The Skeleton
Policy scaffold

Third-Party and Supply Chain Security Policy

Sets what an organisation requires of the parties it depends on, and what happens when they cannot meet it.

What it has to decide

  1. A tiering model tied to actual exposure

    Tier by the data reached and the dependency created, not by contract value. The cheapest supplier is regularly the one with the deepest access.

  2. What is assessed at each tier, and what is accepted as evidence

    State whether a certificate is sufficient, whether you read the report behind it, and whether you check the scope statement. Most organisations collect certificates without ever reading a scope statement, which is where the exclusions live.

  3. Contract clauses that must be present

    Breach notification with a stated period, right to audit, subcontracting restrictions, data location, and return or destruction on exit. Name them, so procurement cannot negotiate them away quietly.

  4. Fourth parties

    Your supplier's suppliers. State whether you require disclosure of material subcontractors and what happens when one changes.

  5. Ongoing monitoring, not just onboarding

    Assessment at onboarding and never again is the common shape. Say what is re-checked and how often, and what triggers an off-cycle review.

  6. Exit

    How data is returned or destroyed, how it is confirmed, and how long the organisation can operate if the supplier disappears tomorrow.

How it is usually got wrong

  • The register lists the contracting entity rather than the system, so nobody can answer which suppliers touch customer data.
  • A certificate is on file and its scope statement excludes the very service being consumed.
  • Onboarding assessment is thorough and there is no re-assessment, so the file describes a company that no longer exists.
  • Breach notification is contracted as "prompt", which is unenforceable.
  • Exit provisions are written and never tested, so the first attempt at data return happens during an acrimonious termination.

Worked extract

What a decision looks like once it has been madeSuppliers are tiered by the classification of data they process and by the recovery time objective of the service they support, not by contract value. Tier 1 suppliers process Confidential data or support a service with a recovery time objective under four hours. For Tier 1, an independent assurance report is required annually and the scope statement is read and recorded against the specific service consumed; a certificate whose scope excludes that service is not accepted as evidence. All Tier 1 contracts require notification of a security incident affecting our data within twenty-four hours of the supplier becoming aware, disclosure of material subcontractors, and confirmed destruction of data within thirty days of termination. Tier 1 suppliers are re-assessed annually and on any change of ownership, material subcontractor or service location.