Category: Customer Trust & Third-Party Risk Tags: customer trust, vendor risk, right to audit, tiering, subprocessors, concentration risk, trust center

A customer's risk team once sent us a reassessment questionnaire that was, section for section, almost exactly the one we sent our own vendors. Same structure, same evidence requests, same slightly hostile phrasing about compensating controls. Reading it was a peculiar experience, because I recognized every question and had never once considered how they looked from this side. Two of them we could not answer well. One asked for evidence we generated but had never assembled into anything presentable. Another asked about a control we genuinely operated, in a way that made our honest answer sound evasive. And the reassessment had been triggered by something nobody at our company knew had happened: their program had moved us up a tier, because a team over there had started using us for something more critical than what we were originally bought for.

That is the reframe I have found more useful than any framework in this area. Whatever you sell, your company is a row in somebody else's vendor register. You have been tiered by people you will never meet, on criteria you have not read, using evidence you did not choose. Every complaint you have about vendors is a complaint your customers are quietly making about you.

You Have Been Scored and Nobody Told You

The first thing that follows is that a good deal of what happens to you commercially is being decided inside a process you cannot see. Somewhere in each of your enterprise customers, a risk analyst has assigned your company a criticality tier, a data classification, and probably a numeric score. That score determines how often you get reassessed, how much evidence you are asked for, whether your incidents trigger an internal escalation over there, and in some organizations whether a renewal needs additional sign-off. None of it is shared with you, and the person you talk to in that account usually has no idea it exists.

Most companies never think about this as a thing to manage, which is strange given how much revenue depends on it. The tier is knowable, or at least inferrable, and the signal is in what your customers ask for. A vendor treated as low criticality gets a short questionnaire every couple of years. One treated as critical gets a long assessment annually, contract terms with teeth, notification windows measured in hours, and eventually a request to come look around. If a customer's demands have escalated, your tier moved, and it moved because your product got more important to them, which is simultaneously good news commercially and a change nobody on your side noticed. Tracking what each major customer asks of you, and when that changes, is close to free and tells you something your account team cannot.

The Audit Right Somebody Signed Years Ago

Then there is the clause. Enterprise agreements routinely carry a right to audit, and it is one of the least examined terms in the contract because it costs nothing on the day it is signed and everything on the day it is used. Sales does not read it, security is often not shown it, and the first time anyone reads it carefully is when a customer's third-party risk team writes to schedule.

What makes that moment survivable is decided long before. The audits that go badly are the ones where nobody owns the response, the scope is undefined so the customer's team defines it for you, and every piece of evidence has to be manufactured under a deadline while the people who could produce it are doing their day jobs. The ones that go well look almost boring: someone owns customer audits as a named responsibility, the standing evidence pack already exists because the same twenty items get requested every time, and the scoping conversation happens early enough to agree what is in bounds, what is answered by an existing report or certification, and what genuinely needs a live walkthrough. That preparation also gives you the standing to push back on the requests that are unreasonable, which you will never have while you are visibly scrambling.

It helps to remember what the person on the other side actually needs, because it is rarely to catch you out. They need to close a finding, and to be able to defend their conclusion to their own examiner or board later. Evidence that lets them do that quickly is the fastest route to the end of the audit. This is the same argument I made about assessments generally in scoring the questionnaire, not the vendor, read from the opposite chair: their process rewards what can be evidenced, and if the reality of your control environment is better than your evidence of it, you will be scored on the evidence.

You Are Also Somebody's Fourth Party

Go one link further out and it gets more interesting. Your customers have customers, and to those people you are a fourth party: invisible, unassessed, and load-bearing. When a customer's own client asks them to map their supply chain, your name appears on a list you never saw, alongside your subprocessors, who are now fifth parties to somebody.

The practical consequence is that your vendor choices propagate outward, and so does your concentration. If you and the two competitors your customer also uses all run in the same cloud region, that customer has a correlated exposure their vendor register will never show, because each of you is a separate row that looks independent. I wrote about that blindness from the buyer's side in the vendor behind your vendor. From the seller's side it creates a genuine opportunity, which is that being straightforward about your own dependencies, your subprocessors, your regions, your material fourth parties, is unusual enough to be a differentiator with sophisticated buyers. The unsophisticated ones will not ask. The ones running real programs will, and they will notice which vendors answer cleanly and which produce a paragraph of marketing.

Run the Mirror Exercise

The single most useful exercise I know here takes a day and costs nothing. Take the vendor assessment your own company sends out, the real one, and complete it about yourself. Honestly, with evidence attached, as though you were a supplier trying to win your business. Then score it with your own criteria, apply your own tiering, and see what you would decide about a vendor with that profile.

It is an uncomfortable exercise and it produces a better roadmap than most gap assessments, for three reasons. It finds the questions where the true answer is fine but the evidence does not exist, which is the most common and most fixable failure. It finds the questions where the honest answer is genuinely weak, which tells you what a serious buyer already knows about you. And it finds the questions where your own questionnaire is badly designed, which is worth knowing given you send it to other people. Every finding maps to something concrete: an artifact to assemble, a control to build, or a commitment to write down and keep, which is where this connects to treating your questionnaire answers as controls rather than as sales collateral.

The deeper payoff is not the findings list. It is that a program run by people who have sat on both sides makes different choices. They ask vendors for evidence that exists rather than evidence that would be ideal. They scope audits before scheduling them. They notice when their own demands have escalated and tell the vendor why, because they know what it is like to be reassessed for reasons nobody explained. Being on the receiving end is the fastest education available in how third-party risk actually lands, and the invoice for that education arrives whether or not you choose to learn from it. You may as well read the questionnaire carefully the first time it shows up, and recognize that the company on the other end of it is doing exactly what you do all day, to you.

PivotRisk is a practitioner-led governance, risk, and resilience practice. Everything published here comes out of programs actually designed, launched, and run inside enterprise software, fintech, and infrastructure companies, not frameworks summarized from a distance.

Point your own assessment back at yourself

The Vendor Risk Assessment workbook is built to tier and score suppliers on criticality and data access, with the scoring visible rather than asserted. Run it on your own company for the mirror exercise: the questions where your evidence does not exist yet are the ones your next enterprise buyer will find.

Get the Vendor Risk Assessment