Supplier & Dependency Review

Every vendor, contract, and dependency, scored for concentration risk.

Your business depends on suppliers. Some are big and visible — the ERP vendor, the cloud provider, the bank. Most are smaller and invisible — the SaaS tools, the third-party libraries, the contractors who set things up and never quite left.

Until you map them, you cannot tell which ones the business actually depends on, which ones you could replace tomorrow, and which ones would take the business down if they failed. The Review tells you, in writing.

That is what this engagement is.

€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.

Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.

The gap we close: the impression of well-governed suppliers versus the operational reality of unknown dependencies, contract auto-renewals, and concentration risk. The Review documents the supplier estate and scores it for exit-readiness.

Why clients commission a review

A Supplier & Dependency Review is usually triggered by a specific moment. Most often, one of these:

  • A board has asked for visibility on technology supplier concentration risk.
  • A major supplier has been acquired, signalled end-of-life, or announced significant price increases.
  • An incident or outage has surfaced unknown dependencies that nobody had documented.
  • A regulatory event (DORA, NIS2, sector-specific outsourcing rules) requires documented vendor risk management.
  • The business is approaching a contract renewal cycle with multiple suppliers at once.
  • A merger or acquisition has created duplicate supplier relationships that need reconciling.
  • Insurance or finance covenants require documented vendor governance and resilience evidence.
  • A new procurement or vendor governance policy is being established and a current-state baseline is needed.

If one of these is the position you are in, the Review is built for it.

Who this is for

Owners, MDs, and CFOs concerned about vendor concentration, exit-readiness, and operational resilience.

Boards governing under DORA, NIS2, or sector-specific outsourcing regimes that require documented vendor risk evidence.

Procurement and risk functions needing a comprehensive technology vendor inventory to manage against.

Acquirers post-deal needing supplier reconciliation and concentration risk assessment for the combined business.

Who this is not for

Pre-revenue businesses with few or no material technology suppliers.

Owners wanting procurement strategy or sourcing transformation. The Review identifies risk; procurement strategy is a separate engagement.

Buyers wanting contract legal review or negotiation. The Review surfaces commercial risk; legal advice is a separate engagement.

Regulatory certification or attestation. The Review can inform one, but does not substitute for one.

What you receive

The Review tells you who you depend on, how concentrated those dependencies are, and what would happen if any of them failed. Five artefacts, delivered together.

Five deliverables of the Supplier and Dependency Review: a vendor and dependency inventory, a contract calendar, a concentration risk assessment, an exit-readiness scoring, and recommendations with board presentation.

A vendor and dependency inventory. Every technology supplier in the business, named, categorised, and described. Plus the dependencies inside dependencies — the SaaS tools, libraries, and contracted individuals that are easy to miss.

A contract calendar. Renewal dates, notice periods, termination terms, auto-renewal triggers. Mapped across the next twenty-four months so leadership can plan rather than react.

A concentration risk assessment. By spend, by function, by data, by geography. Where the business is over-exposed to a single supplier, named explicitly with the implications.

An exit-readiness scoring. For each significant supplier: could the business replace them in ninety days, in six months, or not at all? Scored, evidenced, and tied to the contract terms.

Recommendations and board presentation. What to address first, second, third. A board-cycle session to walk through the findings and the roadmap.

Typical outcomes

Most Reviews result in one of four conclusions.

The supplier estate is well-managed. Maintain current governance. No material concentration risk identified.

Specific concentration risks are identified. Particular suppliers — by spend, by function, or by data — represent more risk than the business should comfortably carry. The roadmap names them.

Significant remediation is needed. Multiple critical dependencies without adequate exit-readiness. A sequenced programme is proposed.

Critical exposure: single points of failure with no exit plan. Material risks that should be addressed before any major investment, transaction, or regulatory event.

The Review tells you which of these your business is in, and what to do about it.

How the Review runs

Three to four weeks, in four phases.

Week one — inventory. Contracts, invoices, system list, vendor management records. Everything that already exists about the supplier estate, brought into one place.

Week two — interviews. CFO, procurement, IT, operations, and senior business stakeholders who depend on specific suppliers. Where documentation differs from reality, we identify both.

Week three — risk scoring and synthesis. Concentration risk calculated. Exit-readiness scored. Contract calendar mapped. Findings written up.

Week four — presentation and roadmap. The board-cycle session. Roadmap sequenced. Revisions if the report needs tightening for board or audit audiences.

Everything is written before it is said. Nothing is presented to your board that you have not read first.

What this is not

Procurement strategy, sourcing transformation, or RFP support. The Review identifies risk; procurement strategy is a separate engagement.

Contract negotiation or legal review. We surface commercial risk; legal advice is a separate engagement.

Implementation of new vendor relationships. We identify what to change; selection and onboarding is a separate engagement.

Regulatory certification under DORA, NIS2, or similar. The Review can inform a certification process, but does not substitute for it.

A supplier review is not a procurement exercise. It is operational risk management.

The purpose of the Review is not to renegotiate every contract. It is to give leadership a clear, written answer to: who the business actually depends on, where the concentration is highest, and what would happen if any of them failed — so contract, investment, and resilience decisions are made with full visibility.

Proof

References available on request. Anonymised excerpts from prior reviews available on request.

What happens next

Start a Conversation

Thirty minutes. We confirm fit, scope, and timing. You decide whether to proceed. No proposal is sent unless you ask for one.

Start with the Technology Control Assessment — €4,950

A scored framework reading in five working days, with vendors and third parties assessed as one of the sixteen pillars. The right starting point if you want to see where supplier risk sits in the broader picture before committing to a focused Review.

For a comprehensive framework review, see Technology Control Review.

Book a Supplier & Dependency Review scoping call