What it has to decide
- A tiering model tied to actual exposure
Tier by the data reached and the dependency created, not by contract value. The cheapest supplier is regularly the one with the deepest access.
- What is assessed at each tier, and what is accepted as evidence
State whether a certificate is sufficient, whether you read the report behind it, and whether you check the scope statement. Most organisations collect certificates without ever reading a scope statement, which is where the exclusions live.
- Contract clauses that must be present
Breach notification with a stated period, right to audit, subcontracting restrictions, data location, and return or destruction on exit. Name them, so procurement cannot negotiate them away quietly.
- Fourth parties
Your supplier's suppliers. State whether you require disclosure of material subcontractors and what happens when one changes.
- Ongoing monitoring, not just onboarding
Assessment at onboarding and never again is the common shape. Say what is re-checked and how often, and what triggers an off-cycle review.
- Exit
How data is returned or destroyed, how it is confirmed, and how long the organisation can operate if the supplier disappears tomorrow.
How it is usually got wrong
- The register lists the contracting entity rather than the system, so nobody can answer which suppliers touch customer data.
- A certificate is on file and its scope statement excludes the very service being consumed.
- Onboarding assessment is thorough and there is no re-assessment, so the file describes a company that no longer exists.
- Breach notification is contracted as "prompt", which is unenforceable.
- Exit provisions are written and never tested, so the first attempt at data return happens during an acrimonious termination.
Worked extract
What a decision looks like once it has been madeSuppliers are tiered by the classification of data they process and by the recovery time objective of the service they support, not by contract value. Tier 1 suppliers process Confidential data or support a service with a recovery time objective under four hours. For Tier 1, an independent assurance report is required annually and the scope statement is read and recorded against the specific service consumed; a certificate whose scope excludes that service is not accepted as evidence. All Tier 1 contracts require notification of a security incident affecting our data within twenty-four hours of the supplier becoming aware, disclosure of material subcontractors, and confirmed destruction of data within thirty days of termination. Tier 1 suppliers are re-assessed annually and on any change of ownership, material subcontractor or service location.