Your suppliers have access you granted and nobody has reviewed since.
The IT provider with domain administrator rights, the software vendor with a permanent remote session, the marketing agency that can send email as your domain. Each was reasonable when it was granted. Together they are an attack surface nobody owns, and most UAE businesses cannot list it.

- List it firstMost organisations cannot
- Access, not paperworkWho can actually reach what
- Both directionsYou assess, and you get assessed
- ProportionateNot a questionnaire for every vendor
Eight things to establish, and the first one usually takes longest.
A list of who actually has access, which rarely exists
Not the vendor list from finance, which is organised around who gets paid. The list that matters is who can reach your systems and data: remote access accounts, administrative credentials, guest accounts in your tenant, API keys, consented applications, and anyone who can send email as your domain. Building this list honestly is the single most valuable output, and in most organisations it does not currently exist anywhere.
Tiering, so the effort goes where the risk is
A supplier with domain administrator rights and a supplier who delivers the water are not the same risk and should not receive the same treatment. We tier by what a compromise of that supplier would actually cost you, which usually means a small number of suppliers get real scrutiny and the rest get a light touch. Uniform treatment is why these programmes stall.
What each one can reach, tested rather than assumed
Contracts describe intended access. Systems show actual access, and the two diverge over time as projects end and permissions persist. We check what the accounts can genuinely do now, which regularly finds a vendor still holding administrative rights from an implementation that finished two years ago and a support account that was meant to be temporary.
Whether your agreements say anything useful
Most UAE supplier contracts we review say nothing about security, incident notification or data handling, because they were drafted around commercial terms. Several frameworks require this explicitly: ADHICS makes Third Party Security one of its eleven control domains and requires prompt notification to the regulator where an incident involves a third party, and PCI DSS requires written agreements covering cardholder data responsibilities.
Evidence, proportionate to what they hold
For a supplier holding significant data or access, an ISO 27001 certificate or a SOC 2 report is a reasonable ask and increasingly a routine one. For a smaller supplier, a short set of specific questions you actually read is worth more than a hundred-item questionnaire nobody scores. What does not work is collecting evidence you never look at, which is common and produces the appearance of diligence rather than the substance.
Concentration and the suppliers behind your suppliers
Where several critical services depend on the same provider, an outage or compromise there is not one incident, it is several at once. The same applies a level down: your supplier subcontractors are your exposure too, and most organisations have never asked who they are. This is the part of the analysis that most often changes a continuity plan.
Offboarding, which is where the real gap usually is
Onboarding a supplier gets attention because somebody wants the service. Ending the relationship gets far less, so access persists after the contract does. We check the last several suppliers you stopped using and establish whether their access was actually removed. The answer is uncomfortable often enough that we now open with it.
Answering the questionnaires you receive
Third party risk flows in both directions, and for many UAE businesses the inbound side is the more immediate cost. Client questionnaires arrive constantly, get answered inconsistently by whoever is free, and inconsistency between two answers to the same client is a real problem. A maintained answer set with evidence behind it turns a multi-day exercise into a short one.
The questionnaire is not the work. The access list is.
Almost every third party risk programme we are asked to rescue failed the same way, and it is worth naming because the failure is predictable and avoidable.
- It started with a questionnaire. Somebody bought or built a long assessment form and sent it to every supplier in the finance system. Responses came back over months, in varying quality, and nobody had the capacity to read them properly. The programme produced a folder rather than a decision, and it quietly stopped.
- It never established who actually has access. The finance vendor list is organised around payment, not around risk, and it will miss the things that matter most: a consented application in your tenant, an API key issued during an integration, a guest account from a project, a marketing platform authorised to send as your domain. None of those necessarily appears as a supplier at all.
- It treated every supplier alike. A provider holding administrative credentials to your estate warrants real scrutiny. A supplier delivering office furniture does not. Uniform treatment guarantees that either the important ones are under-examined or the whole exercise collapses under its own weight, and in practice both happen.
- It had no offboarding half. Organisations put effort into assessing suppliers at the start and almost none into removing access at the end, which is why access outlives contracts routinely. If you do only one thing from this page, check whether the last five suppliers you stopped using can still reach anything.
