Vendor risk assessment

Vendor risk assessment: what to ask, and what to verify.

A vendor risk assessment establishes what could go wrong because of a third party, how likely it is, and what you are going to do about it — before you sign, and repeatedly afterwards. This page covers scoping an assessment to the risk, the questions worth asking, how to validate the answers rather than file them, how to score consistently, and how to keep the result meaningful once the vendor is onboarded and the assessment starts aging.

Last reviewed

What a vendor risk assessment is for

A decision, not a document. If it cannot change the outcome, it is an audit trail.

A vendor risk assessment exists to support a decision: do we engage this vendor, on what terms, with what data, and under what conditions? Everything in the process that does not serve that decision is administration.

That framing has a sharp consequence for timing. The assessment is worth the most before contract signature, because that is the only moment you have leverage: a vendor who wants your business will answer questions, fix findings and accept contract terms that the same vendor will treat as an imposition six months later. A program that assesses after signing has swapped a decision for a record.

Vendor risk assessment, third-party risk assessment and vendor security assessment are used more or less interchangeably. Where they differ in practice: a security assessment looks only at security controls, while a full third-party assessment also covers resilience, concentration, financial stability, regulatory and data protection exposure, and the fourth parties behind the vendor. Scope it explicitly, because assuming the wider version and running the narrower one is a common way to be surprised.

How to run one run

Seven steps. The first decides how much the other six cost.

  1. Scope by what the vendor will actually touch
    What data, at what volume and sensitivity; what systems, with what level of access; how critical the service is and how quickly it could be replaced; whether they will subcontract. Everything downstream should be proportionate to these answers, not to the contract value.
  2. Gather what already exists before you send anything
    A SOC 2 Type II report, an ISO 27001 certificate with its statement of applicability, a completed SIG or CAIQ, a penetration test summary. Asking a vendor to answer 200 questions you could have read from an existing report is how assessments become slow and adversarial.
  3. Assess from the outside first
    Before the questionnaire goes out, look at what their infrastructure shows: exposed services, certificate hygiene, email authentication, leaked credentials, known vulnerabilities in what they run. It costs nothing from the vendor, it is available on day one, and it tells you which parts of their answers deserve scrutiny.
  4. Ask only what you cannot observe
    Reserve the questionnaire for what is genuinely internal: governance, subcontractor use, data flows and residency, incident history and process, access management, recovery objectives, personnel controls. See SIG and CAIQ for the standard sets.
  5. Validate rather than file
    Read the SOC 2 exceptions and the complementary user entity controls, not just the opinion. Check the ISO certificate’s scope covers the service you are buying. Test claimed answers against what you observed externally. A questionnaire that is received and stored has produced a record, not an assessment.
  6. Score, decide, and write down the decision
    Reach a rated outcome, an owner, and one of four decisions: proceed, proceed with compensating controls, proceed subject to remediation by a date, or decline. Record who accepted any residual risk — a program in which nobody ever accepts risk in writing is a program in which nobody is accountable for it.
  7. Convert findings into contract terms
    Incident notification with a stated deadline, evidence and audit rights, subcontractor approval, data location and return, remediation commitments with dates, and the right to act if monitoring shows deterioration.

What to assess, and how to verify it verify

The domains worth covering for a vendor handling sensitive data or holding system access — and, for each, what evidence is worth more than the answer.

DomainWhat you are trying to establishBetter evidence than a yes
GovernanceSomeone owns security, with authority and budgetNamed role, board reporting line, an audited framework with scope stated
Access managementWho can reach your data, and how that is controlledMFA enforced externally (observable), joiner-mover-leaver evidence, privileged access review records
External exposureWhat their perimeter looks like to an attackerOutside-in assessment — services, certificates, email authentication, known CVEs
Data handlingWhere your data lives, who else touches it, when it is deletedData flow description, subprocessor list, contractual retention and return terms
Incident responseWhether they would detect, contain and tell youA tested plan, notification commitment in the contract, and honest incident history
ResilienceWhether you get the service back, and how fastStated RTO and RPO, tested recovery, dependency and concentration disclosure
Fourth partiesWho they depend on that you now depend onSubprocessor register, and their own third-party program
ComplianceObligations that travel with the dataCertification with the right scope, sector attestations, regulatory history

Using a vendor risk assessment template well

Templates make assessments consistent. They also make them lazy.

