What Procurement, Risk and Compliance Need Before Approving a New Supplier
A practical guide to the evidence, judgements and sequencing required before onboarding a new supplier in a regulated business. After reading, you will know what each function should demand, where approvals commonly break down, and how to run the process without either rubber-stamping or paralysis.
Approving a new supplier in a regulated firm is not a form-filling exercise. Procurement, risk and compliance each need distinct evidence, and they need it in a specific order. Get the sequencing wrong and you either onboard a supplier who cannot withstand scrutiny, or you burn six months on a vendor who was never going to clear the bar. This guide sets out what each function actually needs, what good looks like, and where approvals most often stall.
Key Executive Takeaways
- Procurement needs a defensible commercial case and a clear picture of concentration, substitutability and exit; risk needs evidence the supplier can deliver under stress; compliance needs proof the arrangement meets regulatory obligations end to end.
- Most failed approvals stem from starting due diligence too late, treating the supplier questionnaire as the assessment, or letting the business owner drive scope unchallenged.
- Sequence matters: materiality and criticality assessment first, then targeted due diligence, then contract and controls design, then formal approval. Running these in parallel produces gaps no one owns.
Start with materiality, not the questionnaire
Before any diligence pack goes out, agree what the supplier will actually do, whether the service is material or critical under your framework (and under DORA, PRA SS2/21, or equivalent regimes where relevant), and what data, systems or customer outcomes are touched. This single decision drives everything downstream: the depth of due diligence, contract clauses, board or committee involvement, and regulatory notification.
What goes wrong here: the business owner minimises materiality to speed approval, or procurement accepts the supplier's own classification. Both create problems later, usually when an incident forces a reclassification under pressure.
What procurement needs
Procurement's job is not just price. Before approval, procurement should have:
- A documented commercial rationale, including alternatives considered and why this supplier was selected.
- Concentration analysis: how much of this category, or this fourth-party dependency, already sits with the same provider or infrastructure.
- A substitutability view: if this supplier fails or is exited, what replaces them, over what timeframe, at what cost.
- Financial viability evidence covering at least two years, plus sensitivity to the loss of a major client.
- Clear ownership of the relationship on both sides, including named accountable executives.
Good procurement functions push back when the business says "there is no alternative." There almost always is; the question is cost and time.
What risk needs
Risk is testing whether the supplier can deliver the service reliably, securely and within the firm's risk appetite. The evidence base should include:
- Operational resilience testing: recovery time and recovery point objectives, evidence of tested continuity plans, and dependency mapping including sub-outsourcers.
- Information security assessment proportionate to the data involved: SOC 2 Type II, ISO 27001, penetration test summaries, and specific answers on encryption, access management and incident response.
- Change and incident history: how the supplier has handled real failures, not just their policies.
- Concentration and geographic risk, including where data is processed and stored.
- A scenario-based view: what happens to your service if this supplier suffers a ransomware event, a data breach, or insolvency.
The common failure is accepting certifications as answers. Certifications tell you a process exists. They do not tell you it works for your use case.
What compliance needs
Compliance is confirming the arrangement meets regulatory obligations and that the firm can evidence this to a supervisor. Depending on jurisdiction and service, this typically covers:
- Regulatory classification and any notification or pre-approval requirements (for example, PRA/FCA notification for material outsourcing, DORA registration for ICT third parties).
- Data protection: lawful basis, international transfer mechanisms, DPIA where required, and processor terms that actually reflect the processing.
- Sanctions, financial crime and ABC screening of the supplier, its beneficial owners and key personnel.
- Audit and access rights, including regulator step-in rights, sub-outsourcing controls and termination assistance.
- Conduct and consumer duty implications where the supplier touches customer outcomes.
Good compliance functions insist on seeing the actual contract clauses, not a summary. Standard supplier templates rarely meet regulated-firm requirements without negotiation.
Where approvals break down
Three failure patterns recur. First, parallel workstreams with no integration, so procurement signs commercials before risk has seen the security evidence. Second, the business owner treating the risk and compliance review as an obstacle rather than a co-design exercise, which produces adversarial reviews and rushed sign-offs. Third, no clear decision forum: approvals drift between committees until someone forces a call.
Fix this by naming a single accountable executive for the onboarding, setting a decision date at the start, and requiring all three functions to sign a joint recommendation, not separate memos.
The next decision
Before your next supplier goes to approval, ask one question: if a supervisor asked us tomorrow to walk through how we approved this supplier and what we would do if they failed, could we answer in a single document? If not, the process is not ready, regardless of how far the commercial negotiation has run.
