Question headings reproduce wording observed in Google’s People also ask results on October 4, 2026. The answers and practical checklists are written by PBW. Search results vary by time and location.
Vendor risk assessments
How to do a vendor risk assessment?
Identify the service, data and access involved, then consider what would happen if the vendor failed or mishandled information. Request evidence proportionate to that exposure and record gaps. Assign an owner to decide whether safeguards are adequate. Keep the decision, conditions and next review date together rather than collecting answers without acting.
Can I write my own risk assessment?
You can draft a vendor assessment using your business context and relevant guidance. Describe the service, possible harms, existing safeguards and unresolved concerns. Use qualified help where the consequences exceed your expertise. A self-written document is useful only when its assumptions and evidence are checked; it does not establish compliance by itself.
What are the 5 things a risk assessment should include?
For a vendor review, use five practical headings: the service and exposure, possible harms, likelihood and impact, existing safeguards and required actions. Record the evidence, owner and review date under those headings. This is a PBW working structure, not a universal legal checklist. Adapt it to the vendor and applicable obligations.
Try this in your business
- Describe the service and access.
- Request evidence proportionate to the exposure.
- Record unresolved findings and an owner.
- Document the decision and next review.
Vendor due diligence
What is included in vendor due diligence?
Vendor due diligence checks whether a supplier is suitable for the proposed work. Review its identity, ability to deliver, relevant security practices, service dependencies and contractual commitments. The depth should reflect your exposure. Keep supporting evidence and unresolved concerns visible, and distinguish an unanswered question from evidence that a safeguard is absent.
What should be included in a due diligence checklist?
Include the proposed service, verified supplier details, required evidence, responsible reviewer and decision criteria. For technology vendors, consider data handling, access, support, recovery and subcontractors. Add a place for gaps and follow-up actions. A checklist should guide a decision, not imply that ticking boxes guarantees a reliable or secure supplier.
What is a vendor due diligence questionnaire?
It is a set of questions used to understand a vendor before approval or renewal. Ask about the practices relevant to your service and request evidence for important claims. Keep questions proportionate so a small supplier can respond usefully. Review the answers, clarify gaps and document the resulting decision and conditions.
Third-party assessment questionnaires
What questions are typically included in a third-party risk assessment questionnaire?
Typical subjects include the service provided, information handled, system access, security controls, incident reporting, recovery arrangements and subcontractors. Select questions based on your actual relationship rather than sending every vendor the same long form. Ask for supporting evidence on consequential points, then record who reviewed the responses and what remains unresolved.
How to perform a third party risk assessment?
Define the relationship and identify the information, access and operations it affects. Consider failure scenarios, collect relevant evidence and assess whether safeguards address them. Record a decision with any approval conditions and responsible owner. Revisit the assessment when the service changes or new information makes the original judgment unreliable.
Vendor security questionnaires
What is a vendor security questionnaire?
A vendor security questionnaire asks how a supplier protects systems and information involved in your service. It may cover access controls, backups, incident handling and data retention. Match the questions to the exposure and verify important claims with evidence. A completed questionnaire is an input to review, not proof that every risk is controlled.
What are the 5 phases of the TPRM lifecycle?
One useful five-part way to organize third-party risk work is identification, assessment, approval, monitoring and offboarding. Organizations group these activities differently, so the number is not universal. For a small business, make sure each activity has an owner and record, including a clear route for findings that remain unresolved after approval.
How to perform a vendor risk assessment?
Start with the specific service and the harm a failure could cause. Identify access and data exposure, review relevant safeguards and collect evidence rather than relying on sales claims. Document gaps and decide whether to approve, approve with conditions or decline. Set a review trigger tied to changes in the relationship.
Vendor onboarding
What are the steps involved in vendor onboarding?
Confirm the supplier’s identity and business contact, define the service, complete proportionate screening and obtain approval. Agree the required terms and securely verify payment information. Grant only necessary access, record the relationship owner and arrange support contacts. Do not let account setup or an urgent purchase replace the approval decision.
