These answers are educational, not legal, insurance, cybersecurity, or regulatory advice. Requirements depend on the business, contract, industry, location, and facts. When the consequences are significant or the answer is uncertain, involve a qualified professional.
| Business need | Useful first step | PBW resource |
|---|---|---|
| Screen a new vendor | Collect basic facts and assign an initial risk level. | Vendor Pre-Screening Starter Kit |
| Build vendor oversight | Track assessments, evidence, decisions, reviews, and offboarding. | Third-Party Vendor Risk Toolkit |
| Review AI use | Inventory tools, screen risk, and document safeguards. | AI Risk Management Starter Guide |
| Document repeatable work | Interview process owners and write usable procedures. | SOP & Process Documentation System |
Search topic: Vendor risk assessment template for small business
How do you conduct a vendor risk assessment?
Start by defining the service, data access, operational dependency, and potential business impact. Assign a risk tier, send questions that match that tier, review supporting evidence, document unresolved concerns, and record an approval decision. Set a review date and reassess after major service, ownership, security, or contract changes.
Where can you download a vendor risk assessment template?
Vendor risk templates are available from government agencies, software providers, and business-resource publishers. Choose one that includes vendor details, risk tiering, due-diligence questions, evidence review, findings, approval, and follow-up. PBW offers an Excel-based system designed for U.S. small businesses that need a practical process rather than enterprise software.
Can a small business write its own risk assessment?
Yes. A small business can create its own assessment when the process matches its vendors, information, contracts, and operating needs. Use recognized guidance as a reference, keep scoring rules consistent, document decisions, and obtain legal, privacy, security, or insurance advice when a vendor presents consequences the team cannot evaluate confidently.
Search topic: Vendor due diligence checklist
What is included in vendor due diligence?
Vendor due diligence usually covers business identity, ownership, financial stability, references, licenses, insurance, contract terms, data handling, security, legal concerns, service continuity, and subcontractors. The depth should match the risk. A payroll provider needs closer review than an office-supply company because access, dependency, and potential harm differ.
What should be included in a due diligence checklist?
A useful checklist identifies the vendor and service, confirms authority to operate, checks references and insurance, reviews security and privacy practices, evaluates financial and operational reliability, records contract protections, and lists open issues. It should also name the reviewer, decision owner, approval conditions, evidence received, and next review date.
What are the Four Ps of due diligence?
The “Four Ps” is not a universal vendor-risk standard. Different sources use different words, often people, process, performance, and protection. For practical vendor review, focus on facts: who operates the company, how the service works, whether it can perform reliably, and how your money, information, customers, and operations are protected.
Search topic: Third-party risk assessment questionnaire template
What questions belong in a third-party risk assessment questionnaire?
Ask what service the vendor provides, which information and systems it can access, where data is stored, who can view it, which subcontractors are involved, how access is controlled, how incidents are reported, how continuity is maintained, and how data is returned or deleted when the relationship ends.
How do you perform a third-party risk assessment?
Inventory the proposed service, identify access and dependency, assign an initial risk tier, and send a questionnaire suited to that risk. Review answers against evidence, record gaps, decide whether safeguards are needed, and document approval or rejection. Monitor critical vendors and repeat the assessment when material changes or incidents occur.
What should a third-party risk assessment template contain?
A practical template needs vendor information, service scope, business owner, data and system access, risk tier, questionnaire responses, evidence reviewed, findings, required safeguards, decision, approver, and review date. It should distinguish missing information from an unacceptable answer so reviewers know whether to investigate, mitigate, accept, or decline the risk.
Search topic: Vendor security questionnaire template
What is a vendor security questionnaire?
A vendor security questionnaire is a structured set of questions used to understand how a supplier protects systems, accounts, and information. It commonly covers access control, encryption, backups, vulnerability management, incident response, employee practices, subcontractors, and data deletion. The questionnaire supports a decision; it is not proof that every answer is accurate.
What is the best third-party risk management tool?
