Vendor risk assessment: what to ask, and what to verify.
A vendor risk assessment establishes what could go wrong because of a third party, how likely it is, and what you are going to do about it — before you sign, and repeatedly afterwards. This page covers scoping an assessment to the risk, the questions worth asking, how to validate the answers rather than file them, how to score consistently, and how to keep the result meaningful once the vendor is onboarded and the assessment starts aging.
Last reviewed
What a vendor risk assessment is for
A decision, not a document. If it cannot change the outcome, it is an audit trail.
A vendor risk assessment exists to support a decision: do we engage this vendor, on what terms, with what data, and under what conditions? Everything in the process that does not serve that decision is administration.
That framing has a sharp consequence for timing. The assessment is worth the most before contract signature, because that is the only moment you have leverage: a vendor who wants your business will answer questions, fix findings and accept contract terms that the same vendor will treat as an imposition six months later. A program that assesses after signing has swapped a decision for a record.
Vendor risk assessment, third-party risk assessment and vendor security assessment are used more or less interchangeably. Where they differ in practice: a security assessment looks only at security controls, while a full third-party assessment also covers resilience, concentration, financial stability, regulatory and data protection exposure, and the fourth parties behind the vendor. Scope it explicitly, because assuming the wider version and running the narrower one is a common way to be surprised.
How to run one run
Seven steps. The first decides how much the other six cost.
- Scope by what the vendor will actually touchWhat data, at what volume and sensitivity; what systems, with what level of access; how critical the service is and how quickly it could be replaced; whether they will subcontract. Everything downstream should be proportionate to these answers, not to the contract value.
- Gather what already exists before you send anythingA SOC 2 Type II report, an ISO 27001 certificate with its statement of applicability, a completed SIG or CAIQ, a penetration test summary. Asking a vendor to answer 200 questions you could have read from an existing report is how assessments become slow and adversarial.
- Assess from the outside firstBefore the questionnaire goes out, look at what their infrastructure shows: exposed services, certificate hygiene, email authentication, leaked credentials, known vulnerabilities in what they run. It costs nothing from the vendor, it is available on day one, and it tells you which parts of their answers deserve scrutiny.
- Ask only what you cannot observeReserve the questionnaire for what is genuinely internal: governance, subcontractor use, data flows and residency, incident history and process, access management, recovery objectives, personnel controls. See SIG and CAIQ for the standard sets.
- Validate rather than fileRead the SOC 2 exceptions and the complementary user entity controls, not just the opinion. Check the ISO certificate’s scope covers the service you are buying. Test claimed answers against what you observed externally. A questionnaire that is received and stored has produced a record, not an assessment.
- Score, decide, and write down the decisionReach a rated outcome, an owner, and one of four decisions: proceed, proceed with compensating controls, proceed subject to remediation by a date, or decline. Record who accepted any residual risk — a program in which nobody ever accepts risk in writing is a program in which nobody is accountable for it.
- Convert findings into contract termsIncident notification with a stated deadline, evidence and audit rights, subcontractor approval, data location and return, remediation commitments with dates, and the right to act if monitoring shows deterioration.
What to assess, and how to verify it verify
The domains worth covering for a vendor handling sensitive data or holding system access — and, for each, what evidence is worth more than the answer.
| Domain | What you are trying to establish | Better evidence than a yes |
|---|---|---|
| Governance | Someone owns security, with authority and budget | Named role, board reporting line, an audited framework with scope stated |
| Access management | Who can reach your data, and how that is controlled | MFA enforced externally (observable), joiner-mover-leaver evidence, privileged access review records |
| External exposure | What their perimeter looks like to an attacker | Outside-in assessment — services, certificates, email authentication, known CVEs |
| Data handling | Where your data lives, who else touches it, when it is deleted | Data flow description, subprocessor list, contractual retention and return terms |
| Incident response | Whether they would detect, contain and tell you | A tested plan, notification commitment in the contract, and honest incident history |
| Resilience | Whether you get the service back, and how fast | Stated RTO and RPO, tested recovery, dependency and concentration disclosure |
| Fourth parties | Who they depend on that you now depend on | Subprocessor register, and their own third-party program |
| Compliance | Obligations that travel with the data | Certification with the right scope, sector attestations, regulatory history |
Using a vendor risk assessment template well
Templates make assessments consistent. They also make them lazy.
A template is worth having: it makes assessments comparable across vendors and across assessors, it stops the scope being renegotiated every time, and it produces something defensible to an examiner. Ours is inside the TPRM policy template, alongside the tiering model and the contract clauses the assessment feeds.
Two failure modes to design against. The first is one template for everything: sending a critical-vendor questionnaire to a low-tier supplier wastes their time and yours, and teaches everyone that the process is bureaucracy. Tier first, then choose the depth. The second is completeness as the goal: a fully populated template with unvalidated answers scores better on an internal metric and worse in reality than a short assessment where three claims were actually checked.
A practical test for any template: for each question, can you say what you would do differently depending on the answer? Questions that fail that test are there to fill a section heading.
Where vendor risk assessment software helps
And the specific thing to check before you buy any of it.
At a handful of vendors, a spreadsheet works. It stops working somewhere between fifty and a few hundred relationships, and the failure is rarely the assessment itself — it is the tracking: who was assessed, when, what was found, what was promised, whether it was done, and what has changed since. Vendor risk assessment software exists to hold that state.
What separates the useful from the merely administrative is whether the platform brings its own evidence. A system that only stores questionnaires has digitized a filing cabinet: the data still originates entirely with the vendor, and it still ages the moment it arrives. A system that also assesses vendors externally — continuously, without their involvement — gives you a second, independent source, which is the only way a claim gets corroborated.
Questions worth asking any provider: where does your data come from, and how is it attributed to the right company? How quickly does a change in a vendor’s infrastructure show up? Can we assess a vendor before they agree to participate? What happens when the vendor disputes a finding? Third-party risk management software goes through the category, and the platform comparison covers how the main vendors — including us — differ.
Every assessment starts aging immediately
Assessment questions.
What is a vendor risk assessment?
What is the difference between a vendor risk assessment and a security questionnaire?
When should a vendor risk assessment be done?
How long should a vendor risk assessment take?
Can you assess a vendor that will not respond?
Related reading.
Assess one vendor before they answer a thing.
Book a 30-minute call, name a vendor, and we will show you what their external posture looks like — the evidence that tells you which of their answers to press on.