We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Third party risk
Third party risk audit, UAE

Your suppliers have access you granted and nobody has reviewed since.

The IT provider with domain administrator rights, the software vendor with a permanent remote session, the marketing agency that can send email as your domain. Each was reasonable when it was granted. Together they are an attack surface nobody owns, and most UAE businesses cannot list it.

Book a third party risk reviewSee what we assess
Third party and supplier risk assessment for UAE organisations
  • List it firstMost organisations cannot
  • Access, not paperworkWho can actually reach what
  • Both directionsYou assess, and you get assessed
  • ProportionateNot a questionnaire for every vendor
What a third party risk review covers

Eight things to establish, and the first one usually takes longest.

This work fails when it becomes a paperwork exercise, sending the same questionnaire to eighty suppliers and filing the answers. What makes it useful is starting from access rather than from contracts: which third parties can actually reach your systems and your data, and what would happen if one of them were compromised.

A list of who actually has access, which rarely exists

Not the vendor list from finance, which is organised around who gets paid. The list that matters is who can reach your systems and data: remote access accounts, administrative credentials, guest accounts in your tenant, API keys, consented applications, and anyone who can send email as your domain. Building this list honestly is the single most valuable output, and in most organisations it does not currently exist anywhere.

Tiering, so the effort goes where the risk is

A supplier with domain administrator rights and a supplier who delivers the water are not the same risk and should not receive the same treatment. We tier by what a compromise of that supplier would actually cost you, which usually means a small number of suppliers get real scrutiny and the rest get a light touch. Uniform treatment is why these programmes stall.

What each one can reach, tested rather than assumed

Contracts describe intended access. Systems show actual access, and the two diverge over time as projects end and permissions persist. We check what the accounts can genuinely do now, which regularly finds a vendor still holding administrative rights from an implementation that finished two years ago and a support account that was meant to be temporary.

Whether your agreements say anything useful

Most UAE supplier contracts we review say nothing about security, incident notification or data handling, because they were drafted around commercial terms. Several frameworks require this explicitly: ADHICS makes Third Party Security one of its eleven control domains and requires prompt notification to the regulator where an incident involves a third party, and PCI DSS requires written agreements covering cardholder data responsibilities.

Evidence, proportionate to what they hold

For a supplier holding significant data or access, an ISO 27001 certificate or a SOC 2 report is a reasonable ask and increasingly a routine one. For a smaller supplier, a short set of specific questions you actually read is worth more than a hundred-item questionnaire nobody scores. What does not work is collecting evidence you never look at, which is common and produces the appearance of diligence rather than the substance.

Concentration and the suppliers behind your suppliers

Where several critical services depend on the same provider, an outage or compromise there is not one incident, it is several at once. The same applies a level down: your supplier subcontractors are your exposure too, and most organisations have never asked who they are. This is the part of the analysis that most often changes a continuity plan.

Offboarding, which is where the real gap usually is

Onboarding a supplier gets attention because somebody wants the service. Ending the relationship gets far less, so access persists after the contract does. We check the last several suppliers you stopped using and establish whether their access was actually removed. The answer is uncomfortable often enough that we now open with it.

Answering the questionnaires you receive

Third party risk flows in both directions, and for many UAE businesses the inbound side is the more immediate cost. Client questionnaires arrive constantly, get answered inconsistently by whoever is free, and inconsistency between two answers to the same client is a real problem. A maintained answer set with evidence behind it turns a multi-day exercise into a short one.

Why these programmes usually fail

The questionnaire is not the work. The access list is.

Almost every third party risk programme we are asked to rescue failed the same way, and it is worth naming because the failure is predictable and avoidable.