What should be included in an onboarding checklist?
For vendor onboarding, include verified supplier details, service scope, assessment evidence, approval, agreed terms, billing setup and access requirements. Add the relationship owner, incident contact and review date. This is different from employee onboarding. Mark incomplete items and approval conditions explicitly so staff do not interpret a partly completed checklist as final authorization.
Vendor management policies
What is a third-party risk management policy?
It sets the rules for reviewing, approving and overseeing external suppliers. A small-business policy can define which relationships need deeper review, who can approve them and how exceptions are recorded. Link it to practical assessment and offboarding procedures. A policy alone does not establish that the team follows its rules.
What are the 5 phases of third-party risk management?
You can organize the work around identifying vendors, assessing exposure, approving relationships, monitoring performance and ending access safely. This five-phase description is a practical grouping, not a mandatory universal model. Include decision records and issue ownership throughout. A vendor with unresolved findings should not disappear from oversight once the contract is signed.
Can you provide a template for a risk management policy?
Start with headings for purpose, scope, responsibilities, assessment criteria, approval authority, exceptions and review. Under each heading, describe rules your business can actually carry out. For vendor risk, connect the policy to an inventory and findings log. Have the owner approve it and seek specialist advice where regulated obligations or legal terms are involved.
Vendor risk registers
How to assess vendor risk?
Compare the vendor’s role and exposure with the evidence of its safeguards. Consider service disruption, sensitive information, privileged access and hard-to-replace dependencies. Record the important risks separately from the final approval decision. Name an owner for remaining actions and choose review triggers that reflect changes in service or new incident information.
What should be included in a risk register?
Include a clear risk description, affected activity, possible impact, likelihood judgment, existing safeguards, action owner and review date. Add status and links to evidence so entries can be checked later. For vendor risks, identify the supplier and service. Keep approved actions and completed evidence distinct from planned improvements.
Vendor assessment completion checks
What is a vendor audit checklist?
It is a structured list for checking a vendor against defined requirements and retaining evidence of the review. Decide the scope before using it, including the service and controls being examined. Record findings and follow-up owners. A routine supplier review should not be described as an independent audit unless that is actually what was performed.
Reviewing a SOC 2 report
Are SOC 2 Type 2 reports public?
SOC 2 reports are intended for specified knowledgeable users and commonly shared through a vendor’s controlled process rather than as public marketing material. Request access from the supplier and respect its distribution terms. A public badge or summary is not a substitute for examining the report relevant to your service.
How to check SOC 2 compliance?
Request the relevant SOC 2 report and check its service scope, reporting period, auditor’s opinion, exceptions and controls your business must perform. SOC 2 is an assurance examination, not a universal compliance certificate. Have a qualified reviewer interpret significant findings and assess whether the report covers the relationship you actually intend to use.
How long is a SOC 2 report valid?
A SOC 2 report describes a specified date or reporting period; it is not a guarantee that conditions remain unchanged afterward. Check the covered period and ask about significant changes or later incidents. Decide how recent the evidence needs to be for your exposure rather than treating a fixed expiry rule as universal.
What does a SOC2 report look like?
A SOC 2 report generally contains the auditor’s opinion, management’s assertion and a description of the system in scope. A Type 2 report also includes tests of controls and results over the stated period. Review the complete relevant report, including limitations and responsibilities, rather than relying only on an attractive cover or badge.
Vendor offboarding
What is an offboarding checklist?
For a vendor, an offboarding checklist organizes the work needed to end the relationship safely. It covers service transition, access removal, equipment or data return, retention arrangements and remaining obligations. Assign owners and completion evidence. Ending a contract does not necessarily revoke user accounts, integrations or stored copies of business information.
What are the standard offboarding process steps?
A practical vendor sequence is to confirm the termination scope, arrange the replacement or handover, remove access, recover or manage data and assets, reconcile remaining obligations and verify completion. The exact steps depend on the service and agreement. Keep essential operations running and obtain specialist help when data or contractual rights are unclear.