The best tool fits the number and complexity of your vendors. A small company may need a controlled spreadsheet, tiered questionnaires, evidence tracking, and clear review dates. Larger programs may require workflow automation and integrations. Choose the least complex system that reliably records ownership, decisions, exceptions, monitoring, and offboarding.
What are the five phases of the third-party risk management lifecycle?
A common five-phase lifecycle is planning, due diligence, contracting, ongoing monitoring, and offboarding. Names vary by organization, but the work is similar: understand the need, evaluate the vendor, set protections, watch for changes, and end access cleanly. Document ownership and decisions during every phase rather than only at onboarding.
Search topic: Vendor onboarding checklist for small business
What are the Five Cs of effective onboarding?
There is no single recognized “Five Cs” model for vendor onboarding. Employee-onboarding sources often use compliance, clarification, culture, connection, and check-back, which do not fully fit suppliers. Vendor onboarding should instead confirm scope, ownership, due diligence, contract terms, system access, payment setup, escalation contacts, evidence, approval, and the first review date.
What should be included in a vendor onboarding checklist?
Include legal name, tax and payment details, service owner, contract, insurance, licenses, references, risk tier, completed due diligence, security and privacy requirements, approved access, implementation tasks, escalation contacts, and review dates. The checklist should show who completed each item and prevent access or payment before required approvals are recorded.
What are the steps involved in vendor onboarding?
Define the business need, collect vendor information, assign a risk tier, complete due diligence, negotiate terms, approve the relationship, configure payment and access, document contacts, and schedule monitoring. High-risk vendors may also require evidence review, security conditions, continuity planning, or management approval before they handle sensitive data or critical operations.
Search topic: Third-party risk management policy template
What is a third-party risk management policy?
A third-party risk management policy explains how an organization selects, assesses, approves, monitors, and offboards vendors. It establishes scope, roles, risk tiers, minimum review requirements, exception authority, documentation, and review frequency. The policy should describe the organization’s actual process; copying an enterprise policy that employees cannot follow creates little protection.
What are the five phases of third-party risk management?
The five phases are commonly described as planning, due diligence, contracting, monitoring, and termination. Planning defines the need and owner. Due diligence evaluates risk. Contracting sets expectations. Monitoring tracks performance and changes. Termination removes access, returns information, confirms final obligations, and records why the relationship ended.
Can you use a template for a risk management policy?
Yes, but treat a template as a starting structure. Adapt the scope, roles, risk categories, approval rules, review schedule, exceptions, and records to the business. Confirm that employees can perform every required step with available time and tools. Obtain professional advice when contractual, regulatory, privacy, or industry obligations need interpretation.
Search topic: Vendor risk register template Excel
Is there a free Excel template for a risk register?
Yes. Free Excel risk-register templates are widely available, but many are designed for projects rather than vendors. A vendor register should include service owner, risk tier, data access, business dependency, assessment status, findings, safeguards, decision, next review, contract end date, and offboarding status. Test formulas and dropdowns before relying on them.
How do you create a vendor list in Excel?
Create one row per vendor and use consistent columns for legal name, service, owner, department, contract dates, payment details, data access, system access, risk tier, assessment status, review date, and termination status. Add controlled dropdowns, freeze headers, protect formulas, and use filters so users can find overdue or high-risk vendors quickly.
What is the best format for a vendor risk register?
For most small businesses, a structured table works best. Use one row per vendor, controlled categories, visible owners, dates that sort correctly, and separate fields for inherent risk, findings, safeguards, and residual risk. Avoid merged cells and long narrative entries. Link supporting evidence rather than embedding large files inside the register.
Search topic: Vendor risk assessment checklist
How should a vendor risk assessment be completed?
Begin with the vendor’s service, access, and importance to operations. Screen for legal, financial, operational, privacy, security, and concentration risk. Request evidence where the potential harm justifies it. Record findings, safeguards, unresolved issues, and the final decision. Assign an owner and review date so approval does not become permanent by default.
What five things should a risk assessment include?
A practical assessment should identify the asset or activity, possible threats, existing controls, likely impact, and required action. For vendors, also record ownership and timing. A useful five-part summary is: what could go wrong, how likely it is, what harm could result, what already reduces the risk, and what happens next.
