Supplier and third-party review
Your suppliers handle your systems and your information, but your requirements only count if someone follows them up. We map the supply chain, review the critical suppliers against contracts and regulation, and give you a basis you can act on.
Who it is for and when
Suits organisations that have outsourced operations, development or information handling and need to show that the suppliers actually meet the requirements.
- DORA requires a register of information covering your ICT suppliers and contractual terms.
- The Swedish Cybersecurity Act sets requirements on supply chain security and on reviewing contracts.
- You have outsourced IT operations but no independent picture of how security is handled.
- A procurement or change of ownership requires you to account for your critical suppliers and dependencies.
What we do
- Mapping the supply chain. We list suppliers and subcontractors, which information and systems they handle and how critical they are to the business.
- Requirement and contract review. We go through which security requirements the contracts contain, which are missing against current regulation and where the right to follow up is unclear.
- Review of the critical ones. For the most important suppliers we request and review evidence: certifications, audit reports, incident routines, subcontractors and access management.
- Risk and concentration assessment. We assess the risk per supplier and point out dependencies where you are particularly exposed, for example when several services rest on the same party.
- Report and measures. You get a report with observations per supplier, proposed contract additions and a prioritised action plan.
You get
- A mapped supply chain with criticality per supplier
- A review of security requirements and follow-up rights in the contracts
- A review report for the critical suppliers
- An assessment of concentration risk and dependencies
- A prioritised action plan and proposed contract additions
Scope and price
Usually about a week: mapping, contract review and a review of the suppliers that matter most. Where there are many suppliers we split the work into stages.
The price varies from engagement to engagement and depends on the number of suppliers, how much evidence exists and whether a register of information is to be produced. You get a clear proposal after the first conversation.
How it works
- A first conversation. We listen to your situation and explain how we usually set the work up. You get our assessment straight away, at no cost.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work alongside your organisation, report as we go and hand over so that you can manage the result yourselves.
Frequently asked questions
Do you review the supplier on site?
That depends on the engagement and on what the contract entitles you to. A document review with supporting interviews is often enough. For particularly critical suppliers we propose an on-site review.
What is a register of information under DORA?
A structured record of your contracts for ICT services, with details of supplier, function, criticality and subcontractors. The register must be kept current and be available to the supervisory authority.
We have hundreds of suppliers, do they all need reviewing?
No. The mapping shows which ones are genuinely critical, and the review is aimed there. The rest are handled through contractual requirements and lighter follow-up.
Can you help us set the requirements in our next procurement?
Yes. The observations are readily turned into concrete security requirements and follow-up terms for future contracts.
Would you like to know whether your suppliers live up to the requirements?
Contact us