MHA Consulting Blog | Roadmap to Resiliency

Third-Party Risk Management: How to Vet Critical Suppliers

Written by Michael Herrera | Aug 31, 2026, 7:44:54 PM

Weakness in the resilience of their critical suppliers continues to be one of the biggest vulnerabilities of the organizations we work with. Vetting suppliers is challenging, but there are a handful of practical steps companies can take to reduce the chances they will be blindsided by the loss of a key vendor.

Related: Let’s Get Critical: Identifying the Vendors You Truly Depend On

Summary

  • Critical suppliers can create serious continuity risk when an organization depends on them and cannot replace them quickly.
  • Supplier vetting is difficult because vendors may provide limited information, overstate their resilience, or lack strong continuity capabilities.
  • A practical third-party risk process focuses on the suppliers that matter most, sets clear requirements, reviews evidence, and plans alternatives where needed.

The Vendors That Can Bring You Down

These days most discussions of vulnerability in the corporate supply chain start with reminders of how global turmoil and extreme weather have heightened the risks.

In this one, I’d like to start with something smaller, namely an animal’s dinner.

One of our clients is a leading American zoo, and one of their animals eats a special food that is only available through one supplier. Talk about a single point of failure. If that supplier goes down, that animal goes hungry or worse.

But while the zoo’s issue seems more modest than the geopolitical concerns referred to earlier, they’re all part of the same problem.

Almost every organization depends for its ability to carry out its operations, whether that’s making widgets, providing services, or caring for animals, on a far-flung network of suppliers.

In most cases, a good many of those suppliers are not especially critical, or they could easily be replaced on short notice.

However, almost every company has a small number of suppliers that are essential to its ability to carry out its core functions and which it could not easily replace if that vendor were to suffer an outage.

Unfortunately, few companies are doing an adequate job of validating the recovery capabilities of their third-party suppliers.

And the number who have also taken a good look at the resilience of their suppliers’ suppliers, that is, their fourth-party suppliers, is vanishingly small.

Why Supplier Vetting Is So Difficult

In our highly interconnected, deeply outsourced, and increasingly tumultuous times, vetting vendors is a resilience must.

It is also hard to do.

This is an area where a lot of smoke gets blown around. It’s not unusual for vendors to make claims about their resilience which they can’t back up.

Even companies that make a determined effort to secure their supply chains can find their path obscured by mist.

While vendors who have strong continuity programs tend to be forthcoming, the other sorts of vendors, the less-prepared ones, tend to drag their feet about clients’ requests for information on their resilience.

Unfortunately, power dynamics play a big role in how vendor vetting shakes out. Whether the information sought will be provided, or a supplier will exert itself to meet a customer’s request that it improve its resilience, often comes down to a matter of who needs the relationship more.

Even when vendors do undertake to respond to clients’ requests, it’s often in the spirit of high school students doing just enough work to pass. At MHA, we’ve gotten more than a few calls from people saying, “I need a recovery plan today. My client’s been on my back saying I need to have one.” In other words, these callers aren’t really interested in recoverability, they just want to placate their customer.

Organizations that do set out to vet their vendors need to be pragmatic. You might not get everything you want, but at least get everything you can.

How to Vet Your Critical Suppliers

A practical supplier-vetting program doesn’t have to involve putting every vendor under a microscope. The key is to identify the suppliers that matter most, establish appropriate requirements for each category, and focus your time and effort where a failure would hurt the most.

Start With the Suppliers That Are Truly Critical

Don’t try to boil the ocean. Focus on the vendors that really count. Identify the five to seven you really depend on and couldn’t easily replace. Make your vetting effort proportionate to the supplier’s importance to your operations. And don’t assume that a supplier’s size or reputation means it is automatically resilient.

Make Sure Critical Suppliers Know They Are Critical

Make it clear to your designated critical suppliers that you depend on them and must hold them to a higher standard. Articulate your special continuity requirements in your procurement and purchasing processes.

Those requirements might include their providing their recovery plans for review, responding to questions about their capabilities, participating in exercises, or demonstrating that they can meet specified recovery objectives.

Match the Level of Scrutiny to the Level of Risk

A small vendor that provides something your organization can easily replace may warrant little more than due diligence. A supplier whose failure would kneecap your operations warrants a detailed review of its plans, capabilities, and exercise history.