  • It started with a questionnaire. Somebody bought or built a long assessment form and sent it to every supplier in the finance system. Responses came back over months, in varying quality, and nobody had the capacity to read them properly. The programme produced a folder rather than a decision, and it quietly stopped.
  • It never established who actually has access. The finance vendor list is organised around payment, not around risk, and it will miss the things that matter most: a consented application in your tenant, an API key issued during an integration, a guest account from a project, a marketing platform authorised to send as your domain. None of those necessarily appears as a supplier at all.
  • It treated every supplier alike. A provider holding administrative credentials to your estate warrants real scrutiny. A supplier delivering office furniture does not. Uniform treatment guarantees that either the important ones are under-examined or the whole exercise collapses under its own weight, and in practice both happen.
  • It had no offboarding half. Organisations put effort into assessing suppliers at the start and almost none into removing access at the end, which is why access outlives contracts routinely. If you do only one thing from this page, check whether the last five suppliers you stopped using can still reach anything.
Ask us to build the access list first
How we work on this

Four things that keep this from becoming a filing exercise.

We are also a third party to our clients, with access to their systems, so we are describing a standard we are assessed against ourselves. That shapes how we approach it.

We build the access list from your systems, not your invoices

We enumerate what actually holds access: accounts, guest identities, consented applications, API credentials, remote access paths and who can send as your domain. That is a technical exercise rather than a procurement one, and it is where the findings are. The finance vendor list is a useful cross-check and it is not the starting point.

We tier ruthlessly so the work stays finishable

A small number of suppliers get genuine scrutiny and the rest get a recorded decision that they do not need it. This is the difference between a programme that completes and one that collapses. We would rather assess eight suppliers properly than eighty superficially, and we will say which eight and why.

We hold ourselves to the same standard

We have administrative access to client systems, which puts us squarely in the highest tier of our own framework. We expect to be asked for evidence, to have our access reviewed, and to have it removed promptly when an engagement ends. If we are your IT provider, we would encourage you to have somebody else assess us, and we will support that rather than resist it.

We fix the inbound side at the same time

While building your outbound assessment we also build the maintained answer set for the questionnaires you receive, because the underlying evidence is the same. Doing both in one exercise is materially cheaper than doing them separately, and the inbound side is usually the one costing you time right now.

When this becomes urgent

Six situations that bring UAE organisations to this work.

Supplier risk is rarely addressed proactively. It is usually triggered by an external requirement or by something that nearly went wrong.

A client has asked how you manage your own suppliers

Increasingly common in enterprise due diligence, and awkward to answer if the honest response is that nobody does. This is a well-scoped piece of work with a clear finish line, and the artefacts it produces, an access list, a tiering decision and evidence for the top tier, answer the question directly rather than defensively.

A healthcare entity under ADHICS in Abu Dhabi

ADHICS V2 makes Third Party Security one of its eleven control domains in its own right, with requirements around agreements, oversight and prompt notification to the Department of Health where an incident involves a third party. Healthcare entities frequently find this is their weakest domain, because clinical suppliers were contracted on clinical terms.

A regulated financial firm

Outsourcing and third-party arrangements attract supervisory attention, and the questions are specific: what they can access, what happens if they fail, how you would exit. For firms under Central Bank supervision the applicable regulation may impose its own requirements, which we map rather than assume.

An organisation that has changed IT provider

The clearest and most common gap. The previous provider had administrative access to everything, the relationship ended, and nobody verified that the access ended with it. This is worth checking within days of any provider change rather than at the next audit, and it applies equally when we are the incoming provider.

A business that had a near miss through a supplier

A supplier mailbox was compromised and a fraudulent invoice nearly went through, or a vendor had an incident and nobody could work out what it meant for you. These moments are the best available time to do this work, because the organisation has just experienced why the access list matters.

Anyone with data protection obligations

Under UAE federal data protection law, and under free zone regimes for DIFC and ADGM entities, processing carried out on your behalf remains your responsibility. That requires knowing who processes personal data for you, on what basis, where it goes and what happens when the arrangement ends. Most organisations can answer none of those precisely.

Three positions

How UAE organisations actually handle supplier risk.

