
Map the relationship
Record the service provided, the systems and data involved, and the internal owner. Identify critical dependencies so reviews reflect the potential impact on your business.
Supplier monitoringYour security depends on more than your own systems. Bring supplier relationships, assessment evidence and follow-up actions together with Fig Group, so your team knows what needs attention.

Keep the review and the responsibility together.
The useful questions are what each supplier supports, what evidence you hold and what still needs attention. Keep those answers alongside the people responsible for reviewing them.

Record the service provided, the systems and data involved, and the internal owner. Identify critical dependencies so reviews reflect the potential impact on your business.
Supplier monitoring
Bring assessments and supporting documents together. Check the scope and currency of certificates, document shared responsibilities, and record where information is missing or needs clarification.
Controls and evidence
Assign actions from supplier reviews, agree deadlines and retain the outcome. Revisit the assessment when a service changes or new information affects your understanding of the risk.
Remediation workflowsAgree the review approach with the teams that own the relationship. A critical hosting provider and a low-impact supplier do not need identical treatment.
Illustrative relationships, not a live supplier assessment.
List the services you rely on, the data and access involved, and the person responsible for each relationship. Prioritise the suppliers whose failure would have the greatest impact.
Review available evidence against your security requirements and contractual commitments. Record the assessment, missing information, shared responsibilities and any conditions of acceptance.
Assign outstanding work, retain decisions and set review dates. Reassess when there is a material change to the service, evidence, access or risk, as well as at the agreed review interval.
Explore separate engagements for security testing, certification or delivery with your MSP. Scope and permissions are agreed for each service.
Practical questions about evidence, responsibility and review frequency.
It is the process of identifying and managing cybersecurity risks associated with suppliers and service providers. Start with the services, access and data involved, then assess the evidence and track actions with the relationship owner.
No. Review the certificate’s scope, validity and relevance to the service you use. It is one source of evidence, not a complete assessment of every risk in the relationship.
No. Visibility depends on available information, permissions, integrations and the agreed service scope. Where evidence is unavailable, record that limitation and decide what further information or controls are needed.
Set intervals based on the service’s importance, the information involved and your requirements. Review material changes and new findings between scheduled assessments rather than relying only on a calendar date.
Record the missing information and follow up with the supplier. The relationship owner should decide whether further checks, contractual changes, compensating controls or a different supplier are needed. Missing evidence should not be treated as a passed check.
Yes. Your MSP can support the review and follow-up process where responsibilities and access have been agreed. The client organisation should retain ownership of its supplier decisions and risk acceptance.
Tell us where you need better visibility or follow-through. We will discuss your priorities and the appropriate scope of support.
An initial conversation to understand your requirements, not an assessment of your suppliers.
| Factor | Suggested review priority | Evidence to evaluate |
|---|---|---|
| Security certifications | High | Certificate scope, validity and relevance to the supplied service; a certificate is one source of evidence. |
| Patch management | High | Update responsibilities, agreed remediation windows and evidence that critical patches are applied. |
| Incident history and response | High | Relevant disclosures, response arrangements, lessons learned and completed remediation. |
| Data handling | Medium | Access controls, encryption, residency, retention and the data shared with the supplier. |
| Business continuity | Medium | Recovery plans, test results and recovery objectives relevant to the service. |
| Sub-processor management | Medium | The supplier’s own dependencies, oversight arrangements and material changes. |
| Contractual security | Medium | Security commitments, notification terms, audit rights and agreed responsibilities. |
| Financial stability | Context dependent | Available evidence relevant to service continuity and the ability to maintain agreed controls. |
These priorities are an illustrative review framework, not a fixed Fig scoring algorithm. Adjust them to the supplier’s criticality, your data and contractual requirements.