Use the business dependency to decide how much assurance you need. A supplier with access to sensitive information needs a different conversation from one with no access to your systems.

Understand the dependency

Ask the business owner what happens if the supplier becomes unavailable or loses information. Record the systems, data, and subcontractors involved in providing the service.

Ask for relevant evidence

Request material that covers the actual service and review period. Record what was examined, what was outside its scope, and which questions remain unanswered.

Decide before connecting

Agree access boundaries, named owners, and unresolved conditions before onboarding. Ask your commercial and legal advisers to document the responsibilities that need to be contractual.

Plan the next review

Define the changes that should trigger reassessment. Include how access is removed, information is returned or deleted, and essential work continues if the relationship ends.

TAKE IT INTO YOUR NEXT MEETING

A starting checklist.

  • Business dependency and supplier owner
  • Systems, data, and access in scope
  • Relevant assurance evidence and gaps
  • Onboarding decision and conditions
  • Review triggers and exit responsibilities
FURTHER READINGNIST cybersecurity supply-chain risk management

This guide provides general planning questions. Adapt them to your environment and agreed assessment requirements.

Back to resources