Four things that keep this from becoming a filing exercise.
We build the access list from your systems, not your invoices
We enumerate what actually holds access: accounts, guest identities, consented applications, API credentials, remote access paths and who can send as your domain. That is a technical exercise rather than a procurement one, and it is where the findings are. The finance vendor list is a useful cross-check and it is not the starting point.
We tier ruthlessly so the work stays finishable
A small number of suppliers get genuine scrutiny and the rest get a recorded decision that they do not need it. This is the difference between a programme that completes and one that collapses. We would rather assess eight suppliers properly than eighty superficially, and we will say which eight and why.
We hold ourselves to the same standard
We have administrative access to client systems, which puts us squarely in the highest tier of our own framework. We expect to be asked for evidence, to have our access reviewed, and to have it removed promptly when an engagement ends. If we are your IT provider, we would encourage you to have somebody else assess us, and we will support that rather than resist it.
We fix the inbound side at the same time
While building your outbound assessment we also build the maintained answer set for the questionnaires you receive, because the underlying evidence is the same. Doing both in one exercise is materially cheaper than doing them separately, and the inbound side is usually the one costing you time right now.
Six situations that bring UAE organisations to this work.
A client has asked how you manage your own suppliers
Increasingly common in enterprise due diligence, and awkward to answer if the honest response is that nobody does. This is a well-scoped piece of work with a clear finish line, and the artefacts it produces, an access list, a tiering decision and evidence for the top tier, answer the question directly rather than defensively.
A healthcare entity under ADHICS in Abu Dhabi
ADHICS V2 makes Third Party Security one of its eleven control domains in its own right, with requirements around agreements, oversight and prompt notification to the Department of Health where an incident involves a third party. Healthcare entities frequently find this is their weakest domain, because clinical suppliers were contracted on clinical terms.
A regulated financial firm
Outsourcing and third-party arrangements attract supervisory attention, and the questions are specific: what they can access, what happens if they fail, how you would exit. For firms under Central Bank supervision the applicable regulation may impose its own requirements, which we map rather than assume.
An organisation that has changed IT provider
The clearest and most common gap. The previous provider had administrative access to everything, the relationship ended, and nobody verified that the access ended with it. This is worth checking within days of any provider change rather than at the next audit, and it applies equally when we are the incoming provider.
A business that had a near miss through a supplier
A supplier mailbox was compromised and a fraudulent invoice nearly went through, or a vendor had an incident and nobody could work out what it meant for you. These moments are the best available time to do this work, because the organisation has just experienced why the access list matters.
Anyone with data protection obligations
Under UAE federal data protection law, and under free zone regimes for DIFC and ADGM entities, processing carried out on your behalf remains your responsibility. That requires knowing who processes personal data for you, on what basis, where it goes and what happens when the arrangement ends. Most organisations can answer none of those precisely.
How UAE organisations actually handle supplier risk.
| Feature | Access-led and tiered | Questionnaire-led | Nothing formal |
|---|---|---|---|
Complete list of third parties with access | |||
Suppliers tiered by actual impact | Uniform treatment | ||
Access verified in systems, not just contracts | |||
Agreements carry security and notification terms | Some | Rarely | |
Evidence held for high-tier suppliers, and read | Collected, unread | ||
Consented apps and domain senders included | |||
Subcontractor concentration understood | |||
Access removed when a supplier is dropped | Sometimes | Rarely | |
Inbound questionnaires answered from a maintained set | Ad hoc | Ad hoc | |
Effort proportionate to risk | Not applicable |
What level of scrutiny each kind of supplier actually warrants.
| Supplier type | Proportionate scrutiny | |
|---|---|---|
| IT provider with administrative access | Highest. Evidence, agreement terms, access tested, reviewed regularly | |
| Cloud platform hosting your core systems | High. Their certification, plus your own configuration reviewed | |
| Software vendor with a permanent remote session | High. Question whether permanent access is needed at all | |
| Processor handling personal data on your behalf | High. Data protection terms and a documented basis | |
| Payment or finance system provider | High. Compliance status evidenced, not assumed | |
| Marketing platform sending as your domain | Medium. Authentication, alignment and what they can send | |
| Outsourced call centre handling customer data | High. Frequently governed by a contract that never mentions data | |
| Consultant with time-limited project access | Medium, with a hard removal date set at the start | |
| Supplier with no access to systems or data | Low. Record the decision and move on | |
| Subcontractors behind any of the above | Inherit the tier of whoever they work for |
Five stages, and the first produces most of the value.