What is a vendor audit checklist?
A vendor audit checklist is a structured review of whether a supplier follows agreed requirements and can support the service reliably. It may examine contracts, performance, access, security evidence, insurance, licenses, incident history, continuity, and corrective actions. An audit is usually deeper than an onboarding questionnaire and should match contractual audit rights.
Search topic: How to review a SOC 2 report
Are SOC 2 Type 2 reports public?
No. SOC 2 reports usually contain confidential details and are shared under a nondisclosure agreement with customers or qualified prospects. A vendor may provide a summary or certification-style marketing page publicly, but that is not the report. Request the full report when the vendor’s access or importance makes detailed assurance appropriate.
How do you check a vendor’s SOC 2 compliance?
Ask for the current SOC 2 report and verify the audit period, service scope, auditor’s opinion, systems covered, exceptions, complementary user controls, subservice organizations, and management response. Confirm that the report covers the service you buy. SOC 2 is an assurance report, not a government certification or a guarantee of security.
How long is a SOC 2 report good for?
A SOC 2 report covers a stated period or point in time; it does not have a universal expiration date. Many customers expect annual reports and may request a bridge letter after the covered period ends. Evaluate report age alongside service changes, incidents, scope, contract requirements, and the vendor’s importance to your business.
Search topic: Vendor offboarding checklist
What is an offboarding checklist?
An offboarding checklist records the actions required to end a relationship safely. For vendors, it should cover notice, final work and payments, account closure, access removal, credential changes, equipment return, data return or deletion, record retention, replacement arrangements, and confirmation by responsible owners. Keep evidence that critical steps were completed.
What are the standard vendor offboarding steps?
Confirm the end date and contract obligations, identify all accounts and integrations, transfer needed records, remove access, rotate shared credentials, recover equipment, verify data return or deletion, settle final payments, notify affected teams, document unresolved matters, and close the vendor record. Critical services also need an orderly transition or continuity plan.
What belongs on a vendor checklist?
A vendor checklist should reflect the stage of the relationship. At selection, include identity and due diligence. At onboarding, include contracts, payment, access, and ownership. During service, track performance, evidence, incidents, and reviews. At offboarding, remove access, recover information and equipment, settle obligations, and document completion.
Search topic: AI risk assessment checklist for small business
Can AI write a risk assessment?
AI can help draft questions, organize information, or summarize documented risks, but it should not make the final decision without informed human review. The business must verify facts, protect confidential data, consider affected people, and assign accountability. AI output may omit context, invent details, or apply assumptions that do not fit the proposed use.
What is the 10-20-70 rule for AI?
The 10-20-70 rule is a change-management idea often attributed to business consulting: roughly 10% of effort goes to algorithms, 20% to technology and data, and 70% to people and process. It is not a compliance requirement. Its useful message is that successful AI adoption depends heavily on workflow, ownership, training, and oversight.
Can AI create a business checklist?
Yes. AI can produce a useful first draft when you provide the task, audience, risks, and desired decision. Review every item against authoritative sources and actual operations. Remove generic steps, add owners and evidence, protect confidential information, and test the checklist with a realistic example before employees use it for important decisions.
Search topic: AI governance policy template for small business
What is an example of an AI governance policy?
A small-business AI policy can require an inventory of approved tools, prohibit entry of restricted data, assign review for higher-impact uses, require people to verify outputs, define vendor review, document approvals, and establish incident reporting. It should identify who owns the policy and when tools or uses must be reassessed.
What is the 30% rule for AI?
There is no broadly accepted AI-governance standard called the 30% rule. The phrase appears in unrelated discussions about productivity, automation, or content. Do not use it as a control or compliance benchmark. Base decisions on the specific use, information involved, affected people, potential harm, human review, vendor practices, and applicable requirements.
What are good AI policies for small businesses?
Good policies are short enough to follow and specific enough to guide decisions. Cover approved tools, prohibited information, human review, customer and employee impacts, intellectual property, vendor assessment, recordkeeping, incidents, and reassessment. Separate firm rules from guidance, name an owner, and give employees a safe way to disclose current AI use.
