Fig Group · Practical resource
Supplier-risk assessment example and worksheet
A useful supplier-risk assessment links the service you depend on to data access, disruption impact, control evidence and a documented decision. This example shows how to record uncertainty and actions before onboarding a supplier.
By Fig Group · Updated
The supplier and findings below are fictional. The example is a practical assessment method, not a real supplier rating, a legal opinion or Fig Group’s proprietary scoring model.
Define the dependency before scoring
Example: a consultancy is evaluating a hosted appointment service. The supplier would hold customer names and contact details. Staff need it to manage daily bookings, and prolonged unavailability would disrupt appointments. The operations lead owns the service; the privacy lead reviews the proposed data handling.
Record where the service operates, what data it processes, whether it has privileged access, important sub-processors and what the business would do if it stopped. A certificate should be checked for issuer, scope, dates and relevance; it does not answer every question about your use of the supplier.
Worked assessment: fictional booking supplier
| Area | Evidence available | Finding and next action |
|---|---|---|
| Access control | A policy describes MFA; privileged-role coverage is not evidenced | Unknown coverage. IT lead requests a scoped configuration report before onboarding. |
| Recovery | Backups are described; the supplied restore test is out of date | Recovery is not yet demonstrated. Operations lead requests a recent restore result. |
| Data handling | Draft processing terms list the data types but omit a sub-processor | Privacy lead asks for complete processing and sub-processor details. |
| Incident contacts | Support email exists; urgent escalation responsibility is unclear | Procurement obtains named escalation roles and contractual notification requirements. |
| Exit | CSV export demonstrated for bookings; attachments are excluded | Service owner tests a complete export and documents the remaining migration work. |
Record a decision with conditions
Illustrative decision: defer onboarding until access-control and recovery evidence has been reviewed. Assign each request an owner and due date. The absence of evidence is recorded as unknown, rather than marked compliant or converted into a reassuring average score.
If the accountable business owner accepts a residual risk, record what remains, why it is accepted, the authority used, conditions and the next review date. Contract approval, privacy review and technical review may require different decision-makers. Reassess after material changes, incidents, expiring evidence or changes in the service’s importance.
Complete a supplier assessment
Identify scope and impact
Name the supplier, service, owner, data, access and critical dependencies. Agree the disruption and confidentiality consequences.
Assess evidence and uncertainty
Request evidence proportionate to the dependency. Record source, scope and date, distinguishing demonstrated controls from claims and unknowns.
Decide and follow through
Document approval, conditions or rejection. Assign actions, acceptance authority and review dates, then verify the evidence supplied to close each gap.
Copy or download the template
Use the blank worksheet in your own document editor. Replace the prompts with your organisation’s details, obtain the relevant approvals and keep a controlled copy.
SUPPLIER-RISK ASSESSMENT Supplier / service / assessment date: Business owner / technical reviewer / privacy reviewer: Data processed and access granted: Locations and sub-processors: Critical business dependency and disruption tolerance: Control or requirement | Evidence/source/date/scope | Finding or uncertainty | Owner | Due date | Closure evidence Access controls | | | | | Recovery and continuity | | | | | Data handling and retention | | | | | Incident notification and contacts | | | | | Sub-processors | | | | | Exit/export/deletion | | | | | Decision: approve / conditional / defer / reject Residual risks and conditions: Decision-maker and authority: Next review / change triggers: Supplier response and verification record:
Explore the workflow in Fig Group
Fig Group’s supplier-risk workflows connect supplier records, assessments, risk context and remediation evidence. Use this fictional case in a demonstration and ask to see ownership, review history and action closure. Confirm any external monitoring feeds and their coverage for your deployment; a monitoring signal is not proof of every supplier control.
Common questions
Is a supplier certificate enough?
It is one input. Check its scope, issuer and validity, then assess your own service dependency, data access, recovery needs and unanswered questions.
How often should we reassess a supplier?
Set a cadence proportionate to criticality and applicable obligations. Review sooner after incidents, material service or data changes, or expiry of important evidence.
Sources and further reading
Use the current source guidance alongside your own requirements when completing the worksheet.