Third-Party Risk & Due Diligence
Understand the risk from your suppliers
Discuss this capability
How this capability helps
Supplier access and dependencies can expose your business to cyber risk.
Suppliers can hold your data, access your systems or support a service your business depends on. An acquisition also brings cyber risks, often before the buyer has enough evidence or contractual influence to address them.
Third-party risk work should identify the dependencies that matter most to the business. The assessment brings together technical evidence, contracts and business context, then considers changes that could affect the relationship.
What it covers
- Supplier tiering, due diligence and monitoring
- M&A cyber review and integration planning
- Concentration, contract and fourth-party exposure
When this helps
- The supplier register does not show who can access your systems and data
- Questionnaire responses do not give you enough information to decide
- A transaction or critical outsourcing decision is approaching
What you receive
- An assessment of suppliers and dependencies based on their risk
- Due-diligence findings that inform actions and deal decisions
- Named owners for fixes, monitoring and decisions to accept risk
Where delivery can go wrong
Specialists need clear responsibilities and a way to resolve decisions that affect each other.
Problems arise when the right expertise is missing or nobody coordinates the work between specialists.
Relying on supplier statements
Supplier statements can help with an assessment, but may not show whether controls work today or how a recent compromise has affected them.
Assessing every supplier in the same way
A supplier with little business impact needs a different level of scrutiny from a processor holding critical data.
Making decisions under a deal deadline
Bring the evidence, contracts and technical review together in time to inform commercial decisions while terms can still be negotiated.
How the process works
Follow each stage to see the decisions and checks needed to complete the work.
The diagram opens with the whole process in view. Zoom in for detail, then drag or scroll within the frame.
Read the process step by step
- New supplier, renewal or acquisition.
- Assess business impact and access to data or systems.
- Critical or high-risk?
- If no: Complete standard evidence and contract review. Approved with review date.
- If yes: Complete enhanced technical and commercial diligence. Continue to the next decision.
- Gaps acceptable?
- If no: Remediate, add contract controls or reject.
- If yes: Approve with obligations and exit terms.
- Record the outcome and monitoring trigger.
- Due-diligence cycle closed.
Business impact
Prioritise suppliers whose access or services could materially affect the business.
Evidence
Distinguish supplier claims and inherited certificates from current technical evidence.
Decision
Decide how to address each finding: fix it, add contractual controls, monitor it, accept the risk or walk away.
How Musketeers coordinates the work
Musketeers keeps the client and specialist teams working to the same plan.
Specialists deliver the technical work. Musketeers coordinates their involvement, tracks decisions and dependencies, and keeps the evidence available until the work is complete.
- 01Group dependencies by their impact on the business
- 02Review the commercial, technical and governance evidence together
- 03Track significant changes, fixes and decisions about risk
