Supplier Cyber-Risk Assessment: Essential Safe Checklist
Most supplier assurance programmes send a spreadsheet, receive a spreadsheet and file it — producing documentation rather than assessment. This guide sets out a working supplier cyber-risk assessment checklist as a seven-step programme: building an honest supplier inventory from four independent sources, scoring inherent risk before you contact anyone, tiering the base so effort follows exposure, the ten control domains the checklist must cover, choosing an assessment method that matches the tier, demanding the evidence artefact behind every claim, converting answers into residual risk and a dated decision, handling concentration and fourth-party risk, turning findings into remediation with deadlines and consequences, monitoring continuously between reviews, and closing the loop properly at offboarding.