Certified organisations
Your ISMS makes commitments about supplier security. We provide the verification behind those commitments, ready for your own auditors to inspect.
Supplier audits · Third-party assurance
Your suppliers hold your data, run your infrastructure and embed AI in your products. A questionnaire gets you their promises; an audit gets you evidence. We audit the third parties your business depends on, against criteria built from ISO/IEC 27001 and, for AI vendors, ISO/IEC 42001.
The problem
Most supplier security programmes run on self-assessment questionnaires: the supplier ticks the boxes, you file the spreadsheet, and everyone hopes. When the incident comes, "they told us they had backups" is not a defence your customers, your certification body or your regulator will accept. ISO/IEC 27001's Annex A supplier controls expect you to actually verify what your critical suppliers do, and the arrival of AI inside vendor products has raised the stakes: many organisations cannot say which of their suppliers are making AI-driven decisions with their data.
A supplier audit replaces hope with evidence: controls tested, records sampled, and findings you can act on, escalate or contract against.
Deliverables
Who this is for
Your ISMS makes commitments about supplier security. We provide the verification behind those commitments, ready for your own auditors to inspect.
Vendors are embedding AI faster than procurement can assess it. We audit what the AI actually does with your data and who is accountable for it.
Outsourcing rules in financial services and other regulated sectors expect demonstrable oversight of critical providers. Audit evidence is the strongest form of it.
Independence, always: we audit for you, not for the supplier. We take no fees from audited vendors, and we decline engagements where a relationship could colour the findings.
FAQ
You need a contractual basis: most supplier agreements include an audit or assurance clause, and we work within whatever yours provides. Where no audit right exists, we run an evidence review instead, assessing the certifications, reports and documentation the supplier will share, and we tell you plainly how much assurance that does and does not give. It is also the strongest argument for adding audit rights at the next renewal.
Mostly, yes. Document review, interviews and control walkthroughs run well remotely, which keeps costs proportionate. On-site days are worth it for physical security, data centres and the most critical providers, and we recommend them only where they add real assurance.
By default, a criteria set built from ISO/IEC 27001's controls, proportionate to the supplier's criticality, extended with ISO/IEC 42001 based criteria where the supplier provides or embeds AI. If you have your own supplier security standard or contractual security schedule, we audit against that instead, or as well.
Request an audit
Tell us which suppliers keep you up at night and what your contracts allow. We will come back with a proportionate scope, a fixed price and a start date.
Contact Attestware