Learn

What is vendor tiering?

Vendor tiering classifies vendors by inherent risk, based on the service provided and the data and access involved, so the depth of due diligence matches the risk.

In short

Vendor tiering is the practice of classifying vendors into risk tiers, commonly critical, high, moderate, and low, based on inherent risk factors such as the service provided, the sensitivity of data they access, their access to systems, and how critical they are to operations. The tier determines how deep due diligence and ongoing monitoring should be.

This page is for you if
  • You are trying to get a straight answer before you sit through a sales call
  • You need language you can take to a CISO, auditor, or procurement

Common tiering factors

  • Type and sensitivity of data the vendor handles
  • Level of access to systems and networks
  • Criticality of the service to operations
  • Regulatory implications of the relationship
  • Ease of replacing the vendor

What tiers change

TierTypical review
CriticalFull questionnaire, evidence review, contract terms, frequent reassessment
HighStandard questionnaire and evidence, annual reassessment
ModerateShort questionnaire, periodic review
LowBasic screening

When this becomes a buying decision

If every vendor gets the same questionnaire, you do not have a TPRM program. You have a mail merge. Tiering is the first buying requirement.

If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.

Questions

How often should vendor tiers be reviewed?

When the relationship changes and at least periodically, since vendors often expand their scope over time.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.