Risk Management

Vendor & Third-Party
Risk Management

Your security posture is only as strong as your weakest supplier. We assess, monitor, and manage the security risk of your entire vendor ecosystem โ€” so you know what risk you're accepting, and what to do about it.

Assessment TypesQuestionnaire ยท Technical ยท On-site
Turnaround5โ€“15 days per vendor
MonitoringContinuous / quarterly
CertificationsCRISC ยท ISO 31000
0Breaches via Third Parties
0Vendors Assessed
0Standard Assessment Turnaround

The Problem

60% of data breaches involve a third party. The SolarWinds attack, the MOVEit breach, the Change Healthcare incident โ€” all exploited trusted vendor relationships. Most organisations have hundreds of vendors with access to their data or systems, but assess fewer than 20% of them. The rest are unknown risks accepted by default. For regulated industries, this is not just a security problem โ€” it is a compliance failure.

Our Approach

01

Vendor Inventory & Classification

We build a complete inventory of all third parties with access to your data or systems and classify them by inherent risk โ€” data sensitivity, system access level, geographic location, regulatory exposure.

02

Risk-Based Assessment Programme

Assessment depth calibrated to vendor criticality: questionnaire-only for low-risk vendors, technical assessment for medium-risk, full security review for critical suppliers. No wasted effort, no blind spots.

03

Security Questionnaire Management

We design, send, and evaluate security questionnaires โ€” SIG Lite, CAIQ, or custom โ€” managing vendor responses, chasing non-responders, and scoring results consistently.

04

Technical Due Diligence

For critical vendors: we review their security certifications, conduct external attack surface assessments, review their penetration test reports, and verify their controls are operational.

05

Continuous Monitoring

We monitor your critical vendors continuously โ€” tracking their external security posture, breach disclosures, certificate lapses, and cyber ratings for degradation signals.

What You Receive

๐Ÿ“‹

Vendor Risk Register

Complete inventory of all third parties with risk ratings, assessment status, and remediation tracking.

๐Ÿ“Š

Vendor Risk Dashboard

Real-time view of your third-party risk posture โ€” by vendor tier, risk category, and assessment status.

๐Ÿ“„

Assessment Reports

Structured assessment reports for each vendor with findings, risk rating, and recommended actions.

๐Ÿ“

Questionnaire Library

Customised security questionnaire templates calibrated to your vendor tiers and industry requirements.

๐Ÿ””

Continuous Monitoring Alerts

Real-time alerts when critical vendors experience breaches, certificate issues, or posture degradation.

๐Ÿ“‹

Board Risk Report

Quarterly third-party risk summary for board and audit committee โ€” aggregated risk posture and trend.

Security Maturity Model

Third-party risk management maturity spans from informal vendor relationships with no oversight to a fully automated, intelligence-led programme that monitors risk in real time.

Initial
Managed
Defined
Measured
Optimizing
Level 01InitialCMMI-1

Where you are

No formal vendor risk programme. Vendors onboarded without security review. No contractual security requirements. No inventory of who has access to what. Breaches discovered via vendor disclosure or news.

No vendor inventoryNo security clausesReactive
Level 02ManagedCMMI-2

Where you are

Basic vendor list maintained. Security questionnaire sent to some vendors on request. Standard security clauses in contracts. Annual review of top 10 vendors. No continuous monitoring.

Basic inventoryAd-hoc questionnairesAnnual reviews
Level 03DefinedCMMI-3

Where you are

Formal TPRM programme. All vendors classified by risk tier. Questionnaire process standardised. Critical vendors reviewed annually, high-risk semi-annually. Minimum security requirements in all contracts. TPRM owner appointed.

Tiered programmeStandardised processContractual requirements
Level 04MeasuredCMMI-4

Where you are

Continuous monitoring of critical vendors. TPRM metrics reported to board. Security requirements flow down through supply chain. Vendor onboarding gate includes security review. 4th-party (sub-processor) risk visible.

Continuous monitoring4th-party visibilityBoard metrics
Level 05OptimizingCMMI-5

Where you are

Real-time vendor risk intelligence. AI-driven risk scoring. Supply chain attack simulation exercises. Vendor security performance embedded in procurement decisions. Ecosystem risk modelling for business continuity planning.

