01 / THE BUSINESS CASE
Why this service matters
Suppliers may hold sensitive information or support critical services. Understanding those dependencies helps teams apply proportionate due diligence and follow up on important gaps.
02 / THE SERVICE
What is Third-Party & Supplier Risk?
Third-party risk management evaluates supplier relationships and their oversight needs. Assessment depth is matched to information access, criticality, and potential business impact.
03 / PRACTICAL SUPPORT
Key capabilities
- Classify suppliers by risk and criticality
- Review questionnaires and supporting evidence
- Evaluate gaps and follow-up actions
- Define lifecycle and review considerations
04 / YOUR DELIVERY PARTNER
Why F&C?
We connect risk decisions with practical operational action. You work with a team that understands the relationship between cybersecurity, business priorities, and sustainable implementation.
Business-led priorities
Your objectives, existing practices, and available capacity shape the scope.
Clear ownership
We agree responsibilities and evidence expectations with your team.
Premium expertise. Competitive pricing.
Our Philippines-based delivery model offers high-quality support with transparent, proportionate engagement scopes.
05 / WHAT YOU CAN EXPECT
Service scope & deliverables
We agree the boundaries, activities, and outputs before delivery. Depending on the engagement, the scope may include:
- Supplier risk classification method
- Assessment and evidence checklist
- Findings for suppliers in scope
- Remediation and review recommendations
Systems, locations, participants, tools, timelines, and any ongoing support are confirmed in the proposal. External certification, licensing, and third-party costs are included only when explicitly agreed.
06 / WORKING TOGETHER
Engagement process
Understand & scope
Discuss your goals for third-party & supplier risk, relevant stakeholders, and the environment in scope.
Assess & plan
Review available information, confirm priorities, and agree activities, responsibilities, and deliverables.
Deliver & collaborate
Carry out the agreed work with your team and review findings or draft outputs as they develop.
Review & hand over
Walk through outcomes, outstanding actions, and ownership. Agree any follow-up support your team needs.
07 / YOUR QUESTIONS
FAQs
No. A risk-based approach focuses attention on relationships with greater access, criticality, or impact.
Yes. The scope can include established relationships and new supplier onboarding.
We review your scope, complexity, available information, and required support before proposing a timeline and price. You receive an agreed scope before work begins.
