Expert TipCommon Mistakes

The #1 Mistake in Supplier Management

Most organisations treat supplier security as a checkbox exercise. Here's why that fails and what to do instead.

Updated 11 Mar 2026

The Mistake

Sending a generic security questionnaire to every supplier once a year and filing the response. This is checkbox compliance, and auditors know it.

Why It Fails

Questionnaire responses are often aspirational, not factual
One-size-fits-all ignores actual risk differences
Annual review cycles miss changes in supplier risk profile
No verification means no assurance

What to Do Instead

1. Classify Suppliers by Risk

Not all suppliers are equal. A cloud hosting provider with access to production data is very different from an office supplies vendor.

2. Tailor Your Approach

Critical suppliers Detailed assessment, contract clauses, regular review, right to audit
Standard suppliers Simplified assessment, standard contract terms
Low-risk suppliers Basic due diligence, standard terms

3. Focus on What Matters

Key questions for critical suppliers:

Do they have ISO 27001 or SOC 2?
What data do they access or store?
What happens if they have a breach?
Can you audit them if needed?

4. Monitor Continuously

Don't wait for annual reviews. Track:

Security incidents involving suppliers
Changes in services or data access
Certification status changes
Contract renewal dates

The Auditor Perspective

Auditors check whether your supplier management is proportionate to risk. They'd rather see a pragmatic, risk-based approach for 10 critical suppliers than a superficial review of 200.

Related Modules

Suppliers
Risk Register

Related Controls / Clauses

A.5.19
A.5.20
A.5.21
A.5.22

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.