Supplier continuity assessment should answer a practical question: if this provider fails during a severe but plausible disruption, can our important service still remain within its approved recovery requirement? A generic questionnaire with 50 “yes” answers is weak evidence if it never tests the specific service, locations, subcontractors, technology or concentration on which you depend.
Critical supplier tiering
Tier
Typical test
Expected evidence
Tier 1 – service critical
Loss can breach MTPD/RTO/impact tolerance or create severe legal/safety/customer harm
DORA summary — EU financial-sector rules include ICT third-party risk management for in-scope entities.
Critical supplier evidence matrix
Evidence
Strong
Weak / warning sign
Service-specific recovery objective
Supplier commitment maps to the contracted service and your RTO
Generic corporate BCP certificate only
Exercise evidence
Recent test includes the service, location/region and dependencies you use
“We test annually” with no result or scope
Capacity during shared event
Documented allocation/capacity assumptions when many customers invoke recovery
Assumes unlimited recovery seats/people/compute
Subcontractors
Critical fourth parties and locations are known
Provider cannot identify material subcontracted dependencies
Cyber recovery
Immutable/protected recovery, identity, clean restore and incident coordination addressed
Backup mentioned without restore/security evidence
Communications
24x7 incident contacts, severity, cadence and escalation defined
Account manager is the only emergency contact
Exit / substitution
Data portability, transition, alternate route or manual option tested
No practical exit or replacement lead time understood
Supplier concentration analysis
Assess concentration across more than supplier names. Ten vendors can still depend on the same cloud region, telecom carrier, identity provider, logistics hub, software component or specialist workforce. Create a concentration view that maps critical services to fourth parties, locations, infrastructure and common technology. Then exercise a common-mode scenario rather than one vendor at a time.
Contract and SLA questions for BCM
Does the contract define recovery commitments for the exact service you consume?
Does the SLA begin at incident start, provider declaration or customer ticket creation?
Are RTO/RPO commitments accompanied by test evidence rights?
Can you participate in or receive results from relevant resilience exercises?
Are subcontractor changes and material location changes notified?
Is incident notification fast enough for your own regulatory/customer obligations?
Is data export available during distress/termination, and how long does it take?
What capacity is guaranteed when a regional event affects multiple customers?
Are cyber recovery, data integrity and credential rotation addressed?
Does the exit plan work if the provider is unavailable rather than cooperative?