Skip to main content
Category: Third-Party Risk

Supplier Assurance

Also known as: Third-Party Assurance
Simply put

Supplier assurance is the practice of checking that a supplier or other third party can actually support the claims it makes about security, compliance, and responsible business conduct. It typically involves evaluating a supplier's policies and processes before and during a business relationship to reduce the risks of relying on that third party. In many contexts it forms part of procurement and third-party risk activities.

Formal definition

Supplier assurance refers to the set of processes used to evaluate and verify that a third-party supplier can meet stated security, compliance, and corporate social responsibility (CSR) or sustainability expectations, in order to identify and mitigate risks arising from the supplier relationship. It commonly encompasses activities such as evaluating potential suppliers during procurement and assessing a supplier's policies, processes, and functions, often through instruments such as self-assessment questionnaires (SAQs). As a risk management activity, its scope and rigor typically vary by jurisdiction, sector, and the nature of the goods or services procured; the evidence does not establish a single standardized methodology, control set, or maturity model. This entry does not cover specific tooling, contractual terms, or implementation details, and supplier assurance should be distinguished from independent audit or assurance functions where those are separately defined.

Why it matters

Organizations increasingly depend on third parties for critical goods and services, which means that a supplier's weaknesses in security, compliance, or responsible business conduct can become the organization's own exposure. Supplier assurance addresses this by seeking to verify that a supplier can actually support the claims it makes, rather than accepting those claims at face value. Without such verification, an organization may rely on assurances that do not hold up in practice, leaving it exposed to operational, regulatory, and reputational risks arising from the relationship.

Because supplier assurance often forms part of procurement and third-party risk activities, it helps organizations make more informed decisions about which suppliers to engage and how to monitor them over time. Evaluating a supplier's policies, processes, and functions, both before entering a relationship and during it, can surface gaps that would otherwise remain hidden until an incident occurs. This is particularly relevant where suppliers handle sensitive functions such as identity systems, or where expectations extend to corporate social responsibility (CSR) and sustainability.

The scope and rigor of supplier assurance typically vary by jurisdiction, sector, and the nature of what is being procured, and there is no single standardized methodology that applies universally. As a result, its value depends on how well the assurance activities are matched to the specific risks a given supplier relationship presents.

Who it's relevant to

Procurement Professionals
Those responsible for selecting and engaging suppliers use supplier assurance to evaluate potential suppliers before entering a relationship, helping to mitigate the risks associated with the procurement.
Risk Managers
Risk managers rely on supplier assurance as part of third-party risk activities, using it to identify and reduce risks arising from dependence on external suppliers, with rigor scaled to the nature of the relationship.
Compliance Officers
Compliance functions have an interest in verifying that suppliers can support their stated compliance claims, including expectations around CSR and sustainability, which may be assessed through instruments such as self-assessment questionnaires.
Security and Identity Teams
Teams overseeing security, including those managing identity systems, use supplier assurance to check that a third party can substantiate the security claims it makes, rather than accepting those claims without verification.

Inside Supplier Assurance

Due Diligence Assessment
The evaluation of a prospective or existing supplier's financial stability, operational capability, legal standing, and compliance posture before and during engagement. Typically informs onboarding decisions and risk categorisation.
Risk Tiering and Segmentation
The classification of suppliers according to the level of risk they present, commonly based on criticality, data access, spend, geography, or regulatory exposure. Tiering is used to calibrate the depth and frequency of assurance activities rather than applying uniform scrutiny to all suppliers.
Contractual Controls
Provisions embedded in supplier agreements such as right-to-audit clauses, service levels, security and data protection obligations, and reporting requirements. These establish the basis on which assurance can be sought and remedies pursued.
Ongoing Monitoring
Continuous or periodic review of supplier performance, control effectiveness, and changes in the supplier's risk profile throughout the relationship. This distinguishes assurance as a lifecycle activity rather than a one-time onboarding check.
Independent Assurance Evidence
Reliance on third-party attestations, certifications, or audit reports (for example, external audit reports or recognised certifications) as evidence of a supplier's control environment. The value of such evidence depends on its scope, currency, and the independence of the party providing it.
Issue and Remediation Management
The process for logging identified deficiencies, agreeing corrective actions with the supplier, tracking them to closure, and escalating unresolved or material concerns. This links assurance findings to accountable decision-making.

Common questions

Answers to the questions practitioners most commonly ask about Supplier Assurance.

