BOARD THIRD-PARTY CYBER & AI RISK DASHBOARD
Your suppliers are part of your resilience.
Reporting Period: ____________________
Board Meeting: ____________________
Executive Owner: ____________________
Previous Review: ____________________
Reporting Period: ____________________
Board Meeting: ____________________
Executive Owner: ____________________
Previous Review: ____________________
BOARD AT A GLANCE
|
CRITICAL THIRD PARTY
__________________ __________________ __________________ __________________ ___________________________________ |
CRITICALITY
🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 |
CYBER RISK
🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 |
AI / DATA EXPOSURE
🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 |
CONCENTRATION RISK
🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 |
RESILIENCE
🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 🟢 🟠 🔴 |
TREND
↑ → ↓ ↑ → ↓ ↑ → ↓ ↑ → ↓ ↑ → ↓ ↑ → ↓ |
BOARD ACTION
__________________ __________________ __________________ __________________ __________________ __________________ |
WHAT ARE WE MEASURING?
1. CRITICALITY
How dependent are we on this supplier?
Consider:
If this supplier became unavailable tomorrow, how significantly would our organisation be affected?
2. CYBER RISK
How confident are we in their cybersecurity posture?
Consider:
Do we have enough evidence to trust this supplier with our systems, services or information?
3. AI / DATA EXPOSURE
What information do they access, process or expose through AI?
Consider:
Do we know how this supplier uses our information, including within AI-enabled services?
4. CONCENTRATION RISK
Are we too dependent on common providers or platforms?
Consider:
Would one upstream provider failure affect multiple critical suppliers at the same time?
5. RESILIENCE
Can both we and the supplier withstand and recover from disruption?
Consider:
Could we continue delivering critical services if this supplier experienced a major incident?
STATUS
🟢 CONTROLLED / ACCEPTABLE
Risk is understood, appropriate controls and assurance are in place, and no immediate Board intervention is required.
🟠 DEVELOPING / MONITOR
Some controls or assurance exist, but gaps, dependencies or uncertainty require continued management attention.
🔴 PRIORITY ATTENTION
Material exposure exists, assurance is insufficient, or the supplier presents a significant resilience concern requiring action.
TREND
↑ IMPROVING
Evidence shows the risk position or resilience is strengthening.
→ STABLE
No material change since the previous reporting period.
↓ DECLINING
Evidence indicates deterioration, increased dependency or an emerging concern.
KEY BOARD INDICATORS
Critical Supplier Coverage
Percentage of critical suppliers reviewed within the required period:
__________ %
Critical Suppliers with Current Cyber Assurance
__________ %
Critical Suppliers with AI / Data Usage Assessed
__________ %
Critical Suppliers Included in Incident Response Exercises
__________ %
Critical Suppliers with Tested Continuity / Recovery Arrangements
__________ %
Material Fourth-Party or Concentration Risks Identified
__________
BOARD ATTENTION
What has improved?
What concerns us?
Which supplier relationships require Board-level attention?
What action or decision is required?
FIVE QUESTIONS FOR EVERY BOARD REVIEW
1. Who are our most critical third parties?
Do we know which suppliers our organisation depends on most?
2. What do they have access to?
Do we understand the systems, information and data they can access or process?
3. How are they using AI?
Could our information be processed through public or third-party AI platforms?
4. Where are our concentration risks?
Are multiple critical suppliers dependent on the same underlying providers?
5. Could we continue operating without them?
Have we tested what happens if a critical supplier becomes unavailable?
BOARD ESCALATION TRIGGERS
A third-party risk should normally be escalated when:
DON'T JUST ASSESS THE SUPPLIER. ASSESS THE DEPENDENCY.
A supplier may have strong cybersecurity controls and still create significant risk if your organisation is completely dependent on them.
Boards therefore need visibility into both:
Supplier Risk
How well is the third party managing cyber and AI risk?
and
Dependency Risk
What happens to our organisation if they fail?
The combination determines your true exposure.
THE BOARD VIEW
At each quarterly review, Directors should be able to answer:
Which third parties could materially disrupt our organisation?
What evidence do we have that they are managing cyber and AI risk appropriately?
Where are our greatest dependencies?
Which risks are improving, and which are deteriorating?
What are we doing about the risks that matter most?
A FINAL BOARD PRINCIPLE
You can outsource the service. You cannot outsource accountability for the risk.
Strong third-party governance is not about distrusting suppliers.
It is about building trusted relationships supported by appropriate assurance, transparency and resilience.
CYBERPLANZ | THE BOARDROOM GUIDE TO CYBER & AI GOVERNANCE
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.
Helping Boards build secure, resilient and AI-ready organisations.
1. CRITICALITY
How dependent are we on this supplier?
