Supplier risk assessment ISO 27001 wants, without a procurement department
Somebody in marketing signed up for a transcription service with the company card. It processes recordings of customer calls. It was fourteen pounds a month, it solved a real problem, and nobody told you, because there is no process that would have required them to.
That is the shape of supplier risk at forty people. Not a procurement failure, because there is no procurement. A supplier risk assessment iso 27001 asks for under Annex A 5.19 to 5.23 has to work in an environment where anybody with a card can onboard a data processor in four minutes.
Building the register, from what you already have
The register is the prerequisite for everything and people start it from memory, which produces about half of it.
Four sources, in order of yield:
The card statement. Twelve months of it. Every recurring charge is a supplier, and this catches the ones nobody mentioned.
Your identity provider's enterprise applications list. Every SaaS product anybody signed into with a work account, including the ones authorised by a user rather than an administrator. This is frequently the most surprising list in the company.
DNS and email records. A supplier with a CNAME or a DKIM record in your zone is integrated deeply enough to matter, and those records outlive the relationship.
Ask the team. Last, not first, because memory produces the obvious ones and the sources above produce the rest.
Expect the real number to be two to three times what anybody guessed.
Tiering by data access, not by spend
The instinct is to sort by cost. Cost is nearly irrelevant to risk.
The transcription service at fourteen pounds a month processes customer conversations. The accounting package at several hundred a month processes your own invoices. One of those is a sub-processor of customer personal data and one is not, and the cheap one is the problem.
Three tiers are enough:
Tier one: processes customer data, or has production access. Hosting, identity, anything embedded in the product, any sub-processor named in your customer contracts. These get a real assessment and an annual review.
Tier two: holds company data but not customer data. Accounting, HR systems, your code repository if it holds no customer data. Assessment at onboarding, review on a longer cycle.
Tier three: no access to anything sensitive. A design tool, a scheduling app. Recorded in the register, no assessment.
Tiering is what makes this maintainable. Forty suppliers assessed equally is a job nobody completes. Eight tier one suppliers assessed properly and thirty-two recorded is defensible and finishable.
Obtain their assurance rather than sending a questionnaire
This is the part most guidance gets backwards, and it is the difference between a supplier programme that works and one that generates paperwork.
The instinct is to build a vendor security questionnaire and send it to suppliers. Resist it. For a company of forty, that approach fails in both directions: large suppliers will ignore you, because you are not a material customer and they have a trust portal precisely so they do not answer bespoke questionnaires. Small suppliers will answer, and their answers are self-assessed, unverified, and worth very little.
What works instead is obtaining the assurance they already produce. Their ISO 27001 certificate, with the scope checked against what they do for you. Their SOC 2 Type II report, requested under NDA. Their published sub-processor list. Their status page history. Their breach disclosure history, which is a search rather than a request.
That is better evidence than a questionnaire because it is independently verified, and it is less work for everybody. Where a supplier has none of it, that absence is itself the finding, and the question becomes whether the risk is acceptable rather than what they claim about their firewalls.
The lever people forget is the contract. A data processing agreement with an audit clause, and a requirement to notify you of sub-processor changes and of breaches within a stated period, gives you more actual protection than any questionnaire response. Getting that into the agreement at signature is easy; adding it two years later is not.
What to actually check, per tier one supplier
Six things, and it takes under an hour once you know where to look.
Their certification, and its scope. A certificate whose scope excludes the service you use is a common and easily missed problem, the same trap as your own scope statement.
A data processing agreement, signed, covering the categories of data they actually process.
Their sub-processors. Who they pass your data to. This is where data residency questions come from, and it is the part customers ask you about.
Where the data sits, and where it can be accessed from, which are different questions, as the questionnaire note covers.
Breach history, from a search. Not disqualifying, and how they handled it is informative.
What happens when it ends. Data return or deletion, and whether you could actually leave.
Record the answers, the date, and your conclusion. The conclusion is the part that matters, and "acceptable, reviewed 2026-03-01, next review 2027-03-01" is what an auditor is looking for rather than a folder of PDFs.
The onboarding gate
Reviewing annually while anybody can onboard a supplier in four minutes means the register is always out of date.
The gate that works at this size is not a procurement process, it is one question in the expense approval path: does this handle customer data. If yes, it comes to you before the card is used. If no, it goes in the register and nothing else happens.
That is a single question, it is answerable by a non-technical person, and it catches the tier one cases which are the only ones that matter urgently. A heavier process gets routed around, and a supplier onboarded around the process is worse than one onboarded through a light one.
The supplier risk assessment iso 27001 asks for, without procurement
Controls 5.19 through 5.23 cover supplier relationships, addressing security within agreements, managing the ICT supply chain, monitoring and review, and managing changes to supplier services. Written for organisations with a procurement function, and satisfiable without one.
What satisfies them at forty people: a register, a tiering rule, evidence of assurance obtained for tier one, DPAs in place, an annual review with dates and conclusions, and the onboarding question above. That is a page of process and a spreadsheet, and it is genuinely what the controls ask for.
The one that lapses in year two is the review, because nothing prompts it, which is the surveillance audit pattern. Put it in the calendar the week you finish the first one.
The book covers the supplier controls in detail, and the ICO's guidance on processor contracts sets out what a data processing agreement has to contain, which is the half of this that is a legal requirement rather than a standard's requirement.