AI risk scoringSupply chain simulationEcosystem modelling

ACE MATES assessment โ†’ Not sure where you sit? Our free 90-minute threat briefing includes a maturity assessment across all security domains.

How We've Helped

โ—‰ Case Study โ€” Anonymised
Nordic Insurance Group โ€” 450+ vendor relationships

A regulatory examination found the client had no formal third-party risk programme. They needed to demonstrate control over vendor risk within 90 days or face supervisory action.

ACE MATES built their TPRM programme from scratch in 90 days โ€” vendor inventory of 457 suppliers, risk classification, questionnaire programme for the top 80 critical vendors, and continuous monitoring for the top 20. We also renegotiated security clauses in 35 critical supplier contracts and established a vendor onboarding gate that is now standard across procurement.

0Vendors Inventoried
0Vendors Assessed in 90 Days
0Programme Built in Days

Transparent Pricing

We publish indicative pricing because you deserve to know the ballpark before a single call.

TPRM Assessment
โ‚ฌ5,000 โ€“ โ‚ฌ10,000
One-time ยท 4โ€“6 weeks
  • Vendor inventory & classification
  • Risk tier assignment
  • Questionnaire programme design
  • Top 20 vendor assessments
  • Vendor risk register
  • Remediation recommendations
  • Board summary report
TPRM Retainer
โ‚ฌ2,500 / month
Ongoing ยท 12-month minimum
  • Continuous vendor monitoring
  • New vendor onboarding assessments
  • Quarterly reassessment of critical vendors
  • Incident response support
  • Regulatory reporting support
  • Annual programme review
  • Unlimited questionnaire management
All prices excl. VAT. Per-vendor assessment pricing available: โ‚ฌ500 (questionnaire only), โ‚ฌ1,500 (technical review), โ‚ฌ4,000 (full due diligence). Volume discounts for 50+ vendor programmes. Cyber rating platform licensing (BitSight, SecurityScorecard) quoted separately.

Why ACE MATES

Nordic Supply Chain Intelligence

We maintain a database of security assessments for 2,500+ Nordic vendors. If we have assessed your supplier before, you benefit from that knowledge โ€” dramatically reducing assessment time and cost.

Regulatory Alignment

Our TPRM programme is designed to satisfy NIS2 Article 21 supply chain requirements, DORA ICT third-party risk requirements, and GDPR Article 28 processor obligations โ€” in one programme, not three.

Pragmatic Risk Rating

We don't treat every vendor equally. Our risk tiering methodology ensures your resources are focused on the vendors that actually matter โ€” not wasted on low-risk stationery suppliers.

Vendor Engagement Expertise

Getting vendors to complete assessments is half the battle. We have vendor relationship playbooks that achieve 95% response rates within 2 weeks, compared to industry average of 60% after 6 weeks.

Frequently Asked Questions

How do we prioritise which vendors to assess?
We classify vendors by inherent risk โ€” combining data sensitivity (what data can they access?), system access (what systems can they reach?), business criticality (what happens if they go down?), and regulatory exposure (are they a sub-processor under GDPR?). Critical vendors get full assessments; lower-risk vendors get questionnaires only.
What is 4th-party risk?
4th-party risk is the risk from your vendors' vendors โ€” the sub-processors and sub-contractors in your supply chain that you have no direct relationship with. For example, if your payroll vendor uses a cloud provider in a jurisdiction with poor data protection โ€” that is 4th-party risk. We make this visible.
How do you handle vendors who refuse to complete assessments?
This itself is a risk signal. We document non-responsive vendors and escalate to your procurement team. For critical vendors, we conduct external assessments using publicly available information โ€” their security certifications, external attack surface data, and breach history.
Can you help us meet NIS2 supply chain requirements?
Yes. NIS2 Article 21(2)(d) requires entities to have measures addressing supply chain security. Our TPRM programme is designed to demonstrate this requirement to competent authorities. We produce NIS2-mapped evidence packages for regulatory examination.
What contractual requirements should we include in vendor agreements?
At minimum: right to audit, breach notification within 24โ€“72 hours, security certification requirements (ISO 27001 or SOC 2), data handling and sub-processor restrictions, penetration testing obligations, and incident response cooperation. We provide contract clause libraries and can review existing agreements.

Know Your Vendor Risk

Start with a free vendor inventory review. Understand your risk before regulators ask.

Start Vendor Risk Programme โ†’โœ‰ Email Us