Vendor risk management, done proportionately
Most vendor risk programs review every supplier the same way and therefore review none of them well. Tier first: the handful of vendors that could take your business down or expose your customers deserve real work, and the rest deserve a two minute check and a record that you did it.
A workable third-party risk program at a Canadian company of 100 to 500 people reviews about 10 to 25 critical vendors properly each year and handles everything else with a short standard check. It costs roughly $18,000 to $60,000 CAD a year in effort, mostly analyst time rather than executive time, and the largest single saving available is deciding which vendors do not need the full treatment.
Two obligations sit underneath this in Canada and both are frequently missed. Under PIPEDA, an organisation remains accountable for personal information transferred to a third party for processing and must use contractual or other means to provide a comparable level of protection. Under Quebec's Law 25, there are additional requirements around communicating personal information outside Quebec, including an assessment of the privacy implications. Neither duty transfers with the data, which is the same principle OSFI states for financial institutions in Guideline B-10. Put it in your own policy in those words.
Tier first, and be ruthless about it
Tiering is where the program is won or lost. The question is not how large the vendor is, it is what happens to you if they fail or are breached.
| Tier | Definition | Review | Cadence |
|---|---|---|---|
| Critical | Holds customer personal data, or an outage stops you serving customers, or they have privileged access to your production environment | Report review, security questionnaire, contract terms, named contact, exit plan | Annual, plus on material change |
| Important | Holds internal or employee data, or a disruption is painful but survivable | Certification evidence and a short questionnaire | Every two years |
| Standard | No sensitive data, easily replaced | Record the vendor, the owner and the data it touches. That is all | At purchase, and on renewal |
At a 250 person company that usually resolves to something like ten to twenty critical, thirty to sixty important, and a long tail of a few hundred standard, most of which are single-seat tools someone expensed. Trying to run the critical process across all of them is how programs stall in the first quarter and are quietly abandoned in the second.
Two tiering mistakes worth naming
The first is tiering by spend. Your most dangerous vendor is often a small one with an integration token that can read everything, while your largest invoice goes to a company that touches no data at all. The second is ignoring fourth parties: your critical vendor's own critical vendor is where a surprising share of real incidents originate, which is why the subcontracting question below is worth asking even though the answer is usually incomplete.
What to actually ask a critical vendor
Long questionnaires produce long answers nobody reads. Eight questions, answered properly and followed up on, beat two hundred answered by a sales engineer with a template.
Read the report rather than the badge. A SOC 2 Type 2 with a scope that excludes the product you are buying, or with a list of exceptions the vendor never mentioned, is a common and quiet finding. If you do not have anyone who can read one, that is the kind of narrow judgement task a fractional security leader is good value for, and it is priced as a standalone item on fractional CISO services.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The contract terms that matter more than the questionnaire
A questionnaire is a snapshot of one Tuesday. Contract terms are what you can act on in eighteen months when something happens.
| Term | Why | Fight for it? |
|---|---|---|
| Incident notification window | Your own obligations to customers and regulators depend on being told. 24 to 72 hours from discovery is standard | Always |
| Data location and cross-border processing | PIPEDA accountability and Law 25 obligations depend on knowing this | Always where personal data is involved |
| Subprocessor notice and objection | Fourth-party risk is otherwise invisible to you | Usually achievable |
| Return and deletion of data on exit | The clause you will need in a hurry, at the worst possible time | Always |
| Right to evidence, meaning the report rather than an audit | Full audit rights are rarely granted and rarely exercised. Annual evidence is | Ask for the practical version |
| Security control commitments | Turns the questionnaire from marketing into a promise | Where the vendor is genuinely critical |
| Liability carve-out for data breach | Standard caps make a breach clause worth very little | Try, and expect to lose it with a large vendor |
A 200 person Canadian company is not renegotiating terms with a hyperscaler, and pretending otherwise wastes a quarter. Where the vendor will not move, record the gap on your risk register, have the business owner accept it explicitly, and spend your negotiating effort on the mid-sized vendors where it will work.
Keeping it running without hiring for it
- Intercept at procurement, not after. A review that happens after the contract is signed is a report, not a control. The single highest-value change most companies make is a required field in the purchase workflow asking what data the tool will touch.
- Give every vendor a business owner. Security runs the process, the business owner answers for the relationship. A register where security owns every vendor is a register nobody else maintains.
- Reassess on change, not only on the calendar. A vendor that gets acquired, moves hosting, or has a public incident should be reviewed then, regardless of when its annual review is due.
- Watch the concentration. Six critical vendors on one cloud provider in one region is a single point of failure your register may show as six separate low risks.
- Track expiry dates of their certificates. A lapsed SOC 2 at a critical vendor is a finding in your own audit, and nobody will tell you.
The other side of the desk
Most companies reading this are also on the receiving end of somebody else's vendor risk process, and the two problems are the same problem. Every hour spent answering questionnaires is an hour not spent on your own program, and at a B2B company with large customers this can consume half a security retainer. Publishing a trust page with your certification status, your subprocessor list, your data locations and your incident notification commitment removes a large share of inbound questions before they are asked. If your customer is a federally regulated financial institution, what is driving their diligence is covered on OSFI regulated institutions, and it explains why their questions are harder than everyone else's.
If a customer has sent you the questionnaire and there is nobody internally to answer it, answering a security questionnaire with no security owner covers what to say, what you may honestly answer no to, and who should sign it.
Get third-party risk set up once, properly
Tiering, a short questionnaire, contract language and a register is a fixed-scope engagement rather than an ongoing cost. Tell us your vendor count and we will get it quoted.
Get matchedCommon questions
How many vendors should we actually review?
Ten to twenty-five properly, at a company of 100 to 500 people. Those are the ones holding customer personal data, capable of stopping you serving customers, or holding privileged access to production. Everything else gets recorded with an owner and a note about what data it touches. A program that tries to review three hundred vendors reviews none of them well and stops within two quarters.
Does PIPEDA make us responsible for our vendors?
Yes. Under the accountability principle an organisation stays responsible for personal information transferred to a third party for processing, and must use contractual or other means to provide a comparable level of protection. Transferring the data does not transfer the accountability, so a vendor breach involving your customers' information is your notification obligation and your reputational problem.
What about sending data outside Canada?
PIPEDA permits it, with the accountability duty intact, and the Privacy Commissioner's guidance expects organisations to be transparent with individuals about cross-border transfers. Quebec's Law 25 goes further and requires an assessment of the privacy implications before communicating personal information outside Quebec. In practice: know where the data actually sits, say so in your privacy notice, and write the assessment down.
Is a SOC 2 report enough to approve a vendor?
It is the strongest single piece of evidence and it is not sufficient on its own. Read the scope, because it frequently excludes the specific service you are buying, read the exceptions, because they are the interesting part, and check the period covered, because a report from two years ago tells you about a company that no longer exists. Then look at the things it does not cover: data location, subprocessors, notification windows and exit.
Should a vCISO run vendor risk?
They should design it and review the critical vendors. The volume work, chasing certificates, maintaining the register and running standard-tier checks, does not need a security executive at $300 CAD an hour and is a natural thing to keep internal with an operations or procurement person. That split is one of the clearer ways to buy fewer retainer hours without weakening the program.