Home / Consulting / Third-party risk assessment

Consulting · a bounded assessment

Assess the suppliers you cannot get to.

Name the suppliers. We assess them against a risk-based standard and hand back a decision for each one, with the reasoning attached. Bounded by the batch, not by the month — an assessment with named outputs and a fixed price, not a person on loan.

When this is the right one

The backlog is the problem, or one decision is.

  • Due diligence is behind, and new suppliers keep arriving
  • A supplier decision was made and cannot now be explained
  • Questionnaires come back and nobody has time to read them properly
  • Two reviewers reach different answers on the same supplier
  • An audit or a customer has asked how suppliers are assessed
  • A supplier is secure enough but the service itself keeps underperforming

Most third-party programmes do not fail on method. They fail on throughput — the queue grows faster than the team can clear it, and the answers drift as different people work through it.

An assessment fixes a batch in place: the same standard applied to every supplier in it, by the same reviewers, in one pass, with the basis written down.

Named outputs

Five dimensions, and a decision at the end of them.

Inherent risk rating

A vendor inherent risk assessment, so effort follows exposure rather than arrival order.

Cyber control review

Assessed against ISO 27001 or NIST CSF, with any SOC 2 report read rather than assumed.

Service quality assessment

Functional and non-functional quality against ISO 9126 — whether the service will actually perform, which is a separate question from whether it is secure.

Entity due diligence

Company and financial standing from public sources, not from a referral.

Contract position

Cyber terms reviewed and marked up against a standard clause library.

Findings and a decision

What is wrong, what to ask for and what to accept — then proceed, proceed with conditions, or do not, with the reasoning that supports it.

Scope is set by the batch you name and the depth each supplier’s inherent risk earns. Both are agreed before the work starts, and both appear in the engagement letter with a fixed price against them.

For your reviewers

Where this assessment stops

What it is not

  • Not staff augmentation. We assess a named batch and finish; we do not sit in your queue.
  • Not a certification, and not an independent audit opinion.
  • Not a security rating subscription — we read the ratings you hold, we do not sell them.
  • Not legal advice. Contract markup is a cyber-terms review, and your lawyers still sign it.

Fields marked are required. Everything else helps us prepare and can be left blank.

A count and a rough description is enough — “fourteen SaaS vendors added this year”. The batch is what sets the price.

ISO 27001, NIST CSF, your own questionnaire, or nothing settled yet.

An audit, a contract renewal, a backlog, or one supplier decision you need to defend.

A register, a questionnaire, a ratings subscription, past assessments. We build on it rather than starting again.

The person who accepts or rejects a supplier once we report.

A month is fine. It lets us check we can actually start when you want to.

We reply within two business days. The call scopes the batch, the depth and the price, and says plainly if an assessment is not what you need.

If what you need is someone in the queue every week, say so on the call — that is not this, and we will point you to a partner rather than stretch the scope.

Prefer to start smaller? Take the two-minute Workflow Failure Check  ·  Or just call (02) 8213 9000.