About

Third-Party Risk Questions Every Procurement Team Should Ask

Third-Party Risk Questions Every Procurement Team Should Ask
Published on 7/22/2026

Third-party risk starts before a contract is signed, before a purchase order is raised and often before Legal or IT has seen the vendor file. For procurement teams, that creates a practical challenge: how do you move quickly without introducing privacy, cyber security, anti-money laundering, operational or reputational risks into the organisation?

The answer is not to make every supplier complete a 60-page questionnaire. The better approach is to ask the right questions early, match the depth of review to the risk, and keep clear evidence of the decision. This is especially important for Jamaican organisations handling personal data under the Data Protection Act, 2020, or operating in regulated sectors where vendor failures can quickly become board-level issues.

Below are the third-party risk questions procurement teams should build into sourcing, vendor onboarding, contract review and renewal.

Why procurement has a frontline role in third-party risk

Third-party risk is often treated as a compliance, legal or IT security matter. Those teams are essential, but procurement usually sees the vendor first. Procurement controls the intake process, the request for proposal, the comparison of suppliers, the commercial negotiation and, in many organisations, the renewal calendar.

That position gives procurement an early-warning function. If the procurement team can identify high-risk vendors before a deal is approved, the organisation has more room to negotiate contract protections, request evidence, involve the right reviewers and avoid relationships that are not worth the risk.

Third-party risk can arise from many types of vendors, including payroll providers, cloud software platforms, marketing agencies, debt collectors, outsourced IT providers, consultants, payment processors, call centres, security firms and professional advisers. Some suppliers may never touch personal data or critical systems. Others may process customer records, employee information, financial data, credentials or confidential business plans.

The questions below are designed to help procurement make that distinction.

Start with a simple scope question: what is the vendor really doing?

Before asking about certifications or policies, procurement should understand the service itself. A supplier that delivers stationery is not the same risk as a supplier that manages customer databases or hosts your HR platform.

Ask: what process, function or business outcome will this third party support? Who in the organisation will own the relationship? Will the vendor be essential to delivering services to customers, employees, regulators or business partners? If the vendor stops operating tomorrow, what breaks?

This first set of questions helps procurement classify the relationship. It also prevents a common problem: treating the vendor as low risk because the contract value is small. A low-cost software subscription can still create high data protection compliance risk if it collects sensitive personal data or integrates with core systems.

A useful procurement intake form should capture:

  • The business owner requesting the vendor

  • The service description and intended use

  • Whether personal data, confidential data or regulated information is involved

  • Whether the vendor will access systems, premises, networks or credentials

  • Whether the service is critical to operations or customer delivery

  • Whether the vendor will use subcontractors or cloud infrastructure

This information gives Legal, IT, Compliance, Privacy and Finance enough context to decide whether a deeper review is needed.

Ask what data, systems and access the vendor will receive

The most important third-party risk question is simple: what will the vendor be able to see, process, store, transmit or control?

For privacy and data protection purposes, procurement should ask whether the vendor will handle personal data, such as names, addresses, phone numbers, identification numbers, employment records, financial details, health information, customer files, images, recordings, location information or online identifiers. The question should include both live data and test data, since organisations sometimes expose real personal data in testing environments.

Procurement should also ask about system access. A vendor may not process personal data directly, but may have administrator access, remote support access or integration rights that allow it to view or affect sensitive systems. This can be just as important as data storage.

For Jamaican organisations, the Data Protection Act, 2020 makes it important to understand whether a third party is processing personal data on behalf of the organisation and whether appropriate safeguards are in place. The Office of the Information Commissioner in Jamaica provides information and guidance relevant to data protection obligations.

Where teams need practical internal rules for classifying and sharing sensitive information, procurement can align vendor onboarding with the organisation's confidentiality and data handling rules. This helps prevent inconsistent decisions across departments.

Ask which legal, regulatory and contractual obligations apply

Not every supplier creates the same compliance exposure. Procurement should ask which rules apply to the vendor relationship and whether those rules have been reflected in the contract.

For example, a vendor relationship may raise obligations under Jamaica's Data Protection Act, 2020, sector-specific regulations, anti-money laundering requirements, banking or insurance rules, employment laws, confidentiality obligations, consumer protection standards or contractual commitments to clients. If the vendor processes information about individuals in other jurisdictions, international privacy laws may also become relevant.

The point is not that procurement must become a legal department. Rather, procurement should know when to escalate. If a vendor will process personal data, provide a financial service, support customer onboarding, screen transactions, access company bank information or handle government-related work, that relationship deserves more review than a routine purchase.

Good questions include: which jurisdictions are involved? Where will the vendor provide the service from? Will data be transferred outside Jamaica? Will the vendor rely on overseas affiliates or subcontractors? Does the vendor claim compliance with GDPR, ISO standards, PCI DSS, SOC reporting, AML rules or any other framework? If so, can it provide current evidence?

Use risk tiering so the process stays practical

Procurement teams lose support when risk reviews feel too heavy for simple purchases. A tiered model keeps the process proportionate. The aim is to spend more time on vendors that can create greater harm.

