Content Hub

7 things every organisation should check about its digital suppliers 

  • Blog
  • 02 October
  • 8 mins
  • Lee Adams

Please note our content disclaimer in relation to blog posts.

In a previous article, I wrote about how to become your supplier’s favourite client and why the strongest client–supplier relationships work in both directions. 

But choosing the right supplier is only the beginning. Organisations also need to remain confident that their critical suppliers have the resilience to support them throughout the relationship. 

When organisations select a digital partner, they quite rightly spend considerable time evaluating technical capability, sector experience, proposed solutions, costs and contractual commitments. What sometimes receives less attention is the resilience of the business standing behind the proposal. 

That deserves greater leadership attention because appointing a strategic supplier is not simply about buying a website, platform or piece of software. You may be trusting that organisation with sensitive data, business-critical services, institutional knowledge and a transformation programme expected to deliver value over many years. 

Over more than two decades of building and leading Cantarus, I have seen how much organisations invest in these relationships. The contract value is only one part of that investment. Internal teams contribute months - sometimes years - of discovery, planning, decision-making, content creation, data preparation, implementation and organisational change. 

If a critical supplier can no longer support that work, the loss is not confined to the remaining value of the contract. Projects can stall, accumulated knowledge can disappear, programme momentum can be lost and confidence among colleagues, boards and other stakeholders can be damaged. 

That risk is particularly significant when internal teams are already managing competing priorities and limited capacity. If a supplier becomes unable to deliver, the client cannot necessarily absorb the work internally. The disruption can consume leadership time, delay other priorities and require the organisation to rebuild knowledge and confidence as well as replace a service. 

As the CEO of a business that asks clients to trust us with critical digital services, I believe suppliers should expect this scrutiny. We should be prepared to explain how our businesses are structured, how we manage risk, how we protect client knowledge and what safeguards are in place if circumstances change. 

Trust is not strengthened by avoiding difficult questions; it is strengthened by answering them openly. 

Choosing a supplier is therefore not simply a technology decision. It is a decision about capability, continuity, governance and your organisation’s ability to turn investment into lasting value. 

This does not mean attempting to find a supplier with no risk. Such a business does not exist. It means looking beyond the pitch, asking informed questions and satisfying yourself that the supplier has the foundations to support the relationship you are planning. 

Whether you are appointing a new supplier or reviewing an established relationship, here are seven areas I believe every organisation should consider. 

1. Is the supplier financially resilient?

Financial stability may not be the most exciting part of selecting a digital partner, but it can be one of the most consequential. 

The depth of your due diligence should reflect the importance and expected duration of the relationship. If a supplier will be responsible for a business-critical platform, a substantial transformation programme or a long-term managed service, a basic company search is unlikely to be enough. 

Start with a commercial credit check. Providers such as Dun & Bradstreet (D&B) and Experian can provide credit scores, risk ratings and information about a company’s payment behaviour. These can help identify signs of financial pressure that may not be apparent from a supplier’s website, proposal or public profile. 

That should be considered alongside recent accounts, cash and net-asset position, registered charges, statutory filing history and significant changes in directors or ownership. Companies House provides access to a UK company’s accounts, filing history, directors, people with significant control and registered charges. 

No individual score or filing should determine the decision on its own. Accounts are historical, ratings can change and there may be a credible explanation for a particular result. 

The purpose is not to allow an automated score to make the decision for you. It is to identify potential risks, ask better questions and assess how openly and convincingly the supplier responds. 

Financial resilience is also about more than whether a supplier can continue trading. Consider whether it is investing sufficiently in its people, services and technical capabilities to remain relevant throughout the relationship. A supplier may still exist in five years without necessarily being equipped to support where your organisation needs to go next. 

Good suppliers should not be offended by proportionate financial questions. If an organisation is considering entrusting us with a significant budget and an important part of its operation, I believe it is entirely reasonable for its leaders to understand the health and resilience of our business. 

That accountability works both ways. Suppliers also need confidence that clients have the funding, leadership commitment and internal capacity required to make the programme successful.

