Resilience Operations

Supply Chain & Third-Party Risk Management (TPRM)

We look through your vendors to their vendors — surfacing concentration risk, contractual gaps and the exit routes you have never tested.

Tier 1–3
Vendor criticality model
4th party
Chain visibility
Tested
Stressed exit routes
The focus

Your resilience is capped by your weakest critical supplier. We build a tiered third-party register mapped to your important business services, audit the vendors that matter, quantify concentration exposure across cloud and logistics, and develop exit and substitution strategies that can actually be executed under duress.

DORA third-party chapterPRA SS2/21 outsourcingEBA outsourcing guidelines
Key content

Vendor auditing, concentration tracking and cloud exit strategy

From onboarding due diligence through to stressed exit: we test whether a critical provider can be replaced, in what timeframe, at what cost, and whether your contracts give you the rights to do it.

  • Critical and important third-party identification tiered against your IBS
  • Vendor resilience audits, site visits and control attestation review
  • Concentration risk tracking across cloud, connectivity, logistics and payments
  • Fourth-party and sub-outsourcing visibility down the chain
  • Cloud and critical-service exit strategy design plus stressed-exit testing
  • Contractual resilience clauses, SLAs and regulatory register maintenance
What you receive
01

Tiered third-party and fourth-party register

02

Vendor resilience audit reports and remediation plans

03

Concentration risk dashboard

04

Cloud and critical-service exit playbooks

05

Contract clause library and negotiation support

Next capability · Anticipate & Assess

Critical Service & Asset Dependency Mapping