A vendor risk assessment determines how much risk a supplier introduces, and how much scrutiny they therefore deserve. The mistake most programmes make is sending every vendor the same 200-question spreadsheet - which exhausts your team, annoys low-risk suppliers, and still misses the risks that matter. Tier first, then ask.
Step 1 - Tier the vendor
Score each supplier on what they can actually affect:
- Data sensitivity - do they access personal, financial or regulated data?
- Data volume - how many records?
- Operational criticality - what breaks in your business if they go down?
- Access level - do they connect to your network, or hold privileged credentials?
- Regulatory exposure - do they process data covered by a regulator?
- Concentration - could you replace them quickly if you had to?
Then assign a tier:
- Tier 1 - Critical: full assessment, evidence review, contractual security terms, annual reassessment, right to audit.
- Tier 2 - Important: standard questionnaire, certification review, reassess every one to two years.
- Tier 3 - Low: lightweight screening and basic contract terms.
Step 2 - Ask the questions that matter
For Tier 1 and 2 suppliers, cover:
- Certifications - ISO 27001 certificate (check the scope, not just the logo), SOC 2 Type II report, PCI attestation.
- Data handling - what they store, where it is hosted, how long they retain it, and how it is deleted at exit.
- Access control - MFA, privileged access management, joiner and leaver process.
- Encryption - in transit and at rest, and key management.
- Security testing - penetration test cadence and remediation of findings.
- Incident response - notification commitments and timelines in the contract.
- Business continuity - RTO and RPO, and when they last tested.
- Their fourth parties - the subprocessors behind your supplier.
- Insurance - cyber liability coverage.
Assess vendors without the spreadsheet marathon
GRC Copilot tiers your suppliers, generates the right questionnaire per tier, reads the evidence they return, and tracks reassessment dates automatically.
Try GRC Copilot free Generate an AI-powered assessment Download the template Book a demo
Step 3 - Verify, do not just collect
A questionnaire is a set of claims. Evidence is what makes them real:
- Read the SOC 2 report - especially the exceptions and the complementary user entity controls, which describe what you must do.
- Check that the ISO 27001 certificate scope covers the service you are buying, and that it has not expired.
- Confirm penetration test recency and that high findings were remediated.
- Record what you reviewed and when - that record is your audit evidence.
Step 4 - Contract and monitor
- Security requirements, breach notification timelines, audit rights, subprocessor approval and secure return or deletion of data at termination.
- Data processing agreement where personal data is involved.
- Reassess on the tier cadence, and immediately on trigger events: a breach at the supplier, a change of ownership, a new subprocessor, or a change in the service.
- Run a proper offboarding: revoke access, confirm data deletion in writing, and close the record.
Third-party risk is where most frameworks now concentrate. The NCA ECC, SAMA CSF and ISO 27001 all treat supplier and cloud risk as a distinct domain - and it is consistently the weakest area in first assessments.
Frequently asked questions
How often should vendors be reassessed?
Annually for critical suppliers, every one to two years for important ones, and on any trigger event regardless of tier.
Is a SOC 2 report enough on its own?
It is strong evidence, but read it properly: check the period covered, the criteria in scope, the exceptions noted, and the complementary user entity controls you are responsible for.
What about fourth parties?
Ask for the subprocessor list and require notification of changes. Your regulatory obligations do not stop at your direct supplier.
What if a critical vendor refuses to complete an assessment?
Treat refusal as a risk finding. Escalate to the business owner, document the residual risk, and require explicit acceptance from someone with authority to accept it.
Key takeaways
- Tier suppliers first; do not send everyone the same questionnaire.
- Verify claims against evidence - especially SOC 2 exceptions and certificate scope.
- Put security, breach notification and exit terms in the contract.
- Reassess on a cadence and on trigger events, and offboard properly.