Search topic: NIST AI RMF for small business
Is there a NIST AI RMF certification?
No. NIST describes the AI Risk Management Framework as voluntary guidance, not a certification program. A company may use its Govern, Map, Measure, and Manage functions to structure AI oversight, but should not claim NIST certification. Any outside certificate should be evaluated separately for its issuer, criteria, scope, and independent assurance.
What can a small business use AI for?
Small businesses use AI for drafting, research support, customer-service assistance, forecasting, document summaries, workflow automation, coding, and data analysis. Start with low-impact tasks, restrict sensitive data, verify outputs, and define ownership. Uses affecting employment, credit, pricing, health, safety, or legal rights deserve closer review and possibly professional advice.
Is the NIST Risk Management Framework free?
Yes. NIST publishes the AI RMF, playbook, profiles, and related resources at no charge. The documents are voluntary and publicly available. Implementation still requires staff time and judgment, and businesses may choose paid tools or advice. Using NIST material does not create certification, guarantee compliance, or eliminate the need to address applicable laws.
Search topic: Small business AI policy template
What should a small-business AI policy cover?
Cover permitted and prohibited uses, approved tools, sensitive information, human review, accuracy checks, intellectual property, customer disclosures, vendor review, incidents, records, training, and reassessment. The policy should fit actual work. If employees already use AI, begin with an inventory and practical safeguards rather than assuming a written prohibition has stopped unapproved use.
Can you use a template for an AI company policy?
Yes. A template can provide structure, but it must be adapted to the company’s tools, data, customers, workforce, and decisions. Remove rules the business cannot operate, add clear examples, assign decision authority, and check legal or industry requirements. Review the policy whenever approved uses, vendors, or applicable obligations change materially.
Does the 30% rule belong in an AI policy?
Usually not. There is no general regulatory or governance rule requiring 30% human input, review, or modification. A fixed percentage may be meaningless for the actual risk. Define specific review duties instead: who checks the output, what they verify, which sources they use, and when they must reject, correct, or escalate it.
Search topic: SOP template for small business
Are there SOP templates in Word?
Yes. Word includes general process templates, and many business publishers offer SOP files. Choose a format with purpose, scope, owner, prerequisites, numbered steps, decision points, exceptions, records, and revision history. A polished template is only useful if employees can complete the procedure accurately under normal working conditions.
Can ChatGPT write SOPs?
ChatGPT can help organize interview notes, draft steps, simplify wording, and identify missing decisions. A knowledgeable process owner must verify the procedure through observation or testing. Do not enter confidential information without approval. Treat generated text as a draft, because it may invent steps, miss exceptions, or misunderstand how the work is actually performed.
What are the five components of an SOP?
A practical five-part structure is purpose and scope, roles and prerequisites, numbered procedure steps, exceptions and escalation, and records and revision control. Some organizations use different components. What matters is that the document tells the right person what to do, in what order, how to handle unusual situations, and what evidence to retain.
Search topic: How to write an SOP for small business
What are the five main parts of an SOP?
Use five clear parts: purpose and boundaries, responsible roles, required inputs or tools, numbered instructions with decisions, and completion records with revision history. Add warnings or exceptions where needed. Keep background information brief. The main test is whether a trained employee can follow the document without relying on the original author’s memory.
How should a business use AI to draft an SOP?
Give the AI verified process notes, required format, audience, and writing rules. Ask for a draft, then have the process owner test every step using a realistic case. Correct missing decisions, unsafe assumptions, and vague verbs. Remove invented details, protect confidential information, record approval, and retain human responsibility for the final procedure.
What is an example of a good SOP?
A good accounts-payable SOP might explain which invoices qualify, who checks purchase approval, how vendor details are verified, where the invoice is entered, what happens when information is missing, who approves payment, and which records are retained. It uses numbered steps, names decision owners, and distinguishes routine work from exceptions.
Search topic: Process documentation template for small business
What is a process documentation template?
