Tier before you question
Not every supplier needs a 200-question assessment. Tier by data sensitivity and operational dependency: Tier 1 suppliers hold personal or financial data or can halt operations; Tier 3 suppliers hold nothing and touch nothing.
Assess Tier 1 annually with evidence, Tier 2 on a self-attested questionnaire, Tier 3 at onboarding only.
Australian-specific questions people forget
Where is data stored and backed up, and does any support team access it from offshore? Cross-border disclosure triggers Australian Privacy Principle 8 accountability.
Will the supplier notify you within a contractual timeframe short enough for you to meet your own NDB assessment obligation?
The checklist
Governance
- Named security contact and escalation path provided
- Current ISO 27001, SOC 2 Type II or IRAP assessment evidence supplied
- Sub-processor list disclosed and change-notification committed
Data handling
- Primary and backup data hosting locations documented
- Offshore support access disclosed and access controls described
- Encryption in transit and at rest confirmed
- Data return and deletion process on exit documented
Security controls
- MFA enforced for staff and for customer administrative access
- Vulnerability management and penetration test cadence stated
- Logging and monitoring coverage described
Contractual
- Breach notification within 24–48 hours written into the contract
- Right to audit or receive annual assurance reporting
- Cyber liability insurance evidence current
- Availability commitments and credits defined