Third parties and vendors

Does the Applicant review and audit information security/privacy controls of IT, cloud, and non-IT service providers?

The question names non-IT providers deliberately, because the vendors that cause breaches are often the ones nobody considered technical.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether you assess the security and privacy controls of the third parties that handle your data or connect to your systems, and whether that assessment happens before engagement and repeats afterwards. It explicitly includes providers outside the IT category.

Why it is underwritten

A large and growing share of breaches originate at a supplier. From the carrier's perspective the exposure is identical to your own, because your notification obligations and your business interruption follow from a compromise wherever it began. Vendor review is the only control that operates before the exposure is created.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Vendor assessment lives in a procurement or governance process rather than in a cloud tenant, so this is attested. Some of the resulting access is measurable.

PlatformWhere the setting livesWhat has to be true
Vendor registerAn inventory of third parties, with data access and criticalityA maintained register that includes the small vendors and the ones procured outside IT. Attested
Assessment recordsDue diligence performed per vendor, proportionate to riskEvidence collected: certifications, assessment reports, questionnaire responses, with review dates
Entra IDGuest accounts and external identities from vendor organisationsThe vendors with directory access, which is a reality check against the register
Entra IDEnterprise applications and their granted permissionsThird-party applications with consented access to your data, which is vendor access nobody procured
ContractsSecurity requirements, breach notification obligations, and audit rightsContractual controls that make the assessment enforceable
Consented applications are unassessed vendors

Every application a user consented to holds delegated access to your data and never passed through procurement. In most tenants this list is longer than the vendor register and nobody has reviewed it. It is the fastest place to find third-party access you did not know you had.

What a defensible yes requires

  • A vendor register exists, covers non-IT suppliers, and records what data each can reach.
  • Diligence is proportionate to risk, with deeper review for vendors holding regulated data.
  • Review recurs rather than happening once at onboarding.
  • Contracts carry security requirements, breach notification, and audit rights.
  • Consented applications and guest access are reviewed alongside contracted vendors.

How this answer goes wrong

The programme covers the large IT vendors that arrive with certification reports, and misses the marketing platform, the payroll bureau, the facilities contractor with network access, and the fifty applications users consented to. Those are where the incidents have come from.

Frequently asked

Is collecting a certification report enough?

For lower-risk vendors it is proportionate, provided someone reads it, checks its scope, and notes any qualifications. Filing it unread is a common and hollow form of diligence.

How often should we reassess?

Annually for critical vendors, and on any material change. A vendor that changes hands or changes sub-processors warrants a fresh look regardless of cadence.

What about very small suppliers?

Scale the review to the access. A small vendor with administrative access to your systems needs more scrutiny than a large one with none.

Where do we start?

The register. Most organisations cannot list their vendors with data access, and building that list usually surfaces several surprises.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture