Building a third-party risk programme that survives contact with a regulator
Six steps, in the order that actually works, and the one most programmes skip.
Step one: map services, not vendors
Start from your important business services and work outward to what they depend on. A vendor list built from accounts payable tells you who you pay, not what would break.
This is the step most often skipped, and skipping it is why so many registers are simultaneously enormous and useless.
Step two: tier by consequence
Tier on what happens if the vendor fails, not on spend. A small supplier holding privileged access to a critical system outranks a large one supplying stationery.
Then let the tier drive the effort. Assessing every vendor to the same depth guarantees the programme either stalls or becomes a formality.
Step three: assess consistently
One model, applied the same way, so results are comparable. Different assessors with different templates produce scores that cannot be ranked against each other, which quietly destroys the value of the exercise.
Step four: watch from outside
A questionnaire tells you what a supplier believed about themselves on the day they filled it in. External monitoring observes their actual exposure continuously: internet-facing infrastructure, leaked credentials, dark-web mentions, breach disclosure.
The two together are considerably stronger than either alone, and the external half requires no cooperation from the supplier, which is exactly what you want when a relationship is deteriorating.
Step five: answer the concentration question
Several critical suppliers depending on the same underlying provider is the scenario the regulations were written about. It is also the one a conventional vendor register cannot show you, because each entry looks independent.
You need the dependency, not just the relationship. Ask suppliers where they host, who they subcontract to, and what their own concentration looks like.
Step six: make evidence a by-product
The assessment history, monitoring record and remediation trail should be the evidence pack. If your programme produces evidence only when asked, the asking is what you will optimise for.
Under DORA in particular, the register of information is far easier to maintain as an operational record than to reconstruct per submission.
Questions, answered
How many vendors should be in the top tier?
Can we monitor suppliers who will not cooperate?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.