An explainer for compliance, risk and information security
Which suppliers must you monitor – and how far down the chain?
No rulebook answers that for you. Every one of them requires you to answer it – traceably, with reasoning, in writing. This page shows what such a boundary looks like.
The requirement sounds similar in every standard: relevant suppliers must be evaluated and monitored, the supply chain must be considered. What is missing is the list. Whether that means your data centre operator, your calibration service, the cleaning firm with access to production or the office supplies dealer is stated nowhere.
That is deliberate, not an oversight. A fixed list would be wrong for an engineering office and equally wrong for a food producer. What is required is therefore not an outcome but a method: you define the criteria, apply them to everyone, and record the result.
Audits rarely object to a narrow scope. They object to an arbitrary one. The difference is a single document.
What the rulebooks actually say
Depth is not a matter of judgement where the legislator fixed it. Everywhere else it is your reasoned decision.
| Rulebook | Reach | What follows |
|---|---|---|
| ISO 9001, clause 8.4 | Externally provided processes, products and services | Type and extent of control follow the impact on conformity – explicitly graded. |
| ISO 27001, A.5.19–A.5.21 | Supplier relationships, explicitly the ICT supply chain | A.5.21 requires looking at the chain behind the provider – on a risk basis, not exhaustively. |
| NIS2, Art. 21(2)(d) | Direct suppliers and service providers | The wording limits it to tier one. Going further is permitted, not required. |
| German LkSG | Direct suppliers regularly, indirect on a trigger | Beyond tier one only where there is substantiated knowledge of a possible violation. |
| CSDDD | Chain of activities, risk-based | Explicitly no full mapping. Prioritise by severity and likelihood. |
| EU Deforestation Regulation | Down to the plot of production | Here the legislator names the endpoint: the geolocation of the land. No discretion. |
| Conflict Minerals Regulation | Down to the smelter or refiner | Another named endpoint – beyond it the material is no longer distinguishable. |
| UFLPA (United States) | Down to the raw material, with the burden on the importer | The hardest case: the authority does not have to prove; you have to rebut. |
Four questions that set the scope
These four can be answered for any supplier in minutes. Together they produce the classification – and its reasoning at the same time.
- Failure What stops if this supplier delivers nothing tomorrow – and how long can we bear it? Order volume is not the measure; impact is. A calibration service worth a few thousand a year can halt an entire production line.
- Access What could go wrong there? Access to data, to systems, to premises, influence on product quality? This question brings in the providers who never delivered anything and therefore appear on no procurement list.
- Replaceability How quickly do we have a replacement – a qualified, approved one? An alternative that would still need vetting is not an alternative in a crisis.
- Trigger Does a law, a standard or a customer contract explicitly name this supplier, its commodity group or its country of origin? This is where the non-negotiable duties arise – raw materials under due diligence rules, processors handling personal data.
Four classes are enough
More levels raise the upkeep without improving the decision. Grade too finely and you end up debating classifications instead of actions.
| Class | When | What follows |
|---|---|---|
| Critical | Failure stops operations or endangers people; no approved replacement | Full assessment, annual evaluation, audit, documented second source, emergency contacts |
| Material | Access to personal data or systems; noticeable effect on quality or deadlines | Self-disclosure, evidence with deadline monitoring, evaluation on a fixed cycle |
| Relevant | Limited effect, replaceable, but with site access or product contact | Basic evidence, evaluation on a longer cycle, recall dates |
| Recorded | None of the four questions yields anything | Keep master data, nothing more. That too is a documented decision. |
Examples from practice
The same supplier types, classified differently – because the four questions come out differently.
| Supplier | Class | Depth | Reasoning |
|---|---|---|---|
| Data centre or cloud platform | Critical | Tier 2 | Failure halts operations immediately and personal data is involved. A.5.21 and data protection law explicitly require looking at sub-processors. |
| Single source for a casting | Critical | Tier 2 where due diligence applies | Production stops with no replacement. Deeper only where the material falls under a due diligence regime – then to the named endpoint. |
| Payroll or fiduciary services | Material | Tier 1 and sub-processing | Personal data of every employee. Replacement takes weeks. Sub-processors must be approved. |
| Calibration service | Material | Tier 1 | Without traceability, measurement results do not hold – despite a small contract value. |
| Marketing SaaS holding customer data | Material | Tier 1 and sub-processing | The classic omission: delivers no goods, appears on no procurement list, processes personal data. |
| Cleaning service with access to production | Relevant | Tier 1 | Access to production areas, contamination and security risk. Technically simple, but not zero. |
| Forwarder for standard freight | Relevant | Tier 1 | Delivery reliability and integrity of goods. Dangerous goods, temperature control or high value raise the class. |
| Office supplies, coffee service | Recorded | None | No influence on product or data, no access to sensitive areas, immediately replaceable. Master data suffices. |
Depth of the chain: where to stop?
The chain is infinite. Your responsibility is not.
A common objection runs roughly like this: we monitor our IT supplier. Then we would have to monitor the chip manufacturer, then the silicon producer, then the mining company, then the maker of the excavator used to extract it, and finally that excavator’s tyre supplier. That is obviously absurd – which is exactly what makes it a useful example.
The rulebooks resolve it with two limits applied together: your ability to influence, and the presence of a trigger. Where you have neither influence nor a trigger, consideration ends. The excavator tyre fails both tests.
| Tier | When it is considered | Example |
|---|---|---|
| Tier 1 — direct suppliers | Always. Fully recorded, assessed to a depth set by class. | Your IT provider, your casting supplier, your fiduciary. |
| Tier 2 — their suppliers | Only on a trigger: single source, hidden concentration, data access, customer requirement, explicit standard. | The sub-data-centre behind your cloud provider. The payroll processor your fiduciary engages. |
| Named endpoint | Where a law names the point itself – regardless of how many tiers lie between. | The smelter under conflict minerals rules. The plot under the deforestation regulation. The raw material under UFLPA. |
| Everything beyond | Not considered while no trigger exists. That decision is recorded, not left unsaid. | The excavator tyre. The electricity supplier of the chip plant. |
The sentence that carries an audit is not “we checked everything” but “we defined where we stop, and here is why”.
Five mistakes that reliably produce findings
- Classifying by order value
- Office supplies outspend the calibration service and matter less. Impact decides, not the amount.
- Treating everyone alike
- Send every supplier the same questionnaire and you get too little from the critical ones and too much from the rest. Effort dilutes onto the wrong parties.
- Forgetting providers who deliver no goods
- They appear on no procurement list because nothing was ever delivered. The second look belongs on the list of accounts and access rights, not on payables.
- Depth without a trigger
- Mapping tier two across the board costs months and answers no question anyone asked.
- Never writing the scope down
- Without a documented rule, every classification is an individual opinion. That is exactly what cannot be defended in an audit.
What the auditor wants to see
Four things, in this order. Missing one makes the rest of little help.
- The ruleA document describing the criteria and the classes. Two pages will do.
- The applicationEvery supplier classified – including those where the result is “recorded, no monitoring”.
- The exceptionsWhere the rule was departed from, the reason and the decision-maker are stated.
- The recallClassifications age. A supplier that becomes a single source changes class – and somebody has to notice.
How this looks in SCRM
The four questions become fields, the classes become depths of assessment, the triggers become rules. Whoever is classified gets the matching cycle automatically – and the reasoning stays on the record, where the auditor looks for it.