Skip to main content
Category: Third-Party Risk

Supplier Tiering

Also known as: Supplier Tiers, Vendor Tiering
Simply put

Supplier tiering is the practice of grouping an organization's suppliers into categories, or tiers, based on how important they are to the supply chain and how directly they contribute to the final product. Tier 1 suppliers are typically direct suppliers, while lower tiers represent the suppliers of those suppliers and their subcontractors. This categorization helps an organization understand and manage its network of vendors.

Formal definition

Supplier tiering is the categorization of suppliers and subcontractors into hierarchical tiers according to their proximity to the final product and their importance to the supply chain. In common usage, Tier 1 suppliers are direct suppliers of the final product or to the organization itself; Tier 2 suppliers are the suppliers or subcontractors of Tier 1 suppliers; and Tier 3 (and lower) tiers extend further upstream. As a supply chain risk management technique, tiering supports the identification and prioritization of third-party and multi-tier dependencies, though the specific criteria used to assign tiers may vary by organization, sector, and methodology. This entry does not address implementation specifics, tooling, or jurisdiction-specific supply chain due-diligence obligations.

Why it matters

Supplier tiering matters because organizations rarely have direct visibility beyond their immediate, or Tier 1, suppliers, yet significant risks often originate deeper in the supply chain among the suppliers and subcontractors of those direct suppliers. By categorizing vendors according to their proximity to the final product and their importance to the supply chain, an organization can identify and prioritize third-party and multi-tier dependencies rather than treating all suppliers as equivalent. This prioritization supports more proportionate allocation of due-diligence, monitoring, and risk-treatment effort.

As a supply chain risk management technique, tiering helps surface concentration and dependency risks that would otherwise remain hidden. A disruption, quality failure, or compliance issue at a lower-tier supplier can propagate upstream and affect the organization even where no direct contractual relationship exists. Understanding which suppliers sit at which tier allows risk managers to reason about where a single point of failure might exist and where visibility is weakest.

It is important to note that tiering is a categorization method, not a control in itself; it informs how risks are prioritized but does not by itself reduce them or guarantee any outcome. The specific criteria used to assign tiers may vary by organization, sector, and methodology, and tiering does not address jurisdiction-specific supply chain due-diligence obligations, which differ across regions and industries.

Who it's relevant to

Risk Managers
Risk managers use supplier tiering to identify and prioritize third-party and multi-tier dependencies, directing assessment and monitoring effort toward suppliers whose importance or proximity to the final product presents the greatest exposure. Tiering supports prioritization but does not by itself treat or eliminate the underlying risks.
Procurement and Supply Chain Professionals
Those responsible for procurement and supply chain management rely on tiering to understand the structure of their vendor network, distinguishing direct suppliers from the suppliers and subcontractors that sit further upstream. This helps clarify where visibility is strongest and where dependencies extend beyond direct relationships.
Compliance and Governance Professionals
Compliance and governance professionals may use tiering to organize suppliers for due-diligence and oversight purposes, recognizing that supply chain obligations vary by jurisdiction, sector, and organization. Tiering can inform how such obligations are approached, but this categorization does not itself define the applicable legal requirements.

Inside Supplier Tiering

Tiering Criteria
The defined attributes used to classify suppliers into tiers, commonly including criticality to operations, spend, availability of substitutes, access to sensitive data or systems, and potential impact of a supplier failure or breach. Criteria are typically set to reflect an organization's risk appetite and operational dependencies.
Tier Levels
The discrete categories (for example, strategic or critical, important, and transactional or low-risk) into which suppliers are grouped. The number and naming of tiers vary by organization, sector, and jurisdiction; there is no single universal scheme.
Differentiated Oversight
The practice of applying due diligence, contractual requirements, monitoring frequency, and assurance activities in proportion to a supplier's tier. Higher tiers commonly attract more rigorous onboarding, ongoing review, and reporting than lower tiers.
Risk Assessment Linkage
The connection between tiering and third-party risk management, where tier assignment informs how inherent risk is evaluated and how residual risk is monitored after controls are applied. Tiering supports, but does not replace, supplier-specific risk assessment.
Governance and Ownership
The roles and decision rights that determine who assigns tiers, who approves changes, and how tiering feeds into procurement, risk, and compliance decisions. Ownership commonly sits with procurement or a first-line business function, with second-line risk oversight.
Review and Re-Tiering
The periodic or event-driven reassessment of a supplier's tier as circumstances change, such as shifts in spend, criticality, regulatory exposure, or performance. Tiering is typically treated as a dynamic classification rather than a one-time exercise.

