← CISM: manage security, risk, and incidents
13 / 15 · 55 MIN

Suppliers, concentration and demonstrable exit

Analyze third-party dependencies and turn an exit clause into an executable plan.

Start with the service and its flows

Assessment begins with what the supplier does for the service, the data it receives and the access it retains. Two companies with the same commercial contract can create very different risks: one queries synthetic pilot data; another administers production and holds customer-information copies. Also record who supplies identity, keys, support and export capability. If procurement asks only for the supplier’s certification, the actual data and control paths remain unclear. The result should let the owner explain which failures affect availability, integrity or confidentiality and over what time horizon.

Apparent diversification

A service uses two suppliers, but both depend on the same message processor and region. The contract count increased; operational independence has not been demonstrated. Map the complete path, including relevant subcontractors, administrative access and supporting services. An alternative reduces the intended concentration only if it can perform the function when the common dependency fails. Request evidence proportionate to criticality and contractual rights, without assuming unlimited access to supplier systems. A refusal to disclose information is uncertainty to address in the decision, not automatic proof of compromise.

Rehearse exit before it is needed

A clause permits data export within 48 hours. The exercise shows that the file omits the link between transactions and corrections needed for reconciliation. Receiving bytes does not prove functional portability. Define acceptance criteria: integrity, completeness, field meaning, required history, import capability and execution of the destination process. Use synthetic data for rehearsal and record expected differences. Compare total export, transformation, loading and validation time with the business window. Both contract and architecture may need adjustment if the result does not meet the objective.

Finish without losing obligations

Exit includes removing access, transferring responsibilities and handling residual copies under applicable requirements. Do not impulsively order all data deleted: retention and evidence-preservation obligations may need assessment by the appropriate owners. Identify who retains what, for how long and under which restrictions. Billing termination does not revoke tokens or remove service accounts. Request evidence specific to the completed scope and track what remains. If a deletion certificate excludes backups, that exclusion must remain visible with an agreed disposition; do not claim complete deletion.

Supplier decision exercise

Consider a critical supplier changing subcontractor three weeks before year-end close. It offers last year’s assurance report covering the former entity. Prepare three requests: changed data flows, evidence applicable to the new scope and containment or deferral options. Then frame the risk decision with an owner and deadline. The response should neither turn old documentation into current coverage nor automatically reject the entire relationship. Summarize what is known, what remains unknown and which condition prevents approval. Reassess when evidence addressing that condition arrives.

IN PRACTICE

The export contains every record but loses links to corrections. The team keeps exit incomplete until destination reconciliation is demonstrated.

Common pitfalls

Counting suppliers as independence; accepting an out-of-scope report; confusing an exported file with a recovered process; declaring exit complete with active accounts.

Related topics: Concentration risk · Portability and decommissioning

Take this idea with you

Assess the relationship throughout its lifecycle. Exit needs verifiable criteria for data, service, access and residual responsibilities.

Create account

Reference: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations · CISM current outline before November 3, 2026

CISM® is a registered trademark of ISACA. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by ISACA. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.