Third-party tiering
A four-sheet workbook that scores suppliers on five closed-option factors, bands the scores into three tiers, and sets the depth of assurance each earns.
Risk5 Sept 20263 min read
On this page
third-party-tiering.xlsx · 10 kBLicensed CC BY 4.0
What this is
A four-sheet workbook for tiering a supplier estate. Five factors are scored from a closed list, the scores are banded into three tiers, and the tier sets how much due diligence, assurance and exit planning a relationship earns. It is the artefact produced by section 3.1 of Third-party risk across the contract lifecycle.
The tier is a local label, not a regulatory classification. No instrument defines tiers. What the instruments define is criticality and substitutability.
How to use it
- Delete every row marked
EXAMPLE - delete. Three sit on each working sheet. - Agree Tier rules first, before any supplier is scored. The options and the bands are the organisation's own; what matters is that both are fixed in advance.
- Fill Tiering next, one row per supplier and service, resolving the five closed-option columns before any free text.
- Apply the override, not only the arithmetic. A supplier behind a critical or important function is tier 1 whatever the total says 1.
- Score substitutability honestly. A provider that is not easily substitutable is a named pre-contract concern 2.
- Set the due-diligence set from the tier, so assessment depth is a rule rather than a negotiation. NIS2 puts supply-chain security among the required measures, framed around direct suppliers and service providers 3.
- Fill Assurance calendar last, one row per evidence item due, not one per supplier. An overdue row keeps its due date and an empty Received cell. See section 3.5.
Sheets and columns
| Sheet | Columns |
|---|---|
| Read first | Licence, scope, scoring rule, closed lists, as prose |
| Tier rules | Factor, option, score, meaning; then the three tier bands |
| Tiering | ID, supplier, service, the five factors, score, tier, due-diligence set, assurance frequency, exit plan, owner role, next review |
| Assurance calendar | Supplier, tier, evidence type, due, received, reviewer role, outcome |
Each factor takes one option worth 0 to 3 points, so the score runs from 0 to 15.
What good looks like
Six columns from the Tiering sheet, example prefix dropped.
| ID | Function criticality | Access | Substitutability | Score | Tier |
|---|---|---|---|---|---|
| TP-001 | 1. Critical or important | 1. Privileged access to production | 1. Not substitutable | 14 | 1. Tier 1 |
| TP-002 | 2. Supporting | 2. Standard access to production | 2. Substitution is highly complex | 8 | 2. Tier 2 |
| TP-003 | 3. Other | 3. Non-production access only | 4. Easily substitutable | 1 | 3. Tier 3 |
Two things make those rows usable. Every factor is a closed-list value, so two readers cannot disagree about a score. The score sits beside the tier, so a challenged tier is re-argued factor by factor.
Fields
| Field | Required | Meaning | Common mistake |
|---|---|---|---|
| Function criticality | yes | The criticality of the function the service supports | Scoring the supplier's size instead |
| Access | yes | What the supplier reaches in live systems | Recording the contract, not the accounts |
| Substitutability | yes | How hard leaving would be | Optimism with no transition plan |
| Regulatory reach | yes | Whether a supervisor can ask about this by name | Treating everything as in scope |
| Score, Tier | yes | The total, and the band with the override applied | Keeping the tier, dropping the score |
| Exit plan | yes | Whether a plan exists, from a closed list | Recording intent rather than a plan |
Download
- File:
third-party-tiering.xlsx(xlsx, 10 KB) — four sheets. - Markdown variant:
content/templates/assets/_third-party-tiering.md. - Licence: CC BY 4.0 — reuse and adapt with attribution to GRCIDE.
- Version: 1.0, 2026-09-05. No personal data, no organisation names; example rows are invented.
Related
- Playbook: Third-party risk across the contract lifecycle, section 3.1.
- Template: Register of information starter, for the ranked chain.
- Radar: the subcontracting technical standard
References
- Regulation (EU) 2022/2554 (DORA). CELEX 32022R2554. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng 4
- Directive (EU) 2022/2555 (NIS 2 Directive). CELEX 32022L2555. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng 5
Standards and certification names are the property of their respective owners. GRCIDE is an independent publication and is not affiliated with, authorized, sponsored or endorsed by any standards body.
Sources
- 1EU Publications Office CELEX 32022R2554 Art. 3(22) · verified 2026-09-05
- 2EU Publications Office CELEX 32022R2554 Art. 29(1)(a) · verified 2026-09-05
- 3EU Publications Office CELEX 32022L2555 Art. 21(2)(d) · verified 2026-09-05
- 4EU Publications Office CELEX 32022R2554 · verified 2026-09-05
- 5EU Publications Office CELEX 32022L2555 · verified 2026-09-05