Risk tier

Typical vendor profile

Procurement response

Low risk

No personal data, no system access, non-critical service

Basic supplier checks, contract review and conflict screening

Medium risk

Limited personal data, limited system access, replaceable service

Short privacy and security questionnaire, contract clauses and business owner sign-off

High risk

Sensitive data, critical service, privileged access, regulated activity or large-scale processing

Full due diligence, privacy or security assessment, legal review, senior approval and ongoing monitoring

Critical risk

Vendor failure could disrupt essential operations, cause major regulatory exposure or affect many individuals

Enhanced due diligence, board or executive visibility, tested continuity plans, stronger audit and exit rights

Risk tiering should not be based only on spend. A free application can be high risk if employees upload customer records. A small overseas consultant can be high risk if given access to confidential strategy documents. A large facilities vendor may be low privacy risk but high physical security or continuity risk.

For vendors that involve personal data, procurement teams can work with privacy and compliance colleagues to run a simple vendor privacy assessment before information is shared.

Ask for evidence, not just assurances

Many vendors will say they take privacy, security and compliance seriously. Procurement should ask how they prove it.

Evidence does not need to be complicated for every vendor. For a medium-risk supplier, a completed questionnaire, sample policies and confirmation of security controls may be sufficient. For a high-risk vendor, procurement may need current certifications, independent audit reports, penetration test summaries, incident response procedures, data processing terms, cyber insurance confirmation, employee training evidence and business continuity documentation.

Risk area

Question to ask

Useful evidence

Red flag

Privacy governance

Who is responsible for privacy and data protection in your organisation?

Privacy policy, role description, training records

No named owner or unclear accountability

Cyber security

How do you protect systems and data from unauthorised access?

Access control policy, MFA confirmation, security testing summary

Shared accounts, weak password practices or no testing

Incident response

How quickly will you notify us of a suspected incident?

Incident response plan, notification process, contact details

Vague timelines or no escalation process

Subcontracting

Will any subcontractor process our data or support the service?

Subprocessor list, contract flow-down terms

Refusal to identify key subcontractors

Business continuity

How will you continue service during disruption?

Business continuity plan, disaster recovery test summary

No recovery plan or no recent testing

Data retention

How long will you keep our data and how will it be deleted?

Retention schedule, deletion certificate process

Indefinite retention or unclear deletion method

Procurement should also record when evidence was reviewed and by whom. A certificate that was valid three years ago may not support a 2026 vendor decision. A policy without implementation may be of limited value. The strongest vendor files show both the question asked and the evidence relied on.

Ask how incidents and service disruptions will be handled

Third-party risk is not only about preventing failures. It is also about knowing what happens when something goes wrong.

Procurement should ask vendors how they identify, investigate, contain and report incidents. This includes data breaches, cyberattacks, ransomware, unauthorised access, loss of devices, accidental disclosure, service outages, fraud events and suspected insider misuse.

The contract should not leave incident reporting open-ended. Procurement should involve Legal, Privacy and IT to agree on notification timelines, escalation contacts, cooperation duties and evidence preservation. If a vendor handles personal data, the organisation may need enough information to assess whether individuals, regulators or business partners must be notified.

Business continuity questions are equally important. Ask whether the vendor has tested disaster recovery arrangements. Ask what recovery time objectives apply. Ask whether the service relies on a single location, single data centre, single key person or single subcontractor. Ask how the vendor will prioritise your organisation during a widespread disruption.

Procurement, privacy, legal and IT professionals reviewing a vendor risk checklist together at a meeting table with printed documents, folders, and laptops facing the participants, with a clear focus on data protection, cyber security and contract re...

Ask who else will touch the service or data

Many third-party relationships are actually fourth-party relationships. A vendor may rely on cloud providers, payment processors, hosting companies, offshore support teams, analytics tools, software developers, call centres or subcontracted consultants.

Procurement should ask whether subcontractors will be used and what role they will play. It is not always necessary to reject subcontracting. Many modern services depend on trusted infrastructure providers. The risk comes from not knowing who is involved, where they operate, what data they can access and whether the same contractual protections apply.

Key questions include: will the vendor notify us before adding or changing subcontractors? Can we object to high-risk changes? Are subcontractors bound by confidentiality, security, privacy and audit obligations? Does the vendor remain responsible for subcontractor failures? Where will subcontractors process or store data?

Cross-border processing needs careful attention. If personal data is transferred outside Jamaica, procurement should ensure the privacy or legal team reviews the basis for that transfer and the safeguards in place.

Ask whether AML, fraud and integrity risks are relevant

Third-party risk is not limited to privacy and cyber security. Procurement should consider whether the supplier relationship creates anti-money laundering, bribery, corruption, sanctions, fraud or conflict-of-interest concerns.

This is especially relevant for vendors involved in payments, financial services, customer onboarding, debt collection, professional services, real estate, charitable donations, politically exposed persons, government contracts or high-value cross-border transactions. Procurement should ask who owns the vendor, where the vendor is registered, whether beneficial ownership is transparent, whether there are related-party connections, and whether any adverse media or sanctions concerns exist.

For higher-risk relationships, procurement may need support from Compliance or Finance to conduct screening and document the result. The review should be proportionate, but it should not be skipped simply because the vendor is commercially attractive or urgently needed.

