
Publication number: ELQ-64685-1
View all versions & Certificate

Third-Party Risk and Contracting Toolkit — Supplier Tiering, DPA and MSA Checklists, SLA Design, Exit Clauses
Decide how much due diligence a supplier warrants before you run any.
Further information
• Tier your supply base so that deep assessment is done where it matters and nowhere else.
• Scale the security and data protection questionnaire to the tier rather than sending one questionnaire to everyone.
• Read a master agreement commercially before it reaches legal review.
• Design service levels that can be measured and enforced, and secure exit terms while you still can.
• You have more suppliers than you can assess and need a defensible way to prioritise.
• You review supplier contracts and want a structured commercial read.
• You are building or rebuilding a third-party risk process from a low base.
• You need jurisdiction-specific legal drafting; this is commercial guidance, not legal advice.
• You operate in a sector with prescriptive regulatory diligence rules that override a proportionate approach.
• You are looking for a supplier risk monitoring data feed; none is included.
