Skip to main content

Cyber Resilience & Supplier Assurance

Managed Supplier Assurance

Ongoing, independent supplier assurance that turns third-party evidence into risk decisions, remediation and continuing oversight — not another round of questionnaires.
Supplier assurance lifecycle
  1. Inventory
  2. Tier
  3. Assess
  4. Challenge
  5. Remediate
  6. Monitor
  7. Report

Ongoing independent supplier assurance that turns third-party evidence into risk decisions, remediation and continuing oversight.

Suited to organisations whose suppliers hold sensitive data, run critical services or face customer and regulatory scrutiny.

One-off due diligence, or a managed capability?

One-off supplier due diligence is a point-in-time assessment of a supplier, usually before contract. It answers whether a supplier looked acceptable on the day it was assessed.

Managed Supplier Assurance keeps that answer current. IG-Smart governs the assurance process, helps set risk-based requirements, reviews and challenges evidence, identifies findings, tracks remediation, supports exception governance, reassesses where agreed and reports the assurance position.

The client selects suppliers, owns commercial decisions, accepts or rejects risk, approves exceptions, determines contractual action and decides whether supplier relationships are retained, restricted or ended.

The questions it answers

From supplier list to continuing oversight

Each stage answers a question procurement, risk or the Board will ask. Select a stage to see who owns what.

Inventory

What happens
Which suppliers do we rely on, and for what? Intake is governed so new suppliers enter the process.
What IG-Smart does
Establishes or reviews the supplier inventory and intake criteria.
What the organisation owns
Supplier selection, appointment and commercial contracting.
Typical output
Governed supplier inventory.

Tier

What happens
Which suppliers need deeper assurance? Suppliers are classified by data, service criticality and regulatory exposure.
What IG-Smart does
Applies an agreed risk-tiering method and sets due-diligence requirements per tier.
What the organisation owns
Approving the tiering criteria and risk appetite.
Typical output
Supplier risk and tiering record.

Assess

What happens
What evidence should we request? Requirements scale with tier and only cover relevant domains.
What IG-Smart does
Requests and reviews evidence across the domains in scope for each supplier.
What the organisation owns
Supplier access and contractual rights to request evidence.
Typical output
Supplier assessment record.

Challenge

What happens
How reliable is the evidence? Claims are tested against what the supplier can actually show.
What IG-Smart does
Challenges gaps, inconsistencies and out-of-date evidence and rates the findings.
What the organisation owns
Engagement with the supplier relationship owner.
Typical output
Evidence review and challenge record.

Remediate

What happens
What gaps matter, and what risk can management accept? Findings become actions or decided exceptions.
What IG-Smart does
Tracks supplier remediation and prepares exception and risk-acceptance records for decision.
What the organisation owns
Operational risk acceptance and internal remediation.
Typical output
Remediation tracker and exception record.

Monitor

What happens
When should suppliers be reassessed? Frequency follows tier, incidents and changes to the relationship.
What IG-Smart does
Runs periodic reassessment and escalates critical supplier concerns.
What the organisation owns
Decisions to continue, change or end a supplier relationship.
Typical output
Reassessment schedule and escalation log.

Report

What happens
What do procurement, risk and the Board need to see? Coverage, exposure and open decisions.
What IG-Smart does
Produces management reporting on assurance coverage, findings and exceptions.
What the organisation owns
Acting on reported exposure.
Typical output
Supplier assurance summary.

IG-Smart provides governance, assessment, challenge and assurance. Selecting suppliers, contracting, accepting operational risk and deciding whether to continue a relationship remain management decisions.

When organisations engage us

Signals that it is time to act

  1. Suppliers hold sensitive or regulated data and assurance is out of date
  2. Questionnaires are collected but rarely challenged
  3. A customer, regulator or auditor has asked how suppliers are assured
  4. Supplier findings stay open with no clear owner
  5. Procurement onboards suppliers faster than risk can review them
  6. A supplier incident exposed gaps in oversight

What the service covers

Outcomes the service is built to deliver

Intake and tiering
Supplier inventory, intake governance and a risk-tiering method that sets due-diligence depth per tier.
Evidence review and challenge
Evidence collected, reviewed and challenged — so findings rest on what suppliers can show, not on what they say.
Findings, remediation and exceptions
Risk findings, tracked remediation, and exception and risk-acceptance records prepared for the right decision-maker.
Reassessment and escalation
Periodic reassessment by tier and prompt escalation of critical supplier concerns.
Multidisciplinary, risk-based scope
Where relevant to a supplier: cyber security, data protection, information governance, resilience and continuity, regulatory requirements, AI and automated systems, subcontractors and fourth parties, and international data transfers. Not every supplier is assessed against every domain.
Management reporting
Assurance coverage, exposure and open decisions reported to procurement, risk and, where needed, the Board.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Baseline the supplier inventory, tiering and current assurance coverage.

