Free Template
This Vendor Risk Assessment Template helps you evaluate a third-party supplier before you sign, and re-evaluate them on a regular cadence afterward. It works two ways: send the questionnaire to the vendor to complete, or complete it yourself using evidence the vendor provides (security documentation, certifications, contracts, and public disclosures).
Work through it in three steps:
Rules of thumb: a blank or "we will provide later" answer scores 0 until evidence arrives. Any single question scoring 0 in a critical domain (Information Security, Data Protection, or Incident Response) should be flagged regardless of the overall average. Keep a dated copy of every completed assessment so you can show how the vendor's risk posture changed over time.
Complete this section first. It frames the rest of the assessment and determines how strictly you should weigh the scores.
| Field | Detail |
|---|---|
| Vendor (legal entity) name | [Vendor legal name] |
| Trading / product name | [Product or service name] |
| Website | [https://vendor.example] |
| Service / product description | [What the vendor provides and how you use it] |
| Internal business owner | [Name, role, department] |
| Vendor primary contact | [Name, role, email] |
| Vendor security / compliance contact | [Name, email, or security@ address] |
| Contract / renewal date | [Start date] / [Renewal or notice date] |
| Annual spend | [Currency and amount] |
| Data types accessed or processed | [e.g. customer PII, employee data, payment/cardholder data, health data, credentials, source code, financial records, none] |
| Data classification (highest level touched) | [Public / Internal / Confidential / Restricted] |
| Approx. volume of records | [e.g. < 1k, 1k-100k, 100k-1M, > 1M] |
| Hosting / data residency | [Cloud provider(s), regions, countries where data is stored] |
| Integration method | [API, SSO/SAML, SFTP, direct DB, on-prem agent, manual upload, etc.] |
| Access level to your systems | [None / Read-only / Read-write / Admin / Network access] |
| Fourth parties / subprocessors involved | [Key subprocessors, or "see subprocessor list"] |
| Business criticality | [Low / Medium / High / Mission-critical] - would an outage stop a core business process? |
| Replaceability | [Easily replaced / Moderate switching cost / Hard to replace / Single source] |
| Assessment date | [YYYY-MM-DD] |
| Assessor | [Name, role] |
| Assessment type | [New onboarding / Annual review / Triggered re-review / Offboarding] |
Score every question from 0 to 3 based on the evidence provided, not on verbal assurances. Use the Notes column to record what evidence you reviewed (document name, date, version) and any gaps.
| Score | Rating | What it means |
|---|---|---|
| 0 | Missing | No control exists, no evidence provided, or the vendor declined to answer. The risk is unmanaged. |
| 1 | Partial | An informal, undocumented, or incomplete control exists. Evidence is weak, outdated, or applies only to part of the service. |
| 2 | Adequate | A documented control exists and is followed in practice. Evidence is current and covers the relevant scope, with minor gaps. |
| 3 | Strong | A mature, documented, independently verified control that is monitored and improved over time. Evidence is recent, in-scope, and third-party validated where relevant. |
N/A handling: if a question genuinely does not apply (for example, payment card questions for a vendor that never touches cardholder data), mark it N/A in the Notes and exclude it from both the total and the count of scored questions so the average stays accurate.