Consider:
- Importance to critical business services
- Difficulty of replacement
- Operational dependency
- Customer impact if unavailable
- Financial impact of disruption
If this supplier became unavailable tomorrow, how significantly would our organisation be affected?
2. CYBER RISK
How confident are we in their cybersecurity posture?
Consider:
- Security controls
- Access management
- Incident history
- Vulnerability management
- Independent assurance
- Security certifications
- Incident response capability
Do we have enough evidence to trust this supplier with our systems, services or information?
3. AI / DATA EXPOSURE
What information do they access, process or expose through AI?
Consider:
- Customer data
- Employee information
- Confidential business information
- Intellectual property
- Use of generative AI
- Data retention
- AI model training
- Data location and jurisdiction
Do we know how this supplier uses our information, including within AI-enabled services?
4. CONCENTRATION RISK
Are we too dependent on common providers or platforms?
Consider:
- Shared cloud providers
- Common identity platforms
- Telecommunications dependencies
- Payment systems
- AI platforms
- Data centres
- Subcontractors and fourth parties
Would one upstream provider failure affect multiple critical suppliers at the same time?
5. RESILIENCE
Can both we and the supplier withstand and recover from disruption?
Consider:
- Business continuity capability
- Disaster recovery
- Backup arrangements
- Recovery time
- Alternative suppliers
- Incident communications
- Exit and transition plans
Could we continue delivering critical services if this supplier experienced a major incident?
STATUS
🟢 CONTROLLED / ACCEPTABLE
Risk is understood, appropriate controls and assurance are in place, and no immediate Board intervention is required.
🟠 DEVELOPING / MONITOR
Some controls or assurance exist, but gaps, dependencies or uncertainty require continued management attention.
🔴 PRIORITY ATTENTION
Material exposure exists, assurance is insufficient, or the supplier presents a significant resilience concern requiring action.
TREND
↑ IMPROVING
Evidence shows the risk position or resilience is strengthening.
→ STABLE
No material change since the previous reporting period.
↓ DECLINING
Evidence indicates deterioration, increased dependency or an emerging concern.
KEY BOARD INDICATORS
Critical Supplier Coverage
Percentage of critical suppliers reviewed within the required period:
__________ %
Critical Suppliers with Current Cyber Assurance
__________ %
Critical Suppliers with AI / Data Usage Assessed
__________ %
Critical Suppliers Included in Incident Response Exercises
__________ %
Critical Suppliers with Tested Continuity / Recovery Arrangements
__________ %
Material Fourth-Party or Concentration Risks Identified
__________
BOARD ATTENTION
What has improved?
What concerns us?
Which supplier relationships require Board-level attention?
What action or decision is required?
FIVE QUESTIONS FOR EVERY BOARD REVIEW
1. Who are our most critical third parties?
Do we know which suppliers our organisation depends on most?
2. What do they have access to?
Do we understand the systems, information and data they can access or process?
3. How are they using AI?
Could our information be processed through public or third-party AI platforms?
4. Where are our concentration risks?
Are multiple critical suppliers dependent on the same underlying providers?
5. Could we continue operating without them?
Have we tested what happens if a critical supplier becomes unavailable?
BOARD ESCALATION TRIGGERS
A third-party risk should normally be escalated when:
- A critical supplier experiences a significant cyber incident.
- Assurance cannot be obtained.
- Material security weaknesses remain unresolved.
- AI usage creates unacceptable data or confidentiality risk.
- A supplier becomes significantly more critical to operations.
- Multiple suppliers become dependent on the same provider.
- Recovery capability is untested or inadequate.
- Contractual security obligations are repeatedly not met.
- The organisation has no realistic alternative if the supplier fails.
DON'T JUST ASSESS THE SUPPLIER. ASSESS THE DEPENDENCY.
A supplier may have strong cybersecurity controls and still create significant risk if your organisation is completely dependent on them.
Boards therefore need visibility into both:
Supplier Risk
How well is the third party managing cyber and AI risk?
and
Dependency Risk
What happens to our organisation if they fail?
The combination determines your true exposure.
THE BOARD VIEW
At each quarterly review, Directors should be able to answer:
Which third parties could materially disrupt our organisation?
What evidence do we have that they are managing cyber and AI risk appropriately?
Where are our greatest dependencies?
Which risks are improving, and which are deteriorating?
What are we doing about the risks that matter most?
A FINAL BOARD PRINCIPLE
You can outsource the service. You cannot outsource accountability for the risk.
Strong third-party governance is not about distrusting suppliers.
It is about building trusted relationships supported by appropriate assurance, transparency and resilience.
CYBERPLANZ | THE BOARDROOM GUIDE TO CYBER & AI GOVERNANCE
Cyber resilience isn't built by technology. It's built by leadership, enabled by governance, and delivered by people.
Helping Boards build secure, resilient and AI-ready organisations.
Your browser does not support viewing this document. Click here to download the document.