How to answer 'how do you manage third-party risk?'
A short, credible answer for the moment a buyer, investor or auditor asks the question - sized for a small operation, not a FTSE compliance function.
"We keep a single live record of every third party we work with, the documents they need to be current on and the review cadence for each one - sized to the risk of the relationship - and we can produce a signed-off evidence pack for any of them on request."
Short, specific, provable. It tells the person asking that you have a system, not a folder.
The supporting bullets
If they push for detail (they will), these are the five things a credible answer covers. In order.
Suppliers, subcontractors and vendors sit in one place with the documents that matter - insurance, ISO or SOC certificates, DPAs, policies, right-to-work and health-and-safety evidence - not scattered across inboxes and shared drives.
Every document has an expiry date. Reminders go to the right contact at the right cadence before it lapses, so nothing quietly falls out of cover on our watch.
Higher-risk third parties (data processors, on-site contractors, regulated services) carry more evidence and shorter review cycles than a low-risk print supplier. We don't pretend a stationery vendor needs a full security review.
When a buyer, insurer or auditor asks how a specific counterparty is set up, we share a curated pack in minutes - branded, current, traceable - rather than a Friday-night email chain.
Onboarding, annual re-review and off-boarding are actual events with owners and timestamps, so we can show not just the current state but a defensible trail of how we got there.
What not to say
Answers that sound reasonable but quietly cost you the deal.
- "We have a spreadsheet." (Tells the buyer you are the single point of failure.)
- "We follow ISO 27001 principles." (Not the question, and buyers know the difference between following and being certified.)
- "Our legal team handles it." (Fine at scale, unbelievable from a ten-person company.)
- "We ask for their SOC 2 at sign-up." (Onboarding is not third-party risk management. What happens in month thirteen?)
Why this matters for a small company
The question is rarely a compliance test. It is a proxy for "will you be a grown-up counterparty in eighteen months?" For an SMB, the honest answer is that you don't need a governance, risk and compliance suite. You need one live record, expiry dates that don't sneak up on you and the ability to hand over evidence without a scramble.
That is exactly the shape Credbase is built for - the layer between an inbox and an audit, for the person doing this work alongside four other jobs.