Vendor risk management programme
A vendor risk management programme is the standing process for knowing which suppliers can reach your data and systems, checking each one in proportion to that reach, and keeping the picture current until the relationship ends. We design and set up that programme, sized so your own people can run it. A one-off read on a single vendor or an acquisition target is a different engagement: third-party risk and cyber due diligence.
What a vendor risk programme covers
- Vendor inventory. Every supplier, one owner each, and what it touches.
- Tier rule. A short rule that sorts vendors by data and access, with the reason recorded.
- Question sets per tier. Light for the bottom, evidence for the top.
- Contract positions. What each tier must commit to, for your counsel to turn into clauses.
- Monitoring calendar and triggers. Reviews on events as well as dates.
- Offboarding checklist. Access closed, data confirmed returned or deleted.
A spreadsheet runs this well for most organizations. When it stops coping, see GRC platform selection.
How vendor tiering works
Tier by reach, not by spend. A payroll provider holding employee social insurance numbers and bank details is top tier. So is a small IT support firm with remote admin access to your domain controllers, even if the contract is tiny. The office catering supplier is not.
Four questions set the tier: what data the vendor holds, what access it has into your systems, whether your service stops if theirs does, and whether it acts on your customers in your name.
Due diligence sized to the tier
The bottom tier gets a one-page form and a recorded decision. The middle tier gets a focused questionnaire with evidence on the answers that matter. The top tier gets evidence review, a check that any SOC 2 report or ISO 27001 certificate covers the service you buy, and a yearly re-review.
The questions themselves are covered in vendor security questionnaires that actually work. AI suppliers need extra questions, set out on shadow AI discovery and AI vendor risk.
Contract clauses and Canadian obligations
Under PIPEDA you stay accountable for personal information a vendor processes for you, and must use contracts or other means to keep its protection comparable. Federally regulated financial institutions also answer to OSFI Guideline B-10 on third-party risk, and BC public bodies carry their own duties under FIPPA.
We set out the security positions each tier should carry: a breach notification clock, the right to receive evidence, limits on subprocessors and data location, and deletion on exit. We are not lawyers; we work alongside your counsel, who drafts the clauses. Sector detail is on security for credit unions and insurers.
Ongoing monitoring and offboarding
Review dates are not enough. Triggers force an early look: a breach notice, a change of ownership, a new subprocessor, or a request for more access than the tier allows.
Offboarding is the step most often skipped. Accounts, API keys and VPN profiles stay live for months after a contract ends; the checklist closes them. Vendor risks above tolerance go in your cyber risk register.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
How is this different from third-party due diligence?
Due diligence is a one-off read on one company, usually against a deal date. A vendor risk management programme is the standing process that covers every supplier you depend on, year after year, including the one added last week. For a single vendor decision or an acquisition, see third-party risk and cyber due diligence.
Where do we start if we have nothing today?
Start with the inventory and the tiers. Until you know which vendors can reach your data or your production systems, any questionnaire you send is effort spent in the wrong place.
How many vendors need a full assessment?
Fewer than most people expect. Only the top tier, the vendors that hold sensitive data, reach production or would stop your service if they failed, gets evidence review and contract attention every year.
Do you run the programme for us?
We design it, set it up with your staff, and can carry out the top-tier assessments alongside them in the first cycle. The aim is a programme your organization runs without us.
Set up a vendor risk programme
Tell us roughly how many suppliers you have and which ones hold your data or reach your systems. The reply says what the first cycle would cover. See also cyber risk and governance.