Home / Consulting / Third-party risk assessment
Consulting · a bounded assessment
Assess the suppliers you cannot get to.
Name the suppliers. We assess them against a risk-based standard and hand back a decision for each one, with the reasoning attached. Bounded by the batch, not by the month — an assessment with named outputs and a fixed price, not a person on loan.
When this is the right one
The backlog is the problem, or one decision is.
- Due diligence is behind, and new suppliers keep arriving
- A supplier decision was made and cannot now be explained
- Questionnaires come back and nobody has time to read them properly
- Two reviewers reach different answers on the same supplier
- An audit or a customer has asked how suppliers are assessed
- A supplier is secure enough but the service itself keeps underperforming
Most third-party programmes do not fail on method. They fail on throughput — the queue grows faster than the team can clear it, and the answers drift as different people work through it.
An assessment fixes a batch in place: the same standard applied to every supplier in it, by the same reviewers, in one pass, with the basis written down.
Named outputs
Five dimensions, and a decision at the end of them.
Inherent risk rating
A vendor inherent risk assessment, so effort follows exposure rather than arrival order.
Cyber control review
Assessed against ISO 27001 or NIST CSF, with any SOC 2 report read rather than assumed.
Service quality assessment
Functional and non-functional quality against ISO 9126 — whether the service will actually perform, which is a separate question from whether it is secure.
Entity due diligence
Company and financial standing from public sources, not from a referral.
Contract position
Cyber terms reviewed and marked up against a standard clause library.
Findings and a decision
What is wrong, what to ask for and what to accept — then proceed, proceed with conditions, or do not, with the reasoning that supports it.
Scope is set by the batch you name and the depth each supplier’s inherent risk earns. Both are agreed before the work starts, and both appear in the engagement letter with a fixed price against them.
For your reviewers
Where this assessment stops
What it is not
- Not staff augmentation. We assess a named batch and finish; we do not sit in your queue.
- Not a certification, and not an independent audit opinion.
- Not a security rating subscription — we read the ratings you hold, we do not sell them.
- Not legal advice. Contract markup is a cyber-terms review, and your lawyers still sign it.
Prefer to start smaller? Take the two-minute Workflow Failure Check · Or just call (02) 8213 9000.