Covers how the vendor governs security, manages identities, and controls who can reach your data.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Is there a documented information security policy, approved by leadership and reviewed at least annually? | Policy document with version, approval, and review date | [ ] | [ ] | [ ] |
| Is there a named individual or team accountable for security (e.g. CISO or security lead)? | Org chart or role description; named contact | [ ] | [ ] | [ ] |
| Is multi-factor authentication enforced for all employee and administrator access to systems holding customer data? | MFA policy; screenshot or config attestation | [ ] | [ ] | [ ] |
| Is access granted on a least-privilege, role-based basis, and reviewed at least quarterly? | Access control policy; sample access review log | [ ] | [ ] | [ ] |
| Is privileged/admin access logged, restricted, and separated from standard accounts? | Privileged access policy; logging evidence | [ ] | [ ] | [ ] |
| Are joiner/mover/leaver processes in place so access is revoked promptly (within [X] hours/days) on termination? | Offboarding procedure; deprovisioning SLA | [ ] | [ ] | [ ] |
| Are employees screened (background checks) and given security awareness training at hire and annually? | HR/screening policy; training completion records | [ ] | [ ] | [ ] |
| Are passwords/secrets managed with a vault and rotation policy, with no shared credentials? | Secrets management policy; tooling name | [ ] | [ ] | [ ] |
| Are security events centrally logged and monitored, with alerting on suspicious activity? | SIEM/logging description; retention period | [ ] | [ ] | [ ] |
| Will the vendor support SSO/SAML or SCIM so we can manage our own users' access centrally? | SSO/SCIM documentation | [ ] | [ ] | [ ] |
Covers GDPR/DPA obligations, lawful processing, data subject rights, international transfers, and the chain of subprocessors.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Will the vendor sign a Data Processing Agreement (DPA) with standard processor obligations? | Signed or template DPA | [ ] | [ ] | [ ] |
| Does the DPA clearly state the vendor acts only on documented instructions and will not use data for its own purposes (e.g. model training, resale)? | DPA processing clauses | [ ] | [ ] | [ ] |
| Is there a current, maintained list of subprocessors, with advance notice of changes and a right to object? | Subprocessor list; change-notification clause | [ ] | [ ] | [ ] |
| Are flow-down obligations imposed on subprocessors equivalent to those the vendor owes us? | Subprocessor agreement terms or attestation | [ ] | [ ] | [ ] |
| Where is personal data stored and processed, and are international transfers covered by a valid mechanism (SCCs, adequacy, UK IDTA)? | Data residency statement; transfer mechanism docs | [ ] | [ ] | [ ] |
| Can the vendor support data subject rights (access, erasure, rectification, portability) within statutory timeframes? | DSR procedure; response SLA | [ ] | [ ] | [ ] |
| Are documented data retention and secure deletion schedules in place, and is data returned/destroyed on contract termination? | Retention policy; deletion/return clause | [ ] | [ ] | [ ] |
| Is data minimization applied so only the data necessary for the service is collected and accessed? | Data inventory or processing description | [ ] | [ ] | [ ] |
| Has a Data Protection Impact Assessment (DPIA) been completed where high-risk processing applies? | DPIA or confirmation of applicability | [ ] | [ ] | [ ] |
| Is there a named Data Protection Officer or privacy contact, and a published privacy notice? | DPO/contact details; privacy notice URL | [ ] | [ ] | [ ] |
Covers the vendor's ability to keep the service running and to recover from disruption without losing your data.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Is there a documented Business Continuity Plan (BCP) covering the service we rely on? | BCP document with last review date | [ ] | [ ] | [ ] |
| Is there a documented Disaster Recovery (DR) plan with defined RTO and RPO? | DR plan; stated RTO/RPO values | [ ] | [ ] | [ ] |
| Are BCP/DR plans tested at least annually, with results documented and gaps remediated? | Most recent test report or summary | [ ] | [ ] | [ ] |
| Are backups taken on a defined schedule, encrypted, stored separately, and restore-tested? | Backup policy; last successful restore test | [ ] | [ ] | [ ] |
| Is the service architected for high availability (redundancy, multi-zone/region failover)? | Architecture summary or uptime design doc | [ ] | [ ] | [ ] |
| Is there a published uptime SLA, and is historical availability reported (e.g. status page)? | SLA terms; status page URL or uptime history | [ ] | [ ] | [ ] |
| Are there documented dependencies on critical fourth parties (e.g. cloud, CDN, payment), and contingency for their failure? | Dependency map; contingency notes | [ ] | [ ] | [ ] |
