Vendor risk audit

Know which providers can genuinely interrupt or expose your business.

IKNSA connects business criticality, technical dependencies, contracts, security, performance and exit capability to focus the controls on the third parties that matter.

Evidence chainObserve · qualify · prioritise
  1. Scope
  2. Findings
  3. Risks
  4. Trajectory

The decision point

Vendor risk is managed across the whole relationship, not only at signature.

The audit consolidates contracts, services, data, access, subcontractors and incidents, then ranks the third parties by their potential impact. It verifies that the contractual rights can be exercised and that the continuity or exit strategies are technically feasible.

TriggerConcentration, incidents, a renewal or a regulatory requirement
ScopeThird parties, services, data, access, contracts and subcontractors
Expected outputSegmentation and a control plan per vendor

Working scope

The dimensions examined together.

The framing avoids treating separately subjects that condition one another. The final scope remains adapted to the organisation and its priorities.

  1. Service criticality and substitutability
  2. Data, access and localisation
  3. Due diligence and security requirements
  4. Contracts, SLAs and audit rights
  5. Subcontracting and concentration
  6. Continuity, exit and data restitution

A usable result

Control proportionate to the real dependency.

Governance concentrates the effort on the suppliers that contribute to critical functions or hold sensitive access. Renewals, remediation plans and exit exercises become planned decisions.

  1. 01Qualified register and vendor segmentation
  2. 02Analysis of contractual and operational gaps
  3. 03Due-diligence, control and remediation plan
  4. 04Continuity, exit and concentration scenarios

Method

An engagement that stays readable from scope to decision.

01

Scope

Fix the entities, services, assets, periods and frameworks actually examined.

02

Observe

Cross-check interviews, documents, configurations and operational results without relying on declarations alone.

03

Prioritise

Connect each finding to its business impact, its likelihood and the controls already in place.

04

Decide

Produce a costed trajectory with owners, deadlines, dependencies and expected evidence.

Point of vigilance

What the engagement must make explicit.

An annual questionnaire demonstrates neither the effectiveness of the controls nor the exit capability. The supplier's claims must be reconciled with the contracts, the evidence and the architecture consumed.

The first conversation verifies the context, the level of urgency, the stakeholders and the output genuinely expected.

Frame this engagement See Strategy & governance Start with a guided assessment

First conversation

Let’s discuss the next point of control for your information system.

A project to frame, operations to take over, compliance to demonstrate? Describe the context. You will get a first considered reading — not a generic brochure.