Business Risk

Quantifying third party exposure for the board

A board cannot act on 87% of vendor questionnaires returned. It can act on a credible estimate of what a supplier failure would cost and how long the business could absorb it.

26 August 2026 · 6 min read

Why questionnaire programmes stall

Traditional third party programmes measure activity: assessments issued, responses received, tiers assigned. None of these describe exposure. They also assume the answers are current, when a questionnaire is a point-in-time self-attestation that ages from the day it is signed.

The gap widens with concentration. Several critical suppliers frequently depend on the same underlying cloud region, identity provider or payments processor, so a register that treats them as independent understates correlated failure.

Quantify the dependency, not the vendor

Start from the business service, not the supplier list. For each service that would materially hurt revenue, safety, or regulatory standing if it stopped, record the suppliers it depends on, the data they hold, the maximum tolerable outage, and the manual fallback if one exists.

That reframing produces a shorter list than procurement's vendor inventory and it is the list executives actually need. It also makes over-tiering visible: a supplier holding no data and touching no critical service does not warrant a deep assessment.

Use an established quantification method

Open FAIR gives a defensible structure for expressing risk as loss event frequency multiplied by loss magnitude, in currency, with ranges rather than single numbers. Continuous external ratings and attack surface monitoring can inform frequency, but they are inputs, not conclusions — a good rating tells you nothing about whether a supplier can restore your service inside your tolerance.

Where regulation applies — DORA for EU financial entities, or contractual obligations flowing from customers — the same register should carry the evidence those regimes ask for, so quantification and compliance are one exercise.

What the board pack should contain

Four things, repeated each cycle so trends are visible:

  • Critical business services with their supplier dependencies and tolerable outage windows.
  • Concentration and single points of failure, including fourth-party dependencies.
  • Quantified exposure for the top scenarios, expressed as a range with stated assumptions.
  • The decisions being asked for: exit, remediate, contractually transfer, or accept — each with an owner and a date.

Book Assessment

Navigate Risk. Build Confidence.

A focused executive session to establish where you stand across AI, cyber and business risk.