Vendor Risk Tiering: How Much Diligence Is Enough
Treating every vendor the same wastes effort on low-risk tools and under-scrutinises the ones that matter. Tiering fixes both problems.
By Kellwick Team · August 1, 2026 · 5 min read
Most vendor risk programmes fail in one of two directions. Either they apply the same heavy questionnaire to every supplier, which buries the team and delays the business, or they wave everything through and only notice the risk after an incident. Tiering is how you spend your limited diligence where it actually reduces risk, and stop spending it where it does not.
Why Uniform Diligence Fails
Sending a full security assessment to a payroll processor and to a font provider makes no sense, yet plenty of programmes do exactly that. The instinct is understandable. Uniform process feels fair and defensible. In practice it produces two bad outcomes at once.
First, it slows the business. Every new tool, however trivial, gets stuck behind the same review. Teams learn to route around procurement entirely, and now you have shadow vendors you know nothing about. That is a worse position than a slower official process.
Second, it dilutes attention. When every vendor gets the same treatment, the genuinely dangerous ones do not get the extra scrutiny they need. Your reviewers are too busy assessing a screen-recording plugin to properly examine the provider that holds your customer database.
Tiering solves both. It matches the depth of diligence to the risk the vendor actually carries, so effort flows to where it matters.
How to Tier: The Factors That Matter
A tier is a judgement about how much damage a vendor could cause if it failed or was breached. A few factors drive most of that judgement:
- Data access. Does the vendor process personal data, financial data, or your crown-jewel information? A vendor handling customer PII is inherently higher tier than one that never touches sensitive data.
- Criticality to operations. If this vendor went down, would your product stop working? A core infrastructure provider is high tier regardless of data.
- Integration depth. Does the vendor have privileged access into your environment, such as a tool with broad API scopes or admin rights?
- Regulatory exposure. Does using this vendor create obligations, for example an ICT third party under DORA or a subprocessor you must disclose?
- Substitutability. How easily could you exit and replace them? Hard-to-replace vendors carry concentration risk.
Most organisations land on three tiers. Critical vendors touch sensitive data or are essential to operations. Moderate vendors have some access or importance but limited blast radius. Low vendors touch nothing sensitive and could be swapped out tomorrow. Three tiers is usually enough. More than four tends to create false precision and decision paralysis.
Matching Diligence to Tier
Once a vendor is tiered, the level of diligence should follow automatically. The point of the tier is to make the process decision for you.
Critical vendors justify real depth:
- Review of their ISO 27001 or SOC 2 report, including scope and exceptions, not just the badge.
- A completed security questionnaire and evidence for the answers that matter.
- Contractual protections: data processing terms, breach notification timelines, audit rights, and exit provisions.
- Ongoing monitoring, not a one-time check. Annual reassessment at minimum, plus alerts on their security posture where available.
Moderate vendors warrant proportionate checks:
- Confirmation of relevant certifications or attestations.
- A lighter questionnaire focused on data handling and access.
- Standard contractual terms.
- Reassessment on a longer cycle or on trigger events.
Low vendors need little more than a record:
- Basic due diligence that they are a legitimate operating business.
- A note of what data, if any, they touch.
- Inclusion in your inventory so they are not invisible.
The discipline is to actually hold the line. The temptation is always to add just one more check to the low tier, and before long the low tier looks like the critical tier and you are back to uniform diligence.
The Inventory Is the Foundation
None of this works without a complete vendor inventory. You cannot tier what you have not recorded, and you cannot record what you do not know about. The single most common weakness in supplier risk programmes is not weak assessment. It is an incomplete list.
Build the inventory before you refine the tiering. Pull vendors from accounts payable, from your SSO provider, from expense reports, and from engineering's list of integrated services. Expect to find vendors nobody remembered signing up for. Capture, for each one, what it does, what data it touches, who owns the relationship, and its assigned tier.
Keep it alive. New vendors should be tiered at onboarding, ideally as part of procurement, so the classification is made once and reused. A vendor inventory that is accurate at audit time and nowhere in between is a compliance artefact, not a risk tool.
Reviewing Tiers Over Time
A vendor's tier is not fixed. Relationships deepen. A tool you adopted for one small team gets rolled out company-wide and suddenly touches far more data. A provider becomes critical because you built a core feature on top of it. Your tiering has to keep up.
Re-tier on trigger events: a material change in what data a vendor handles, a change in how deeply they are integrated, a merger or acquisition on their side, or a reported breach. Beyond triggers, sweep the whole inventory at least annually, ideally as an input to your management review. Ask a simple question of each critical vendor: if this one failed tomorrow, do we have a plan? For the truly critical, that plan should include how you would exit.
This review is also where concentration risk becomes visible. If three of your critical vendors sit on the same underlying cloud region, that is a single point of failure your tiering should surface and your leadership should see.
Bottom Line
Good vendor risk management is not about assessing everything equally. It is about tiering vendors by the damage they could do, matching diligence to tier, and holding that discipline against the constant pull toward uniform process. The foundation is a complete, living inventory, and the safeguard is regular re-tiering as relationships change.
If you want to know whether your vendor programme would satisfy an auditor and actually reflect where your risk sits, a Kellwick readiness review can assess your inventory, tiering, and diligence against what the standard and your buyers expect.
Need a second pair of eyes before the auditor does?
A readiness review shows exactly where your ISMS stands - and what to fix first - while there is still time to act on it.
Stay audit-ready
Occasional, practical notes on ISO 27001 readiness and ISMS maintenance. No noise.