Start with the service and its flows
Assessment begins with what the supplier does for the service, the data it receives and the access it retains. Two companies with the same commercial contract can create very different risks: one queries synthetic pilot data; another administers production and holds customer-information copies. Also record who supplies identity, keys, support and export capability. If procurement asks only for the supplier’s certification, the actual data and control paths remain unclear. The result should let the owner explain which failures affect availability, integrity or confidentiality and over what time horizon.
Apparent diversification
A service uses two suppliers, but both depend on the same message processor and region. The contract count increased; operational independence has not been demonstrated. Map the complete path, including relevant subcontractors, administrative access and supporting services. An alternative reduces the intended concentration only if it can perform the function when the common dependency fails. Request evidence proportionate to criticality and contractual rights, without assuming unlimited access to supplier systems. A refusal to disclose information is uncertainty to address in the decision, not automatic proof of compromise.
Rehearse exit before it is needed
A clause permits data export within 48 hours. The exercise shows that the file omits the link between transactions and corrections needed for reconciliation. Receiving bytes does not prove functional portability. Define acceptance criteria: integrity, completeness, field meaning, required history, import capability and execution of the destination process. Use synthetic data for rehearsal and record expected differences. Compare total export, transformation, loading and validation time with the business window. Both contract and architecture may need adjustment if the result does not meet the objective.
Finish without losing obligations
Exit includes removing access, transferring responsibilities and handling residual copies under applicable requirements. Do not impulsively order all data deleted: retention and evidence-preservation obligations may need assessment by the appropriate owners. Identify who retains what, for how long and under which restrictions. Billing termination does not revoke tokens or remove service accounts. Request evidence specific to the completed scope and track what remains. If a deletion certificate excludes backups, that exclusion must remain visible with an agreed disposition; do not claim complete deletion.
Supplier decision exercise
Consider a critical supplier changing subcontractor three weeks before year-end close. It offers last year’s assurance report covering the former entity. Prepare three requests: changed data flows, evidence applicable to the new scope and containment or deferral options. Then frame the risk decision with an owner and deadline. The response should neither turn old documentation into current coverage nor automatically reject the entire relationship. Summarize what is known, what remains unknown and which condition prevents approval. Reassess when evidence addressing that condition arrives.
The export contains every record but loses links to corrections. The team keeps exit incomplete until destination reconciliation is demonstrated.
Common pitfalls
Counting suppliers as independence; accepting an out-of-scope report; confusing an exported file with a recovered process; declaring exit complete with active accounts.
Related topics: Concentration risk · Portability and decommissioning
Assess the relationship throughout its lifecycle. Exit needs verifiable criteria for data, service, access and residual responsibilities.
Reference: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations · CISM current outline before November 3, 2026