TechFoundations · Third-Party Risk · NIST CSF 2.0 GV.SC

A third-party risk program, and the register it runs on

Operating model grounded in NIST CSF 2.0 supply-chain governance, built against Anthropic's own compute counterparties from public announcements, SEC filings and reporting. No inside information. Every supplier here is named, because every one of them announced the arrangement itself.


4of 8

Supplier count overstates diversification.

4 of 8 suppliers are simultaneously investors. A supplier who is also on the cap table has different incentives in a dispute, a capacity squeeze, and a renegotiation. Counting them as independent counterparties overstates diversification.

Portfolio findings

Structural, not per-vendor. Each of these is invisible in a supplier-by-supplier view, which is why portfolio-level reporting is a programme capability rather than a dashboard nicety.

Mission Critical tier5 of 8
Supplier is also an investor4 of 8
Supplier runs a competing model effort4 of 8
No locatable security attestation4 of 8
Shares an upstream with another supplier4 of 8

Two honest observations about this data. The distribution is 5 mission critical / 2 high / 1 medium — for a portfolio this small that reflects a scoring model tuned conservatively, not a claim that everything is dangerous. And where a supplier has no locatable attestation, residual equals inherent: an unevidenced supplier is unmeasured, not demonstrably weak. That inversion is deliberate and it is the number most likely to move once real diligence is possible.

The register

Eight compute counterparties, assembled from public announcements, SEC filings and reporting — no inside information. Inherent is scored before controls; residual after publicly evidenced ones. Where a supplier has no locatable attestation, residual equals inherent, because an unevidenced supplier is unmeasured, not demonstrably safe.

IDSupplierTierInherentResidual InvestorOpenFourth-party
ANT-SUP-001Amazon Web ServicesPrimary cloud provider (2023) and primary training partner (2024). Project Rainier.Mission Critical9257investor3Annapurna Labs (Trainium silicon)
ANT-SUP-002Google CloudTPU compute capacity; Vertex AI distribution.Mission Critical8752investor3Broadcom (TPU co-development)
ANT-SUP-003Microsoft AzureCompute purchase; Foundry distribution.Mission Critical8348investor3NVIDIA (GPU supply underlying Azure capacity)
ANT-SUP-004NVIDIAGPU architecture and supply.Mission Critical7060investor3TSMC (foundry — industry-wide dependency)
ANT-SUP-008TeraWulfDirect 20-year data centre lease, Justified Data campus, Hawesville, Kentucky.Mission Critical68682Kentucky grid interconnection (former Century Aluminum smelter load), GPU/accelerator supply chain, TSMC (foundry, via all accelerator architectures)
ANT-SUP-005BroadcomCo-development of next-generation TPUs with Google.High40401
ANT-SUP-006FluidstackNeocloud data centre build-out, Texas and New York; now also owner/developer at Abernathy following the July 2026 JV buyout.High38381Regional power grids (ERCOT, NYISO), GPU supply chain
ANT-SUP-007SpaceXCompute capacity; exploring orbital compute.Medium37371NVIDIA (reported 220,000+ GPUs)

This is the head of the portfolio, and only the head. The tail is Anthropic's published subprocessor list — 20 vendors covering cloud infrastructure, traffic routing, billing, single sign-on, user support across three jurisdictions, fraud and identity, web search and text-to-speech. It carries no assessment here, because no public assessment exists and inventing one would be the defect this instrument argues against. Reconciling the two populations is where a real engagement starts — and three vendors sit in both halves at once, carrying a multi-billion-dollar compute commitment and a data-processing relationship under different instruments.

Generated from the endpoint. This table is built by build_register.py against techfoundations.ai/mcp/tprm, so the page and the server cannot disagree. Until 27 July 2026 they did — the page served a different register entirely, and every count in the packet inherited the discrepancy.

The lifecycle

Each stage traces to a NIST CSF 2.0 subcategory, so the program is auditable against something other than my opinion.

  1. Intake and pre-contract due diligence Diligence proportionate to exposure, performed before the relationship exists. Critical tier requires a business impact analysis reference — tiering asserted without a BIA is a guess with a label. GV.SC-06 · ID.RA-10
  2. Criticality tiering Suppliers known and prioritised by criticality; tier drives both assessment depth and review cadence. GV.SC-04
  3. Contracting Security requirements written into the agreement: annual attestation delivered unasked, bridge letter on request, subprocessor change notice, incident notification window, transition assistance. If refresh isn't contractual it dies with the analyst who set it up. GV.SC-05
  4. Assessment and issue management Attestation reviewed properly — Type I vs II, period gap, TSC scope, system boundary, opinion, CUECs assigned to internal owners, carve-outs chased to the subservice organisation's own report. Findings written as risk statements with a named owner and a date. GV.SC-07
  5. Ongoing monitoring Cadence by tier, plus event-driven triggers: breach, change of control, subprocessor change, certification lapse, qualified opinion. Tracked on report period end, never on date received. GV.SC-07 · GV.SC-09
  6. Incident response Suppliers included in incident planning, response and recovery — impact assessment and post-incident risk treatment as a designed capability, not an improvisation. GV.SC-08
  7. Termination and exit Provisions for what happens after the agreement ends: data return and destruction evidence, access revocation, transition assistance, and a tested cutover where feasible. GV.SC-10

What gets measured

Definitions matter more than the numbers. Each of these is chosen because the obvious alternative hides something.

Coverage, by tier

Aggregate coverage hides the case where the uncovered remainder is the critical tier.

Attestation currency

Keyed on report period end plus bridge letter held — never on date received, which shows green forever.

Assessment cycle time

Long cycle time is what pushes the business to route around the process entirely.

Time to remediation

The only measure of whether findings cause anything to change.

Overdue reassessments

The direct year-two indicator. Count and age, by tier.

Fourth-party coverage

Share of critical vendors whose carve-out subservice orgs were chased to their own report. Rarely measured; often where the exposure is.

Recalibration

Any scoring model encodes somebody's judgement. A different organisation has a different risk appetite, different regulators and different data classes — so the model takes practitioner input rather than hard-coding mine.

Submit

A policy, SOP, control standard or scoring model. Parsed into candidate rules, each traced back to the line of your document that produced it.

See the diff first

"Re-tiers 3 vendors High → Critical, opens 7 findings." Population impact shown before commit — a scoring change that lands silently is a governance failure.

Backtest

Candidate rules run against a held-out set of human-tiered vendors. Precision and recall reported with the direction of the errors.

Weight the asymmetry

Under-tiering a critical vendor costs far more than over-tiering a trivial one. False negatives are reported separately, not averaged into an accuracy figure.

Version and roll back

Every score carries the calibration version that produced it, so a finding from March is interpretable in July.

Keep the boundary

The model drafts risk statements and extracts CUECs. It does not make the risk acceptance decision — a named human does. That boundary is the control.