Attestware

Supplier audits · Third-party assurance

Supplier audits: know what the third parties holding your data actually do.

Your suppliers hold your data, run your infrastructure and embed AI in your products. A questionnaire gets you their promises; an audit gets you evidence. We audit the third parties your business depends on, against criteria built from ISO/IEC 27001 and, for AI vendors, ISO/IEC 42001.

Remote-first Scoped per supplier Risk-ranked findings Portfolio programmes

The problem

Questionnaire assurance is not assurance

Most supplier security programmes run on self-assessment questionnaires: the supplier ticks the boxes, you file the spreadsheet, and everyone hopes. When the incident comes, "they told us they had backups" is not a defence your customers, your certification body or your regulator will accept. ISO/IEC 27001's Annex A supplier controls expect you to actually verify what your critical suppliers do, and the arrival of AI inside vendor products has raised the stakes: many organisations cannot say which of their suppliers are making AI-driven decisions with their data.

A supplier audit replaces hope with evidence: controls tested, records sampled, and findings you can act on, escalate or contract against.

Deliverables

What an engagement includes

  • D1Scope matched to criticalityDeep audits for the suppliers your survival depends on, lighter evidence reviews for the long tail. You spend audit effort where the risk is.
  • D2Control testing against recognised criteriaAudit criteria built from ISO/IEC 27001 controls, extended with an ISO/IEC 42001 lens where the supplier provides or embeds AI, so findings map to standards both sides understand.
  • D3Risk-ranked findingsEvery finding rated by the risk it creates for your business specifically, with a plain-English explanation and a recommended remediation you can put to the supplier.
  • D4Remediation trackingAgreed supplier actions tracked to closure and verified, so the audit changes something rather than filing something.
  • D5A portfolio viewFor programmes covering multiple vendors: comparable results across your supplier base, so procurement and renewal decisions rest on evidence.

Who this is for

Three situations we see most

Certified organisations

Your ISMS makes commitments about supplier security. We provide the verification behind those commitments, ready for your own auditors to inspect.

Buyers of AI products

Vendors are embedding AI faster than procurement can assess it. We audit what the AI actually does with your data and who is accountable for it.

Regulated businesses

Outsourcing rules in financial services and other regulated sectors expect demonstrable oversight of critical providers. Audit evidence is the strongest form of it.

Independence, always: we audit for you, not for the supplier. We take no fees from audited vendors, and we decline engagements where a relationship could colour the findings.

FAQ

Fair questions, straight answers

Do we need the supplier's agreement to audit them?

You need a contractual basis: most supplier agreements include an audit or assurance clause, and we work within whatever yours provides. Where no audit right exists, we run an evidence review instead, assessing the certifications, reports and documentation the supplier will share, and we tell you plainly how much assurance that does and does not give. It is also the strongest argument for adding audit rights at the next renewal.

Can supplier audits run remotely?

Mostly, yes. Document review, interviews and control walkthroughs run well remotely, which keeps costs proportionate. On-site days are worth it for physical security, data centres and the most critical providers, and we recommend them only where they add real assurance.

What criteria do you audit suppliers against?

By default, a criteria set built from ISO/IEC 27001's controls, proportionate to the supplier's criticality, extended with ISO/IEC 42001 based criteria where the supplier provides or embeds AI. If you have your own supplier security standard or contractual security schedule, we audit against that instead, or as well.

Request an audit

Find out what your suppliers actually do.

Tell us which suppliers keep you up at night and what your contracts allow. We will come back with a proportionate scope, a fixed price and a start date.

Contact Attestware