Cyber Security
Cyber Security Glossary

Supplier Assurance

The practice of assessing and monitoring the cyber security of third parties, so that risk introduced through the supply chain is understood and managed.

Also known as
Third-party risk management (TPRM)
What it addresses
Cyber risk introduced by suppliers, partners and subcontractors
Where it is required
CAF principle A4, government procurement, and data protection law
Key failure mode
Assessing every supplier equally instead of proportionately

Supplier assurance is how an organisation gains confidence that the third parties it depends on are managing cyber security adequately. It covers assessing suppliers before contract, monitoring them during the relationship, and acting when their security position changes.

It is also referred to as third-party risk management, or TPRM. The underlying problem is straightforward: an organisation can be compromised through a supplier’s weaknesses as easily as its own, and its internal controls stop at the contract boundary.

Done well, it is proportionate and continuous. Done badly, it becomes an annual questionnaire exercise that consumes effort without materially reducing risk.

What good supplier assurance involves

  1. SegmentationDecide how much assurance each supplier actually warrants, based on what they access, how critical they are, and what happens if they fail.
  2. AssessmentUse questionnaires, evidence review and, where the risk justifies it, independent testing — rather than relying on a single questionnaire for every supplier.
  3. Evidence reviewRead certifications, audit reports and policies for scope and applicability instead of simply collecting and filing them.
  4. Continuous monitoringRe-check the supplier’s position during the relationship, so a material change is noticed before it becomes an incident.
  5. RemediationAgree actions with named owners and dates, and track them to closure so findings result in change rather than a record.

Why point-in-time assessment falls short

A questionnaire answered at onboarding describes the supplier on the day they completed it. Staff, systems, subcontractors, certifications and ownership all change, sometimes significantly, well before the next annual review comes round.

Continuous approaches re-check key signals during the relationship — certification status, externally observable posture, breach disclosures and material changes — so that the assurance position reflects the supplier as they are now, not as they were at onboarding.

Where it is required

Supply chain security appears explicitly in the NCSC Cyber Assessment Framework as principle A4, and supply chain expectations run throughout UK government procurement. Departments completing GovAssure need supplier evidence to assess systems their suppliers operate or support.

Data protection law adds separate obligations where a supplier processes personal data, requiring appropriate technical and organisational measures and written terms governing that processing.

Supplier Assurance, answered

What is the difference between supplier assurance and TPRM?
In practice they describe the same activity. Third-party risk management is the more common term in financial services and in the US, whereas supplier assurance is more common in UK government and defence.
Do we need to assess every supplier to the same depth?
No, and attempting to is the most common failure. Assurance effort should be proportionate to the risk a supplier presents — what they access, how critical they are, and the consequence if they fail.
Is a certificate such as ISO 27001 enough on its own?
It is useful evidence rather than an answer. A certificate has a defined scope which may not cover the service you actually buy, and it describes a position at the time of audit rather than today.
How often should suppliers be reassessed?
Rather than a fixed interval for everyone, tie reassessment to risk and to change. Critical suppliers warrant continuous monitoring, while low-risk suppliers may justify little beyond basic checks.

Related terms

Authoritative sources

How we help

We build supplier assurance that is proportionate and continuous — so effort lands on the suppliers that actually matter, and the evidence stays current.