- 1
Enumerate who actually has access
From your systems: accounts and guest identities, consented applications, administrative credentials, remote access paths, API keys where discoverable, and who is authorised to send email as your domain. Cross-checked against the finance vendor list to catch anything holding access under a name nobody recognises.
- 2
Tier by impact, with the business deciding
What a compromise or failure of each supplier would actually cost you, in operational and data terms. This is a business judgement rather than a technical one, and recording the reasoning matters as much as the tier, because the decision to treat a supplier lightly needs to be defensible later.
- 3
Assess the top tier properly
Evidence appropriate to what they hold, agreement terms covering security, incident notification and data handling, access verified against what they actually need, and their own critical dependencies where those matter to you. A small number of suppliers, examined seriously.
- 4
Close the access gaps, starting with former suppliers
Remove access that outlived its purpose, reduce standing administrative access to what is genuinely needed, put expiry on project access, and establish an offboarding step that actually runs. This stage usually produces the quickest measurable risk reduction of the whole engagement.
- 5
Build the inbound answer set and a review cadence
A maintained set of answers with evidence behind them for the questionnaires you receive, and a fixed point in the year when the access list and the top tier are re-examined. Supplier estates drift constantly, so a review that happens once is a snapshot rather than a control.
What organisations ask about supplier risk.
Fifteen questions, and the first five are the ones that matter.
Who can reach what
- Can you list every third party with access to your systems?Not the payment list. The access list.
- Which suppliers hold administrative credentials?Including your IT provider and any implementation partner.
- How many guest accounts in your tenant belong to suppliers?They accumulate and nobody removes them.
- Which third-party applications have consent in your tenant?A standing access path most people never audit.
- Who can send email as your domain?Marketing platforms, invoicing tools, agencies past and present.
What you have agreed
- Do your contracts require incident notification, and how fast?Usually absent. Required explicitly by several frameworks.
- Do they address data handling, location and deletion?Needed for UAE data protection obligations.
- Do you have a right to audit, and have you ever used it?An unused right is still worth having, but check it exists.
- Do you hold current evidence for your highest-tier suppliers?Certificates expire. Reports cover a past period.
- Do you know who their critical subcontractors are?Your exposure runs a level deeper than your contract.
The inbound side
- How long does a client security questionnaire take you?If the answer is days, there is no maintained answer set.
- Are your answers consistent between clients?Inconsistency is noticed and is hard to explain.
- Can you evidence what you claim in those answers?Claiming a control you cannot evidence is the real risk.
- Was access removed for the last five suppliers you dropped?Check rather than assume. This is the common gap.
- Is one person accountable for all of this?Split between IT, finance and legal usually means nobody.
The pages around this one.
IT audit services in Dubai
The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.
Microsoft 365 security audit
Where much of the supplier access actually lives: guest accounts, consented applications and the third parties inside your tenant.
Virtual CISO in Dubai
If the finding is that nobody owns this, that is a governance gap rather than a supplier one, and this is the role that closes it.
Check whether your last five former suppliers can still reach anything.
It takes an afternoon, it costs nothing, and it is the single most revealing thing you can do in this area. If the answer is uncomfortable, the access list is where a proper review starts and we will build it with you.
Related Services
Explore more solutions that work great with this service
Access Rights Review
Certification that removes access, not one that gets approved
Shadow IT Discovery
Find the SaaS nobody sanctioned, without driving it underground
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
Virtual CISO Dubai
Security governance and accountability, not more tools
Active Directory Audit
Privilege paths, service accounts and local admin passwords
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
ADHICS V2 Compliance
The Abu Dhabi healthcare standard, read from the source