Does the Applicant review and audit information security/privacy controls of IT, cloud, and non-IT service providers?
The question names non-IT providers deliberately, because the vendors that cause breaches are often the ones nobody considered technical.
What the carrier is actually asking
The carrier is asking whether you assess the security and privacy controls of the third parties that handle your data or connect to your systems, and whether that assessment happens before engagement and repeats afterwards. It explicitly includes providers outside the IT category.
Why it is underwritten
A large and growing share of breaches originate at a supplier. From the carrier's perspective the exposure is identical to your own, because your notification obligations and your business interruption follow from a compromise wherever it began. Vendor review is the only control that operates before the exposure is created.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Vendor assessment lives in a procurement or governance process rather than in a cloud tenant, so this is attested. Some of the resulting access is measurable.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Vendor register | An inventory of third parties, with data access and criticality | A maintained register that includes the small vendors and the ones procured outside IT. Attested |
| Assessment records | Due diligence performed per vendor, proportionate to risk | Evidence collected: certifications, assessment reports, questionnaire responses, with review dates |
| Entra ID | Guest accounts and external identities from vendor organisations | The vendors with directory access, which is a reality check against the register |
| Entra ID | Enterprise applications and their granted permissions | Third-party applications with consented access to your data, which is vendor access nobody procured |
| Contracts | Security requirements, breach notification obligations, and audit rights | Contractual controls that make the assessment enforceable |
Every application a user consented to holds delegated access to your data and never passed through procurement. In most tenants this list is longer than the vendor register and nobody has reviewed it. It is the fastest place to find third-party access you did not know you had.
What a defensible yes requires
- A vendor register exists, covers non-IT suppliers, and records what data each can reach.
- Diligence is proportionate to risk, with deeper review for vendors holding regulated data.
- Review recurs rather than happening once at onboarding.
- Contracts carry security requirements, breach notification, and audit rights.
- Consented applications and guest access are reviewed alongside contracted vendors.
How this answer goes wrong
The programme covers the large IT vendors that arrive with certification reports, and misses the marketing platform, the payroll bureau, the facilities contractor with network access, and the fifty applications users consented to. Those are where the incidents have come from.
Frequently asked
Is collecting a certification report enough?
For lower-risk vendors it is proportionate, provided someone reads it, checks its scope, and notes any qualifications. Filing it unread is a common and hollow form of diligence.
How often should we reassess?
Annually for critical vendors, and on any material change. A vendor that changes hands or changes sub-processors warrants a fresh look regardless of cadence.
What about very small suppliers?
Scale the review to the access. A small vendor with administrative access to your systems needs more scrutiny than a large one with none.
Where do we start?
The register. Most organisations cannot list their vendors with data access, and building that list usually surfaces several surprises.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture