← Consultancy
Third-party risk management

Know which suppliers could hurt you

We tier your suppliers, run the assessments, chase the evidence and keep the register current, so DORA, NIS2 and your customers get the answers they need.

DORA & NIS2 readyRisk-tieredEvidence chased for youLive register
Supplier register142 suppliers
Tier 1 Cloud hosting providerISO 27001, SOC 2 reviewed Low
Tier 1 Payroll platformMFA gap, fix agreed Medium
Tier 2 Marketing agencyHolds customer data, no DPA High
Tier 3 Office suppliesNo data access Low
Why it's different

Supplier risk managed, not just questioned

The usual way With Touchpoint
The same 300-question questionnaire for every supplier Questions matched to the supplier’s tier and data access
Questionnaires sent and never chased We chase, review and score the evidence for you
A spreadsheet that’s out of date on day one A live register, with renewal reminders
No view of suppliers’ external exposure External exposure checks on your critical suppliers
Findings with no follow-up Remediation agreed and tracked with each supplier
What’s included

The full supplier lifecycle

Supplier inventory Every supplier, what data they hold and what they can reach.
Risk tiering Criticality scored, so effort goes where risk is.
Assessments Questionnaires, evidence review and follow-up calls.
External exposure checks What your critical suppliers expose to the internet.
Contract clauses Security and audit clauses for DORA and NIS2.
Ongoing monitoring Reassessments, renewals and change alerts.
How it works

From spreadsheet to live register

  1. 01 Inventory We build the supplier list with finance, IT and procurement.
  2. 02 Tier Suppliers scored by data access and business criticality.
  3. 03 Assess We send, chase and review the evidence.
  4. 04 Remediate Gaps agreed with each supplier and tracked to closure.
  5. 05 Monitor Reassessments on schedule, with exposure monitoring for Tier 1.
What you get

Answers for regulators and customers

Everything a DORA register of information or a customer audit asks about your supply chain.

✓ Supplier registerTiered, current and exportable.
✓ Assessment reportsOne per critical supplier.
✓ DORA register of informationIn the format regulators expect.
✓ Exit and concentration analysisWhere a single supplier failing would hurt.
✓ Contract clause librarySecurity terms ready for procurement.
✓ Board summaryTop supplier risks, quarterly.
Engagement options

Choose your coverage

Starter Critical suppliers Your top 10 to 20 suppliers, assessed properly.
  • ✓Inventory and tiering
  • ✓Tier 1 assessments
  • ✓Live supplier register
  • ✓Annual refresh
Get a fixed quote →
Most chosen Managed programme We run third-party risk for you.
  • ✓All tiers covered
  • ✓Evidence chased for you
  • ✓Quarterly board summary
  • ✓DORA register of information
Get a fixed quote →
Regulated DORA & NIS2 For financial entities and essential services.
  • ✓ICT third-party register
  • ✓Concentration and exit analysis
  • ✓Contract clause review
  • ✓Regulator-ready reporting
Get a fixed quote →
Questions

Before you ask

What if suppliers don’t respond?+

We chase them, escalate through your contract owner and record the outcome, so non-response is itself a scored risk.

Can we use our existing questionnaire?+

Yes. We can map it to your tiers or replace it with ours.

Does this cover DORA?+

Yes, including the register of information and concentration risk analysis.

What format is the register in?+

Whatever suits you: your GRC tool, or a structured register we maintain.

Get your supply chain under control

Send us your supplier list, however messy. We’ll come back with a tiered view and a plan.

Assess your suppliers
Other consultancy services Penetration testing→ Cloud security→ Tabletop exercises→ vCISO→