Knowledge Centre
Cyber Security GuidesChecklist

Supplier Access Review

15 minutes to completeEvergreen guide — kept up to date

IT providers, software vendors, accountants, marketing agencies and contractors often hold access to business systems long after the work that justified it has finished. A supplier access review lists who can reach your systems, confirms whether they still need to, and checks that the access which remains is protected and logged.

Attackers increasingly reach businesses through their suppliers, because one compromised provider account can open doors into many customers at once. You cannot control a supplier's security, but you can control what their accounts can reach in your systems.

Step 1: List everyone with access

Go wider than the obvious IT provider. Include anyone who can sign in to, administer or remotely connect to something your business relies upon:

  • Managed IT provider or IT contractor
  • Website developer or hosting company
  • Accountant or bookkeeper (accounting software, payroll, banking)
  • Marketing agency (website, social media, email platform, analytics)
  • Software vendors with remote-support access
  • Telephone and printer/copier suppliers
  • CCTV, alarm and door-access maintainers
  • Former contractors and freelancers

Step 2: Record what each supplier can reach

For each supplier, record the systems they can access, the level of access (user or administrator), the business reason, who approved it and when it was last used.

SupplierSystemAccess LevelStill Needed?Last Used

Step 3: Remove what is no longer needed

  • Accounts for suppliers you no longer work with have been disabled or removed.
  • Access granted for a one-off project has been removed now the project is finished.
  • Administrator rights have been reduced to user rights where administration is no longer required.
  • Shared passwords known to former suppliers have been changed.
  • Remote-access tools installed by previous providers have been uninstalled.

The most dangerous account is the one nobody remembers: a former supplier's administrator login that still works. Removal, not monitoring, is the fix.

Step 4: Protect the access that remains

  • Each supplier uses named accounts for their staff, not one shared login.
  • Multi-factor authentication is enforced on all supplier accounts.
  • Access follows least privilege — enough to do the job and no more.
  • Administrative access is time-limited or activated on request where the system supports it.
  • Supplier accounts are clearly identifiable (named or tagged as external).

Step 5: Log and document

  • Sign-in and administrative activity by supplier accounts is logged.
  • Remote-management and remote-support tools in use are documented.
  • Contracts state how the supplier protects their access to your systems.
  • Contracts require the supplier to tell you about a security incident on their side.
  • You know how access will be handed over or removed if you change supplier.

Step 6: Repeat on a schedule

  • The review is repeated at least twice a year.
  • It is triggered immediately when a supplier relationship ends.
  • It is triggered when a supplier reports a security incident.
  • One named person owns the review and its follow-up actions.

Goes hand in hand with resilience

Supplier access is one part of the wider resilience picture — incident notification, backups and continuity are covered in our Cyber Resilience Readiness Guide.

Cyber Resilience Readiness Guide

Plain-English Takeaway

Suppliers accumulate access; businesses rarely take it back. List who can reach your systems, remove what is no longer needed, protect what remains with named accounts and MFA, and repeat the review on a schedule.

Downloadable guide

Download the Supplier Access Review Checklist

A one-page printable checklist and access register template for reviewing third-party access to your systems.

Download PDF

Free download. No email address required.

Related Knowledge Centre resources

Cyber Resilience Readiness Guide

Review your critical systems, IT suppliers, incident response, backups and business-continuity arrangements.

View guide

Employee Leaver Checklist

Close accounts, recover devices and remove access when someone leaves.

Coming Soon

Cyber Essentials Readiness Checklist

Work through the key controls to review before applying for Cyber Essentials.

View guide

DMARC: Three Questions to Ask Your IT Provider

Check whether your business email domain is protected against spoofing and impersonation.

Coming Soon

Still unsure what applies to your business?

Ask the IT Club Advisor about Microsoft 365, browsers, cyber security, productivity or any everyday technology problem.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.