| Is there a defined process and timeframe for exit / data export so we are not locked in? | Exit plan; supported export formats | [ ] | [ ] | [ ] |
Covers independent attestations and certifications that validate the vendor's controls, and their regulatory posture.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Does the vendor hold a current SOC 2 Type II report covering the relevant trust service criteria? | SOC 2 Type II report (within 12 months); bridge letter if needed | [ ] | [ ] | [ ] |
| Is the vendor certified to ISO/IEC 27001, and does the certificate scope include the service we use? | ISO 27001 certificate; Statement of Applicability scope | [ ] | [ ] | [ ] |
| Have you reviewed any exceptions/qualifications in the audit report and assessed their impact? | Exceptions section of SOC 2; vendor response | [ ] | [ ] | [ ] |
| If payment card data is in scope, is the vendor PCI DSS compliant (with current AOC)? | PCI Attestation of Compliance | [ ] | [ ] | [ ] |
| If health data is in scope, can the vendor meet HIPAA / equivalent obligations and sign a BAA? | HIPAA attestation; BAA template | [ ] | [ ] | [ ] |
| Does the vendor hold other relevant certifications (e.g. Cyber Essentials Plus, ISO 27017/27018, FedRAMP, HITRUST)? | Relevant certificates | [ ] | [ ] | [ ] |
| Are certifications kept current, with a clear renewal/surveillance schedule? | Certificate dates; renewal confirmation | [ ] | [ ] | [ ] |
| Can the vendor demonstrate compliance with sector or regional regulations applicable to us (e.g. GDPR, UK DPA, CCPA, DORA, NIS2)? | Compliance statement or mapping | [ ] | [ ] | [ ] |
Covers how the product is built, hosted, tested, and hardened against attack.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Is data encrypted in transit (TLS 1.2+) and at rest (e.g. AES-256), including backups? | Encryption standards statement; cipher/config evidence | [ ] | [ ] | [ ] |
| Are independent penetration tests performed at least annually, with findings remediated? | Most recent pen test summary; remediation status | [ ] | [ ] | [ ] |
| Is vulnerability scanning run regularly, with defined SLAs for patching by severity? | Vulnerability management policy; patch SLA | [ ] | [ ] | [ ] |
| Is a secure software development lifecycle followed (code review, dependency scanning, separate environments)? | SDLC/SSDLC description | [ ] | [ ] | [ ] |
| Are production, staging, and test environments separated, with no real customer data in non-production? | Environment segregation statement | [ ] | [ ] | [ ] |
| Is customer data logically or physically segregated between tenants in multi-tenant systems? | Tenancy/isolation architecture | [ ] | [ ] | [ ] |
| Are network controls in place (firewalls, segmentation, WAF, DDoS protection)? | Network security overview | [ ] | [ ] | [ ] |
| Is there a public vulnerability disclosure or bug bounty channel, and a hardened API (authentication, rate limiting)? | Disclosure policy URL; API security docs | [ ] | [ ] | [ ] |
| Is change management documented so production changes are reviewed, approved, and reversible? | Change management policy | [ ] | [ ] | [ ] |
| Are endpoints/servers protected (EDR/anti-malware, hardening baselines, asset inventory)? | Endpoint security policy; tooling names | [ ] | [ ] | [ ] |
Covers how the vendor detects, responds to, and notifies you about security incidents and breaches.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Is there a documented incident response plan with defined roles, severity levels, and escalation paths? | IR plan with last review date | [ ] | [ ] | [ ] |
| Is the contractual breach-notification timeframe defined (e.g. notify us within [24/48/72] hours of discovery)? | Contract/DPA breach clause | [ ] | [ ] | [ ] |
| Does the plan cover regulator and data-subject notification obligations (e.g. 72-hour GDPR reporting)? | IR plan notification section | [ ] | [ ] | [ ] |
| Is the incident response plan tested or exercised (e.g. tabletop) at least annually? | Exercise records or summary | [ ] | [ ] | [ ] |
| Are post-incident reviews conducted with documented root cause and corrective actions? | Sample post-incident report (redacted) | [ ] | [ ] | [ ] |
| Has the vendor disclosed any security incidents or breaches in the last 24 months, and how were they handled? | Incident history statement; public disclosures | [ ] | [ ] | [ ] |
| Is there a 24/7 monitoring and on-call capability to detect and respond to incidents out of hours? | SOC/on-call description; coverage hours | [ ] | [ ] | [ ] |
| Is there a single, monitored security contact channel for us to report and track incidents? | Named contact; ticketing/SLA details | [ ] | [ ] | [ ] |
Covers whether the vendor is likely to remain a viable, well-run business for the life of the contract.