Is supplier assurance the same as having a signed supplier contract or a completed questionnaire?
No. A signed contract or a returned questionnaire is an input to supplier assurance, not the assurance itself. Supplier assurance refers to the activities an organization performs to gain confidence that a supplier meets defined requirements, which typically involves evaluating evidence rather than relying solely on the supplier's own attestations. Contractual clauses establish obligations; questionnaires gather self-reported information. Neither, on its own, confirms that controls are designed and operating effectively. Assurance commonly draws on a combination of self-attestation, independent evidence such as third-party audit reports or certifications, and, where warranted, direct testing or on-site review. Treating a completed questionnaire as equivalent to assurance is a common misuse that can overstate the confidence actually obtained.
Does supplier assurance transfer the organization's own compliance or risk responsibility to the supplier?
Not typically. In many regulatory and framework contexts, outsourcing an activity does not outsource accountability for it; the organization commonly remains responsible for outcomes even where a supplier performs the work. Supplier assurance is a means of managing the risk arising from that retained responsibility, not a mechanism to discharge it. Contractual allocation of liability between the parties is a separate matter and may be shaped by the governing law and the specific agreement. This entry does not address the enforceability of any particular contractual term, which is a legal question dependent on jurisdiction.
How is the depth of supplier assurance usually determined?
The intensity of assurance activity is commonly calibrated to the risk associated with the supplier, often described as a risk-based or tiered approach. Factors frequently considered include the criticality of the service to the organization's objectives, the sensitivity of any data the supplier handles, the substitutability of the supplier, and applicable regulatory expectations for the sector and jurisdiction. Higher-risk relationships may warrant independent audit reports, on-site assessments, or direct control testing, while lower-risk relationships may rely on lighter evidence such as self-attestation. The specific criteria and thresholds vary by organization and are typically defined in a supplier or third-party risk management policy.
What types of evidence are commonly used in supplier assurance?
Evidence sources commonly used include supplier self-attestations and questionnaire responses, independent third-party audit or attestation reports, recognized certifications, and, where justified by risk, direct testing or on-site review by the acquiring organization. Independent evidence generally provides greater confidence than self-reported information because it is produced or validated by a party other than the supplier. The relevance of any certification or report depends on its scope, the period it covers, and whether it addresses the specific services and controls the organization relies upon. This entry does not recommend particular tools or providers.
How does supplier assurance relate to the three lines model?
Responsibilities are commonly distributed across lines. The management function that owns the supplier relationship generally performs first line assurance activities, such as defining requirements and reviewing evidence. A second line function, such as procurement risk, compliance, or a dedicated third-party risk team, may set the framework, provide oversight, and challenge the adequacy of assurance obtained. Internal audit, as a third line assurance function, may independently evaluate whether the supplier assurance process itself is designed and operating effectively, but does not typically own or perform the ongoing supplier management. Keeping these roles distinct helps preserve the independence and objectivity of the assurance provided.
How often should supplier assurance be performed after onboarding?
Assurance is commonly treated as an ongoing activity rather than a one-time event at onboarding, because a supplier's controls, ownership, and risk profile can change over time. Many organizations set periodic reassessment cycles that reflect the supplier's risk tier, with higher-risk relationships reviewed more frequently, and supplement scheduled reviews with event-driven reassessment triggered by incidents, significant changes, or material findings. The specific cadence and triggers vary by organization and by any applicable regulatory expectations, and are typically documented in the relevant policy. This entry does not prescribe a fixed interval.

Common misconceptions

Supplier assurance guarantees that a supplier will not fail or cause a control breach.
Assurance activities reduce and provide visibility into risk; they do not eliminate it. Evidence such as certifications reflects a point in time and a defined scope, and residual risk typically remains after assurance is performed.
Obtaining a supplier's certification or third-party report is sufficient to consider the supplier assured.
The relevance of any attestation depends on its scope, boundaries, date, and the objectivity of the issuer. A certification may not cover the specific services, locations, or controls that matter to the buying organisation, so it should be evaluated rather than accepted at face value.
Supplier assurance is solely a procurement responsibility completed at onboarding.
Effective supplier assurance is typically a shared, ongoing activity spanning the relationship lifecycle, drawing on risk, compliance, information security, and business owners, with second-line oversight distinct from independent assurance provided by internal audit.

Best practices

Apply a risk-tiered approach so that assurance depth and frequency are proportionate to each supplier's criticality and risk profile rather than applying a single standard to all suppliers.
Embed enforceable assurance mechanisms in contracts, such as right-to-audit clauses, security and data protection obligations, and defined reporting requirements, before relying on them.
Critically evaluate the scope, boundaries, and currency of any third-party attestation or certification rather than accepting it as blanket evidence of control effectiveness.
Treat supplier assurance as a lifecycle activity by maintaining ongoing monitoring and periodic reassessment, especially following material changes in the supplier's services, ownership, or risk exposure.
Maintain clear roles between management activities and independent assurance, so that business and second-line monitoring of suppliers is not conflated with the objective review performed by internal audit.
Track identified deficiencies through a documented remediation process with agreed actions, ownership, and escalation paths for unresolved or material concerns.
Application Security Isn’t Optional Anymore.