JJC SystemsBook a Consultation
Microsoft Defender · Audit

Supplier and third-party access audit

Twenty checks on who outside your organization can reach your systems, and what would happen if one of them were compromised.

Why run this

What this checklist is for

Public sector organizations work with many suppliers, and each one that reaches your systems extends your attack surface into an organization whose security you do not control.

This audit is about knowing the extent of that, which most organizations have never established.

Run it with

CIO or Head of Digital

And with

Security and identity teams

And with

Procurement and contract managers

0 of 0 complete · 0%
The checklist

20 checks, in the order we would run them

Tick only what you can genuinely evidence today. An item you intend to do is not an item you have done, and scoring yourself generously here only produces a comfortable number and an uncomfortable project.

Section 1

Inventory

Establishing who actually has access.

Section 2

Controls

Whether the access is appropriately constrained.

Section 3

Contract and assurance

Whether the obligations are written down.

Section 4

Ongoing management

Whether this stays current.

What your score means

Read this against the number above

These bands are deliberately blunt. The middle band is where most organizations honestly sit, and it is a perfectly reasonable place to proceed from — provided the gaps are written down with owners rather than carried as optimism.

0–59%Significant gaps

Do not proceed yet. More than four in ten items are unaddressed, and the ones that fail here are usually the foundational ones that make everything after them harder.

60–84%Mostly ready, with known gaps

Proceed on a defined scope, with the outstanding items written into the plan as risks with owners and dates. This is the most common honest position.

85–100%Ready

The remaining gaps are small enough to handle during delivery rather than before it. Confirm the unticked items are genuinely minor rather than simply unexamined.

Your score highlights automatically as you tick items above. Nothing is saved, sent or tracked — refreshing the page clears it.

Closing the gaps

If you could not tick these, start here

The four items below are the ones whose absence causes the most trouble downstream. If your unticked items include any of these, they are worth addressing before the rest.

No complete inventory

Build it from the directory rather than from procurement records. The gap between the two is itself the finding.

Supplier accounts exempt from MFA

Close the exemption. These are among the most targeted accounts you have and the exemption is almost always for convenience.

Standing rather than time-bound access

Move to time-bound. Access that must be manually revoked depends on somebody remembering after a project ended.

Ownership split between procurement and IT

Name one accountable person. Shared ownership of third-party risk reliably means nobody reviews it.

Want a second opinion on your score?

We will build the third-party access inventory from your directory and produce a prioritised remediation list, which usually starts with a number nobody expected.

Talk through your result Read the related guides We reply to every message within one business day.
Keep going

Related checklists

purview
public-sectorReadiness

Records compliance audit

Whether your retention schedule is operating or merely documented, across twenty specific checks.

April 25, 2026 · 20 checksOpen
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.