What is vendor tiering?
Vendor tiering classifies vendors by inherent risk, based on the service provided and the data and access involved, so the depth of due diligence matches the risk.
Vendor tiering is the practice of classifying vendors into risk tiers, commonly critical, high, moderate, and low, based on inherent risk factors such as the service provided, the sensitivity of data they access, their access to systems, and how critical they are to operations. The tier determines how deep due diligence and ongoing monitoring should be.
- You are trying to get a straight answer before you sit through a sales call
- You need language you can take to a CISO, auditor, or procurement
Common tiering factors
- Type and sensitivity of data the vendor handles
- Level of access to systems and networks
- Criticality of the service to operations
- Regulatory implications of the relationship
- Ease of replacing the vendor
What tiers change
| Tier | Typical review |
|---|---|
| Critical | Full questionnaire, evidence review, contract terms, frequent reassessment |
| High | Standard questionnaire and evidence, annual reassessment |
| Moderate | Short questionnaire, periodic review |
| Low | Basic screening |
When this becomes a buying decision
If every vendor gets the same questionnaire, you do not have a TPRM program. You have a mail merge. Tiering is the first buying requirement.
If that is the situation you are in, see the product pages linked below, or ask us for a 30-minute demo on one real document.
Questions
How often should vendor tiers be reviewed?
When the relationship changes and at least periodically, since vendors often expand their scope over time.
See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.