Recognize That Large Suppliers May Require a Different Approach

Here we have to face up to harsh reality. If you’re a smaller organization, giant suppliers are likely not going to go out of their way to respond to your requests for information about their resilience.

With companies like Microsoft or Salesforce, you may have to rely primarily on the high-level assurance information they make available, such as SOC reports. But remember: just because a company is big or famous, it doesn’t mean it’s invulnerable to disruptions.

Have Someone Who Knows Continuity Review the Information

The nice people in procurement should not be the ones who sign off on a vendor’s recovery plan. I’ve seen such people be satisfied by plans a BC practitioner would laugh out of court.

Some vendors are not above trying to fake their way through your resilience requirements. The person who evaluates their plans needs to know what he or she is looking at.

Build the Requirements Into Supplier Agreements

The gold standard, if you can get it, is to put your continuity requirements into contracts and other supplier agreements. This is especially worth pursuing for your most important suppliers.

Create a Process That Tells You What to Review and When

Get organized. Once you have identified your critical suppliers, create a review schedule and a consistent process for evaluating them.

This allows the BC team to concentrate its limited resources on the suppliers that pose the greatest risk rather than constantly chasing information from hundreds of vendors.

Make Procurement and BC Partners in the Process

Procurement will lead here, but ideally BC can wrangle a place riding shotgun. The organization will benefit if the two groups can work together rather than operating in separate silos.

Procurement brings the supplier relationships and contractual leverage. BC can tell whether the information and plans provided actually demonstrate resilience.

If Necessary, Line Up Alternatives

If a critical vendor is unable to meet your requirements for recoverability, look for ways to reduce your dependence on them.

Qualify a second supplier, identify an alternate source, or establish a contingency arrangement that can be activated if the primary vendor goes down.

When Ready, Move On to Your Fourth-Party Vendors

This can’t be rushed; you have to walk before you can run. But once you have your critical third-party suppliers identified and a solid process for vetting them, start looking at fourth-party risk. A disruption at one of your suppliers’ suppliers can be just as damaging to your organization as an outage at the vendor itself.

Vetting suppliers is never going to be a cakewalk. But by identifying the ones you truly depend on, setting clear expectations about their resilience, and tailoring your approach to the level of risk, you can make substantial improvements in the resilience of your supply chain.

Building a More Resilient Supply Chain

Supply-chain resilience starts with understanding which suppliers your organization truly depends on and validating that those suppliers can support you when something goes wrong. You don’t need to scrutinize every vendor equally, but you do need to identify the critical ones, establish appropriate requirements, and focus your attention where a disruption would hurt the most.

Supplier vetting can be difficult, particularly when vendors are reluctant to provide information. But a practical, risk-based approach can substantially strengthen resilience and reduce the chances of being blindsided by the failure of a critical supplier.

MHA Consulting helps organizations identify critical suppliers, assess third-party resilience, and develop practical vendor-vetting programs. Contact MHA to learn how we can help strengthen your organization’s supply-chain resilience.

Further Reading

Frequently Asked Questions

Why are critical suppliers such an important business continuity concern?

Most organizations depend on a small number of suppliers that are essential to their operations and difficult to replace. If one of those suppliers suffers an outage, the impact can extend directly to the organization’s ability to function.

Why is vetting suppliers so difficult?

Vendors vary widely in their willingness and ability to provide meaningful information about their resilience. Organizations also have limited leverage over some suppliers, making it difficult to obtain more than assurances or high-level documentation.

How should organizations prioritize their supplier-vetting efforts?

They should identify the relatively small number of suppliers that are truly critical and focus the most time and scrutiny on those vendors. A supplier’s size or reputation should not be treated as proof of resilience.

What should organizations look for when vetting a critical supplier?

They should establish clear continuity requirements, obtain and evaluate information about the supplier’s recovery capabilities, and tailor the level of scrutiny to the risk posed by the supplier. Someone with business continuity expertise should review the information rather than relying solely on procurement staff.

When should organizations begin assessing fourth-party risk?

After they have identified their critical third-party suppliers and established a sound process for vetting them. Once that foundation is in place, organizations can investigate their critical vendors’ dependencies and determine where fourth-party relationships create additional risk.