Skip to content

Monitoring

Continuous monitoring: spotting changes before the annual review begins

Continuous monitoring combines contractual information, performance data, security events, evidence and internal changes.

Back to Third-party risk

8 minute read · Content as of 21.07.2026

Monitoring is more than an external cyber score

External ratings can provide signals, but they see neither the contractual scope nor internal dependencies. Reliable monitoring connects objective signals with committed evidence, SLA trends, incidents and changes to the service.

Triggers beat rigid calendars

A change of ownership, new subcontractors, a relocation, a substantial architecture change, repeated SLA breaches or a severe incident should trigger an unscheduled reassessment.

  • evidence with expiry date and owner
  • risk triggers and escalation thresholds
  • open measures and exceptions
  • an annual overall decision per critical relationship

Sources used

Back to Third-party risk