Vetting
Supplier & Third-Party Vetting
Know what your suppliers actually do with your data — and prove it to your regulator.
The situation
What the client receives
Schedule of deliverables
- Supplier criticality tiering model and risk appetite
- Vetting questionnaires and evidence requirements per tier
- On-site or remote supplier assessments and findings reports
- Security and resilience clauses for contracts and DPAs
- Concentration risk and exit strategy analysis
- Third-party register aligned to NIS2 / DORA reporting formats
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- NIS2 Art. 21(2)(d)
- DORA Ch. V
- ISO/IEC 27036
- ISO/IEC 27001 A.5.19–A.5.23
Related services
Discuss this engagement
Tell us about the supplier estate or the single supplier in question and we will set out the scope, the method and the reporting format.