Template

Supplier Business Continuity Assessment Template

A 50-question critical-supplier continuity assessment with tiering, evidence-quality matrix, concentration risk, contract topics, joint testing and exit planning.

Supplier continuity assessment should answer a practical question: if this provider fails during a severe but plausible disruption, can our important service still remain within its approved recovery requirement? A generic questionnaire with 50 “yes” answers is weak evidence if it never tests the specific service, locations, subcontractors, technology or concentration on which you depend.

Critical supplier tiering

TierTypical testExpected evidence
Tier 1 – service criticalLoss can breach MTPD/RTO/impact tolerance or create severe legal/safety/customer harmDetailed resilience review, recovery evidence, escalation, testing participation, concentration and exit analysis
Tier 2 – importantLoss materially degrades service but workaround existsBCP/DR evidence, SLA, contacts, workaround and periodic review
Tier 3 – non-criticalLoss is tolerable beyond normal procurement replacement timeBasic due diligence and normal supplier management

50-question supplier continuity assessment

Service and dependency

  1. What exact service/product do you provide to us?
  2. Which of our business services depend on it?
  3. Which locations/data centres/cloud regions deliver it?
  4. What operating hours and peak capacity are supported?
  5. Which parts are subcontracted?
  6. Which utilities/telecom/cloud platforms are material dependencies?
  7. Can one event affect multiple locations?
  8. What customer-specific configuration or data is needed to recover?

Governance and plans

  1. Is there an approved continuity policy?
  2. Who is accountable for continuity?
  3. When was the service BIA last reviewed?
  4. What recovery objectives are approved?
  5. Does the plan cover people, technology, facilities and suppliers?
  6. What triggers plan activation?
  7. Who may declare a disaster/failover?
  8. How often are plans reviewed after change?

Technology and data

  1. What RTO/RPO commitment applies to our service?
  2. What recovery architecture supports it?
  3. Are backup/restoration procedures tested?
  4. How is backup isolation/immutability handled where relevant?
  5. How are identity/DNS/network dependencies recovered?
  6. How are transactions reconciled after recovery?
  7. How is cyber clean recovery handled?
  8. What is the last demonstrated recovery time and recovery point?

People and location

  1. What minimum staffing is needed?
  2. Are alternates cross-trained?
  3. Can service operate remotely or from another site?
  4. Are both primary and alternate teams exposed to the same regional event?
  5. What specialist or privileged roles are single points of failure?
  6. What absenteeism assumption has been tested?

Exercises and incidents

  1. When was the service last exercised?
  2. Was the exercise technical, business or integrated?
  3. What scenario was used?
  4. Were customers invited or evidence shared?
  5. Which material findings remain open?
  6. Have actual incidents exceeded recovery targets?
  7. How are lessons learned tracked?
  8. Can we participate in a joint scenario test?

Contract, communication and exit

  1. What emergency support route and escalation contacts exist?
  2. What incident-notification commitment exists?
  3. What information is provided during disruption?
  4. Are resilience obligations flowed to material subcontractors?
  5. What audit/assurance rights exist?
  6. What service credits/remedies apply and do they actually reduce continuity risk?
  7. What data-return/deletion obligations apply on exit?
  8. How long would transition to an alternate take?

Concentration and resilience

  1. Which other critical suppliers share the same underlying cloud/telecom/data centre?
  2. Is there geographic/provider concentration?
  3. Can primary and DR capacity be exhausted by multiple customers at once?
  4. Is recovery capacity reserved or best effort?
  5. What dependency cannot currently meet our target?
  6. What compensating controls exist?
  7. What change would force immediate reassessment?
  8. Who in our organisation owns the residual supplier risk?

Requirement-to-evidence matrix

ClaimWeak evidenceStronger evidence
“RTO 2 hours”Sales proposal or unchecked questionnaire answerRecent service-specific test result with measured timeline, scope, dependencies and exceptions
“Multiple data centres”Architecture diagram onlyEvidence that recovery has been exercised and sites do not share a critical failure domain
“Backups are daily”Backup job configurationSuccessful restore evidence and reconciliation to a known recovery point
“We have a BCP”Plan cover pageRelevant plan sections, last exercise evidence, open findings and named service owners
“Subcontractors are resilient”Contract boilerplateMaterial subcontractor mapping, due diligence and continuity obligations
“Exit is possible”Termination clauseData export format, migration lead time, credentials, test/transition plan and alternate capacity

Contract clauses BCM should discuss with procurement/legal

  • Service and recovery objectives defined in measurable terms.
  • Incident notification and update expectations appropriate to the dependency.
  • Participation in exercises or provision of meaningful test evidence.
  • Subcontractor and material-change notification where appropriate.
  • Access to continuity/assurance evidence and corrective-action status.
  • Data availability, backup, restoration, return and secure deletion responsibilities.
  • Exit assistance, transition period, format and portability.
  • Emergency escalation contacts and authority.
  • Location/jurisdiction/concentration information where relevant to risk.
  • No contract clause replaces the organisation’s own contingency strategy.

Official references and further reading

Critical supplier evidence matrix

EvidenceStrongWeak / warning sign
Service-specific recovery objectiveSupplier commitment maps to the contracted service and your RTOGeneric corporate BCP certificate only
Exercise evidenceRecent test includes the service, location/region and dependencies you use“We test annually” with no result or scope
Capacity during shared eventDocumented allocation/capacity assumptions when many customers invoke recoveryAssumes unlimited recovery seats/people/compute
SubcontractorsCritical fourth parties and locations are knownProvider cannot identify material subcontracted dependencies
Cyber recoveryImmutable/protected recovery, identity, clean restore and incident coordination addressedBackup mentioned without restore/security evidence
Communications24x7 incident contacts, severity, cadence and escalation definedAccount manager is the only emergency contact
Exit / substitutionData portability, transition, alternate route or manual option testedNo practical exit or replacement lead time understood

Supplier concentration analysis

Assess concentration across more than supplier names. Ten vendors can still depend on the same cloud region, telecom carrier, identity provider, logistics hub, software component or specialist workforce. Create a concentration view that maps critical services to fourth parties, locations, infrastructure and common technology. Then exercise a common-mode scenario rather than one vendor at a time.

Contract and SLA questions for BCM

  • Does the contract define recovery commitments for the exact service you consume?
  • Does the SLA begin at incident start, provider declaration or customer ticket creation?
  • Are RTO/RPO commitments accompanied by test evidence rights?
  • Can you participate in or receive results from relevant resilience exercises?
  • Are subcontractor changes and material location changes notified?
  • Is incident notification fast enough for your own regulatory/customer obligations?
  • Is data export available during distress/termination, and how long does it take?
  • What capacity is guaranteed when a regional event affects multiple customers?
  • Are cyber recovery, data integrity and credential rotation addressed?
  • Does the exit plan work if the provider is unavailable rather than cooperative?