- Programme design
- Scoring
Vendor risk tiering: how to classify third parties and set a review cadence
Updated 7 min read
A vendor programme that treats every third party the same fails in one of two ways. Either the critical vendors get the same shallow check as the office plant supplier, or every vendor gets the full assessment and the programme stalls under its own weight. Tiering is the mechanism that puts effort where the exposure is, and it is the first thing an auditor asks about, because it explains everything that follows.
This guide gives three questions that assign a tier consistently, the four tiers and what each one earns, the reassessment cadence per tier, and how to keep tiers honest as vendors change.
Three questions that assign the tier
Inherent-risk questionnaires with twenty factors produce precise-looking numbers and inconsistent results. Three questions, each with a small number of answers, produce tiers that two people assign the same way.
1. What can they access?
The data and systems the vendor touches. Rank the most sensitive thing they can reach:
- Sensitive: special-category personal data, payment card data, credentials, source code, or production systems with privileged access.
- Confidential: customer personal data, employee data, financial records, or contractual and commercial information.
- Internal: business contact details, internal documents that would be embarrassing but not damaging if disclosed.
- None: no data, no system access.
2. How badly would an outage hurt?
The operational dependence on the service:
- Severe: the business stops or a legal obligation is missed within a day (hosting, payments, payroll).
- Significant: a team stops or customers notice within a week.
- Minor: inconvenience; a workaround exists.
3. How hard are they to replace?
Substitutability, which turns a bad outage into a long one:
- Hard: months of migration, proprietary formats, deep integration.
- Moderate: weeks; alternatives exist but need setup.
- Easy: days; commodity service.
The four tiers, and what each one earns
Combine the answers with a simple rule: the access answer sets the floor, and the outage and substitutability answers can raise it by one level. So a vendor with confidential data (high) whose failure would be severe and who is hard to replace becomes critical; a vendor with internal data (medium) is high only if the outage would be severe.
| Tier | Typically | Assessment | Evidence required | Review cadence |
|---|---|---|---|---|
| Critical | Sensitive access, or confidential access plus severe outage and hard to replace. Hosting, core SaaS holding customer data, payroll. | Full questionnaire across all domains, plus privacy where personal data is involved | SOC 2 Type II or ISO 27001 with scope, pen test summary, DPA, BCP/DR test results, sub-processor list | Annual, plus on any trigger |
| High | Confidential access; or internal access with severe outage. CRM, support desk, HR tools. | Full questionnaire, may accept a recent standard questionnaire (SIG Lite, CAIQ) | Certification or completed questionnaire with evidence, DPA, sub-processor list | Annual to 18 months, plus on any trigger |
| Medium | Internal access; or no access with significant outage. Project tools, analytics with pseudonymised data. | Short questionnaire (15–25 questions) or public trust page review | DPA where personal data is involved; certification if available | Every 2–3 years, plus on any trigger |
| Low | No data, no access, minor outage. Office supplies, one-off services, content tools. | None — tier recorded with reasoning | Contract terms confirmed | On material change only |
Setting a review cadence that runs
The cadence in the table is the policy; what makes it happen is the mechanism. Three rules keep reassessments from being the thing that always slips.
- Set the next date when the current review closes. Not at the start of the year, not when someone remembers. The review record includes the next due date, and the register shows it.
- Let the reminder find the owner, not the coordinator. Each vendor has an internal owner who would notice if the service changed. The reminder goes to them, with the compliance owner copied, so a review does not depend on one person’s inbox.
- Report overdue reviews upward. A quarterly line to leadership — “two critical vendors overdue” — makes the cadence visible enough to be kept.
Triggers for an early review
Cadence covers drift. Events need their own response. Any of the following moves a review forward regardless of tier:
- a security incident or breach notification from the vendor;
- a change of ownership, a merger, or signs of financial distress;
- a sub-processor change, particularly one affecting data location or transfers;
- a material change in what you share — a new data category, a new integration, a wider scope;
- expiry of the certification or report the last assessment relied on;
- repeated SLA misses or a pattern of support failures.
A triggered review is usually narrower than a scheduled one: it examines what changed, decides whether the tier or the conditions change with it, and records that decision.
Keeping tiers honest
- Record the reasoning, not just the tier. “High — customer personal data, significant outage, moderate to replace” can be checked and re-derived. “High” alone cannot.
- Re-tier at each review. Ask the three questions again. Integrations are switched off, data flows widen, vendors are replaced. A tier that never moves is a tier nobody is looking at.
- Resist tiering by spend. The expensive vendor is not necessarily the risky one. A free analytics tool with a script on every page is critical; a large consulting contract with no data access may be low.
- Resist tiering by comfort. A vendor you have used for years and like is still critical if it holds your customer database.
What the auditor checks
A SOC 2 auditor testing CC9.2, or an ISO 27001 auditor testing Annex A 5.19, will ask for the tier criteria, pick vendors from the register, and check that the tier assigned follows from the criteria and that the treatment — assessment depth, evidence, cadence — matches what the policy says the tier requires. The finding that results from tiering is almost never “the criteria are wrong”; it is “this vendor is tiered critical and was last reviewed three years ago”. The cadence is the control.
Where to go next
With tiers assigned, Vendor risk assessment questionnaire: what to ask, and how to score the answers gives the question set for each one, and Vendor due diligence: a practical guide for small and mid-sized businesses the process the assessment sits in. For the programme design that tiering serves, Third-party risk management for small businesses: a programme without a GRC team.
Frequently asked questions
- What is vendor risk tiering?
- Vendor risk tiering is the practice of classifying third parties into a small number of risk levels — usually critical, high, medium and low — based on what they can access, how much their failure would hurt, and how hard they are to replace. The tier then determines how deeply each vendor is assessed and how often it is reviewed.
- How many vendor risk tiers should I have?
- Four. Three tends to put too many vendors in the middle, where the treatment is ambiguous; five or more creates distinctions nobody can apply consistently. Critical, high, medium and low is the convention auditors recognise, and each maps to a clearly different level of effort.
- How often should each vendor tier be reviewed?
- A common and defensible cadence is annual for critical, annual or every 18 months for high, every two to three years for medium, and on material change only for low. Any tier gets an early review after a breach, ownership change, sub-processor change, or change in the data you share.
- Should vendor tiers ever change?
- Yes, whenever the facts change: a vendor given access to a new data category moves up, one whose integration is switched off moves down. Record the change and the reason. A tier that has never moved for any vendor usually means nobody is looking.
Related guides
- Questionnaires
- Scoring
Vendor risk assessment questionnaire: what to ask, and how to score the answers
The questions that matter by risk tier, mapped to the controls auditors recognise, with a scoring method you can explain.
8 min read
- Programme design
- SMB
Third-party risk management for small businesses: a programme without a GRC team
Enterprise TPRM assumes a department. This is the version for a company with none — and what it still must not skip.
7 min read
- Fundamentals
- Checklist
Vendor due diligence: a practical guide for small and mid-sized businesses
The end-to-end process — scoping, questionnaires, evidence, scoring, review cadence — sized for a team of one.
9 min read