Galink Logo

Solution

Partners

Resources

About

Log in

Galink the TPRM solution No. 1

"You don’t secure a contract. You secure a relationship."

Sep 4, 2026

A robust contract has never been enough to prevent a supplier relationship from going wrong.


Years spent managing supplier portfolios in demanding environments have convinced me of one thing: what provides protection is not so much the document itself as what happens around it. Who speaks to whom, who makes the decisions, who raises the alarm when things start to go wrong.


Four principles underpin the way I approach this subject.


Properly defining the risk means properly identifying the people involved


The legal team is an essential ally, but it is not enough. Properly defining a risk requires preliminary work on knowledge mapping and power mapping.


In practical terms, this means seeking out information where it is found – amongst those who know – and decisions where they are made – amongst those who take action. Experience on the ground shows that these are not always the people who hold the contract.


Bear in mind that procurement and legal departments can be very knowledgeable. My point is rather that the day-to-day operations of the service provided do not fall within their remit. However, if we want the right answers, we need to identify the right people to speak to.


The corollary is just as important: knowing how to identify uncooperative individuals amongst your contacts.


This may take the form of mistrust or a lack of transparency. Other cases may be more insidious, such as a third party citing their ISO certification to avoid completing a questionnaire.


In such scenarios, the problem is twofold.


Firstly, this reveals a certain lack of operational nuance: an ISO 27001 or other certification is defined by its statement of applicability. It may cover technology but not HR, the parent company but not an acquired product, and sometimes even that of the hosting provider rather than the supplier itself. We regularly see certification scopes that do not include what the client will actually be using.


Secondly, the implications for the relationship: a third party that uses its certificate to fend off any questions sets the tone for the collaboration that will follow.


Building the relationship, and building it early


The interests of the client and the supplier are intertwined. Getting this across requires explanation, and above all, time invested at the right moment.


The start of the relationship is one of the best opportunities to establish the right dynamic. This is when the supplier is at their most open, and when requirements can be set out without this being perceived as a challenge to their authority. Waiting six months to raise these issues means forfeiting this leverage and ultimately negotiating from a less favorable position.


Once the relationship is up and running, I generally recommend meeting at least once a year. This allows us to identify changes in contact persons, re-engage newcomers, and interpret both what is said and what is left unsaid.


The shared objective remains consistently the same: to ensure that processes are properly in place and maintain an acceptable level of risk. I say ‘acceptable’ because, of course, risk will never be zero. This will involve regular audits and penetration tests, the intensity of which should be proportionate to the level of criticality.


All the whilst remaining supportive and constructive, of course.


Making the most of your operational committee


Meeting once a year is good practice. However, it is not enough on its own. The operational committee is a forum that requires preparation.


These two hours can set the tone for the whole year, provided they are run effectively.


Its success cannot be improvised. Three principles underpin those that work well.

  • Set the agenda a month in advance: Everyone prepares their responses. Barring any last-minute developments, there should be no surprises during the meeting. A committee that is only just discovering the topic at hand is a committee that makes no progress.

  • Ensure a consistent group of participants: This point is not within your remit, but it will give you an indication of how the issue of security is handled by your supplier and/or the smoothness of cyber-related issue management. Make sure to invite the experts on a regular basis. The principle remains the same: bring together those who know and those who make decisions around the table.

  • A three-part structure: In the first third of the committee meeting, give the floor to the supplier so they can share their latest business updates. This is where you gauge the mood: staff turnover, internal upheavals, ongoing takeovers, changes in shareholding. These signals do not come through in a questionnaire; they are picked up during the meeting. The second third is spent reviewing materials on screen, assessing the evidence and looking at what’s going on behind the scenes. The final third is dedicated to jointly drawing up the reverse schedule and commitments.


Investing in your allies


Procurement and legal departments aren’t just necessary steps. They are allies.


However, you still need to fulfil your part of the implicit agreement. We ask them to incorporate security at an early stage, within a process they manage and which has its own time constraints. In return, we owe them a certain level of delivery: a clear decision-making framework, deadlines met, and no last-minute vetoes that derail an advanced negotiation.


Without this reciprocity, security becomes the step that procurement learns to bypass.


The time you invest in explaining the need—and in giving them the means to decide for themselves on straightforward cases—is time you will save in the medium term.


Conclusion


Bringing the right people together and collaborating effectively is half the battle. The other half lies in addressing the right issues. We’ll discuss this further in my next column.


In the meantime, if these topics resonate with challenges facing your organisation, we’ll have the opportunity to discuss them on 30 September at 10.00 am with six other supplier risk experts. Free registration.