Vendor Risk Assessment
Third-party security questionnaire across Access Control, Data Protection, Incident Response, Business Continuity, Compliance, Supply Chain, and Vulnerability Management. Risk tier derived automatically.
Before you start — what to have ready for Vendor Risk
Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.
Decide your scope first
Every control in this framework is assessed, so there is no scope step to complete first. Have these decided before you begin so your answers describe one consistent thing.
- Which systems, services and locations are in scope — write this down before you answer anything.
- Who owns each area, so an answer about it is somebody’s to give.
- The period the evidence should cover, where the framework opines on a period rather than a moment.
Gather these documents
What Vendor Risk is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.
- Vendor / third-party risk management policy
- Vendor inventory with criticality ratings
- Due-diligence questionnaires or assessments for key vendors
- Contracts and Data Processing Agreements with vendors
- Vendor security certifications (SOC 2, ISO 27001) or AOCs
- Ongoing vendor monitoring / re-assessment records
Have the right people
Who needs to be involved, and what changes if it is only you.
- Someone who can find the documents — usually whoever owns the control day to day.
- A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
- One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
- A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.
Prepare the files
Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. Vendor assessments name contacts and can carry commercial terms. Mask personal contact details of vendor staff; the policy, the inventory and the assessment structure are what is assessed.
- Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
- A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
- The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
- Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
- A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.
Know what you will get
So the result is what you expected when you started.
- You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
- You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
- Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
- A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
Your assessment journey
Four steps from the vendor's profile to a risk position backed by the vendor's own documents.
Who the vendor is, what data they touch and how critical they are to you. It sets the risk tier the answers are read against.
Open →Nineteen questions across access, data protection, incident response, continuity, compliance, supply chain and vulnerability management.
Open →The derived risk tier, the critical findings, and each finding raisable as a corrective action you can track.
Open →Each question names the VENDOR's artefacts that would answer it - their SOC 2 report, their DPA, their penetration test. A vendor assessment evidenced with your own policies proves nothing about the vendor.
Open →Risk tier derivation
Critical
Unacceptable risk — remediation before or immediately after onboarding.
High
Significant gaps — mitigating controls or remediation plan required.
Medium
Some deficiencies — monitor and address within 90 days.
Low
Acceptable posture — annual reassessment.