中文

Insight · Internal Audit & Assurance

Third-party risk management in an interconnected economy

The risk you inherit is not the risk you assessed — tiering, contracts, monitoring and exit planning.

21 September 2026Internal Audit7 min read

Most companies now assess their suppliers carefully at the point of purchase. Fewer keep assessing them afterwards, and fewer still know who their suppliers’ suppliers are. That gap is where third-party risk actually materialises: not in a failure at onboarding, but in a dependency that grew quietly while nobody was looking.

Tier your suppliers, or the process will tier you

Due diligence applied uniformly is either too heavy to sustain or too light to matter. Three tiers are usually enough:

TierTestTypical treatment
CriticalIf this supplier stopped for a week, operations stop, or there is a regulatory consequence, or it holds sensitive data or system accessFull due diligence, contractual controls, annual review, named internal owner, exit plan
ImportantDisruption is painful and visible but recoverable within weeksAbbreviated due diligence, key clauses in the contract, review every two years
RoutineReplaceable quickly, no sensitive accessStandard terms, no bespoke process — but keep the list, so the tier is a decision rather than an assumption

The useful discipline is forcing the question “what would this look like on Monday morning?” A supplier that punctually delivers a peripheral service and a supplier whose system holds your customer data should not sit in the same tier because both invoices clear thirty days.

Due diligence at onboarding

For a critical supplier, the file should answer: financial standing and ownership, licences required for the service, security and privacy posture, the subcontractors they will rely on, business continuity arrangements, insurance, and references you actually called. Where your own business is subject to anti-money laundering obligations, customer due diligence and screening of counterparties are legal duties rather than good practice, and the same discipline applies to suppliers who are themselves regulated or located in higher-risk jurisdictions.

Two documents repay the effort more than any questionnaire: the ownership chain, and the subcontractor list. A counterparty that is vague about who ultimately controls it, or that discovers its subcontractors only when asked, is telling you something about how it will behave during an incident.

Contracts that do the work

A well-drafted schedule is worth more than a monthly review meeting. The clauses that earn their keep:

AreaWhat to write down
Service levelsMeasurable commitments, how they are reported, and what happens when they are missed — service credits are only useful if someone actually claims them
Security and incidentsA notification deadline in hours, not “promptly”; who investigates; what the supplier owes you afterwards
SubcontractingConsent before engagement, an obligation to flow down equivalent terms, notice of change
Business continuityTested plans, recovery objectives, right to information during an outage
Audit and assuranceA right to audit or to receive acceptable assurance reports, and the obligation to answer follow-up questions
ExitTransition assistance, data return format, deletion on completion, and a defined period of overlap
LiabilityA cap in proportion to the harm the clause is meant to cover — and an honest look at whether your own insurance already covers the same loss

Personal data in a vendor relationship is a legal requirement, not a preference

Where a supplier handles personal data on your behalf, the Personal Data (Privacy) Ordinance (Cap. 486) requires you to adopt contractual or other means to prevent the data being kept longer than necessary, being used for a purpose other than the one you collected it for, and being improperly accessed or processed. In practice that means the contract must address purpose limitation, retention and deletion, security, sub-processor control, assistance with access and correction requests, breach notification, and the return or destruction of data at the end of the relationship. If those terms are not in the agreement, the gap is not a negotiating position — it is a compliance finding waiting to be written up.

Monitoring is the part that gets dropped

Supplier risk management fails on the maintenance, not the paperwork. Three habits keep it alive. First, a calendar: critical suppliers reviewed annually, with the review recorded rather than discussed. Second, event triggers that reopen a file immediately — a breach, a change of ownership, adverse press, a key contact leaving, or a sudden change in pricing. Third, concentration: add up how many of your critical services depend on one cloud provider, one logistics partner, one payment provider or one contract manufacturer. If the answer is “all of them”, the individual assessments were never the real risk picture.

Then go one layer further. The fourth party — your supplier’s data centre, hosting region or manufacturing subcontractor — is where several recent disruptions originated, and it is the layer most organisations cannot describe when asked.

Exit plans belong at onboarding

An exit plan written during termination negotiations is a concession, not a plan. Agree the following while you still have leverage: the format and completeness of returned data, the length of the transition period and who pays for it, what happens to bespoke configurations you funded, and how long the supplier keeps a copy after the relationship ends. For critical suppliers, an exit plan is a one-page document that a successor could work from. If it does not exist, write it this quarter.

Where to start

  1. List your twenty largest and most operationally important suppliers.
  2. Tier them — the argument over the tier is more valuable than the tier itself.
  3. Read the contracts for the five critical ones. Note which of the clauses above are missing.
  4. Fix the two gaps that could hurt you most, starting with personal data.
  5. Put the annual review dates in a calendar and give each critical supplier an internal owner.

That is a fortnight of work, and it converts a paper exercise into something that would make the next incident a shorter conversation.

Ask about a supplier risk review