The middle column looks like diligence and produces very little of it. Effort has been spent, a folder exists, and the questions that would matter in an incident have not been answered.
Complete list of third parties with access
Access-led and tiered
Questionnaire-led
Nothing formal
Suppliers tiered by actual impact
Access-led and tiered
Questionnaire-ledUniform treatment
Nothing formal
Access verified in systems, not just contracts
Access-led and tiered
Questionnaire-led
Nothing formal
Agreements carry security and notification terms
Access-led and tiered
Questionnaire-ledSome
Nothing formalRarely
Evidence held for high-tier suppliers, and read
Access-led and tiered
Questionnaire-ledCollected, unread
Nothing formal
Consented apps and domain senders included
Access-led and tiered
Questionnaire-led
Nothing formal
Subcontractor concentration understood
Access-led and tiered
Questionnaire-led
Nothing formal
Access removed when a supplier is dropped
Access-led and tiered
Questionnaire-ledSometimes
Nothing formalRarely
Inbound questionnaires answered from a maintained set
Access-led and tiered
Questionnaire-ledAd hoc
Nothing formalAd hoc
Effort proportionate to risk
Access-led and tiered
Questionnaire-led
Nothing formalNot applicable
Feature
Access-led and tiered
Questionnaire-led
Nothing formal
Complete list of third parties with access
Suppliers tiered by actual impact
Uniform treatment
Access verified in systems, not just contracts
Agreements carry security and notification terms
SomeRarely
Evidence held for high-tier suppliers, and read
Collected, unread
Consented apps and domain senders included
Subcontractor concentration understood
Access removed when a supplier is dropped
SometimesRarely
Inbound questionnaires answered from a maintained set
Ad hocAd hoc
Effort proportionate to risk
Not applicable
Tiering in practice

What level of scrutiny each kind of supplier actually warrants.

This is the shape we use as a starting point, adjusted to your business. The point is that the column on the right differs sharply by row, because uniform treatment is what makes these programmes unmanageable.
Supplier typeProportionate scrutiny
IT provider with administrative accessHighest. Evidence, agreement terms, access tested, reviewed regularly
Cloud platform hosting your core systemsHigh. Their certification, plus your own configuration reviewed
Software vendor with a permanent remote sessionHigh. Question whether permanent access is needed at all
Processor handling personal data on your behalfHigh. Data protection terms and a documented basis
Payment or finance system providerHigh. Compliance status evidenced, not assumed
Marketing platform sending as your domainMedium. Authentication, alignment and what they can send
Outsourced call centre handling customer dataHigh. Frequently governed by a contract that never mentions data
Consultant with time-limited project accessMedium, with a hard removal date set at the start
Supplier with no access to systems or dataLow. Record the decision and move on
Subcontractors behind any of the aboveInherit the tier of whoever they work for
How the review runs

Five stages, and the first produces most of the value.

Typically two to four weeks depending on how many suppliers hold access. The access enumeration is technical and quick. The tiering conversation is the one that needs the business in the room.
  1. 1

    Enumerate who actually has access

    From your systems: accounts and guest identities, consented applications, administrative credentials, remote access paths, API keys where discoverable, and who is authorised to send email as your domain. Cross-checked against the finance vendor list to catch anything holding access under a name nobody recognises.

  2. 2

    Tier by impact, with the business deciding

    What a compromise or failure of each supplier would actually cost you, in operational and data terms. This is a business judgement rather than a technical one, and recording the reasoning matters as much as the tier, because the decision to treat a supplier lightly needs to be defensible later.

  3. 3

    Assess the top tier properly

    Evidence appropriate to what they hold, agreement terms covering security, incident notification and data handling, access verified against what they actually need, and their own critical dependencies where those matter to you. A small number of suppliers, examined seriously.

  4. 4

    Close the access gaps, starting with former suppliers

    Remove access that outlived its purpose, reduce standing administrative access to what is genuinely needed, put expiry on project access, and establish an offboarding step that actually runs. This stage usually produces the quickest measurable risk reduction of the whole engagement.

  5. 5

    Build the inbound answer set and a review cadence

    A maintained set of answers with evidence behind them for the questionnaires you receive, and a fixed point in the year when the access list and the top tier are re-examined. Supplier estates drift constantly, so a review that happens once is a snapshot rather than a control.

