Sample template. A starting point to adapt to your organization — not legal advice, and not a finished or binding document. Review with your own counsel before you rely on it.

Vendor risk assessment template & checklist

Updated

A vendor risk assessment evaluates the security, compliance, and operational risk a third party introduces before you rely on them, and on a recurring cadence afterward. This template covers the two decisions that make a TPRM program work: how to tier a vendor by criticality, and which questions to ask at each tier — so effort scales with the risk rather than treating every vendor the same.

Use the criticality tiering first to decide how deep to go, then work the assessment checklist for that tier. The goal is not a longer questionnaire; it is a proportionate one that captures the risks that actually matter for how this vendor is used.

Step 1 — Tier the vendor by criticality

Before assessing anything, decide how much the vendor matters. Criticality is driven by what data they touch, whether they are in the path of a critical process, and how hard they would be to replace. The tier sets both the depth of the initial assessment and how often you re-review.

Vendor criticality tiers and review cadence
TierTypical characteristicsSuggested review cadence
CriticalHandles sensitive/regulated data or is in a critical process pathAnnual, in depth
HighAccess to some sensitive data or important but recoverable serviceAnnual, standard
ModerateLimited data access, replaceable serviceEvery 1–2 years
LowNo sensitive data, easily replacedLightweight / at renewal

Step 2 — Work the assessment checklist

For each in-scope vendor, capture answers and, wherever possible, evidence rather than assertions. A vendor claiming a certification should provide the report; one claiming encryption should say what and how. Scale the number of questions to the tier — a critical vendor warrants the full list, a low-tier vendor a short subset.

  • Security certifications held (SOC 2 report, ISO 27001) — obtain the actual report, not just a badge.
  • Data handled: types, sensitivity, and whether any is regulated (PII, PHI, cardholder).
  • Data location and sub-processors — where data is stored and who else touches it.
  • Encryption in transit and at rest, and key management approach.
  • Access controls and authentication (SSO, MFA, least privilege).
  • Incident history and breach-notification commitments (timeframe, channel).
  • Business continuity and disaster recovery posture; recovery objectives.
  • Contractual protections: DPA, security addendum, right to audit, liability terms.
  • Compliance obligations they must meet on your behalf (e.g., GDPR, HIPAA).
  • Offboarding: how data is returned or destroyed when the relationship ends.

Step 3 — Decide, document, and set the next review

Close each assessment with a decision and a date. Record the residual risk you are accepting, any remediations the vendor committed to, who approved onboarding, and when the next review is due based on the tier. An assessment with no owner, no decision, and no next date is a document, not a control.

Track the portfolio, not just individual vendors. A single view of every vendor, its tier, its last assessment date, and its next due date is what turns one-off reviews into a program — and surfaces the vendors that have quietly gone past their review cadence.

Frequently asked questions

What should a vendor risk assessment include?

Criticality tiering first, then a checklist covering certifications (with the actual report), data handled and its location, sub-processors, encryption and key management, access controls, incident history and breach-notification terms, business continuity, contractual protections, compliance obligations, and offboarding. Depth should scale with the vendor's tier.

How do you tier vendors by criticality?

By what data they touch, whether they sit in a critical process path, and how replaceable they are. Critical vendors handle sensitive or regulated data or are hard to replace and get an in-depth annual review; low-tier vendors touch no sensitive data and get a lightweight review at renewal. The tier sets both assessment depth and review cadence.

How often should vendors be reassessed?

By tier: critical and high vendors annually, moderate vendors every one to two years, and low-tier vendors lightly at renewal. The key discipline is tracking a next-review date per vendor so the portfolio surfaces any vendor that has gone past its cadence rather than being reviewed only once at onboarding.

Run TPRM as a program, not a spreadsheet

ShipReady tracks each vendor's criticality tier, review cadence, and portfolio status, so vendors that drift past their next-review date surface automatically.