Common questions

Answers to the questions practitioners most commonly ask about Supplier Tiering.

Does supplier tiering rank suppliers by how much money the organization spends with them?
Not primarily. While spend can be one input, supplier tiering in a GRC context typically classifies suppliers by the level of risk they present and their criticality to the organization's objectives, rather than by contract value alone. A low-spend supplier providing a critical service or handling sensitive data may warrant a higher tier than a high-spend supplier of commodity goods. Conflating tiering with spend segmentation is a common misuse, and it can leave significant third-party risks under-managed.
Once a supplier is assigned to a tier, does that classification stay fixed?
No. Tier assignment is generally treated as a point-in-time assessment that may change as circumstances evolve. Changes in the services provided, data access, regulatory scope, the supplier's own risk profile, or the organization's reliance on that supplier can all warrant re-tiering. Many programs re-evaluate tier assignments periodically or upon defined triggering events, so treating a tier as permanent may cause monitoring effort to become misaligned with actual risk over time.
What criteria are commonly used to assign suppliers to tiers?
Criteria vary by organization and sector, but commonly considered factors include the criticality of the service to business operations, the sensitivity and volume of data the supplier can access, the potential impact of a supplier failure or disruption, regulatory or contractual obligations attached to the relationship, and the difficulty of substituting the supplier. Organizations typically define and document these criteria so that tiering is applied consistently and defensibly. The specific weighting and thresholds are matters of program design rather than a universal standard.
How does a supplier's tier relate to the due diligence and monitoring activities applied to it?
Tiering is commonly used to calibrate the depth and frequency of due diligence, assessment, and ongoing monitoring in a risk-based manner. Higher-tier suppliers may be subject to more extensive onboarding assessments, more frequent reviews, stronger contractual controls, and closer performance monitoring, while lower-tier suppliers may receive lighter, less frequent oversight. The intent is to allocate finite assurance resources proportionately to risk. The precise controls attached to each tier should be defined by the organization's policies and may differ across jurisdictions and industries.
How often should supplier tier assignments be reviewed?
There is no single mandated frequency; review cadence is generally a matter of program design and may be shaped by regulatory expectations in a given sector or jurisdiction. Many programs combine periodic reviews with event-driven reassessments triggered by material changes, such as a change in the service scope, a new data-processing arrangement, a significant incident, or a change in regulatory obligations. Documenting the review cadence and triggers supports consistency and auditability.
Who is responsible for maintaining supplier tiering within an organization?
Responsibilities are commonly distributed. Under a three-lines perspective, the business or procurement functions that own supplier relationships typically perform tiering and manage the associated risks as first-line activity, while a second-line function such as risk management or compliance may set the tiering methodology, provide oversight, and challenge assignments. Assurance functions such as internal audit remain independent and would evaluate the design and operation of the tiering process rather than perform it. The exact allocation of roles depends on the organization's operating model and should be defined in its governance documentation.

Common misconceptions

Supplier tiering is the same as a full third-party risk assessment.
Tiering is a classification mechanism that helps prioritize and scale oversight; it informs but does not substitute for a supplier-specific risk assessment. A supplier's tier and its assessed residual risk are related but distinct.
A supplier's tier is fixed once assigned.
Tier assignments commonly change as spend, criticality, data access, or regulatory exposure evolve. Many organizations conduct periodic or event-driven re-tiering, so a tier reflects a point-in-time judgment rather than a permanent status.
Tiering is driven solely by how much is spent with a supplier.
Spend is one common criterion, but tiering typically also weighs criticality to operations, substitutability, and access to sensitive data or systems. A low-spend supplier can warrant a high tier if its failure or breach would carry significant impact.

Best practices

Define transparent, documented tiering criteria that reflect the organization's risk appetite and account for criticality, substitutability, and data or system access rather than spend alone.
Assign clear ownership and decision rights for tier assignment and changes, with first-line business or procurement typically owning the classification and second-line risk providing oversight.
Use tiering to scale due diligence, contractual terms, and monitoring proportionately, applying more rigorous oversight to higher tiers and lighter-touch controls to lower-risk suppliers.
Treat tiering as dynamic by establishing periodic reviews and event-driven triggers for re-tiering when a supplier's spend, criticality, or exposure changes.
Keep tiering integrated with, but distinct from, supplier-specific risk assessments so that classification informs prioritization without replacing detailed evaluation of inherent and residual risk.
Adapt the tiering scheme to the organization's jurisdictional and sectoral context, since applicable obligations and expectations for third-party oversight can differ across regions and industries.
Application Security Isn’t Optional Anymore.