Third-party risk service

Supply Chain & Third-Party Cyber Risk Management

Know which suppliers actually carry your risk before one of them becomes your incident. We tier every supplier by inherent risk, run an assessment scaled to that tier, and track every finding to closure — with evidence attached to every answer, not a spreadsheet nobody trusts.

This is an advisory risk management service. A supplier's tier and assessment score are risk measures prepared by My CISO Partner; they are not a certification of the supplier and do not substitute for your own contractual due diligence.

What the service is

A single system of record for every supplier that touches your risk.

Every supplier is scored on eleven inherent-risk factors — data sensitivity, system and privileged access, network access, regulatory and customer impact, operational dependency, single-point-of-failure exposure and more — and placed into one of four tiers. The tier decides how deep the assessment goes; it is never a flat, one-size-fits-all questionnaire.

  • Tier 1 (Critical) through Tier 4 (Low), computed from the inherent-risk score, with a documented override path when a consultant's judgment differs from the formula — the override always needs a justification, an approver and, where appropriate, an expiration date.
  • An assessment scaled to the tier: Basic, Standard, Enhanced or Critical Supplier, each pulling in more of the question bank as depth increases — a Tier 1 supplier is never assessed with the same shallow set of questions as a low-risk one.
  • An unanswered question is never counted as compliant, and "Not Applicable" is never counted as automatically compliant — the score's denominator is every question on the assessment, so gaps in the record show up in the number, not just the footnotes.
  • Findings and remediation reuse the same evidence and findings engine your internal assessments already use — a supplier finding is never a second, disconnected system.
Who it is for

Any organization whose risk doesn't stop at its own perimeter.

Growing companies scaling vendor relationships

Cloud providers, MSPs, payroll and payment processors — the vendor list grows faster than anyone is tracking what each one can actually touch.

Regulated organizations with vendor-oversight obligations

SOC 2, ISO 27001, HIPAA, GLBA and CMMC all expect documented oversight of the vendors and subcontractors who can reach your data or systems.

Procurement and legal teams

Need a consistent, defensible answer to "did we assess this vendor before we signed" — with the assessment record, not a memory of a call.

Leadership and boards

Who need to know, in plain terms, which handful of suppliers actually carry material risk — not a 200-row spreadsheet with no priority order.

Problems it solves

A vendor list is not a risk program.

Every supplier treated the same

A cleaning contractor and your core cloud host answer the same questionnaire. Tiering means the depth of scrutiny actually matches the risk.

Self-attestation with no evidence

A "yes" on a questionnaire with nothing behind it. Every response can carry attached evidence, and the evidence-coverage score is tracked separately from the answer score.

Assessments that go stale

A vendor assessed once at onboarding and never again. Each supplier carries its own assessment history, so re-assessment on a cadence is a scoped, repeatable action, not a rebuild.

Findings that never get tracked

A gap noted on a call and never followed up. Supplier findings flow into the same findings and remediation register your internal program uses, with an owner and a due date.

No visibility into fourth parties

Your vendor's subcontractors carry your risk too. Fourth-party relationships are recorded against the supplier that introduces them, not left invisible.

Data and system access nobody mapped

What data types can this supplier actually reach, and through which systems? Recorded per supplier, not inferred from the contract months later.

How an assessment moves

One workflow, start to close.

Every supplier assessment moves through the same stages, forward-only, with one documented exception for sending a supplier back into fieldwork after a remediation finding.

DraftSentSupplier StartedIn ProgressSubmittedInternal ReviewCISO ReviewApproved / Remediation Required
  • The question set is filtered to the chosen assessment type at the moment it's created, so a Basic assessment and a Critical Supplier assessment are never the same questionnaire wearing a different label.
  • Submission requires at least one answered question — an assessment cannot be moved to Submitted while every question sits blank.
  • The score recomputes at every stage from Internal Review onward, from the full question set — never from just the questions someone got around to answering.
  • A Remediation Required outcome can send the assessment back into fieldwork — the one documented loop in an otherwise forward-only workflow — and it closes only once the remediation is verified.
What we assess

Thirteen control domains, weighted by your supplier's tier.

