Skip to main content

Supplier & Third-Party Assurance

Supplier Assessments & Audits

Understand a supplier’s risks and controls before making an important decision.

A focused assessment or audit helps you examine relevant evidence, identify gaps and prioritise actions before onboarding, renewal or another significant supplier decision. The engagement can combine document review, interviews and on-site examination where appropriate.

View relevant evidence — View Relevant Evidence

When this service fits

For a specific supplier decision — onboarding, renewal, a concern or a change in what the supplier does for you — where you need an independent, evidence-based view rather than a continuing programme.

  • A new supplier will hold or process sensitive information

  • A contract renewal needs evidence, not just a questionnaire

  • A concern, incident or complaint has been raised about a supplier

  • The supplier’s service, location or sub-contractors have changed

  • A regulator, auditor or customer is asking how a supplier was assured

  • Physical records, facilities or on-site handling are part of the risk

The service

Choose the method the decision needs

Desk-based assessment. We review the supplier’s documentation, policies, certificates and responses against an agreed scope, then test what matters through structured interviews. Suitable where the supplier’s evidence can be examined remotely and the risk does not depend on physical arrangements.

On-site audit. We examine controls where they operate — facilities, physical and environmental security, access arrangements, records handling, retention and disposal — alongside document review and interviews. Suitable where the risk sits in how the supplier actually works on site.

Hybrid. Many engagements combine both: desk review first, then a targeted site visit to the areas the evidence leaves uncertain.

A standalone engagement can be purchased without a retainer. Your organisation remains accountable for the supplier decision; the supplier remains responsible for any remediation.

What changes for your organisation

Outcomes the service is built to deliver

  • Data protection and information governance

    How the supplier meets the relevant obligations for the information it handles for you.

  • Security controls

    Policies, access control, identity verification and audit trails within the agreed scope.

  • Physical and environmental security

    Facility protection and handling arrangements, where on-site work is in scope.

  • Retention and disposal

    How information is kept, returned and destroyed.

  • Incident response and continuity

    How the supplier detects, reports and recovers from incidents.

  • Contractual and sub-contractor arrangements

    Whether commitments and onward dependencies are reflected in practice.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Agree the decision, scope, criteria and method (desk, on-site or hybrid).

  2. Build

    Request and review evidence; plan interviews and any site visit.

  3. Manage

    Optional — continuing supplier assurance is scoped separately.

  4. Assure

    Report findings, limitations and prioritised actions.

  5. Improve

    Follow-up review of supplier actions, if expressly scoped.

Improve feeds the next Assess cycle, so evidence stays current.

What you receive

The working records this service produces

Illustrative examples of the registers, records and executive reporting that may support the engagement.

Supplier Assurance Dashboard · Q3 periodIllustrative data — not client data
Overall positionAmber — improving
Critical suppliers assessed
18 / 22
▲ 3 this period
Open supplier findings
11
▼ 4 vs last period
Evidence requests outstanding
6
▼ 2 vs last period
Contracts awaiting review
4
No change

Supplier risk by tier

  • High2
  • Medium3
  • Low2

Assurance evidence received

74%

Overdue remediation
3
Reassessments due
5
Matters for escalation
2

Illustrative output

Supplier Assurance Dashboard

Ongoing oversight

A recurring view of supplier risk and assurance evidence, so weak suppliers are seen and escalated before they become exposure.

What it helps you see

  • Supplier assessment coverage
  • Open findings and remediation
  • Outstanding evidence requests
  • Reassessments and escalations

Likely format

Dashboard / reporting view · Supporting registers and evidence records · Executive PDF summary where agreed

Supplier Findings ReportIllustrative data — not client data
Illustrative Supplier Findings Report
AreaFindingEvidenceRating
Access controlLeaver process not evidencedSample reviewMedium
RetentionSchedule in placePolicy + recordsLow

Illustrative output

Supplier Findings Report

Findings

What was examined, what was found and the limits of the review — deliverables are agreed during scoping.

