Most organisations treat supplier security as a checkbox exercise. Here's why that fails and what to do instead.
Updated 11 Mar 2026
The Mistake
Sending a generic security questionnaire to every supplier once a year and filing the response. This is checkbox compliance, and auditors know it.
Why It Fails
•Questionnaire responses are often aspirational, not factual
•One-size-fits-all ignores actual risk differences
•Annual review cycles miss changes in supplier risk profile
•No verification means no assurance
What to Do Instead
1. Classify Suppliers by Risk
Not all suppliers are equal. A cloud hosting provider with access to production data is very different from an office supplies vendor.
2. Tailor Your Approach
•Critical suppliers Detailed assessment, contract clauses, regular review, right to audit
•Standard suppliers Simplified assessment, standard contract terms
•Low-risk suppliers Basic due diligence, standard terms
3. Focus on What Matters
Key questions for critical suppliers:
•Do they have ISO 27001 or SOC 2?
•What data do they access or store?
•What happens if they have a breach?
•Can you audit them if needed?
4. Monitor Continuously
Don't wait for annual reviews. Track:
•Security incidents involving suppliers
•Changes in services or data access
•Certification status changes
•Contract renewal dates
The Auditor Perspective
Auditors check whether your supplier management is proportionate to risk. They'd rather see a pragmatic, risk-based approach for 10 critical suppliers than a superficial review of 200.
Related Modules
Suppliers
Risk Register
Related Controls / Clauses
A.5.19
A.5.20
A.5.21
A.5.22
26 practitioner guides — included free with your workspace
27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.