibility for supplier risk remains with your organisation.

General information, not a legal opinion.

Discuss your case