A process documentation template is a repeatable structure for recording how work moves from trigger to completion. It usually captures purpose, owner, participants, inputs, outputs, systems, steps, decisions, exceptions, controls, measures, and related records. Unlike a narrow SOP, process documentation can show handoffs across several people or departments.
How do you create process documentation?
Choose one process, define its start and finish, interview the people who perform it, and observe the work when possible. Map steps, handoffs, decisions, systems, delays, exceptions, and evidence. Validate the draft with users, correct differences between stated and actual practice, assign an owner, publish it, and schedule review.
What are examples of business process documentation?
Examples include customer onboarding maps, invoice approval workflows, employee hiring procedures, vendor selection processes, incident escalation paths, order-fulfillment diagrams, and month-end close checklists. The best format depends on the work: a flowchart shows handoffs and decisions, while an SOP gives detailed instructions for completing a specific task.
Search topic: Business continuity plan template for small business
What are the five key components of a business continuity plan?
A practical plan includes critical activities and priorities, disruption scenarios and impacts, response roles and communications, recovery procedures and resources, and testing with maintenance. Include key vendors, technology dependencies, manual workarounds, contact information, and decision authority. Keep essential instructions available when normal systems or facilities cannot be reached.
How do you structure a business continuity plan?
Begin with scope, assumptions, and activation authority. List critical operations, recovery priorities, people, facilities, technology, information, and vendors. Add communication methods, immediate response actions, recovery procedures, alternate arrangements, and return-to-normal steps. Finish with contact lists, plan storage, training, exercise schedules, ownership, and revision history.
What are FINRA’s business continuity plan requirements?
FINRA Rule 4370 requires member firms to create and maintain written business continuity plans addressing specified operational areas, conduct annual reviews, and provide emergency contact information. These requirements apply to FINRA member firms, not every small business. Regulated firms should read the current rule and guidance and obtain qualified compliance advice.
Search topic: Emergency response plan template for small business
What are the five elements of an emergency response plan?
A useful five-part plan covers likely emergencies, reporting and activation, evacuation or shelter actions, roles and communications, and accountability with recovery. OSHA requirements may apply depending on the workplace and plan type. Include emergency contacts, assembly locations, assistance for people who need it, critical shutdown steps, training, and exercises.
How do you write an emergency response plan?
Identify credible emergencies, workplace hazards, legal requirements, and available resources. Define who declares an emergency, how people are warned, when to evacuate or shelter, who contacts responders, how everyone is accounted for, and which operations require safe shutdown. Document contacts, maps, supplies, training, drills, review dates, and plan ownership.
Where can you find a free emergency action plan template?
OSHA provides a free Emergency Action Plan Expert System and guidance for covered workplaces. Ready.gov also offers business preparedness resources. Use official material as a starting point, then adapt it to your facility, hazards, workforce, local responders, and applicable rules. A generic download should not replace site-specific planning or required professional advice.
Search topic: Cyber insurance vendor management requirements
What are typical requirements for cyber insurance?
Applications often ask about multifactor authentication, backups, endpoint protection, patching, security training, incident response, privileged access, encryption, and third-party controls. Requirements vary by insurer, policy, industry, and risk. Answer accurately, retain supporting records, and ask the broker or insurer to clarify uncertain terms rather than assuming a checklist guarantees coverage.
What is the 80-20 rule in cybersecurity?
The phrase usually suggests that a small number of controls or causes account for much of the result, but it is not a cyber-insurance standard. Do not use it to skip required safeguards. Prioritize controls using actual threats, business impact, insurer questions, contractual duties, and authoritative guidance, then document why resources were allocated that way.
What are the Five Cs of cybersecurity?
There is no single authoritative Five Cs model. Different sources use terms such as change, compliance, cost, continuity, and coverage. For a small business, a clearer foundation is asset and data visibility, secure access, system maintenance, backups, employee awareness, incident response, vendor oversight, and regular review aligned with current risks and obligations.
Which authoritative sources can help you go deeper?
Use primary guidance when the decision requires more detail. Helpful starting points include: