Skip to content
Supplier oversight

Know your suppliers.
Understand your exposure.

Your security depends on more than your own systems. Bring supplier relationships, assessment evidence and follow-up actions together with Fig Group, so your team knows what needs attention.

Business colleagues discussing documents at a meeting table
A connected approachRelationships. Evidence. Action.

Keep the review and the responsibility together.

From a register to a review

A list of suppliers is not the whole picture.

The useful questions are what each supplier supports, what evidence you hold and what still needs attention. Keep those answers alongside the people responsible for reviewing them.

Network connections in server racks
Understand the dependency

Map the relationship

Record the service provided, the systems and data involved, and the internal owner. Identify critical dependencies so reviews reflect the potential impact on your business.

Supplier monitoring
A professional reviewing printed documents
Establish the evidence

Review the evidence

Bring assessments and supporting documents together. Check the scope and currency of certificates, document shared responsibilities, and record where information is missing or needs clarification.

Controls and evidence
Colleagues coordinating work around laptops
Manage the response

Follow through on findings

Assign actions from supplier reviews, agree deadlines and retain the outcome. Revisit the assessment when a service changes or new information affects your understanding of the risk.

Remediation workflows
A repeatable process

Give each review a clear owner and next step.

Agree the review approach with the teams that own the relationship. A critical hosting provider and a low-impact supplier do not need identical treatment.

Put each relationship in context
Your organisationServices · systems · data
Hosting
Business software
Service partners
Relationship ownerSupporting evidenceNext review

Illustrative relationships, not a live supplier assessment.

  1. Identify suppliers and dependencies

    List the services you rely on, the data and access involved, and the person responsible for each relationship. Prioritise the suppliers whose failure would have the greatest impact.

  2. Assess against your requirements

    Review available evidence against your security requirements and contractual commitments. Record the assessment, missing information, shared responsibilities and any conditions of acceptance.

  3. Manage actions and review changes

    Assign outstanding work, retain decisions and set review dates. Reassess when there is a material change to the service, evidence, access or risk, as well as at the agreed review interval.

Clear responsibilities

Better oversight.
Not a blanket assurance.

Fig Group helps you organise the evidence and the work. Your team retains the decisions.

Explore the Fig Group platform

Be clear about what you can see

An assessment is only as reliable as its evidence. Supplier information, integrations and agreed checks determine what can be monitored. Missing information should remain visible; it is not evidence that a supplier is secure.

Keep risk decisions with your organisation

Your organisation remains responsible for supplier selection, risk acceptance and applicable obligations. Fig Group supports the workflow and evidence record; it does not replace legal advice, an independent assessment or the supplier’s own security responsibilities.

Need specialist support alongside your reviews?

Explore separate engagements for security testing, certification or delivery with your MSP. Scope and permissions are agreed for each service.

Practical answers

Questions before you start.

Practical questions about evidence, responsibility and review frequency.

What is supply chain cyber risk management?

It is the process of identifying and managing cybersecurity risks associated with suppliers and service providers. Start with the services, access and data involved, then assess the evidence and track actions with the relationship owner.

Does a supplier certificate mean no further review is needed?

No. Review the certificate’s scope, validity and relevance to the service you use. It is one source of evidence, not a complete assessment of every risk in the relationship.

Can Fig Group see inside every supplier’s systems?

No. Visibility depends on available information, permissions, integrations and the agreed service scope. Where evidence is unavailable, record that limitation and decide what further information or controls are needed.

How often should we review suppliers?

Set intervals based on the service’s importance, the information involved and your requirements. Review material changes and new findings between scheduled assessments rather than relying only on a calendar date.

What happens if a supplier does not provide evidence?

Record the missing information and follow up with the supplier. The relationship owner should decide whether further checks, contractual changes, compensating controls or a different supplier are needed. Missing evidence should not be treated as a passed check.

Can our MSP help manage supplier risk?

Yes. Your MSP can support the review and follow-up process where responsibilities and access have been agreed. The client organisation should retain ownership of its supplier decisions and risk acceptance.

Speak to Fig Group

Start with your critical suppliers.

Tell us where you need better visibility or follow-through. We will discuss your priorities and the appropriate scope of support.

  • Identify the relationships that matter most
  • Discuss evidence, access and responsibilities
  • Agree a practical next step

An initial conversation to understand your requirements, not an assessment of your suppliers.

Speak to Fig

Tell us what you need. We’ll help you take the next step.

A brief message is all we need to get started.

Supplier-risk assessment factors
FactorSuggested review priorityEvidence to evaluate
Security certificationsHighCertificate scope, validity and relevance to the supplied service; a certificate is one source of evidence.
Patch managementHighUpdate responsibilities, agreed remediation windows and evidence that critical patches are applied.
Incident history and responseHighRelevant disclosures, response arrangements, lessons learned and completed remediation.
Data handlingMediumAccess controls, encryption, residency, retention and the data shared with the supplier.
Business continuityMediumRecovery plans, test results and recovery objectives relevant to the service.
Sub-processor managementMediumThe supplier’s own dependencies, oversight arrangements and material changes.
Contractual securityMediumSecurity commitments, notification terms, audit rights and agreed responsibilities.
Financial stabilityContext dependentAvailable evidence relevant to service continuity and the ability to maintain agreed controls.

These priorities are an illustrative review framework, not a fixed Fig scoring algorithm. Adjust them to the supplier’s criticality, your data and contractual requirements.