Straight answers

What organisations ask about supplier risk.

With the access list, not with a questionnaire. Work out which third parties can actually reach your systems and data: accounts and guest identities in your tenant, consented applications, administrative credentials, remote access, API keys, and anyone authorised to send email as your domain. In most organisations this list does not exist and building it is genuinely revealing. Everything else in the programme depends on it, and a questionnaire sent before you have it will ask the wrong people the wrong things.

No, and doing so is the most common way these programmes fail. A supplier with domain administrative rights and a supplier delivering office supplies present entirely different risk, and treating them alike means either the important ones get superficial attention or the exercise collapses. Tier first, assess the top tier properly, and record a decision for the rest. Eight suppliers examined seriously is worth far more than eighty questionnaires nobody reads.

It is a normal arrangement and it puts them in your highest risk tier, which means it warrants evidence, agreement terms and periodic review rather than being taken on trust. We say this as a provider that holds exactly that access with our own clients. The reasonable position is that your provider expects to be asked for evidence, expects access to be reviewed, and expects it to be removed promptly when an engagement ends. A provider who resists any of that is telling you something.

At minimum, for suppliers holding access or data: a security obligation proportionate to what they hold, an incident notification requirement with a timeframe, terms covering how data is handled, where it is held and what happens to it when the arrangement ends, and a right to seek evidence. Several frameworks require this explicitly rather than treating it as good practice. Drafting is a matter for your legal advisers; what we contribute is what the terms need to cover technically for them to be meaningful.

Proportionate to what they hold. For a supplier with significant access or data, an ISO 27001 certificate or a SOC 2 report is reasonable and increasingly routine, and both are worth actually reading rather than filing: check the scope covers the service you buy and, for SOC 2, check the period and any exceptions. For smaller suppliers, a short set of specific questions you will genuinely read is more useful than a long form. Evidence you collect and never look at is theatre.

It depends entirely on their tier and your leverage. For a critical supplier, refusal is itself information and worth escalating commercially, because an organisation unwilling to describe its security posture to a customer with a legitimate interest is making a statement. For a low-tier supplier, insisting is usually not worth the relationship cost. Record the refusal and the decision you took in response, which is a perfectly defensible position provided the tiering behind it is sound.

They are your exposure and most organisations have never asked. If your critical platform depends on a hosting provider, and that provider depends on one region of one cloud, your continuity position is different from what your direct contract suggests. For your highest-tier suppliers it is reasonable to ask who their critical dependencies are. You will not map the whole chain and you do not need to; you need to know where concentration exists.

The access list, at least annually and after any provider change, because it drifts continuously as projects start and end. The top-tier supplier assessments, annually, since certificates expire and attestation reports cover a past period. Offboarding should not be periodic at all, it should be an event triggered by the relationship ending. Most of the risk we find comes from the gap between those two ideas: reviews happen on a calendar while access changes on a business timetable.

Directly. Under UAE federal data protection law, and under the DIFC and ADGM regimes for entities in those free zones, processing carried out on your behalf remains your responsibility. That requires knowing who processes personal data for you, what they do with it, where it is held and what happens when the arrangement ends. The access list and the tiering exercise answer most of that, which is why we run the two together rather than treating them as separate projects.

Access that outlived the relationship. A previous IT provider whose administrative account still works, a consultant from a project that finished, a vendor support account created during an implementation and never removed. After that: consented applications in the Microsoft 365 tenant that nobody can account for, guest accounts belonging to people who have changed employer, and marketing platforms still authorised to send email as the domain long after the agency was dropped.

Two to four weeks for a typical UAE organisation, weighted toward the access enumeration and the tiering conversation rather than toward assessing suppliers. Assessing the top tier then runs at the pace of supplier responses, which you do not control. The remediation, removing access that should not exist, is usually quick and produces the most immediate risk reduction, so we do it in parallel rather than waiting for the assessments to complete.

