Third Party

Supplier BCM Assessment: Criticality, Assurance and Risk Decisions

A risk-based method for deciding how much continuity assurance a supplier needs, evaluating the evidence, scoring material gaps and escalating residual third-party continuity risk.

A supplier BCM assessment is the assurance decision that follows supplier criticality analysis and evidence collection. Its purpose is to decide whether a supplier's demonstrated continuity capability is sufficient for the business dependency—not merely whether a questionnaire was completed.

Use this page for the assessment decision

Use this guide when you need to classify assurance depth, evaluate submitted evidence, determine whether recovery claims are credible, record gaps and decide whether the residual supplier risk is acceptable. If you need the actual questions to send to a supplier, use the Supplier Business Continuity Questionnaire Guide.

Start with business criticality, not a standard questionnaire

Map the supplier to the business service it supports and record the service disruption tolerance, required supplier recovery time, minimum capacity, geographic or technology concentration, substitutability and any regulatory or contractual constraints. A payroll stationery supplier and a sole-source transaction platform should not receive the same assurance treatment.

Supplier tierTypical dependencyAssurance depth
CriticalFailure can breach disruption tolerance before substitution is practicalEvidence review, recovery-test results, exceptions, assurance meeting and scenario challenge
ImportantMaterial degradation but workable alternatives existTargeted questionnaire plus evidence for key recovery claims
StandardLow continuity impact or rapid substitutionProportionate screening and contractual baseline

Evaluate claims against evidence

Separate the supplier's statement from the evidence that supports it. “We have a BCP” has little assurance value by itself. Stronger evidence identifies the contracted service, approved recovery objective, last exercise scope, achieved recovery timing, capacity during degraded operation, unresolved findings and dependencies on subcontractors or shared infrastructure.

Evidence quality test

  • Relevant: it applies to the exact contracted service, location and delivery model.
  • Current: it reflects the present architecture, workforce and supplier chain.
  • Tested: recovery claims are supported by exercises, restores, failovers or incident evidence.
  • Measurable: time, capacity, data loss and backlog assumptions have observable acceptance criteria.
  • Transparent: exceptions and sub-tier dependencies are disclosed rather than hidden behind certification.

Turn gaps into decisions

For every material gap record the affected business service, requirement, current demonstrated capability, evidence weakness, consequence, owner, treatment and due date. Then choose an explicit disposition: accept the risk, require remediation, add a contractual control, create an alternate source, reduce dependency, increase internal workaround capacity or escalate for management decision.

Worked assessment example

A critical hosted-service supplier states a four-hour recovery target. Its latest exercise restored infrastructure in three hours but business interfaces were not validated until hour seven and the test excluded its identity provider. The assessment should not record “RTO met.” It should record the demonstrated end-to-end capability, the untested identity dependency and the resulting exposure against the customer's tolerance. Management can then require a joint test or formally accept the gap.

Challenge concentration and common-mode failure

Ask whether the primary and fallback arrangements share the same cloud region, carrier, identity service, key personnel, subcontractor, logistics route or facility utility. Two suppliers are not independent if both depend on the same constrained upstream provider. Record concentration explicitly because it changes the value of diversification and substitution strategies.

Assessment output and governance

The output should be a short decision record: supplier tier, protected service, required capability, demonstrated capability, evidence confidence, material gaps, treatment, accountable business owner and next review trigger. Procurement can own contractual actions, but the business owner should remain accountable for accepting continuity exposure.

When to reassess

Reassess after a material service or hosting change, acquisition, location change, major subcontractor change, failed exercise, significant incident, repeated SLA failure, contract renewal or a change to the dependent business service's tolerance. High-criticality suppliers should also be reviewed on a defined assurance cycle.

Relationship to the supplier questionnaire

The supplier continuity questionnaire is an evidence-collection instrument. This assessment is the risk and assurance process that interprets those answers. Keeping the two purposes separate avoids awarding a supplier a pass merely for completing a form.

Evidence confidence and scoring

Score the quality of evidence separately from the supplier's claimed capability. A current independent certification, recent exercise result or customer-specific recovery test provides stronger assurance than an unchecked questionnaire response. Use a simple confidence scale such as verified, supported, asserted and unknown, and prevent a high capability score from masking weak evidence. The assessment should make uncertainty visible to the business owner so risk acceptance is informed rather than implied.

Concentration and fourth-party exposure

Two suppliers can appear diversified while depending on the same cloud region, telecom carrier, logistics hub, specialist subcontractor or software platform. Ask enough architecture and dependency questions to identify material concentration without demanding unnecessary confidential detail. For critical services, document known fourth parties, geographic concentration, substitution lead time and whether the alternate supplier has actually been onboarded. A theoretical alternative with a six-month onboarding period is not an incident-time continuity option.

Contract and remediation decisions

Translate findings into specific treatment. Examples include stronger recovery commitments, notification deadlines, participation in exercises, evidence rights, alternate routing, minimum inventory, dual sourcing, escrow, exit support or a funded internal workaround. Each action should have an owner and due date. Where treatment is not proportionate or feasible, record the residual exposure and obtain acceptance from the accountable business owner at the appropriate authority level.

Test the service boundary, not only the supplier organization

A large supplier may have a mature enterprise continuity program while the specific service purchased by your organization depends on a fragile team, region or subcontractor. Define the assessed service boundary before scoring. Confirm the locations, platforms, support teams, data flows and fourth parties that actually deliver the service. Evidence should correspond to that boundary; a corporate certificate or generic plan is useful context but does not by itself demonstrate recovery of the contracted service.

Use findings in sourcing and renewal decisions

Continuity assessment should influence decisions before leverage is lost. Feed material requirements into tender evaluation, contract negotiation and renewal planning, and distinguish mandatory controls from improvements that can be completed after award. Where a supplier cannot meet the required recovery capability, evaluate an internal workaround, alternate supplier, inventory buffer, architecture change or explicit tolerance adjustment. Record the decision and its assumptions so a later incident does not expose an undocumented dependency that stakeholders believed had already been treated.