What a security review is trying to establish
A security review asks a single practical question: if we let this supplier hold our data or reach into our systems, what could go wrong, how likely is it, and could we live with it. It is a risk assessment, not an examination with a pass mark, and understanding that changes how it should be answered. Reviewers expect to find gaps in every supplier they assess. What they are looking for is whether the supplier knows where its gaps are.
The review usually sits alongside legal review and data protection review inside a procurement process rather than after them. Treating the three as sequential is one of the most common and most avoidable causes of a slipped close date, because each of them is queue-driven and they can generally run at the same time.
