An engagement pattern, not a named client. The sequence, the constraints and the decisions below are how these programmes actually run. No client is identified, and no outcome figures are claimed.
The trigger
A supplier suffered a ransomware incident. The client organisation was not breached, and no data of theirs was confirmed lost, so from the outside this was a near miss.
Inside, it was not. The board asked one question at the next meeting: "Which other suppliers could do this to us?" Nobody could answer it. The organisation had a mature-looking supplier assurance programme, hundreds of completed questionnaires and a scoring model, and none of it could answer the only question that had ever mattered.
The constraint
The programme was not neglected. It was well run and answering the wrong question.
Questionnaires measure what a supplier is willing to assert about itself, on the day they filled it in. They do not measure what that supplier can reach inside your estate. A supplier with an immaculate questionnaire and a persistent VPN tunnel into your network is a materially larger risk than a supplier with a poor questionnaire who receives a monthly CSV by email - and the scoring model ranked them the other way round.
The second constraint was that the answer was needed in weeks. A full re-assessment of several hundred suppliers was not going to happen in that time, and doing it would have re-run the same flawed measurement at greater expense.
What was delivered
Tiering by access and dependency, not by spend. Every supplier was placed against two axes: what they can reach - network connectivity, data categories, administrative privilege, physical access - and what breaks if they stop. Spend was deliberately excluded. The cheapest supplier in the estate held domain administrative credentials.
A shortlist that fitted on one page. Of several hundred suppliers, a small number could cause material harm. That list was the answer to the board's question, and it was produced from data the organisation already held rather than from new questionnaires.
Evidence requests aimed at the shortlist. For those suppliers only, the ask moved from self-assertion to artefacts: current certification scope statements rather than logos, penetration test summaries with dates, incident notification terms as written in the contract rather than as remembered.
Contract reality checked against assumption. Several critical suppliers had no contractual obligation to notify an incident within any defined period. That had been assumed rather than verified, and it is the single most common gap found at this stage.
A standing process rather than an annual campaign. Re-tiering triggered by change - a new integration, a new data flow, a change of ownership - rather than by a calendar. A supplier's risk changes when the relationship changes, not in March.
What made the difference
The reframe, not the tooling. Moving the question from "is this supplier secure?" to "what can this supplier reach, and what breaks if they stop?" changed which suppliers mattered, and it did so using information that was already in the building.
It also made the programme smaller. Deep assurance on the suppliers who can cause harm, and a light proportionate check on everyone else, costs less than uniform questionnaires across the whole estate - and it answers the board.
Where this usually goes next
Two places. The tiering feeds incident response: knowing which suppliers are critical is only useful if the playbook names them and someone has rehearsed the call. And it feeds contract renewal, because the leverage to fix a notification clause exists at renewal and almost nowhere else.
The awkward part is usually neither of those. It is that the shortlist tends to include one supplier everybody knows is a problem and nobody has had the authority to challenge.