Supplier & Third-Party Assurance
Supplier Assessments & Audits
Understand a supplier’s risks and controls before making an important decision.
A focused assessment or audit helps you examine relevant evidence, identify gaps and prioritise actions before onboarding, renewal or another significant supplier decision. The engagement can combine document review, interviews and on-site examination where appropriate.
Not sure this is the right service? Find the Right Service
When this service fits
For a specific supplier decision — onboarding, renewal, a concern or a change in what the supplier does for you — where you need an independent, evidence-based view rather than a continuing programme.
A new supplier will hold or process sensitive information
A contract renewal needs evidence, not just a questionnaire
A concern, incident or complaint has been raised about a supplier
The supplier’s service, location or sub-contractors have changed
A regulator, auditor or customer is asking how a supplier was assured
Physical records, facilities or on-site handling are part of the risk
The service
Choose the method the decision needs
Desk-based assessment. We review the supplier’s documentation, policies, certificates and responses against an agreed scope, then test what matters through structured interviews. Suitable where the supplier’s evidence can be examined remotely and the risk does not depend on physical arrangements.
On-site audit. We examine controls where they operate — facilities, physical and environmental security, access arrangements, records handling, retention and disposal — alongside document review and interviews. Suitable where the risk sits in how the supplier actually works on site.
Hybrid. Many engagements combine both: desk review first, then a targeted site visit to the areas the evidence leaves uncertain.
A standalone engagement can be purchased without a retainer. Your organisation remains accountable for the supplier decision; the supplier remains responsible for any remediation.
What changes for your organisation
Outcomes the service is built to deliver
Data protection and information governance
How the supplier meets the relevant obligations for the information it handles for you.
Security controls
Policies, access control, identity verification and audit trails within the agreed scope.
Physical and environmental security
Facility protection and handling arrangements, where on-site work is in scope.
Retention and disposal
How information is kept, returned and destroyed.
Incident response and continuity
How the supplier detects, reports and recovers from incidents.
Contractual and sub-contractor arrangements
Whether commitments and onward dependencies are reflected in practice.
How we deliver
Assess → Build → Manage → Assure → Improve
Assess
Agree the decision, scope, criteria and method (desk, on-site or hybrid).
Build
Request and review evidence; plan interviews and any site visit.
Manage
Optional — continuing supplier assurance is scoped separately.
Assure
Report findings, limitations and prioritised actions.
Improve
Follow-up review of supplier actions, if expressly scoped.
Improve feeds the next Assess cycle, so evidence stays current.
What you receive
The working records this service produces
Illustrative examples of the registers, records and executive reporting that may support the engagement.
- Critical suppliers assessed
- 18 / 22 ▲ 3 this period
- Open supplier findings
- 11 ▼ 4 vs last period
- Evidence requests outstanding
- 6 ▼ 2 vs last period
- Contracts awaiting review
- 4 No change
Supplier risk by tier
Assurance evidence received
74%
- Overdue remediation
- 3
- Reassessments due
- 5
- Matters for escalation
- 2
Illustrative output
Supplier Assurance Dashboard
Ongoing oversight
A recurring view of supplier risk and assurance evidence, so weak suppliers are seen and escalated before they become exposure.
What it helps you see
- Supplier assessment coverage
- Open findings and remediation
- Outstanding evidence requests
- Reassessments and escalations
Likely format
Dashboard / reporting view · Supporting registers and evidence records · Executive PDF summary where agreed
| Area | Finding | Evidence |
|---|---|---|
| Access control | Leaver process not evidenced | Sample review |
| Retention | Schedule in place | Policy + records |
Illustrative output
Supplier Findings Report
Findings
What was examined, what was found and the limits of the review — deliverables are agreed during scoping.
What it helps you see
- Scope and criteria
- Evidence reviewed
- Findings by area
- Limitations
Likely format
| Action | Owner | Priority |
|---|---|---|
| Evidence leaver process | Supplier | High |
Illustrative output
Prioritised Action Plan & Management Summary
Actions
A concise view of the actions required and the decision in front of you.
What it helps you see
- Priority actions
- Supplier owner
- Your decision points
- Summary for leadership
Likely format
Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.
Scope boundaries
What is included, and what is scoped separately
Included in the core service
- Agreed assessment scope and criteria
- Document and evidence review
- Structured interviews
- On-site examination where in scope
- Findings and prioritised actions
- Concise management summary
Separately scoped where required
- Technical penetration testing or vulnerability scanning
- Certification audits or formal certification opinions
- Implementing the supplier’s remediation
- Formal legal opinions on contracts
- Follow-up review, unless expressly scoped
Scope, deliverables and assumptions are agreed in writing before work begins.
Relevant evidence
Relevant supplier assessment and audit evidence
Selected engagements showing independent evidence review and on-site audit capability. The audited supplier is not named.
View the evidence: AIGNamed client · Financial Services
AIG
Supplier data-governance audit
Nationwide supplier audit
View the evidence: A FTSE 100 organisationAnonymised engagement · Technology / SaaS / RegTech
A FTSE 100 organisation
Three-stage governance and audit-readiness plan
Audit-ready UK policies ahead of a third-party maturity assessment
Explore all case studies →Request Supplier Assurance Evidence →
Your IG-Smart team
Specialist expertise, coordinated around your requirement
Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.


Client & programme contact
Julia Andrade
Coordinates scope, practitioners, delivery and stakeholder communication.
View profile
Buyer decisions
Questions before you engage
Is this the right service?
Do we need a retainer?
When is an on-site audit worth it?
What will the engagement involve?
What do you need from us and the supplier?
What remains our responsibility?
Does the audit certify the supplier?
How do we scope and buy it?
What do we receive?
Is a follow-up review included?
Investment
Scoped to requirement
Scope, deliverables, assumptions and fees are agreed in writing before work begins. Where on-site work is required, travel arrangements and associated costs are agreed in advance.
The fee depends on
- Number of suppliers and sites
- Desk-based, on-site or hybrid method
- Breadth of the assessment criteria
- Supplier evidence available
- Travel and timescale
Procurement or supplier-assurance review?
Visit our Trust CentreReady to move forward?
Need an evidence-based view of a supplier before you decide?
Not sure which service applies? Find the Right Service
Still defining your requirement?
Discuss an Assessment or Audit
Discuss the requirement, risk, scope and the right engagement model with an experienced practitioner.
Discuss an Assessment or AuditHave a defined scope, tender or RFP?
Request a Supplier Assessment
Share a defined requirement, RFP, tender, statement of work or existing scope for senior review.
Request a Supplier AssessmentProcurement or supplier assurance
Prepare for Procurement Review
Access company, security and assurance information for supplier review, with controlled evidence available on request.
Open Trust Centre

