ISO 27001 Maturity Assessment
Extend Annex A supplier controls with comprehensive ISMS assessment.
Learn moreThird-Party Risk
Evaluate third-party and supply chain cybersecurity risks with a comprehensive vendor assessment framework.
The Third-Party & Supply Chain Security Assessment provides a comprehensive framework for evaluating your organisation's management of vendor and supply chain cybersecurity risks. With 96 questions across 8 domains, this assessment covers the full vendor lifecycle from due diligence through to exit management.
Through structured evaluation criteria aligned to TPRM best practices and regulatory expectations, you will assess your organisation's governance, vendor risk classification, onboarding controls, contractual requirements, ongoing monitoring, incident management, concentration risk, and offboarding processes.
The assessment employs a maturity-based scoring model to help you understand your current TPRM posture, identify programme gaps, and develop a prioritised remediation roadmap for enhanced supply chain security.
This assessment is designed for:
Organisations using this assessment typically gain:
The assessment comprehensively evaluates TPRM across 8 domains:
Important Disclaimer
This assessment is a self-assessment tool designed to help organisations evaluate their third-party risk management programme. It does not constitute a formal TPRM audit, regulatory assessment, or attestation of compliance.
Board-ready overview with maturity scores by TPRM domain, exportable to Word format.
Comprehensive findings mapped to vendor lifecycle stages with risk ratings, exportable to Excel.
Charts showing domain-by-domain programme maturity for Board presentations.
Actionable recommendations ranked by risk for TPRM programme improvement.
Get immediate access to the Third-Party & Supply Chain Security Assessment Tool.
Purchase AssessmentComplement TPRM with broader security assessments.
Extend Annex A supplier controls with comprehensive ISMS assessment.
Learn moreComplement TPRM with broader cybersecurity programme evaluation.
Learn more