Frequently Asked Questions
How long should new supplier approval realistically take?
For a material or critical supplier in a regulated firm, twelve to twenty weeks is typical from initial scoping to signed contract, assuming the supplier engages promptly. Non-material suppliers can move in four to six. Compressing material approvals below eight weeks usually means something has been skipped.
Who should own the final approval decision?
A named senior executive accountable for the service the supplier supports, not a committee. Committees advise; individuals decide. For critical suppliers, the decision should be recorded at board or executive committee level with the joint recommendation from procurement, risk and compliance attached.
What if the business says the supplier is the only option?
Treat this as a risk finding, not a reason to relax diligence. Sole-source arrangements require stronger exit planning, contractual protections and contingency, not weaker. Document the alternatives considered and why they were rejected.
How do we handle fourth-party risk without endless chains of diligence?
Focus on material sub-outsourcers that support the specific service you are buying. Require the supplier to disclose them, notify you of changes, and flow down key controls. Concentration in shared infrastructure (cloud, payment rails, market data) needs firm-wide tracking, not per-supplier review.
When should we involve the regulator?
Early, where the rules require notification or where the arrangement is genuinely novel. Late or reluctant engagement damages credibility. A short, well-prepared conversation ahead of a material outsourcing is almost always better than a written notification that raises questions the firm has not yet answered.
Frequently asked questions
How long should new supplier approval realistically take?
For a material or critical supplier in a regulated firm, twelve to twenty weeks is typical from initial scoping to signed contract, assuming the supplier engages promptly. Non-material suppliers can move in four to six. Compressing material approvals below eight weeks usually means something has been skipped.
Who should own the final approval decision?
A named senior executive accountable for the service the supplier supports, not a committee. Committees advise; individuals decide. For critical suppliers, the decision should be recorded at board or executive committee level with the joint recommendation from procurement, risk and compliance attached.
What if the business says the supplier is the only option?
Treat this as a risk finding, not a reason to relax diligence. Sole-source arrangements require stronger exit planning, contractual protections and contingency, not weaker. Document the alternatives considered and why they were rejected.
How do we handle fourth-party risk without endless chains of diligence?
Focus on material sub-outsourcers that support the specific service you are buying. Require the supplier to disclose them, notify you of changes, and flow down key controls. Concentration in shared infrastructure (cloud, payment rails, market data) needs firm-wide tracking, not per-supplier review.
When should we involve the regulator?
Early, where the rules require notification or where the arrangement is genuinely novel. Late or reluctant engagement damages credibility. A short, well-prepared conversation ahead of a material outsourcing is almost always better than a written notification that raises questions the firm has not yet answered.
Related guides
How to Build a Credible Operational Resilience Self-Assessment
This guide sets out how to produce an operational resilience self-assessment that stands up to board challenge and supervisory review. After reading it, senior leaders will know how to structure the document, where the evidence typically falls short, and how to demonstrate genuine capability rather than paper compliance.
How to Prepare a Credible SM&CR Statement of Responsibilities Update After a Senior Hire
A practical guide to producing an accurate, defensible Statement of Responsibilities update when a Senior Manager joins or changes role. Readers will finish knowing how to sequence the drafting, capture handovers cleanly, and submit something that stands up to FCA scrutiny.
How to Build a Regulator-Ready Wind-Down Plan That Demonstrates Operational Credibility
This guide sets out how to build a wind-down plan that stands up to regulatory challenge and reflects genuine operational capability. Readers will finish with a clear view of what makes a plan credible, where firms typically fall short, and what to fix first.
How to Structure a Section 166 Skilled Person Review Response
This guide sets out how senior leaders in regulated firms should structure their response to a Section 166 skilled person review, from the moment the requirement notice arrives to the remediation phase. It covers governance, evidence, stakeholder handling, and the judgement calls that determine whether the firm emerges credibly or damaged.
What Regulators Look For in a Submission: A Practical Guide
This guide sets out what regulators actually assess when they receive a submission from a regulated firm, from authorisation applications to skilled person responses and change-in-control filings. After reading, you will know how to prepare submissions that demonstrate genuine compliance, sound judgement, and credible governance.
Where internal confidence may exceed external evidence
Polar Insight helps leadership teams test critical assumptions against stakeholder, market, regulatory, and operational reality before risk compounds.
Explore Stakeholder Proximity