← All insights

Risk Management & Resilience July 23, 2026 · E-KMC.EU P.S.A.

Third-party risk without the questionnaire flood

Before this year’s questionnaire goes out to two hundred vendors, answer one question: which five of them can stop your operations by Friday? If nobody in the room can name them within a day, the campaign will measure everything and control nothing, and the folder of returned PDFs will document diligence no decision ever used.

Triage before questions

Sort vendors along two axes: what happens to your service when theirs stops, and what data of yours they touch. Three tiers usually do the job. Critical: an outage halts a core process within days, or the vendor handles client data at scale. Important: workarounds exist and the damage stays bounded. The rest: replaceable within a week without client impact.

Effort then follows the tier. The bottom tier gets contract hygiene and spend monitoring. The middle tier gets a short, specific question set and a look at incident history. The critical tier gets evidence, hard contract clauses and an exit plan. A questionnaire of identical length for the stationery supplier and for the hosting provider tells you that nobody made this decision.

Evidence, contracts, exit

A yes ticked in a questionnaire is a declaration. From critical vendors collect artefacts: the latest resilience test summary, incident notifications from the past year, the subcontractor chain behind the service, insurance and financial standing. Ask for fewer documents and read them; ten read artefacts beat eighty unread checkboxes.

Contracts carry the second layer: information and access rights, notification duties for incidents and for changes of subcontractors, defined service levels, termination assistance. For critical services add the exit plan: where your data sits, in what format you get it back, who the fallback provider is, how long switching takes and what runs in degraded mode meanwhile. Walk through the assumptions on paper once a year.

The test arrives uninvited. Your hosting provider announces an acquisition and a new price list; at the next management meeting someone asks what happens on Monday if the service fails on Friday. A maintained register answers in five minutes. Without it, a task force spends three weeks rediscovering the company’s own supply chain.

What DORA teaches everyone else

Financial entities operate under DORA, Regulation (EU) 2022/2554, applicable since 17 January 2025. The mechanism worth copying is the register of information: a structured record of ICT contracts, reported to supervisors in annual cycles. The register forces questions a questionnaire never asks. Which functions depend on which contract? Who subcontracts to whom? Which arrangements support critical functions?

No supervisor requires this from a firm outside finance, which changes nothing about its usefulness: one table, one owner, one annual cycle, and the panic inventory during an incident disappears.

What we recommend now

Two weeks, five steps.

  • Build a one-page register: vendor, service, data touched, tier, contract end date, notice period, exit notes. Start with the twenty largest by spend and by dependency.
  • Assign the three tiers and let operations, security and the service owners challenge the split once.
  • For every critical vendor, check the contract for information rights, incident notification and termination assistance. List the gaps as input for renewal talks.
  • Write a one-page exit note per critical service: data location, export format, fallback option, realistic switching time.
  • Cancel the blanket questionnaire and replace it with tiered requests: artefacts from critical vendors, a short question set for important ones, contract hygiene for the rest.

Sources: Regulation (EU) 2022/2554 (DORA), EUR-Lex

This material is provided for general information and does not constitute legal, investment, tax, audit or other regulated professional advice. Its application depends on the facts, jurisdiction and current law. Verify the current status of the cited sources and obtain appropriate advice before acting.