Make vendor risk decisions traceable to dependency, evidence and action
Connect supplier due diligence, criticality, assurance evidence, findings, incidents, resilience and exit decisions instead of treating third-party risk as an annual questionnaire exercise.
Five vendor-risk decisions that need stronger evidence
The objective is not to score every supplier the same way. It is to understand critical dependencies, collect proportionate evidence, keep findings accountable and know when the risk decision must change.
Supplier due diligence
Supplier due diligence should establish what the supplier or product does, which business process and data it can affect, how critical the dependency is, what is known about ownership and provenance, which foundational cyber practices are evidenced, how resilient the service appears, what sub-tier dependencies matter, and which unresolved risks require treatment before onboarding or renewal.
Open guide →Third-party risk guideVendor criticality
Classify vendors by consequence and dependency. Consider the business service supported, sensitive data handled, privileged or network access, production integration, concentration risk, substitutability, expected outage tolerance and recovery dependency. Use the criticality result to scale due diligence, evidence requests, monitoring, contract controls and incident coordination.
Open guide →Third-party risk guideOngoing assurance
Monitor the conditions that could change the risk decision: evidence freshness, unresolved findings, significant incidents, material service or ownership changes, privileged-access changes, resilience issues, contractual exceptions and remediation commitments. Review frequency should reflect vendor criticality and event triggers, not a fixed annual questionnaire alone.
Open guide →Third-party risk guideVendor incident coordination
Treat the supplier incident as a business dependency problem as well as a vendor issue. Establish affected services and data, create an internal incident owner, preserve available evidence and communications, confirm supplier contacts and notification facts, assess compensating controls and access changes, track recovery dependencies, and keep decisions and unknowns in one timeline.
Open guide →Third-party risk guideVendor offboarding
Verify that accounts, API keys, tokens, certificates, remote access and integrations are revoked or transferred; required data is returned, migrated or disposed of under the applicable agreement; assets and dependencies are updated; unresolved findings and incidents are closed or transferred; and evidence of the exit decision is retained.
Open guide →Third-party risk evidence library
See what should support due-diligence and ongoing-assurance decisions rather than relying on questionnaire completion alone.
Explore evidenceHow Cybatar separates supplier claims from assurance
Read the rules for criticality, evidence freshness, findings, review triggers and explicit non-claims.
Read methodologyResilience & Vendor Assurance
Review the actual Cybatar workflow surface for resilience plans, vendor records, questionnaires, evidence and findings.
Platform capability