Third Party and Vendor Risk
Your security perimeter includes every supplier holding a login. Support vendors with standing administrative access, cloud providers processing personal information, and contractors whose accounts were never removed all sit inside the boundary regardless of what the network diagram shows. Under POPIA you remain accountable for operators acting on your behalf, which makes this a compliance question as much as a security one.
1
Inventory
Who has access to what
2
Tier
Rank by exposure
3
Assess
Their controls
4
Contract
Clauses versus reality
5
Monitor
Offboard and review
How We Assess
01
Vendor and Access Inventory
We build the list, which rarely exists. Procurement knows who is paid; IT knows who has accounts; the two lists never match. Dormant accounts belonging to suppliers whose contracts ended years ago are a routine finding.
- Inventory of suppliers holding system access
- Access level and standing versus on request
- Reconciliation of procurement records against active accounts
- Dormant and orphaned vendor accounts identified
02
Risk Tiering
Not every supplier warrants the same scrutiny. A cleaning contractor and a payroll bureau present different exposure, and treating them identically wastes effort on one while under assessing the other.
- Tiering by data sensitivity and access level
- Criticality to service continuity
- Concentration risk where one supplier is irreplaceable
- Assessment depth set per tier
03
Supplier Control Assessment
For higher tier suppliers we assess their actual controls, through questionnaires, certification review and, where warranted, direct enquiry. A supplier unwilling to answer is itself a finding worth reporting.
- Structured security questionnaires by tier
- Review of ISO 27001 or SOC 2 reports where held
- Verification that certification scope covers your service
- Escalation where a supplier declines to engage
04
Contract and Operator Review
We compare what the contract permits against what the supplier can technically reach. POPIA requires written operator agreements with specific provisions, and older contracts predating the Act frequently lack them entirely.
- Security clauses assessed against actual access
- POPIA operator agreement provisions
- Breach notification obligations and timeframes
- Right to audit and cross border transfer terms
05
Offboarding and Ongoing Review
Vendor risk is not a one off assessment. Access has to be removed when a contract ends, and higher tier suppliers reassessed periodically rather than trusted indefinitely on the strength of one questionnaire.
- Offboarding checklist with access revocation verified
- Periodic reassessment cycle by tier
- Trigger events prompting early reassessment
- Vendor risk reporting to the audit committee
What You Receive
- Vendor inventory reconciled against active system access
- Risk tiering with assessment depth per tier
- Supplier control assessment results for higher tier vendors
- Contract gap analysis including POPIA operator provisions
- Offboarding checklist with verification steps
- Reassessment calendar and committee reporting template
Indicative Timeline
An initial assessment normally runs three to five weeks. Building the inventory takes longer than expected, and supplier response times govern the control assessment stage rather than our own effort.
- Inventory and reconciliation: one to two weeks
- Risk tiering and questionnaire issue: one week
- Supplier responses and assessment: two weeks, supplier dependent
- Contract review and reporting: one week
What We Examine
Assessment covers the access itself, the supplier controls behind it, and the contract that is supposed to govern both.
Access Inventory
Every supplier account, its privilege level, and whether access is standing or granted on request.
Supplier Controls
Their security posture, assessed proportionately to the exposure their access creates.
Certification Scope
Whether an ISO or SOC report actually covers the service you buy, which frequently it does not.
POPIA Operators
Written operator agreements with the provisions the Act requires, not a generic services contract.
Breach Notification
Whether the supplier is obliged to tell you, how quickly, and what happens if they do not.
Offboarding
Whether access is actually removed at contract end, verified rather than assumed.
Frequently Asked Questions
How many suppliers should we assess?
Only those with access to systems or personal information, tiered by exposure. Most organisations find the list of suppliers with real access is far shorter than the supplier list overall, and only the top tier warrants deep assessment.
What is an operator under POPIA?
A party processing personal information on your behalf without owning it, such as a payroll bureau, a cloud host or an IT support provider. You remain accountable for their processing, and the Act requires a written agreement with specific provisions.
Our supplier has ISO 27001. Is that sufficient?
It is a good indicator, but read the scope statement. Certification frequently covers a specific site or service line and not the one you buy. Verifying scope is a standard step and it disqualifies more certificates than people expect.
What if a supplier refuses to complete an assessment?
That is a finding in itself and worth escalating. Where a supplier is genuinely irreplaceable, the response is compensating controls on your side: reduced access, tighter monitoring and clearer contractual obligations at renewal.
How often should suppliers be reassessed?
Annually for the top tier, less frequently below that, and immediately on a trigger event such as a breach at the supplier, a change of ownership or a material change to the service.
Who should own vendor risk?
It falls between procurement, IT and risk, which is why it is so often owned by nobody. We recommend a named owner with procurement supplying contract data and IT supplying access data, reporting periodically to the audit committee.
Related Services
This sits inside our Cyber Security Assessments practice. Related work: POPIA Readiness for the operator obligations in full, and IT General Controls Reviews where third party access is tested as part of access management.