| Question | Evidence required | Response | Score (0-3) | Notes |
|---|---|---|---|---|
| Is the vendor financially stable (profitable or adequately funded), with no signs of distress? | Financial statements, credit report, or funding history | [ ] | [ ] | [ ] |
| How long has the vendor operated, and how large/established is its customer base? | Company background; reference customers | [ ] | [ ] | [ ] |
| Does the vendor carry adequate insurance (cyber liability, professional indemnity, general liability)? | Certificates of insurance with coverage limits | [ ] | [ ] | [ ] |
| Are there any material legal, regulatory, or sanctions issues affecting the vendor? | Litigation/sanctions check; vendor attestation | [ ] | [ ] | [ ] |
| Can the vendor provide recent, relevant customer references? | 2-3 reference contacts or case studies | [ ] | [ ] | [ ] |
| Is there concentration risk (we are a very large/small share of revenue, or they depend on one investor/partner)? | Vendor disclosure; analyst notes | [ ] | [ ] | [ ] |
| Is there continuity protection if the vendor fails (e.g. source code or data escrow, transition assistance)? | Escrow agreement or exit support clause | [ ] | [ ] | [ ] |
| Does the vendor manage its own supply chain / fourth-party risk with a documented program? | Vendor risk management policy | [ ] | [ ] | [ ] |
Total the scores per domain, then divide by the number of questions actually scored (excluding any marked N/A) to get the domain average. Record both the total and the average so you can see which domains drag the vendor down even when the overall picture looks acceptable.
| Domain | Questions scored | Total score | Max possible | Average (0-3) |
|---|---|---|---|---|
| 1. Information Security and Access Control | [ /10] | [ ] | 30 | [ ] |
| 2. Data Protection and Privacy | [ /10] | [ ] | 30 | [ ] |
| 3. Business Continuity and Resilience | [ /8] | [ ] | 24 | [ ] |
| 4. Compliance and Certifications | [ /8] | [ ] | 24 | [ ] |
| 5. Application and Infrastructure Security | [ /10] | [ ] | 30 | [ ] |
| 6. Incident Response | [ /8] | [ ] | 24 | [ ] |
| 7. Financial and Operational Stability | [ /8] | [ ] | 24 | [ ] |
| Overall | [ /62] | [ ] | 186 | [ ] |
Use the overall average score (total score divided by number of questions scored) to assign a risk tier. Then apply the override rules below, because a single critical gap can outweigh a healthy average.
| Overall average | Risk tier | Interpretation | Recommended action | Review cadence |
|---|---|---|---|---|
| 2.5 - 3.0 | Low | Mature, well-evidenced controls across all domains. | Approve. Standard contractual terms. | Annual |
| 2.0 - 2.49 | Medium | Generally sound with some documented gaps. | Approve with a remediation plan for the lowest-scoring items. | Every 6-12 months |
| 1.0 - 1.99 | High | Significant gaps or weak/missing evidence in important areas. | Conditional approval only. Require remediation milestones and added contract safeguards before or shortly after signing. | Quarterly until remediated |
| 0 - 0.99 | Critical | Controls are largely missing or unverifiable. | Do not proceed without executive sign-off and a formal risk acceptance, or reject the vendor. | Monthly / before any go-live |
Override rules (apply after calculating the average):
Summarize the outcome, list the gaps that must be closed, and capture approval. Re-run this assessment on the cadence set by the risk tier, or sooner if the vendor's scope, data access, or security posture materially changes.
| Field | Detail |
|---|---|
| Calculated risk tier | [Low / Medium / High / Critical] |
| Key strengths | [Summary of strong areas] |
| Key gaps / concerns | [Summary of weak or missing controls] |
| Required remediation actions | [List items, owners, and due dates] |
| Compensating controls applied on our side | [e.g. restricted data sharing, contractual safeguards, monitoring] |
| Decision | [Approve / Approve with conditions / Reject / Escalate] |
| Next review date | [YYYY-MM-DD] |
Remediation tracker:
Sign-off:
| Role | Name | Decision | Date |
|---|---|---|---|
| Business owner | [ ] | [ ] | [ ] |
| Security / risk reviewer | [ ] | [ ] | [ ] |
| Data protection / privacy (if applicable) | [ ] | [ ] | [ ] |
| Approver (executive, if required by tier) | [ ] | [ ] | [ ] |
A point-in-time assessment goes stale the day after you finish it. PageCrawl keeps it live by monitoring each vendor's trust center, subprocessor list, and certifications, and alerting you when their posture changes.
Start monitoring free →This free template is provided by PageCrawl.io, website change monitoring and alerts. Reuse and adapt it freely.