Tiering third-party vendors by risk
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 2 min read · Compliance
Treating every vendor the same is how third-party risk management dies of its own weight. Tier by the data they touch, then spend your effort accordingly.
Why tiering, not uniform review
A growing company has dozens to hundreds of vendors. Diligencing all of them to the same depth is impossible and pointless — your payroll processor and your office-snack subscription do not carry the same risk. Tiering concentrates effort where it matters and is itself the sign of a mature, risk-based program that auditors look for.
Two axes that decide the tier
Tier on two questions: how sensitive is the data the vendor touches (customer PII, card data, credentials, source code — or nothing sensitive), and how critical is the vendor to operations (would an outage stop the business). A vendor high on either axis is a high tier; low on both is a low tier.
What each tier gets
- High tier: obtain and review their SOC 2 or ISO 27001 report (or a completed security questionnaire) at onboarding and at renewal; confirm a DPA where personal data is involved; track their subprocessors.
- Medium tier: a lighter review and a contract with security terms; revisit periodically.
- Low tier: a register entry — who they are, what they touch — and little more.
Keep the register current
Tiering is only useful if the register stays current as vendors are added and dropped. Make onboarding a new vendor trigger a tier decision, and tie high-tier reviews to a renewal cadence so they do not lapse. A stale vendor list is worse than none because it gives false assurance.
One model, every framework
A tiered vendor program satisfies SOC 2 risk mitigation, ISO 27001 supplier controls, PCI service-provider management, and the vendor-oversight expectations in HIPAA and NIST CSF. SentinelPanda keeps the register, assigns tiers, schedules the reviews, and stores the reports — one program, credited everywhere.