Governance

A documented, executive-approved information security policy and program accountability.

Identity & Access Management

Unique accounts, periodic access recertification, and a documented joiner/mover/leaver process.

Multi-Factor Authentication

MFA on remote access, administrative access, and access to the systems covered by the engagement.

Encryption

Data at rest and in transit, and a documented key-management process.

Vulnerability Management

Scanning cadence, remediation SLAs, and coverage across cloud and container workloads.

Incident Response

A documented, tested plan with a defined client-notification timeline.

Business Continuity & Disaster Recovery

A tested plan with documented RTO/RPO for the systems supporting your engagement.

Data Protection & Privacy

Retention and disposal, customer-data segregation, and data-subject request handling.

Personnel Security

Background checks, and annual and role-specific security awareness training.

Subcontractors & Fourth Parties

Inventory and contractual flow-down of security requirements to your supplier's own subcontractors.

Software Supply Chain & SBOM

A software bill of materials, dependency vulnerability monitoring, and protected build pipelines.

AI Governance & Cyber Insurance

AI use disclosure and data-exclusion commitments, plus active cyber liability coverage appropriate to the engagement.

Deliverables

What you receive.

  • A tiered supplier inventory with contacts, contracts, data access and system access recorded per supplier.
  • A completed assessment record per supplier, with the assessment score and evidence-coverage score shown separately, never blended into one number.
  • A findings register with rating, owner, due date and remediation plan per supplier finding.
  • A prioritized view of your highest-tier suppliers, so leadership sees the handful that matter first.
  • A risk-acceptance record for any tier or finding you choose to formally accept rather than remediate, with an expiration so it doesn't silently stand forever.
  • Ongoing program support through your Fractional CISO relationship: re-tiering, re-assessment cadence, and remediation follow-through.
Risk-based, not one-size-fits-all

Depth matched to what a supplier can actually reach.

Eleven inherent-risk factors — from privileged access to single-point-of-failure exposure — decide the tier, and the tier decides how deep the assessment goes. A documented, justified override is available when a consultant's judgment differs from the formula.

Free Supply Chain Risk Assessment

See where your program stands first.

Our free, ten-question Supply Chain Risk Assessment scores your inventory, tiering, evidence and remediation program across five domains — yours to keep, no account required, and a natural first step before an engagement.

Fractional CISO support

Ownership after the assessment.

Supplier risk is not a one-time exercise. Our Fractional CISO service carries the program forward: re-tiering as relationships change, re-assessing on a cadence, and keeping remediation moving.

FAQ

Questions, answered directly.

No. A supplier's tier and assessment score are risk measures prepared by My CISO Partner from the evidence and responses available at the time of assessment. They are not a certification of the supplier, and they don't substitute for your own contractual and legal due diligence.

Today, a consultant collects and enters supplier responses and evidence as part of the engagement. A direct supplier-facing portal, so a vendor can log in and answer their own assessment, is on our roadmap and not yet available.

It counts against the assessment score. The denominator is every question on the assessment, not just the ones that were answered, and "Not Applicable" is never treated as automatically compliant. This is a deliberate design choice, not an oversight.

Fourth-party relationships your suppliers disclose are recorded against the supplier that introduces them, giving you a documented view beyond your direct vendor list. This depends on what your suppliers disclose; it is not independent discovery of undisclosed subcontractors.

Policy resources

Not sure your vendor policy will hold up?

A Third-Party & Vendor Risk Management Policy sample — how vendor risk should be assessed before and during an engagement — is available free from our policy library, alongside 227 other templates spanning governance, risk, privacy, operational and compliance requirements.

Download the Vendor Risk Policy Template →

Start with your highest-risk suppliers.

A short conversation tells us how many suppliers you're managing and where the exposure likely sits. A consultant scopes the tiering and assessment plan from there.

Take the Free AssessmentTalk to a Supply Chain Risk Advisor