2. Do you understand who you are actually appointing?

Technology businesses can operate through groups of parent companies, subsidiaries, regional entities and associated brands. The name on the presentation may not be the legal entity named in your contract. 

Make sure you understand precisely which organisation you are appointing, who owns it, who controls it and where financial and operational responsibility ultimately sits. 

If a supplier belongs to a wider group, do not assume that the parent company’s resources or financial strength automatically support the entity with which you are contracting. If the business has recently been acquired or restructured, understand what has changed and what that could mean for its people, priorities and services. 

Ownership change is not inherently negative. Investment or acquisition can create access to greater resources and expertise. But it can also alter leadership, culture, commercial priorities and the services in which the business intends to invest. 

At Cantarus, we publish our group structure because I believe clients should be able to understand which Cantarus business provides which services and where responsibility sits. 

The important thing is to understand the commercial reality behind the brand and consider whether appropriate contractual protections or guarantees are required. 

3. Will the people you meet be the people delivering the work?

Supplier selection processes can place considerable emphasis on the pitch team. Those individuals may be knowledgeable, credible and genuinely impressive - but will they remain involved once the contract has been signed? 

Understand who will lead the relationship, who will undertake the work and which people are genuinely committed to the proposed programme. Ask whether important roles will be fulfilled by permanent employees, contractors, subcontractors or specialist partners. 

There is nothing inherently wrong with a blended delivery model. External specialists can bring valuable expertise. The issue is whether those dependencies are visible, stable and properly managed. 

You should also consider what would happen if a key person became unavailable. Is knowledge shared and documented? Is there sufficient capacity elsewhere in the team? Could someone appropriately skilled step in without materially disrupting delivery? 

A resilient supplier should not depend on one heroic individual holding everything together. 

The same consideration applies to the client. Successful transformation requires active participation from both sides. A credible supplier should be willing to discuss the internal roles, decision-making capacity and subject-matter expertise the client will need to provide - not simply what its own team will deliver. 

4. Can its clients validate the complete relationship?

Case studies are useful, but they are naturally designed to present successful outcomes. Reference conversations should help you understand what happened between those headline moments. 

Speak to organisations with comparable requirements and complexity. Where possible, include clients whose projects are already live and have progressed into ongoing support, optimisation or further development. 

Do not only ask whether the finished platform was good. Ask whether the proposed team remained involved, whether the supplier was realistic about costs and responsibilities and how it responded when something did not go to plan. 

Did the supplier communicate openly and take ownership? Did it retain knowledge about the organisation? Did the final cost and level of internal effort broadly reflect what had been described at the outset? Has it continued to contribute ideas after the initial implementation—and would the client appoint it again? 

In my experience, the most revealing references are not those in which everything went perfectly. Every substantial digital programme encounters challenges. How a supplier behaves when circumstances become difficult tells you far more about the likely relationship than a flawless presentation ever could. 

Long-term client relationships can also provide evidence of commercial sustainability. They suggest that the supplier is capable not only of winning work, but of maintaining trust, delivering ongoing value and remaining relevant as its clients’ needs change. 

5. Can it protect your organisation and maintain essential services?

A supplier can be financially secure and technically capable but still lack the operational maturity required to support an important service. 

Security, data protection, quality management, insurance, business continuity and disaster recovery should all be considered in proportion to the work involved. 

Independent certification to standards such as ISO 9001 and ISO 27001 can provide evidence that recognised quality and information-security management systems are in place and regularly audited. However, certificates should not replace practical questions and clients should understand the precise scope of a certification rather than simply seeing an accreditation logo and making assumptions about what it covers. 

Ask how incidents are managed, when continuity and recovery arrangements were last tested, how quickly you would be notified of a serious issue and who would lead the response. Understand how access is controlled, how knowledge is documented and how essential services would be maintained during a significant disruption. 

At Cantarus, we expect clients to examine our security, quality, governance and continuity arrangements. That includes understanding the precise scope of our certifications. We make these investments because organisations should not have to rely solely on reassurance from a sales presentation when entrusting a supplier with critical services and information. 

You are not simply checking whether policies exist. You are assessing whether the supplier has the discipline, people and governance to put them into practice.