Not independently, and we would say so rather than pretend otherwise. Where we hold administrative access to your estate, our assessment of ourselves is worth very little to a regulator, an insurer or a demanding client. We can perform the rest of the programme and support a third party assessing us, which is the arrangement we would recommend and the one we take the same view on across every audit service on this site.

Build a maintained answer set with evidence behind each answer, owned by one named person. The three problems with ad hoc responses are that they consume senior time repeatedly, that answers drift and become inconsistent between clients, and that people occasionally claim controls the organisation cannot evidence. That last one is the genuine risk, because a claim you cannot support is worse than an honest gap. We build this alongside the outbound work since the underlying evidence is the same.

It is the practical core of one. Frameworks place this within governance rather than treating it as a procurement task, and NIST CSF 2.0 for instance puts cybersecurity supply chain risk management inside its GOVERN Function. What that reflects is that the decisions here are about accountability and risk appetite rather than about technology. The technical work, enumerating access and closing gaps, is the part that produces measurable change.

We scope per organisation, driven mostly by how many third parties hold access and how many fall into the top tier. What we will tell you free in the first conversation is the one exercise worth running yourself first: take the last five suppliers you stopped using and check whether their access was actually removed. That takes an afternoon and it usually tells you how much of a problem you have.
Supplier access reality check

Fifteen questions, and the first five are the ones that matter.

The first group can be answered from your own systems this week. The second is about what you have agreed. The third is the inbound side, which for many UAE businesses is the more immediate cost.

Who can reach what

  • Can you list every third party with access to your systems?
    Not the payment list. The access list.
  • Which suppliers hold administrative credentials?
    Including your IT provider and any implementation partner.
  • How many guest accounts in your tenant belong to suppliers?
    They accumulate and nobody removes them.
  • Which third-party applications have consent in your tenant?
    A standing access path most people never audit.
  • Who can send email as your domain?
    Marketing platforms, invoicing tools, agencies past and present.

What you have agreed

  • Do your contracts require incident notification, and how fast?
    Usually absent. Required explicitly by several frameworks.
  • Do they address data handling, location and deletion?
    Needed for UAE data protection obligations.
  • Do you have a right to audit, and have you ever used it?
    An unused right is still worth having, but check it exists.
  • Do you hold current evidence for your highest-tier suppliers?
    Certificates expire. Reports cover a past period.
  • Do you know who their critical subcontractors are?
    Your exposure runs a level deeper than your contract.

The inbound side

  • How long does a client security questionnaire take you?
    If the answer is days, there is no maintained answer set.
  • Are your answers consistent between clients?
    Inconsistency is noticed and is hard to explain.
  • Can you evidence what you claim in those answers?
    Claiming a control you cannot evidence is the real risk.
  • Was access removed for the last five suppliers you dropped?
    Check rather than assume. This is the common gap.
  • Is one person accountable for all of this?
    Split between IT, finance and legal usually means nobody.
Related reading

The pages around this one.

IT audit services in Dubai

The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.

Learn more

Microsoft 365 security audit

Where much of the supplier access actually lives: guest accounts, consented applications and the third parties inside your tenant.

Learn more

Virtual CISO in Dubai

If the finding is that nobody owns this, that is a governance gap rather than a supplier one, and this is the role that closes it.

Learn more
Next step

Check whether your last five former suppliers can still reach anything.

It takes an afternoon, it costs nothing, and it is the single most revealing thing you can do in this area. If the answer is uncomfortable, the access list is where a proper review starts and we will build it with you.

Book a third party risk reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Access Rights Review

Certification that removes access, not one that gets approved

Learn more

Shadow IT Discovery

Find the SaaS nobody sanctioned, without driving it underground

Learn more

IT Audit Services Dubai

Assessment, technical test or certification, scoped properly

Learn more

Microsoft 365 Security Audit

Tenant review, and how far back your evidence really goes

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more

Active Directory Audit

Privilege paths, service accounts and local admin passwords

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

ADHICS V2 Compliance

The Abu Dhabi healthcare standard, read from the source

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy