A supplier BCM assessment is the assurance decision that follows supplier criticality analysis and evidence collection. Its purpose is to decide whether a supplier's demonstrated continuity capability is sufficient for the business dependency—not merely whether a questionnaire was completed.
Use this page for the assessment decision
Use this guide when you need to classify assurance depth, evaluate submitted evidence, determine whether recovery claims are credible, record gaps and decide whether the residual supplier risk is acceptable. If you need the actual questions to send to a supplier, use the Supplier Business Continuity Questionnaire Guide.
Start with business criticality, not a standard questionnaire
Map the supplier to the business service it supports and record the service disruption tolerance, required supplier recovery time, minimum capacity, geographic or technology concentration, substitutability and any regulatory or contractual constraints. A payroll stationery supplier and a sole-source transaction platform should not receive the same assurance treatment.
| Supplier tier | Typical dependency | Assurance depth |
|---|---|---|
| Critical | Failure can breach disruption tolerance before substitution is practical | Evidence review, recovery-test results, exceptions, assurance meeting and scenario challenge |
| Important | Material degradation but workable alternatives exist | Targeted questionnaire plus evidence for key recovery claims |
| Standard | Low continuity impact or rapid substitution | Proportionate screening and contractual baseline |
Evaluate claims against evidence
Separate the supplier's statement from the evidence that supports it. “We have a BCP” has little assurance value by itself. Stronger evidence identifies the contracted service, approved recovery objective, last exercise scope, achieved recovery timing, capacity during degraded operation, unresolved findings and dependencies on subcontractors or shared infrastructure.
Evidence quality test
- Relevant: it applies to the exact contracted service, location and delivery model.
- Current: it reflects the present architecture, workforce and supplier chain.
- Tested: recovery claims are supported by exercises, restores, failovers or incident evidence.
- Measurable: time, capacity, data loss and backlog assumptions have observable acceptance criteria.
- Transparent: exceptions and sub-tier dependencies are disclosed rather than hidden behind certification.
Turn gaps into decisions
For every material gap record the affected business service, requirement, current demonstrated capability, evidence weakness, consequence, owner, treatment and due date. Then choose an explicit disposition: accept the risk, require remediation, add a contractual control, create an alternate source, reduce dependency, increase internal workaround capacity or escalate for management decision.
Worked assessment example
A critical hosted-service supplier states a four-hour recovery target. Its latest exercise restored infrastructure in three hours but business interfaces were not validated until hour seven and the test excluded its identity provider. The assessment should not record “RTO met.” It should record the demonstrated end-to-end capability, the untested identity dependency and the resulting exposure against the customer's tolerance. Management can then require a joint test or formally accept the gap.
Challenge concentration and common-mode failure
Ask whether the primary and fallback arrangements share the same cloud region, carrier, identity service, key personnel, subcontractor, logistics route or facility utility. Two suppliers are not independent if both depend on the same constrained upstream provider. Record concentration explicitly because it changes the value of diversification and substitution strategies.
Assessment output and governance
The output should be a short decision record: supplier tier, protected service, required capability, demonstrated capability, evidence confidence, material gaps, treatment, accountable business owner and next review trigger. Procurement can own contractual actions, but the business owner should remain accountable for accepting continuity exposure.
When to reassess
Reassess after a material service or hosting change, acquisition, location change, major subcontractor change, failed exercise, significant incident, repeated SLA failure, contract renewal or a change to the dependent business service's tolerance. High-criticality suppliers should also be reviewed on a defined assurance cycle.
Relationship to the supplier questionnaire
The supplier continuity questionnaire is an evidence-collection instrument. This assessment is the risk and assurance process that interprets those answers. Keeping the two purposes separate avoids awarding a supplier a pass merely for completing a form.
Evidence confidence and scoring
Score the quality of evidence separately from the supplier's claimed capability. A current independent certification, recent exercise result or customer-specific recovery test provides stronger assurance than an unchecked questionnaire response. Use a simple confidence scale such as verified, supported, asserted and unknown, and prevent a high capability score from masking weak evidence. The assessment should make uncertainty visible to the business owner so risk acceptance is informed rather than implied.
Concentration and fourth-party exposure
Two suppliers can appear diversified while depending on the same cloud region, telecom carrier, logistics hub, specialist subcontractor or software platform. Ask enough architecture and dependency questions to identify material concentration without demanding unnecessary confidential detail. For critical services, document known fourth parties, geographic concentration, substitution lead time and whether the alternate supplier has actually been onboarded. A theoretical alternative with a six-month onboarding period is not an incident-time continuity option.
Contract and remediation decisions
Translate findings into specific treatment. Examples include stronger recovery commitments, notification deadlines, participation in exercises, evidence rights, alternate routing, minimum inventory, dual sourcing, escrow, exit support or a funded internal workaround. Each action should have an owner and due date. Where treatment is not proportionate or feasible, record the residual exposure and obtain acceptance from the accountable business owner at the appropriate authority level.
Test the service boundary, not only the supplier organization
A large supplier may have a mature enterprise continuity program while the specific service purchased by your organization depends on a fragile team, region or subcontractor. Define the assessed service boundary before scoring. Confirm the locations, platforms, support teams, data flows and fourth parties that actually deliver the service. Evidence should correspond to that boundary; a corporate certificate or generic plan is useful context but does not by itself demonstrate recovery of the contracted service.
Use findings in sourcing and renewal decisions
Continuity assessment should influence decisions before leverage is lost. Feed material requirements into tender evaluation, contract negotiation and renewal planning, and distinguish mandatory controls from improvements that can be completed after award. Where a supplier cannot meet the required recovery capability, evaluate an internal workaround, alternate supplier, inventory buffer, architecture change or explicit tolerance adjustment. Record the decision and its assumptions so a later incident does not expose an undocumented dependency that stakeholders believed had already been treated.