  2. Build

    Agree tiering criteria, evidence requirements, owners and reporting.

  3. Manage

    Run assessment, challenge, remediation tracking and exceptions month to month.

  4. Assure

    Report coverage and exposure; escalate critical supplier concerns.

  5. Improve

    Adjust tiering and reassessment as suppliers, incidents and regulation change.

Scope boundaries

Included, and separately scoped where required

Included in the core service

  • Supplier inventory, intake governance and risk tiering
  • Due-diligence requirements per tier
  • Evidence review and challenge
  • Remediation and exception tracking
  • Periodic reassessment and escalation
  • Management reporting

Separately scoped where required

  • Penetration testing of supplier systems
  • On-site supplier audits
  • Legal review of supplier contracts
  • Supplier selection and commercial negotiation

Sample outputs

Example outputs you may receive

Representative reports, registers and records, so you can picture the output before you engage.

Illustrative structure — not a client document. Examples show the type, format and level of detail clients may receive. Exact outputs depend on the agreed scope.

Illustrative output

Supplier Assurance Register

A living view of every in-scope supplier: risk tier, domains assessed, assurance position, owner, outstanding actions and next review. Not every supplier is assessed against every domain.

  • Supplier
  • Tier
  • Domains in scope
  • Position

Likely format

  • IG-Smart branded spreadsheet / register
  • IG-Smart branded PDF
  • Dashboard or reporting capture

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Evidence Review & Challenge Record

Supplier assertion, evidence received and reviewed, challenge raised and the resulting assurance position.

  • Requirement
  • Supplier claim
  • Evidence shown
  • Challenge

Likely format

  • IG-Smart branded spreadsheet / register
  • Evidence pack / supporting records
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Remediation & Exception Record

Findings, actions, owners, due dates, closure evidence and accepted exceptions.

  • Finding
  • Action / exception
  • Decision owner
  • Due

Likely format

  • IG-Smart branded spreadsheet / register
  • Client-system capture (e.g. Jira) where used
  • IG-Smart branded PDF

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Illustrative output

Supplier Assurance Summary

Executive view of assurance coverage, material third-party exposure, unresolved issues, trends and decisions required.

  • Measure
  • This period
  • Direction
  • Decision needed

Likely format

  • IG-Smart branded PDF
  • Dashboard or reporting capture
  • IG-Smart branded spreadsheet / register

The structure, format and level of detail depend on the agreed scope. This is not a client document.

Relevant evidence

Featured supplier-assurance evidence

The named client has approved reference to the third-party supplier relationship; the supplier remains unnamed. The description does not extend the engagement beyond its approved record.

  • Named client · Financial Services

    AIG

    Supplier data-governance audit

    Nationwide supplier audit

    View the evidence: AIG

Explore all case studies →Request Relevant Evidence →

Evidence relevance

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

Subject-matter expert

Michael Abtar

CEO and Founder

Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.

Experience includes governance and assurance work involving more than 100 million consumer records.

View profile

Subject-matter expert

Dr Bright Mawudor

Senior Cyber Security Consultant

Cybersecurity specialist with 10+ years' experience and founder of Africahackon, combining security engineering and technical assurance with expertise in cyber governance, resilience, vulnerability management and organisational risk.

View profile

Client & programme contact

Julia Andrade

Head of Client & Programme Success

A key point of contact from prospective-client scoping through programme and project delivery, coordinating practitioners, workstreams and client stakeholders.

View profile

Related needs

Where this naturally leads

Investment

Starting investment: £5,000 + VAT per month

More complex managed supplier-assurance programmes are scoped according to supplier population, criticality, assessment depth, reassessment frequency, remediation workload and reporting requirements. Scope, deliverables, assumptions and fees are agreed in writing before work begins.

Talk to a Senior Practitioner How engagements & investment work

The fee depends on

  • Supplier population
  • Supplier criticality and tiering
  • Review volume, including new-supplier onboarding
  • Assessment depth
  • Reassessment frequency
  • Remediation workload
  • Jurisdictions
  • Reporting requirements
  • Integration with procurement and risk processes

Questions

Frequently asked questions

Is this just supplier questionnaires?

No. Questionnaires are one input. The service prioritises suppliers by risk, challenges the evidence behind answers, tracks remediation and exceptions, and reports the position so decisions can be made.

Who makes the decision about a supplier?

You do. IG-Smart provides assessment, challenge and assurance. Appointing suppliers, contracting, accepting operational risk and continuing or ending a relationship remain management decisions.

Is every supplier assessed against every domain?

No. Scope is risk-based: each supplier is assessed only against the domains relevant to the data it holds, the service it provides and the regulation that applies.

Can it work with our existing procurement and risk process?

Yes. The service is designed to fit your existing intake, contracting and risk registers rather than replace them.

Next step

Need supplier assurance that leads to decisions, not just questionnaires?

Not sure what applies?Find the Right Service