Vendor Tiering
Definition
The classification of vendors into risk tiers, typically Tier 1 (critical), Tier 2 (significant), and Tier 3 (low), based on factors such as the sensitivity of data shared, the depth of system integration, the regulatory obligations triggered, and the business impact of vendor failure. Tier assignment drives due diligence depth, contractual requirements, and reassessment frequency.
- Typical tiers
- Tier 1 (critical), Tier 2 (significant), Tier 3 (low)
- Tiering factors
- Data sensitivity, system integration depth, regulatory exposure, business impact
- Drives
- Due diligence depth, contractual requirements, reassessment frequency
- Field
- Third-party risk management
Common questions
Why doesn't every vendor get the same level of security review?+
Applying the deepest due diligence to every vendor, including one supplying office stationery, would consume assessment resources without a matching risk reduction, so tiering concentrates the most intensive reviews and contractual controls on vendors that touch sensitive data or critical systems.
What happens when a low-tier vendor's role in the business changes?+
A change such as a new integration granting the vendor access to sensitive systems should trigger a re-tiering review, since the original tier assignment was based on the vendor's relationship at onboarding and can become outdated as that relationship expands.
Related terms
- Due Diligence Questionnaire (DDQ)
- A structured questionnaire sent to a prospective vendor before onboarding, asking the vendor to describe its security controls, certifications, incident history, subprocessor...
- Offboarding Controls
- The set of actions taken when a vendor relationship ends: revoking access credentials, recovering or destroying shared data, terminating network connectivity, and...
- Right-to-Audit Clause
- A contractual provision that gives the organisation the right to audit or assess the vendor's security controls, either directly or through a...
- Subprocessor
- A third party engaged by a vendor (the processor) to perform part of the service that involves the organisation's data. Under GDPR...
- Third-Party Risk
- The information security, operational, legal, or reputational risk introduced to an organisation by its relationships with external parties including vendors, suppliers, cloud...