Supplier Security in TISAX Preparation
Your scope does not stop at your perimeter. How to identify third parties that matter, assess them proportionately, and — the part most organisations skip — follow findings to closure.
Supplier security is where readiness programmes most often discover that their scope is larger than they thought. Information moves outward — to cloud services, engineering partners, logistics providers, and subcontractors reached through another supplier — and the obligations move with it.
Start with a register that is actually complete
The first exercise is not assessment. It is discovery.
Ask a specific question rather than a general one. "Which suppliers do we use?" produces the procurement list. "Which third parties access, process, store or transmit information that is in our scope?" produces a different and more useful list.
Sources worth checking beyond procurement:
- Cloud and SaaS subscriptions, including ones bought on a departmental card
- Engineering and development partners who receive technical data
- Logistics and transport providers handling prototype or pre-series material
- Facilities and maintenance contractors with physical access to sensitive areas
- Subcontractors of your suppliers, where a supplier passes work on
That last category is where registers are most commonly incomplete, and it is a reasonable question to put to your critical suppliers directly.
Tier by criticality before assessing anything
Sending the same questionnaire to every supplier produces a large amount of paper and very little security. It also guarantees that the responses will not be read carefully, because there are too many of them.
Tier the register first. A workable set of criteria:
- What information do they access, and how sensitive is it?
- Could their failure stop our production or our customer's?
- Do they have physical access to sensitive areas or material?
- Do they hold information about identifiable people?
- Could they pass our information onward?
Three tiers is usually enough. The top tier gets a real assessment and a real conversation. The middle tier gets a proportionate questionnaire. The bottom tier gets contractual requirements and a periodic check that nothing has changed.
Fifteen serious assessments produce more security than a hundred generic ones, and considerably less resentment.
Agree requirements before information is shared
The sequence matters. Security requirements agreed after information has been shared are requests; agreed before, they are terms.
Practically, this means security requirements belong in the contract or an annex to it, and the point of leverage is before signature. That in turn means security has to be involved in supplier onboarding rather than consulted afterwards — which is an organisational change more than a security one, and usually the harder part.
Assess what you can actually verify
A questionnaire response is an assertion. That is not worthless — an assertion creates accountability — but it is worth knowing what it is.
For critical suppliers, ask for something verifiable alongside the questionnaire: a current certification or assessment result, a summary of their most recent internal audit, evidence of a specific control operating. For the most critical, a conversation with the person who actually runs their security tends to be more informative than any document.
Where a supplier holds a relevant assessment result or certification, understand its scope before relying on it. A certificate covering a different site or a different service is a common and easily missed trap.
Follow findings to closure
This is the step that most distinguishes a real programme from a paper one, and the one most commonly skipped.
Questionnaires come back. Some responses contain concerning answers. Those answers are frequently the most actionable security information the programme will generate — and they are frequently never read, because by the time responses arrive the team has moved on.
What closure requires:
- A finding log separate from the questionnaire responses
- An owner on your side for each finding, not just on theirs
- An agreed date, and a mechanism for what happens if it passes
- Verification — evidence that the thing was actually done, not an email saying it was
An assessment programme with no findings log is a programme that collects opinions.
Reassess on a cycle
Supplier security is not a onboarding-time property. Set a review cycle proportionate to tier, and reassess additionally on change: a new service, a new location, a merger, a significant incident on their side.
A register where every assessment date is two years old describes a programme that ran once.
The evidence this produces
For readiness purposes: the third-party register with criticality tiering; agreed security requirements in contracts or annexes; completed assessments with dates and outcomes; and the follow-up log showing findings raised and closed with verification.
Those four records are what demonstrate supplier security. A folder of returned questionnaires demonstrates that you sent questionnaires.
A note on proportion
It is possible to build a third-party risk programme so demanding that suppliers stop responding to it, or so bureaucratic that your own organisation routes around it.
The programme that works is the one that is small enough to run properly every cycle. If your assessment set takes so long that it slips, reduce its scope rather than its frequency — an annual serious assessment of fifteen critical suppliers beats a biennial attempt at ninety.
For how supplier work fits into the wider programme, see our TISAX readiness guide.
- supplier security
- third-party risk
- assessment
How ready is your organisation?
The free ISAREADY self-assessment covers the themes in this article and returns an indicative readiness view with prioritised next steps.
Start Free Assessment