Ask what contract terms will protect the organisation

Procurement questions should lead to contract protections. If a risk is identified during due diligence but not addressed in the agreement, the organisation may have little leverage later.

Important contract areas include scope of service, confidentiality, data protection, security controls, breach notification, audit rights, subcontracting approval, data location, data retention, return or deletion of information, business continuity, regulatory cooperation, insurance, liability, termination rights and exit assistance.

For privacy-related vendors, the contract should clearly state what the vendor may and may not do with personal data. The vendor should not use the data for unrelated purposes, retain it indefinitely or share it with unauthorised parties. The organisation should be able to obtain confirmation that data has been returned or securely deleted at the end of the relationship.

Procurement should also check whether the vendor's standard terms conflict with the organisation's requirements. Some vendor terms limit liability heavily, permit broad data use, allow unilateral changes, restrict audit rights or provide weak support if an incident occurs. Those clauses should be escalated before signature, not discovered after a problem.

Ask what happens after onboarding

A common mistake is treating due diligence as a one-time exercise. Vendor risk changes over time. A supplier may introduce new subcontractors, change hosting locations, launch new features, suffer a breach, be acquired, expand the service scope or become more critical to operations.

Procurement should ask how often the vendor will be reviewed and what changes must trigger reassessment. A high-risk vendor may need annual review. A medium-risk vendor may need review at renewal or when the service changes. A low-risk vendor may only need basic refresh checks.

Procurement can also use renewal dates as control points. Before renewing, ask: have there been incidents? Has the scope changed? Is the business owner satisfied? Has the vendor met service levels? Are certificates or insurance documents current? Do privacy, cyber security or AML concerns remain open?

When a vendor is high risk or the organisation is uncertain about the scale of personal data processing, a broader data protection risk assessment can help teams define the scope, identify controls and document the evidence behind the decision.

Red flags procurement teams should not ignore

Some warning signs deserve attention even when the vendor is popular, inexpensive or strongly recommended by a business unit. Red flags do not always mean the vendor must be rejected, but they should trigger escalation.

Watch for vendors that refuse to answer basic privacy or security questions, cannot explain where data is stored, will not identify material subcontractors, demand excessive rights to use your data, provide outdated compliance evidence, resist breach notification commitments, lack a clear business continuity plan, or pressure the organisation to sign before reviews are complete.

Other warning signs include inconsistent ownership information, unexplained offshore payment instructions, unusual urgency, reluctance to provide references, conflicts of interest involving employees, and contract terms that shift most operational or compliance risk back to your organisation.

A mature procurement process gives staff permission to pause. Speed matters, but a preventable vendor failure can cost far more than a delayed onboarding decision.

How to build these questions into the procurement workflow

The most effective third-party risk programme is embedded into normal procurement activity. It should not depend on heroic efforts by one compliance officer or an informal email chain.

Start with an intake form that identifies data, access, criticality and regulatory exposure. Use risk tiering to decide whether the vendor needs basic screening, a short questionnaire or enhanced due diligence. Involve Privacy, Legal, IT, Compliance, Finance and the business owner only when their input is necessary. Store the completed assessment and supporting evidence in the vendor file. Revisit higher-risk vendors at renewal or when their service changes.

This approach helps procurement support the business without becoming a bottleneck. It also strengthens corporate governance because decisions are documented, responsibilities are clear and risks are reviewed before they become incidents.

Frequently Asked Questions

What is third-party risk in procurement? Third-party risk is the possibility that a vendor, supplier, contractor or service provider could expose the organisation to privacy, cyber security, legal, financial, operational, AML or reputational harm. Procurement teams help manage this risk by asking the right questions before onboarding and at renewal.

Should every vendor complete the same risk questionnaire? No. A risk-based approach is more practical. Low-risk vendors may only need basic checks, while vendors that process personal data, access systems or support critical operations should undergo deeper due diligence.

When should procurement involve the privacy or legal team? Procurement should escalate when the vendor will handle personal data, transfer data across borders, access confidential information, use subcontractors, support regulated activities, or request contract terms that weaken confidentiality, security, audit or incident response protections.

How often should third-party risk be reviewed? High-risk vendors should be reviewed regularly, often annually or at renewal. Medium-risk vendors can be reviewed when the service changes or the contract renews. Low-risk vendors may only need periodic confirmation that the relationship has not changed.

What is the biggest mistake procurement teams make with vendor risk? One of the biggest mistakes is focusing only on price and contract value. A low-cost vendor can create significant data protection, cyber security or compliance exposure if it handles sensitive information or has privileged access to systems.

Strengthen your third-party risk process

Procurement teams do not need to solve third-party risk alone. They need a clear process, proportionate questions, reliable evidence and the right internal support.

Privacy & Legal Management Consultants Ltd. helps organisations in Jamaica improve data protection implementation, corporate governance, anti-money laundering compliance, cyber security readiness, GRC integration, privacy training and risk assessment practices. If your organisation is reviewing its vendor onboarding or procurement controls, contact PLMC to discuss a practical approach that fits your risk profile and compliance obligations.