The inputs are unglamorous questions asked consistently: what data does the vendor store or process, does it integrate into production, could its outage stop revenue, could its breach become your breach? The answers place each vendor in a tier — commonly three or four levels running from critical to negligible. The classification is itself a control auditors sample, so the criteria need writing down and the inventory needs to be complete; the vendor nobody registered is always the one that bites.
Tier drives everything downstream: what you demand up front (a SOC 2 Type 2 and a completed questionnaire for critical vendors, a policy attestation for trivial ones), how often you re-review, who must approve the purchase, and how fast offboarding runs when the relationship ends. Without tiers, teams default to one of two failure modes — interrogating every free tool like a payment processor, or waving everything through. Both are expensive; only one of them is visibly so.
Tiers rot when nobody re-scores: the pilot tool that quietly became load-bearing keeps the “low risk” label it earned on onboarding day. Re-tiering at renewal and on scope change keeps the map honest, and pairing each tier with a documented risk-acceptance path keeps exceptions from going underground. If standing all that up sounds like a quarter of someone’s job, that is roughly what it is — Agency’s vendor security review service runs the tiering, the reviews, and the annual re-checks as a managed function; the broader failure pattern lives under vendor risk.