Skip to content
  • Programme design
  • Scoring

Vendor risk tiering: how to classify third parties and set a review cadence

Updated 7 min read

A vendor programme that treats every third party the same fails in one of two ways. Either the critical vendors get the same shallow check as the office plant supplier, or every vendor gets the full assessment and the programme stalls under its own weight. Tiering is the mechanism that puts effort where the exposure is, and it is the first thing an auditor asks about, because it explains everything that follows.

This guide gives three questions that assign a tier consistently, the four tiers and what each one earns, the reassessment cadence per tier, and how to keep tiers honest as vendors change.

Three questions that assign the tier

Inherent-risk questionnaires with twenty factors produce precise-looking numbers and inconsistent results. Three questions, each with a small number of answers, produce tiers that two people assign the same way.

1. What can they access?

The data and systems the vendor touches. Rank the most sensitive thing they can reach:

  • Sensitive: special-category personal data, payment card data, credentials, source code, or production systems with privileged access.
  • Confidential: customer personal data, employee data, financial records, or contractual and commercial information.
  • Internal: business contact details, internal documents that would be embarrassing but not damaging if disclosed.
  • None: no data, no system access.

2. How badly would an outage hurt?

The operational dependence on the service:

  • Severe: the business stops or a legal obligation is missed within a day (hosting, payments, payroll).
  • Significant: a team stops or customers notice within a week.
  • Minor: inconvenience; a workaround exists.

3. How hard are they to replace?

Substitutability, which turns a bad outage into a long one:

  • Hard: months of migration, proprietary formats, deep integration.
  • Moderate: weeks; alternatives exist but need setup.
  • Easy: days; commodity service.

The four tiers, and what each one earns

Combine the answers with a simple rule: the access answer sets the floor, and the outage and substitutability answers can raise it by one level. So a vendor with confidential data (high) whose failure would be severe and who is hard to replace becomes critical; a vendor with internal data (medium) is high only if the outage would be severe.

TierTypicallyAssessmentEvidence requiredReview cadence
CriticalSensitive access, or confidential access plus severe outage and hard to replace. Hosting, core SaaS holding customer data, payroll.Full questionnaire across all domains, plus privacy where personal data is involvedSOC 2 Type II or ISO 27001 with scope, pen test summary, DPA, BCP/DR test results, sub-processor listAnnual, plus on any trigger
HighConfidential access; or internal access with severe outage. CRM, support desk, HR tools.Full questionnaire, may accept a recent standard questionnaire (SIG Lite, CAIQ)Certification or completed questionnaire with evidence, DPA, sub-processor listAnnual to 18 months, plus on any trigger
MediumInternal access; or no access with significant outage. Project tools, analytics with pseudonymised data.Short questionnaire (15–25 questions) or public trust page reviewDPA where personal data is involved; certification if availableEvery 2–3 years, plus on any trigger
LowNo data, no access, minor outage. Office supplies, one-off services, content tools.None — tier recorded with reasoningContract terms confirmedOn material change only

Setting a review cadence that runs

The cadence in the table is the policy; what makes it happen is the mechanism. Three rules keep reassessments from being the thing that always slips.

  1. Set the next date when the current review closes. Not at the start of the year, not when someone remembers. The review record includes the next due date, and the register shows it.
  2. Let the reminder find the owner, not the coordinator. Each vendor has an internal owner who would notice if the service changed. The reminder goes to them, with the compliance owner copied, so a review does not depend on one person’s inbox.
  3. Report overdue reviews upward. A quarterly line to leadership — “two critical vendors overdue” — makes the cadence visible enough to be kept.

Triggers for an early review

Cadence covers drift. Events need their own response. Any of the following moves a review forward regardless of tier:

  • a security incident or breach notification from the vendor;
  • a change of ownership, a merger, or signs of financial distress;
  • a sub-processor change, particularly one affecting data location or transfers;
  • a material change in what you share — a new data category, a new integration, a wider scope;
  • expiry of the certification or report the last assessment relied on;
  • repeated SLA misses or a pattern of support failures.

A triggered review is usually narrower than a scheduled one: it examines what changed, decides whether the tier or the conditions change with it, and records that decision.

Keeping tiers honest

  • Record the reasoning, not just the tier. “High — customer personal data, significant outage, moderate to replace” can be checked and re-derived. “High” alone cannot.
  • Re-tier at each review. Ask the three questions again. Integrations are switched off, data flows widen, vendors are replaced. A tier that never moves is a tier nobody is looking at.
  • Resist tiering by spend. The expensive vendor is not necessarily the risky one. A free analytics tool with a script on every page is critical; a large consulting contract with no data access may be low.
  • Resist tiering by comfort. A vendor you have used for years and like is still critical if it holds your customer database.

What the auditor checks

A SOC 2 auditor testing CC9.2, or an ISO 27001 auditor testing Annex A 5.19, will ask for the tier criteria, pick vendors from the register, and check that the tier assigned follows from the criteria and that the treatment — assessment depth, evidence, cadence — matches what the policy says the tier requires. The finding that results from tiering is almost never “the criteria are wrong”; it is “this vendor is tiered critical and was last reviewed three years ago”. The cadence is the control.

Where to go next

With tiers assigned, Vendor risk assessment questionnaire: what to ask, and how to score the answers gives the question set for each one, and Vendor due diligence: a practical guide for small and mid-sized businesses the process the assessment sits in. For the programme design that tiering serves, Third-party risk management for small businesses: a programme without a GRC team.

Frequently asked questions

What is vendor risk tiering?
Vendor risk tiering is the practice of classifying third parties into a small number of risk levels — usually critical, high, medium and low — based on what they can access, how much their failure would hurt, and how hard they are to replace. The tier then determines how deeply each vendor is assessed and how often it is reviewed.
How many vendor risk tiers should I have?
Four. Three tends to put too many vendors in the middle, where the treatment is ambiguous; five or more creates distinctions nobody can apply consistently. Critical, high, medium and low is the convention auditors recognise, and each maps to a clearly different level of effort.
How often should each vendor tier be reviewed?
A common and defensible cadence is annual for critical, annual or every 18 months for high, every two to three years for medium, and on material change only for low. Any tier gets an early review after a breach, ownership change, sub-processor change, or change in the data you share.
Should vendor tiers ever change?
Yes, whenever the facts change: a vendor given access to a new data category moves up, one whose integration is switched off moves down. Record the change and the reason. A tier that has never moved for any vendor usually means nobody is looking.