Third Party and Vendor Risk

Your security perimeter includes every supplier holding a login. Support vendors with standing administrative access, cloud providers processing personal information, and contractors whose accounts were never removed all sit inside the boundary regardless of what the network diagram shows. Under POPIA you remain accountable for operators acting on your behalf, which makes this a compliance question as much as a security one.

1

Inventory

Who has access to what

2

Tier

Rank by exposure

3

Assess

Their controls

4

Contract

Clauses versus reality

5

Monitor

Offboard and review

How We Assess

01

Vendor and Access Inventory

We build the list, which rarely exists. Procurement knows who is paid; IT knows who has accounts; the two lists never match. Dormant accounts belonging to suppliers whose contracts ended years ago are a routine finding.

02

Risk Tiering

Not every supplier warrants the same scrutiny. A cleaning contractor and a payroll bureau present different exposure, and treating them identically wastes effort on one while under assessing the other.

03

Supplier Control Assessment

For higher tier suppliers we assess their actual controls, through questionnaires, certification review and, where warranted, direct enquiry. A supplier unwilling to answer is itself a finding worth reporting.

04

Contract and Operator Review

We compare what the contract permits against what the supplier can technically reach. POPIA requires written operator agreements with specific provisions, and older contracts predating the Act frequently lack them entirely.

05

Offboarding and Ongoing Review

Vendor risk is not a one off assessment. Access has to be removed when a contract ends, and higher tier suppliers reassessed periodically rather than trusted indefinitely on the strength of one questionnaire.

What You Receive

Indicative Timeline

An initial assessment normally runs three to five weeks. Building the inventory takes longer than expected, and supplier response times govern the control assessment stage rather than our own effort.

What We Examine

Assessment covers the access itself, the supplier controls behind it, and the contract that is supposed to govern both.

Access Inventory

Every supplier account, its privilege level, and whether access is standing or granted on request.

Supplier Controls

Their security posture, assessed proportionately to the exposure their access creates.

Certification Scope

Whether an ISO or SOC report actually covers the service you buy, which frequently it does not.

POPIA Operators

Written operator agreements with the provisions the Act requires, not a generic services contract.

Breach Notification

Whether the supplier is obliged to tell you, how quickly, and what happens if they do not.

Offboarding

Whether access is actually removed at contract end, verified rather than assumed.

Frequently Asked Questions

Only those with access to systems or personal information, tiered by exposure. Most organisations find the list of suppliers with real access is far shorter than the supplier list overall, and only the top tier warrants deep assessment.

A party processing personal information on your behalf without owning it, such as a payroll bureau, a cloud host or an IT support provider. You remain accountable for their processing, and the Act requires a written agreement with specific provisions.

It is a good indicator, but read the scope statement. Certification frequently covers a specific site or service line and not the one you buy. Verifying scope is a standard step and it disqualifies more certificates than people expect.

That is a finding in itself and worth escalating. Where a supplier is genuinely irreplaceable, the response is compensating controls on your side: reduced access, tighter monitoring and clearer contractual obligations at renewal.

Annually for the top tier, less frequently below that, and immediately on a trigger event such as a breach at the supplier, a change of ownership or a material change to the service.

It falls between procurement, IT and risk, which is why it is so often owned by nobody. We recommend a named owner with procurement supplying contract data and IT supplying access data, reporting periodically to the audit committee.

Related Services

This sits inside our Cyber Security Assessments practice. Related work: POPIA Readiness for the operator obligations in full, and IT General Controls Reviews where third party access is tested as part of access management.

Discuss vendor risk assessment