Assessment Supply chain

Third-Party / Vendor Risk Assessment

Your suppliers hold your data, run your processes and carry your uptime. A returned questionnaire tells you what they are willing to claim. We tell you what they can evidence.

Service overview

Third-party assessment is where most control environments quietly fail. The organisation is certified, the policies are current, the internal audit is clean, and then a payroll processor with an unpatched file transfer server loses the lot.

ZULTIV assesses your suppliers the way an auditor would assess you: against a defined criterion, on evidence, with a graded finding for every gap. You end up knowing which vendors genuinely carry the controls their contract promises, which need remediation clauses added at renewal, and which represent a risk you should be escalating now.

What is assessed

  • Governance and accountability: who owns security at the vendor, and whether that person has any authority
  • Certifications and attestations: scope statements read properly, not just certificate logos collected
  • Data handling: what they hold, where it lives, who can reach it, and how long it survives
  • Access control: joiner-mover-leaver, privileged access, and their own remote workforce
  • Technical controls: patching cadence, encryption in transit and at rest, logging and monitoring
  • Incident response, notification timelines in the contract versus the ones in their playbook
  • Business continuity, their recovery objectives against your tolerance for their outage
  • Fourth parties: who your vendor depends on, because their concentration risk is now yours
  • Contractual position: audit rights, security schedules, data processing terms and exit provisions

Scope

Scope is agreed in writing before anything begins, because "assess our vendors" means very different amounts of work depending on the answer to three questions: how many, how deep, and how much evidence you are entitled to demand.

Tier review

A whole supplier population classified by criticality and data exposure, so effort lands where the risk is. Usually the right first engagement.

Standard assessment

Evidence-based review of a defined vendor against an agreed criterion, with a graded finding register and a remediation position.

Deep assessment

For critical vendors: interviews, control walkthroughs, sampling and, where your contract permits, an on-site or live systems review.

Approach

01: Classify

We inventory the vendors in scope and tier them by data sensitivity, business criticality and substitutability. Not every supplier deserves the same scrutiny.

02: Set the criterion

We agree what each tier is assessed against: your own control set, ISO/IEC 27001 Annex A, NIST CSF, or a regulator's expectations. The bar is written down first.

03: Collect evidence

Questionnaire, then verification: certificates and their scope statements, SOC 2 reports and their exceptions, policies, tickets, configuration extracts, interviews.

04: Test the claims

Where a control is asserted, we sample it. A stated 30-day patch SLA is checked against actual patch records, not accepted because the box was ticked.

05: Grade and report

Every gap is written with the requirement, the evidence and the shortfall separated, then graded by residual risk to you, not by how awkward it is to raise.

06: Remediate and re-check

You get a remediation position per vendor: accept, remediate by a date, add a contractual clause at renewal, or replace. We re-verify when you are ready.

Key deliverables

Vendor risk register

Every assessed supplier with tier, criterion, residual risk rating and owner: a live document, not a one-off PDF.

Per-vendor assessment report

Scope, method, evidence examined and each graded finding, in a form you can send to the vendor without rewriting it.

Remediation and contract actions

What each vendor must fix, by when, and which gaps are better closed through the contract at the next renewal.

Management summary

A two-page read for your board or risk committee: concentration risk, the vendors that need a decision, and what changed since last time.

Who needs this

  • Organisations certified to ISO/IEC 27001 that must evidence supplier controls under Annex A 5.19 to 5.22
  • Companies whose own customers now send them a supplier security questionnaire every quarter
  • Regulated sectors: BFSI, healthcare, and anyone processing personal data under the DPDP Act as a data fiduciary
  • Teams that outsource development, support or infrastructure and have never verified what those partners actually do
  • Anyone who has just been through a vendor incident and does not want a second one

Standards and frameworks we assess against

The criterion is chosen to fit your obligations, not our convenience. Commonly:

  • ISO/IEC 27001:2022Annex A 5.19 to 5.23 supplier controls
  • ISO/IEC 27036Supplier relationship security
  • SOC 2Trust Services Criteria & report exceptions
  • NIST CSF 2.0Govern & supply chain risk management
  • HIPAABusiness associate obligations
  • DPDP Act, 2023Data processor engagement duties
  • GDPRArticle 28 processor requirements

Frequently asked questions

It is a good signal, and it is not an answer. The question is what the certificate's scope statement covers: it is entirely possible for a vendor to be certified for a business unit, a location or a product line that has nothing to do with the service you buy. Reading that scope statement properly is one of the first things we do.

That is itself a finding, and we report it as one. In practice, the leverage is contractual: audit rights and security schedules agreed at signature are worth far more than requests made afterwards. Where those rights are missing, we tell you what to add at renewal.

Not all of them. Tier the population first, then assess the critical tier properly and handle the rest with a lighter, evidence-checked questionnaire. Spreading equal effort across two hundred suppliers assesses none of them well.

Only if you want us to, and always with your introduction. Some clients prefer we work entirely through their vendor management team; others find an independent assessor asks harder questions and gets straighter answers. Either arrangement works.

Critical vendors annually, and immediately on a material change: an acquisition, a breach, a move to a new sub-processor, or a shift in what data they hold. Lower tiers can run on a longer cycle.

Request an assessment

Discuss your requirement

Tell us roughly how many vendors are in play and what they touch. We will come back with a scope, a method and a number, not a brochure.

WhatsApp Us instead

Everything you share is treated as confidential.