A template is worth having: it makes assessments comparable across vendors and across assessors, it stops the scope being renegotiated every time, and it produces something defensible to an examiner. Ours is inside the TPRM policy template, alongside the tiering model and the contract clauses the assessment feeds.

Two failure modes to design against. The first is one template for everything: sending a critical-vendor questionnaire to a low-tier supplier wastes their time and yours, and teaches everyone that the process is bureaucracy. Tier first, then choose the depth. The second is completeness as the goal: a fully populated template with unvalidated answers scores better on an internal metric and worse in reality than a short assessment where three claims were actually checked.

A practical test for any template: for each question, can you say what you would do differently depending on the answer? Questions that fail that test are there to fill a section heading.

Where vendor risk assessment software helps

And the specific thing to check before you buy any of it.

At a handful of vendors, a spreadsheet works. It stops working somewhere between fifty and a few hundred relationships, and the failure is rarely the assessment itself — it is the tracking: who was assessed, when, what was found, what was promised, whether it was done, and what has changed since. Vendor risk assessment software exists to hold that state.

What separates the useful from the merely administrative is whether the platform brings its own evidence. A system that only stores questionnaires has digitized a filing cabinet: the data still originates entirely with the vendor, and it still ages the moment it arrives. A system that also assesses vendors externally — continuously, without their involvement — gives you a second, independent source, which is the only way a claim gets corroborated.

Questions worth asking any provider: where does your data come from, and how is it attributed to the right company? How quickly does a change in a vendor’s infrastructure show up? Can we assess a vendor before they agree to participate? What happens when the vendor disputes a finding? Third-party risk management software goes through the category, and the platform comparison covers how the main vendors — including us — differ.

Every assessment starts aging immediately

The most accurate vendor risk assessment you will ever run describes one day. The vendor then migrates a system, exposes a service during a busy release, lets a certificate lapse, acquires a company with a weaker estate, or gets breached — and none of that reaches you through the assessment process, because that process next runs in eleven months. Assessment establishes the baseline. Continuous monitoring is what tells you the baseline stopped being true, and the two are not substitutes for each other.

Assessment questions.

What is a vendor risk assessment?
A structured evaluation of the risk a third party introduces — across security, data handling, resilience, compliance and their own dependencies — used to decide whether to engage them, on what terms, and with what safeguards.
What is the difference between a vendor risk assessment and a security questionnaire?
The questionnaire is one input to the assessment. The assessment is the whole process: scoping, gathering existing evidence, external verification, the questionnaire, validation, scoring and a recorded decision.
When should a vendor risk assessment be done?
Before contract signature, when you still have leverage — then on a cadence set by the vendor’s tier, and again whenever something triggers it: a breach, an acquisition, a material change of service, or a deterioration in external monitoring.
How long should a vendor risk assessment take?
Proportionate to tier. A low-risk vendor should be minutes of screening. A critical vendor with production access warrants weeks, most of which is validating evidence rather than waiting for a form to come back — which is why gathering existing reports and assessing externally first shortens the whole thing.
Can you assess a vendor that will not respond?
Partly, and usefully. External assessment works from public evidence — exposed services, certificates, email authentication, leaked credentials, technology in use — and needs no cooperation. It cannot tell you about governance or subcontractors, but it does tell you whether the perimeter matches the claims.

Assess one vendor before they answer a thing.

Book a 30-minute call, name a vendor, and we will show you what their external posture looks like — the evidence that tells you which of their answers to press on.