Cyber Security
Case Study

Clearing a supplier assurance backlog

An organisation with far more suppliers than it could assess, treating every one of them to the same depth and therefore assuring none of them well.

Supplier assuranceTPRMSupply chain

The challenge

The assurance team had a queue of suppliers awaiting review and a steady flow of new procurements arriving. Every supplier was being sent the same long questionnaire regardless of what they actually accessed.

The result was predictable: the queue grew, business owners routed around the process to avoid delay, and the suppliers that genuinely mattered received no more scrutiny than a low-risk stationery contract.

Our approach

  1. Segment before assessingTier suppliers by what they access, how critical they are to operations, how quickly they could be replaced, and how deeply integrated they are — so effort is directed by consequence.
  2. Match the assurance to the tierReserve deep assessment and evidence review for the suppliers that warrant it, and apply proportionate checks to the rest instead of a single questionnaire for everyone.
  3. Capture intake onceReplace email chains with a single structured intake completed by the business owner, so the tiering happens automatically at the point of request.
  4. Review evidence properlyRead certificates and audit reports for scope and applicability rather than filing them, since a certificate covering the wrong entity or service proves nothing about what you are buying.
  5. Escalate and trackRoute findings into an agreed escalation path with owners and dates, so assurance produces change rather than a record of concerns.

What changed

Assurance effort moved onto the suppliers whose failure would actually hurt, and the process became fast enough for the business to use rather than avoid.

Because tiering happens at intake, the backlog stopped being replenished faster than it could be cleared.

This is an anonymised, representative engagement. We do not publish client names, or figures we cannot substantiate, without explicit permission — in government and critical infrastructure, naming a client can itself be a security concern.

Other case studies

Recognise this situation?

If yours looks similar, the useful first step is usually a conversation about what is actually driving the requirement.