Skip to main content
Loyca
Service reference 18Audit & AssuranceACTIVE PRACTICE PROTOCOL

Third-Party & Vendor Risk

Your suppliers' security is your security

Tiered assessment of vendor risk, plus the contract clauses and monitoring to keep it managed.

PROTOCOL OVERVIEW

Executive Context & Technical Scope

Most breaches now arrive through a supplier. We inventory your third parties, tier them by the access and data they hold, assess the critical ones properly, and give you a repeatable onboarding process so the next vendor is assessed before they get credentials — not after.

TARGET PROFILES

Who Requires This Protocol

Organisations with critical outsourced services
Regulated firms with supervisory outsourcing requirements
Procurement teams asked to assess security they cannot evaluate

ENGAGEMENT ARTIFACTS

Verifiable Outputs & Deliverables

Third-party inventory with data and access mapping

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Risk tiering model and assessment questionnaires per tier

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Assessment reports for critical vendors

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

Security schedule clauses for contracts and a monitoring cadence

Delivered under strict NDA with executive presentation and engineering remediation roadmap.

PRACTITIONER FAQ

Frequently Asked Scoping Questions

A vendor refuses to complete our questionnaire. Now what?
That is itself a finding. We help you decide whether to escalate commercially, compensate with your own controls, or accept and document the risk.
Is a SOC 2 report enough?
It is good evidence if the scope and period cover what you rely on. We read the exceptions section, which is where the useful information usually is.
PRACTICE CONTINUUM

INTELLIGENCE WITHOUT LIMITS

Scope Third-Party & Vendor Risk for your organization.

Get a fixed-scope proposal, verifiable deliverables list, and exact timeline for third-party & vendor risk.

Direct Hotline:+254 740 658 068
NO-OBLIGATION GUARANTEE

What to expect in your scoping call

  • Direct Senior Lead

    You talk to a seasoned cybersecurity consultant, never a sales script.

  • Strict Confidentiality

    We operate under mutual NDA before discussing sensitive architecture.

  • Actionable Next Steps

    Immediate priorities and costed options, whether you engage us or not.

Message Loyca on WhatsApp