Context: what third-party risk management has to withstand
A software enterprise operating in regulated markets inherits risk from every supplier that processes its data, supports a critical service or sits inside its delivery chain. Customers test that exposure during procurement, auditors test it during SOC 2 and BSI C5 engagements, and investors test it during diligence. A third-party risk programme therefore has to satisfy three audiences simultaneously: the business that needs suppliers onboarded quickly, the assurance functions that need evidence, and leadership that needs a defensible view of residual exposure.
The problems identified
Assessment depth untied to risk
Every supplier attracted broadly the same due diligence, so critical providers received no more scrutiny than low-impact ones while assessment queues lengthened.
Overlapping control frameworks
SOC 2 and BSI C5 obligations were evidenced separately, duplicating effort across assessment cycles and audit preparation.
Detective, not preventive, assurance
Control deficiencies surfaced during audit rather than in the ordinary course of business, compressing remediation windows.
Reporting without a risk narrative
Executive reporting captured assessment throughput but not residual risk, concentration exposure or remediation health.
The redesign
- 01
Risk-tiered due diligence
Policies, standards and control requirements were rewritten so inherent risk — data sensitivity, criticality of the supported service, integration depth and substitutability — determines the depth of assessment, the evidence demanded and the reassessment cadence.
- 02
Control mapping to SOC 2 and BSI C5
Supplier control requirements were mapped once against both frameworks, so a single evidence set satisfies each obligation and the programme remains continuously audit-ready rather than being reconstructed each cycle.
- 03
Second-line controls surveillance
A surveillance capability was established to test control operation independently and identify deficiencies proactively, strengthening assurance coverage ahead of audit and measurably reducing findings.
- 04
Critical supplier review cycle
More than fifty critical supplier reviews are conducted annually, examining resilience, subcontracting, concentration and remediation progress rather than repeating the onboarding questionnaire.
- 05
Executive risk reporting
Reporting was reframed around residual risk, exception ageing and remediation health, giving leadership a defensible view of the supplier estate through IPO readiness.
What I would carry into the next programme
- Tiering is the single highest-return change. Until assessment depth is tied to inherent risk, additional headcount only lengthens the queue.
- Map controls to every applicable framework once. Duplicated evidence gathering is the largest hidden cost in most TPRM functions.
- Assurance must be continuous. A second line that tests control operation between audits converts findings into managed work rather than escalations.
- Report residual risk, not throughput. Boards act on exposure and concentration; assessment counts alone do not support a decision.
Common questions on third-party risk management
- What is third-party risk management?
- Third-party risk management (TPRM) is the discipline of identifying, assessing, treating and monitoring the risks an organisation inherits from its suppliers, vendors and service providers — spanning information security, resilience, privacy, financial stability and regulatory compliance across the full engagement lifecycle.
- How is a third-party risk assessment tiered?
- Assessments are tiered by inherent risk: the data the supplier handles, whether it supports a critical business service, the depth of system integration and its concentration or substitutability. Criticality drives the depth of due diligence, the evidence required and the frequency of reassessment, so scarce assurance effort is spent where the exposure is greatest.
- How does TPRM map to SOC 2 and BSI C5?
- Both frameworks expect documented supplier due diligence, contractual security obligations, ongoing monitoring of critical suppliers and evidence that findings are tracked to closure. Designing TPRM controls so a single set of artefacts satisfies both avoids duplicated assessment cycles and keeps the programme audit-ready.
If you are assessing a third-party risk mandate, I am happy to discuss how this approach would apply to your estate.