
When a Supplier Refuses to Be Assessed
"We're too busy."
"We don't complete customer questionnaires."
"We've already done this for someone else."
"Our legal team won't allow it."
Or sometimes, nothing at all. Just silence, and a request that quietly disappears into an inbox never to be seen again.
If you have spent any time in third-party risk management, you will know this moment well. You send a reasonable request for a supplier to complete a risk assessment, and instead of a response you get resistance, delay, or the kind of quiet defiance that makes you wonder whether the email even arrived. It has a familiar feel to it, almost like being back in the school yard, facing down the kid who knows nobody is going to stop them. Not because they are malicious. Because they know they have the leverage, and they are fairly confident nothing will happen if they simply refuse to play along.
Maybe they are the only provider capable of delivering a service your business depends on. Maybe switching to an alternative would take the better part of a year and cost more than anyone wants to admit. Maybe the relationship predates the current risk team by a decade, and nobody wants to be the one who rocks the boat. Whatever the reason, the supplier senses that the balance of power sits with them, and they act accordingly. Often, frustratingly, they are right to.
The Real Problem Isn't the Questionnaire
It is tempting to treat this as a compliance problem. Get the form filled in, tick the box, move on. But the unanswered assessment is really just a symptom of something more uncomfortable. What it actually reveals is that your organisation has a critical dependency it cannot see clearly into.
Think about what you genuinely know, right now, about that supplier. Could they keep operating through a serious cyber incident? Would they tell you quickly if something went wrong, or would you find out from a news headline? Are they financially sound, or one bad quarter away from real trouble? Do they have a business continuity plan that has actually been tested, or one that exists mainly to satisfy an auditor? If they failed tomorrow, would your operations feel it immediately, or would you have time to adjust?
When you cannot answer these questions with any confidence, you are not managing risk. You are making assumptions and hoping they hold. And assumptions have an unfortunate habit of falling apart at exactly the wrong moment, whether that is a regulatory review, an audit, or a genuine operational incident where everyone suddenly wants to know why nobody flagged this earlier.
The Stick Approach
The instinctive response for a lot of organisations is pressure. Suspend onboarding. Escalate to procurement. Bring in legal. Threaten to walk away from the contract entirely.
There are situations where this is exactly the right call. If you are bringing on a new supplier and they will not complete reasonable due diligence before the relationship even begins, that tells you something important, and it is entirely fair to decline to move forward. For existing suppliers, many contracts already contain obligations around participating in ongoing risk reviews, and it is reasonable to hold people to what they agreed to.
But the stick has real limits, and it is worth being honest about them. If the supplier delivers something genuinely unique, or something your business cannot easily do without, threatening them rarely gets you what you want. More often it slows things down further, or turns a manageable relationship into an adversarial one that makes every future conversation harder. You cannot bully your way to trust, and trust is ultimately what you are trying to build here, not just a completed form.
The Carrot Approach
A more useful way in is to show the supplier that the assessment is not something being done to them, but something that can genuinely help them too. This starts with how you frame the conversation. An audit puts people on the defensive. An opportunity to strengthen the relationship tends to open doors instead.
Frame it around what is actually in it for them. The process can surface operational weaknesses before those weaknesses turn into incidents that damage their reputation as much as yours. It gives them a chance to demonstrate strong governance, not just to you but to every other customer asking similar questions. Good evidence, once produced, can be reused across multiple customer relationships instead of being rebuilt from scratch every time someone new asks. And over time, a supplier who consistently shows up well in these conversations builds a level of confidence with you that translates into a stronger, longer relationship rather than a transactional one.
Once a supplier understands that the goal is to improve the resilience of what they deliver rather than to catch them doing something wrong, the whole tone of the conversation tends to shift. People engage differently when they believe you are actually on their side. Trust becomes the outcome you are working toward, with compliance simply following along behind it.
When Neither Works
Sometimes, despite your best efforts on both fronts, the supplier still refuses. This is the point where mature third-party risk management stops chasing the questionnaire and starts asking better questions instead.
How critical is this supplier really, once you strip away assumption and look at the actual dependency? What business services rely on them, and how directly? Is there a realistic alternative, even if it is not an easy one? What contractual leverage do you actually hold, as opposed to what you assume you hold? Could you get meaningful assurance another way, through independent certifications, third-party reports, or ongoing monitoring rather than a self-reported form? And ultimately, is this a level of risk your business is genuinely willing to accept, with eyes open?
The conversation stops being "why won't they complete the assessment" and becomes "what does this refusal actually mean for our operational resilience." That second question is the one worth spending your time on, because it leads somewhere useful.
Start With Where
Every supplier relationship carries a different balance of influence, and pretending otherwise rarely helps anyone. The less leverage you have with a given supplier, the more it matters that you understand precisely where your business depends on them and how deeply that dependency runs. Because when a critical supplier digs in and refuses to engage, the real danger was never the missing form.
The real danger is discovering, usually at the worst possible moment, that you had no alternative and no plan. Understanding your own dependencies before you need to is what gives you options when a supplier decides to play the school yard bully. And in this line of work, options will always serve you better than arguments.
