The Problem
60% of data breaches involve a third party. The SolarWinds attack, the MOVEit breach, the Change Healthcare incident โ all exploited trusted vendor relationships. Most organisations have hundreds of vendors with access to their data or systems, but assess fewer than 20% of them. The rest are unknown risks accepted by default. For regulated industries, this is not just a security problem โ it is a compliance failure.
Our Approach
Vendor Inventory & Classification
We build a complete inventory of all third parties with access to your data or systems and classify them by inherent risk โ data sensitivity, system access level, geographic location, regulatory exposure.
Risk-Based Assessment Programme
Assessment depth calibrated to vendor criticality: questionnaire-only for low-risk vendors, technical assessment for medium-risk, full security review for critical suppliers. No wasted effort, no blind spots.
Security Questionnaire Management
We design, send, and evaluate security questionnaires โ SIG Lite, CAIQ, or custom โ managing vendor responses, chasing non-responders, and scoring results consistently.
Technical Due Diligence
For critical vendors: we review their security certifications, conduct external attack surface assessments, review their penetration test reports, and verify their controls are operational.
Continuous Monitoring
We monitor your critical vendors continuously โ tracking their external security posture, breach disclosures, certificate lapses, and cyber ratings for degradation signals.
What You Receive
Vendor Risk Register
Complete inventory of all third parties with risk ratings, assessment status, and remediation tracking.
Vendor Risk Dashboard
Real-time view of your third-party risk posture โ by vendor tier, risk category, and assessment status.
Assessment Reports
Structured assessment reports for each vendor with findings, risk rating, and recommended actions.
Questionnaire Library
Customised security questionnaire templates calibrated to your vendor tiers and industry requirements.
Continuous Monitoring Alerts
Real-time alerts when critical vendors experience breaches, certificate issues, or posture degradation.
Board Risk Report
Quarterly third-party risk summary for board and audit committee โ aggregated risk posture and trend.
Security Maturity Model
Third-party risk management maturity spans from informal vendor relationships with no oversight to a fully automated, intelligence-led programme that monitors risk in real time.
Where you are
No formal vendor risk programme. Vendors onboarded without security review. No contractual security requirements. No inventory of who has access to what. Breaches discovered via vendor disclosure or news.
Where you are
Basic vendor list maintained. Security questionnaire sent to some vendors on request. Standard security clauses in contracts. Annual review of top 10 vendors. No continuous monitoring.
Where you are
Formal TPRM programme. All vendors classified by risk tier. Questionnaire process standardised. Critical vendors reviewed annually, high-risk semi-annually. Minimum security requirements in all contracts. TPRM owner appointed.
Where you are
Continuous monitoring of critical vendors. TPRM metrics reported to board. Security requirements flow down through supply chain. Vendor onboarding gate includes security review. 4th-party (sub-processor) risk visible.
Where you are
Real-time vendor risk intelligence. AI-driven risk scoring. Supply chain attack simulation exercises. Vendor security performance embedded in procurement decisions. Ecosystem risk modelling for business continuity planning.
ACE MATES assessment โ Not sure where you sit? Our free 90-minute threat briefing includes a maturity assessment across all security domains.
How We've Helped
A regulatory examination found the client had no formal third-party risk programme. They needed to demonstrate control over vendor risk within 90 days or face supervisory action.
ACE MATES built their TPRM programme from scratch in 90 days โ vendor inventory of 457 suppliers, risk classification, questionnaire programme for the top 80 critical vendors, and continuous monitoring for the top 20. We also renegotiated security clauses in 35 critical supplier contracts and established a vendor onboarding gate that is now standard across procurement.
Transparent Pricing
We publish indicative pricing because you deserve to know the ballpark before a single call.
- Vendor inventory & classification
- Risk tier assignment
- Questionnaire programme design
- Top 20 vendor assessments
- Vendor risk register
- Remediation recommendations
- Board summary report
- Everything in Assessment
- Full vendor inventory (unlimited)
- Questionnaire management (all tiers)
- Contract clause review & update
- TPRM policy & procedure library
- Team training & handover
- GRC platform integration
- 3 months support included
- Continuous vendor monitoring
- New vendor onboarding assessments
- Quarterly reassessment of critical vendors
- Incident response support
- Regulatory reporting support
- Annual programme review
- Unlimited questionnaire management
Why ACE MATES
Nordic Supply Chain Intelligence
We maintain a database of security assessments for 2,500+ Nordic vendors. If we have assessed your supplier before, you benefit from that knowledge โ dramatically reducing assessment time and cost.
Regulatory Alignment
Our TPRM programme is designed to satisfy NIS2 Article 21 supply chain requirements, DORA ICT third-party risk requirements, and GDPR Article 28 processor obligations โ in one programme, not three.
Pragmatic Risk Rating
We don't treat every vendor equally. Our risk tiering methodology ensures your resources are focused on the vendors that actually matter โ not wasted on low-risk stationery suppliers.
Vendor Engagement Expertise
Getting vendors to complete assessments is half the battle. We have vendor relationship playbooks that achieve 95% response rates within 2 weeks, compared to industry average of 60% after 6 weeks.