Skip to content
Fig platform · protect

Supplier Risk MonitoringConnected to the bigger picture.

Monitor suppliers, dependencies, control evidence and remediation actions without relying on annual questionnaires alone.

IT specialist inspecting computer hardware
What this means for your team
  • Map suppliers to services and data.
  • Track assurance evidence and actions.
  • Surface third-party risk before renewal or procurement decisions.
The practical difference

See supply chain risk as part of your operating model.

Third-party vendor risk is assessed once per contract, then forgotten. Supplier compliance drifts. Breaches at critical partners go undetected until they impact you.

01

Continuous Assessments

Automated control assessments via questionnaires, audit reports, and external scanning. Compliance status refreshes monthly without manual chase-ups.

02

Risk Scoring

Suppliers scored by controls coverage, remediation responsiveness, and breach history. Portfolio risk visualised by criticality and risk tier. Integrates with SecurityScorecard, BitSight, and EcoVadis for external risk signals.

03

Incident Propagation

Supplier breaches, CVEs, and compliance lapses trigger automatic risk recalculation and escalation workflows for dependent systems.

04

Audit Trail

Complete vendor risk history documented for regulatory oversight. Assessment responses and remediation evidence pre-packaged for auditors. Includes data processing agreement (DPA) lifecycle management and sub-processor cascade tracking.

Plan your next step

What to know before you choose.

Fig Group brings supplier assessments, risk context and follow-up actions into one workflow. Start with the service a supplier delivers, the information it can access and the business impact of failure, then use evidence to decide the review and treatment required.

How should we onboard and score a supplier?

Record the supplier owner, service, data access, dependencies and contract context before assessing controls. Review questionnaire answers alongside supporting documents and available external signals. Keep inherent criticality, evidence gaps and residual risk distinguishable; missing evidence is unknown, not proof that a control passed.

How often should supplier risk be reviewed?

Agree a review cadence based on criticality, contractual obligations and evidence expiry. Reassess when a service changes, a material incident occurs or remediation is overdue. Confirm the refresh frequency of each connected source during onboarding; an annual questionnaire and a frequently updated external signal provide different coverage.

What can external supplier monitoring tell us?

External signals can identify issues that warrant investigation, but they do not establish the effectiveness of every internal control or guarantee that a supplier is safe. Confirm the supported feeds and assessment paths in your scope. Assign an owner to investigate material changes, request evidence and escalate unresolved risk to the authorised decision-maker.

A worked workflow

A fictional payroll supplier holds employee information but supplies an expired assurance report. Record the evidence gap, request a current report and assign a review deadline. The owner decides whether temporary acceptance is justified, with conditions and a review date; the expired report is not counted as current assurance.

Ask to see the supplier assessment, its supporting evidence, the resulting action and the approval history together. Confirm how an overdue response is surfaced.

Discuss this workflow with Fig
Inside Fig

See the work.
Keep the evidence.

Explore the supplier governance view within the Fig platform.

A tailored walkthrough lets you review the relevant workflows, supported connections and reporting before deciding whether Fig is right for your team.

See it in a demo
Fig supplier governance overview showing contract coverage, criticality and review status
Fig mobile app Home screen showing framework compliance, monitoring coverage and device posture
Fig platform · Supplier governance
Built around your role

One platform. Different responsibilities.

Bring delivery, oversight and assurance together without losing sight of who owns the next action.

Colleagues working together with laptops in an office

MSPs & MSSPs

Third-party risk management for your entire client base. White-label vendor assessments and risk reporting strengthen your MSP compliance story.

Explore Fig for MSPs
Business team discussing shared priorities

In-house teams

Board and risk committee visibility into supplier compliance. Automate vendor audits and reduce due diligence workload for procurement and legal teams.

Explore Fig for organisations
Reviewing business records and supporting documentation

Compliance & audit teams

Documented vendor risk assessments, remediation tracking, and breach impact analysis for third-party risk control audits.

Discuss your requirements
A considered start

Evaluate the fit. Then agree the rollout.

Start with the outcomes you need. We will discuss scope, delivery and commercial terms with you before you commit.

  1. 1

    Start with critical suppliers

    Agree the first supplier group, service owners, data access and dependency records. Identify the evidence needed for approval.

  2. 2

    Review the assessment method

    Choose relevant questions and available sources, document the scoring approach and agree how unknown or expired evidence will be handled.

  3. 3

    Exercise escalation and review

    Follow an unresolved finding through an assigned action and approval decision. Set the next review and material-change triggers before expanding coverage.

Platform functionality and automation depend on the agreed scope, configuration and connected systems. Software supports your compliance programme; it does not replace an independent assessment or guarantee certification.

Before you decide

Your questions, answered.

Need to discuss a specific requirement or client scenario?

Speak to Fig
Do suppliers have to complete questionnaires?

Fig Group offers multiple assessment paths: automated external scans (no supplier action), questionnaires (email-based), and integration with vendor risk platforms. Choose the path that suits your supplier relationships.

How do we identify critical suppliers?

You define supplier criticality based on data access, system dependencies, or regulatory scope. Risk scores then emphasise critical suppliers, ensuring your team focuses remediation efforts where impact is highest.

How many suppliers can we monitor?

There is no limit. Fig Group scales from a handful of critical suppliers to hundreds of vendors. Risk scoring and alerting apply consistently regardless of portfolio size.

What if a supplier refuses to complete an assessment?

Fig Group flags non-responsive suppliers and escalates them through your defined workflow. You can also assess non-responsive suppliers using external scanning data alone, which gives you a partial risk score without requiring any supplier action.

Can we share supplier risk reports with our own customers?

Yes. MSPs can generate white-labelled supplier risk summaries for their clients. Reports show assessment status, risk scores, and remediation progress without exposing your internal methodology or scoring logic.

Practical resource

Supplier-risk assessment example and worksheet

A useful supplier-risk assessment links the service you depend on to data access, disruption impact, control evidence and a documented decision. This example shows how to record uncertainty and actions before onboarding a supplier.

Use the guide and template
Take the next step

See how supplier risk monitoring could work for you.

Tell us what you would like to achieve. We will arrange a relevant conversation about the platform, your requirements and the right next step.

  • A walkthrough focused on your priorities
  • Clarity on scope, connections and delivery
  • A discussion of pricing for your requirements

Speak to Fig

Tell us what you need. We’ll help you take the next step.

A brief message is all we need to get started.