6. Do you understand the true cost and critical dependencies?

A low initial price does not necessarily mean a lower-cost relationship. 

Understand the likely total cost, not only the initial implementation, but also integrations, licences, hosting, support, upgrades, change requests and eventual transition. An attractively priced proposal can become considerably less attractive if essential costs emerge only after the relationship has begun. 

Commercial transparency is another indicator of supplier quality. A responsible supplier should be clear about what is included, the assumptions underpinning the price, what the client must provide and where future costs may arise. 

You should also understand the people, platforms and partners on which the service depends. 

Is an essential element reliant on one subcontractor or employee? Who controls the hosting environment, domains and repositories? Are important third-party licences held in your name or the supplier’s? What happens if a technology provider changes its product, pricing or commercial strategy? 

In a connected digital ecosystem, a website, CRM, app, community platform, payment service and data-integration layer may all depend on one another. A weakness in one part of that chain can affect the experience delivered through the rest of it. 

The aim is not to remove every dependency. It is to ensure that material dependencies are visible, responsibly managed and reflected in both your continuity planning and commercial decisions.

7. Could another supplier take over if necessary?

The strongest supplier relationships are built with the expectation that they will succeed. They should still be structured so that neither organisation becomes dangerously dependent on the other. 

Before signing a contract, establish who will own and control the code, data, documentation, domains, cloud environments, source-code repositories, administrative credentials and third-party accounts. 

You should also understand the practical consequences of ending the relationship. What are the notice periods? What transition support will be provided? In what format will information be returned? Are there additional exit charges? Could another supplier access everything required to maintain the service? 

Exit planning is not evidence that you expect the partnership to fail. It is responsible governance. 

A supplier that is confident in the quality of its work and relationships should not need to manufacture unnecessary dependency through restricted access, poor documentation, unclear ownership arrangements or contractual and technical barriers that were not made clear at the outset. 

The best protection is not simply a termination clause. It is ensuring throughout the relationship that knowledge is documented, access is appropriately shared and the client retains sufficient control over its own digital estate. 

Due diligence should not end when the contract is signed 

A thorough supplier review protects you at the point of selection, but organisations do not remain static. 

Financial positions fluctuate. Key people move. Businesses are acquired. Operating models evolve. Technology partners change direction. A supplier that was low risk three years ago may present a different profile today. 

Ongoing oversight should therefore reflect the importance of the relationship. A supplier responsible for your core digital platform, hosting, CRM or sensitive data may warrant regular financial and operational reviews. A provider of a low-value, readily replaceable service will require a lighter approach. 

This does not need to become a burdensome annual procurement exercise. Regular strategic conversations can create space to discuss staffing, capacity, security, financial or ownership changes, technology dependencies and future investment. 

That openness benefits both parties. It allows emerging risks to be addressed before they become urgent and helps the supplier plan effectively around the client’s longer-term needs.


Strong partnerships require confidence on both sides

I have always believed that the strongest supplier relationships are built on mutual commitment. 

Clients should invest in helping good suppliers succeed. That means making timely decisions, providing access to the right people, sharing relevant information and treating the supplier as a partner rather than simply a source of capacity. 

In return, suppliers should provide the transparency, resilience and responsible stewardship that justify that trust. 

Due diligence is not about beginning every relationship with suspicion. Nor is it about assuming that the largest supplier will always be the safest choice. Scale does not automatically guarantee stability, responsiveness, cultural fit or quality. 

It is about understanding the risks you are accepting, deciding whether they are proportionate to the importance of the work and making sure appropriate safeguards are in place. 

At Cantarus, we want clients to choose us with their eyes open - not simply because we have delivered a persuasive presentation, but because they have examined our experience, people, governance, security, financial resilience and record of long-term partnership. 

Any supplier asking to become an important part of your organisation should be comfortable with the same level of scrutiny. 

You will rightly examine the technology on which your transformation depends. Apply the same care to the organisation standing behind it. 

When the relationship may shape your organisation for years, that is not excessive caution, it is responsible leadership. 

Related content for digital leaders

Explore our latest articles and webinars for digital leaders.

Loading...