What is a vendor checklist?
A vendor checklist is a working aid for a defined stage such as screening, onboarding, review or termination. It identifies required checks, evidence and responsible people. Use different checks when the purpose changes. A single generic list is unlikely to cover every supplier, and completed boxes should not replace a documented decision.
Vendor evidence for cyber-insurance questions
What are the typical requirements for cyber insurance?
Insurers may ask about access protection, backups, security updates, staff practices and service providers, but requirements vary by insurer, policy and business. Use the actual application and your broker’s guidance. Answer accurately and retain evidence. A generic checklist or vendor toolkit cannot confirm eligibility, coverage or that a claim will be paid.
Vendor comparison scorecards
How do I create a vendor scorecard?
Choose criteria tied to the purchase, define how each will be judged and use the same evidence requirements for comparable suppliers. Record price, delivery capability and relevant risk factors separately. Explain weights before scoring, and flag non-negotiable requirements. A high total should not conceal a failure on a critical requirement.
What is a vendor scorecard?
A vendor scorecard records how suppliers compare or perform against defined criteria. It makes the basis of a decision visible and repeatable. Keep scores linked to evidence and distinguish a selection scorecard from an ongoing performance review. Update judgments when facts change instead of carrying an old rating forward indefinitely.
What are the 5 key supplier evaluation criteria?
For a practical comparison, consider capability, reliability, total cost, relevant risk safeguards and service support. These five groups are a starting point, not a universal supplier standard. Adapt them to the purchase and define pass conditions for critical requirements. Ask for evidence so an attractive score reflects more than a strong sales presentation.
Can you provide an example of a supplier scorecard?
For a software supplier, a scorecard might compare functional fit, support response, total cost, data handling and recovery evidence. Give each criterion a defined rating and attach the supporting source. Mark missing evidence rather than guessing a score. Review any critical gap separately before treating the overall total as approval.
Vendor risk tiers
What are some examples of vendor risk?
Examples include a service outage that stops customer work, misuse of sensitive information, privileged access that is poorly controlled or dependence on a supplier with no practical replacement. Identify the risks tied to your service rather than copying an entire list. Record the possible harm, evidence and owner for safeguards or follow-up.
What are risk tiers?
Risk tiers group relationships by exposure so review effort can be proportionate. A supplier with sensitive data or essential system access may need more evidence than a replaceable low-impact service. Define your criteria and explain each assignment. A tier is a screening aid, not proof that a particular supplier is safe.
Vendor review schedules
What should a vendor list include?
Include the supplier, service, relationship owner, contact details, relevant access and data exposure, contract or renewal dates and assessment status. Add risk tier and review triggers where useful. Keep the list current as services change. An inventory helps you find dependencies; it is not a completed risk assessment by itself.
What are the four stages of vendor management?
A useful four-stage grouping is selection, onboarding, ongoing oversight and offboarding. Organizations may name or divide stages differently. Make each stage practical by assigning an owner and retaining decisions and evidence. Ongoing oversight should include changes and incidents, not only a calendar review or a check before the renewal bill arrives.
How do you measure vendor performance?
Compare actual delivery with agreed service expectations using measures the relationship supports, such as timeliness, quality, response and unresolved issues. Record evidence and customer impact, not just a score. Discuss concerns with the supplier and set an action owner. Review service performance alongside risk information because they answer different questions.
Vendor incident escalation
What are the 7 steps of incident response?
There is no single universal seven-step sequence for every incident. For a small-business working plan, prepare contacts, identify the issue, assess impact, contain harm safely, coordinate response, restore operations and review lessons. Get qualified responders involved for serious events. Do not let this simplified sequence replace specialist or legally required response procedures.
Vendor data return and deletion
What is a certificate of data erasure?
It is a record describing a claimed data-erasure action, often including the asset, method, date and responsible party. Review what it actually covers and how completion was verified. A certificate does not automatically prove every backup, shared copy or subcontractor record was removed. Match the evidence to your agreement and data requirements.