What it helps you see

  • Scope and criteria
  • Evidence reviewed
  • Findings by area
  • Limitations

Likely format

Prioritised Action Plan & Management SummaryIllustrative data — not client data
Illustrative Prioritised Action Plan & Management Summary
ActionOwnerPriorityDecision
Evidence leaver processSupplierHighCondition of renewal

Illustrative output

Prioritised Action Plan & Management Summary

Actions

A concise view of the actions required and the decision in front of you.

What it helps you see

  • Priority actions
  • Supplier owner
  • Your decision points
  • Summary for leadership

Likely format

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Scope boundaries

What is included, and what is scoped separately

Included in the core service

  • Agreed assessment scope and criteria
  • Document and evidence review
  • Structured interviews
  • On-site examination where in scope
  • Findings and prioritised actions
  • Concise management summary

Separately scoped where required

  • Technical penetration testing or vulnerability scanning
  • Certification audits or formal certification opinions
  • Implementing the supplier’s remediation
  • Formal legal opinions on contracts
  • Follow-up review, unless expressly scoped

Scope, deliverables and assumptions are agreed in writing before work begins.

Relevant evidence

Relevant supplier assessment and audit evidence

Selected engagements showing independent evidence review and on-site audit capability. The audited supplier is not named.

  • Named client · Financial Services

    AIG

    Supplier data-governance audit

    Nationwide supplier audit

    View the evidence: AIG
  • Anonymised engagement · Technology / SaaS / RegTech

    A FTSE 100 organisation

    Three-stage governance and audit-readiness plan

    Audit-ready UK policies ahead of a third-party maturity assessment

    View the evidence: A FTSE 100 organisation

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

  • Subject-matter expert

    Michael Abtar

    LLB (Hons), PG.Dip.Law, Cert. DPO

    View profile
  • Client & programme contact

    Julia Andrade

    Coordinates scope, practitioners, delivery and stakeholder communication.

    View profile

Buyer decisions

Questions before you engage

Is this the right service?

Do we need a retainer?

No. A standalone assessment or audit can be purchased on its own. If you later want continuing oversight, Managed Supplier Assurance is scoped separately.
Managed Supplier Assurance

When is an on-site audit worth it?

When the risk depends on how the supplier operates physically — facilities, records handling, access or disposal — or when documentary evidence leaves material questions unanswered. Otherwise a desk-based assessment is usually proportionate.

What will the engagement involve?

What do you need from us and the supplier?

A named contact on each side, the supplier’s agreement to participate, access to relevant documents and people, and site access where on-site work is in scope.

What remains our responsibility?

Does the audit certify the supplier?

No. It gives an independent, evidence-based view against the agreed scope at a point in time. It is not a certification and does not transfer accountability for the supplier decision.

How do we scope and buy it?

What do we receive?

Typically a findings report, prioritised actions and a concise management summary. The exact deliverables are agreed during scoping.

Is a follow-up review included?

Only if expressly scoped. A follow-up can check whether the supplier has completed agreed actions.

Investment

Scoped to requirement

Scope, deliverables, assumptions and fees are agreed in writing before work begins. Where on-site work is required, travel arrangements and associated costs are agreed in advance.

The fee depends on

  • Number of suppliers and sites
  • Desk-based, on-site or hybrid method
  • Breadth of the assessment criteria
  • Supplier evidence available
  • Travel and timescale

Procurement or supplier-assurance review?

Visit our Trust Centre

Ready to move forward?

Need an evidence-based view of a supplier before you decide?

Not sure which service applies? Find the Right Service

  • Still defining your requirement?

    Discuss an Assessment or Audit

    Discuss the requirement, risk, scope and the right engagement model with an experienced practitioner.

    Discuss an Assessment or Audit
  • Have a defined scope, tender or RFP?

    Request a Supplier Assessment

    Share a defined requirement, RFP, tender, statement of work or existing scope for senior review.

    Request a Supplier Assessment
  • Procurement or supplier assurance

    Prepare for Procurement Review

    Access company, security and assurance information for supplier review, with controlled evidence available on request.

    Open Trust Centre