What does deletion of data mean?
Deletion can mean removing active access or removing information from a particular system; it does not always establish that every retained copy has been destroyed. Ask the vendor about backups, retention periods and subcontractors. Define the required outcome and evidence with qualified help when sensitive data or legal obligations are involved.
How to request a data deletion?
Identify the service, records and authorized contact, then use the vendor’s agreed termination or privacy process. Ask what will be deleted, what must be retained and when completion can be confirmed. Avoid transmitting unnecessary sensitive information in the request. Your legal rights and the vendor’s obligations depend on the circumstances and jurisdiction.
Vendor subcontractors and dependencies
Is a subcontractor considered a vendor?
A subcontractor may be a supplier to your vendor rather than a direct supplier to your business. Its role still matters if it handles your data or supports an essential service. Record that dependency and ask the direct vendor about oversight and change notices. Contractual labels and obligations should be reviewed with qualified advice.
What are the red flags in due diligence?
Examples include inconsistent identity details, unclear ownership of the service, unsupported security claims, refusal to explain relevant subcontractors and unresolved evidence gaps. A warning sign calls for investigation rather than an automatic accusation. Document the concern, request clarification and decide whether the remaining exposure is acceptable before granting access or committing to the relationship.
Vendor findings and action tracking
What is the vendor assessment process?
Define the service and review criteria, gather relevant evidence, assess the responses and document the decision. Record findings with an owner, due date and required completion evidence. Follow up on open actions after approval. An assessment process should lead to accountable decisions, not simply a folder of questionnaires and reports.
What is a vendor tracker?
A vendor tracker is a maintained record of suppliers and the work needed to manage them. It can show relationship owners, reviews, findings and next actions. Decide which system is the source of truth and keep entries current. A spreadsheet tracker requires manual upkeep unless its actual features provide verified integrations or automation.
What are the best ways to monitor vendor performance?
Review service results, support records, recurring issues and agreed actions at a cadence appropriate to the relationship. Use meaningful evidence rather than collecting a score nobody acts on. Assign an owner to discuss concerns and confirm improvements. Reassess separately when the service, data exposure or dependencies change, even if performance appears satisfactory.
Critical vendor continuity
What are the compliance requirements for vendors?
Requirements depend on the service, industry, contracts, data and applicable jurisdiction. Start with the obligations relevant to your business and ask qualified advisers which must flow to suppliers. Separate legal requirements from your preferred safeguards. A vendor’s certificate or checklist should be assessed for scope; it cannot establish every obligation is satisfied.
Vendor approval exceptions
What is exception approval?
Exception approval is a documented decision to depart from a normal requirement under defined conditions. State the reason, remaining exposure, approving authority and expiry or review trigger. Include any compensating safeguard and responsible owner. An exception should not quietly become the new default or be used to override an obligation your business cannot waive.
What is a vendor approval process?
It identifies who reviews a proposed supplier, which evidence is required and who can authorize the relationship. Define how incomplete findings and exceptions are handled, then record the decision and conditions. Make access or purchasing setup follow approval, not substitute for it. Use a proportionate route for lower-impact suppliers.
What does "approved by exception" mean?
It means approval was granted despite a departure from the usual criteria, not that the missing requirement was met. Keep the exception reason and approving person visible, with conditions and a review date. Confirm the decision is within that person’s authority. Some contractual or legal requirements cannot be waived through an internal exception.
Put the answers to work
Begin with the free 10 Vendor Red Flags checklist. For initial screening, compare the Vendor Pre-Screening Starter Kit ($15). The full toolkit helps organize ongoing assessments and follow-up; it does not certify a vendor or replace specialist review.
Our vendor risk guide explains how to build a proportionate review routine.
Sources and scope
PBW’s examples and suggested routines are practical starting points, not mandatory standards. This information is educational, not legal, tax, accounting, employment, or regulatory advice. Adapt it to your business and get qualified help for consequential decisions.