The tier decides the checklist
Conditional logic reads the first task. A Tier 3 vendor with no personal data gets a short assessment, a processor gets the Article 28 checks, and an ICT provider to a bank gets the DORA phase.
A vendor risk assessment is the security and risk due diligence on a third party before you depend on it, repeated while you do. This free vendor risk assessment checklist is for security, risk and privacy teams assessing SaaS, cloud and IT suppliers, outsourcers and other third parties. It takes one vendor from criticality tiering and inherent risk, through questionnaire and assurance evidence, to a residual risk rating, contract clauses and a signed approval, and runs the annual reassessment too. Answers on the first task add a data protection phase for processors and a DORA phase for EU financial entities. Each run leaves a dated record of what you knew, what you accepted and who accepted it.
Onboarding makes a supplier payable. A risk assessment answers a different question. If this vendor failed or was breached, how much harm would it do, and how much of that do its controls and our contract remove? The first half is inherent risk. The second is residual risk, which someone accountable must accept in writing.
Evidence is not all equal. An independent report, such as a SOC 2 Type 2 or an accredited ISO/IEC 27001 certificate whose scope covers the service you buy, outweighs a questionnaire. A standard questionnaire, such as the Shared Assessments SIG or the Cloud Security Alliance’s CAIQ, outweighs a bespoke one. Most failures come from mixing the levels up: treating self-attested answers as assurance, or a certificate for the vendor’s data centre as cover for its SaaS platform.
Covers: business need, legal entity, tax and bank details, insurance, ERP setup and kickoff.
Cadence: once, when the vendor is added.
Output: an active, payable supplier record.
Covers: criticality, inherent risk, assurance evidence, data protection terms, residual risk and exit.
Cadence: before contract, then annually or on a trigger, by tier.
Output: a residual risk rating, remediation actions and a signed approval or risk acceptance.
A low-cost analytics script on your checkout page can see every customer’s session. A six-figure facilities contract may touch no data at all. Tier on what the vendor can reach and what stops if it fails, then let the tier decide the questionnaire, the evidence and how often you look again.
Four phases take every vendor from tiering to signed approval. Phases 4, 6 and 7 appear only for processors, annual reassessments and DORA financial entities.
The answers on the first task decide whether Phases 4, 6 and 7 appear, and how deep Phase 3 goes.
For Tier 3 vendors only the questionnaire and follow-up tasks appear.
Shown only when the vendor will process personal data on your behalf. Article numbers are the same in the EU GDPR and the UK GDPR.
Shown only for an annual reassessment. Start it alongside Phase 1 so the re-rating reflects what changed.
Shown only when the organisation is an EU financial entity in scope of DORA and the vendor provides ICT services.
Regulators and frameworks describe the same life cycle in different words: plan, assess before you sign, contract, monitor and exit. The table maps the main sources to the phase that produces the evidence. Which rows bind you depends on your sector and where you operate, so treat the table as a starting point, not legal advice.
| Applies to | Source and what it expects | Evidenced in |
|---|---|---|
| US banking organisations | Interagency Guidance on Third-Party Relationships: Risk Management (June 2023): planning, due diligence and selection, contract negotiation, ongoing monitoring and termination | Phases 1–6 |
| EU financial entities | DORA, Regulation (EU) 2022/2554, applying from 17 January 2025: register of information and pre-contract assessment (Art. 28), key contractual provisions (Art. 30), exit strategies (Art. 28(8)) | Phases 5 and 7 |
| Controllers using processors | EU GDPR and UK GDPR Art. 28: processors with sufficient guarantees, a written contract with the Art. 28(3) terms, controls on subprocessors; Art. 33(2) breach notice to the controller | Phase 4 |
| NIS2 essential and important entities | Directive (EU) 2022/2555 Art. 21(2)(d) and 21(3): supply chain security, weighing each direct supplier’s vulnerabilities and security practices | Phases 2 and 3 |
| ISO/IEC 27001:2022 certified organisations | Annex A 5.19 to 5.23: supplier relationships, supplier agreements, ICT supply chain, monitoring of supplier services, cloud services | Phases 1, 3, 5 and 6 |
| SOC 2 service organisations | Common criterion CC9.2: assessing and managing risks from vendors and business partners | Phases 3, 5 and 6 |
| Any organisation using NIST guidance | NIST CSF 2.0 GV.SC-04 to GV.SC-07 and GV.SC-10 (criticality, contract requirements, due diligence, monitoring, post-relationship); NIST SP 800-161 Rev. 1 for supply chain practices | Phases 1–6 |
On 11 September 2026 the OCC, the Federal Reserve, the FDIC and the NCUA proposed guidance that would rescind and replace the 2023 interagency guidance, moving the focus from “critical activities” to the size and likelihood of harm. Comments are due by 16 November 2026; at the time of review the 2023 guidance still applies. Questionnaires change too: Shared Assessments releases a new SIG each year, and the Cloud Security Alliance published CAIQ v4.1 in January 2026, accepting v4.0 in its STAR registry until December 2027. Record which version each vendor answered.
Conditional logic reads the first task. A Tier 3 vendor with no personal data gets a short assessment, a processor gets the Article 28 checks, and an ICT provider to a bank gets the DORA phase.
A recurring schedule per vendor starts the annual reassessment before it falls due and assigns it to the vendor’s owner. Keep the vendor inventory in a data set and each checklist opens with tier and owner filled in.
Residual risk sign-off runs as an approval, evidence sits on the task it supports, and the activity trail shows who rated each risk and when. When an auditor samples five vendors, each file is complete.
CheckFlow is not a GRC or third-party risk platform, a security ratings scanner or a certification body, and it does not score questionnaires. It runs the assessment work and sign-offs around your vendors’ evidence. Setting the vendor up is a separate job: the Vendor Onboarding Checklist covers entity details, bank verification and AP setup, and CheckFlow’s vendor onboarding software shows how legal, security and finance steps run in sequence.
When a vendor sends a SOC 2 report, the SOC Report Review Checklist takes the detailed read of opinions, exceptions and user entity controls. Our vendor onboarding guide covers access provisioning and offboarding, and CheckFlow’s compliance checklist software shows how recurring reviews and approvals work across your compliance calendar.
It is the due diligence an organisation carries out on a third party to decide whether to accept the risk the relationship creates. It covers what the vendor can access, how critical the service is, what evidence of control it can show and which contract terms are needed. It ends in a rating and a decision, and is repeated on a schedule set by the vendor’s tier.
Inherent risk is the exposure the relationship creates before any control: the data, access and dependency involved. Residual risk is what remains after the vendor’s demonstrated controls and your contract terms. Inherent risk decides how hard you look; residual risk decides whether you proceed.
Most rules set no fixed interval and expect monitoring in proportion to risk. A common pattern is annual reassessment for the top tier, every two or three years for the middle tier and review at renewal for the lowest. Reassess early after a breach, a change of ownership or a new subprocessor.
The SIG, from Shared Assessments, is a broad third-party risk questionnaire covering security, privacy, resilience and other risk domains. It is available to members and subscribers, updated every year and scoped at Lite, Core or Detail level. The CAIQ, from the Cloud Security Alliance, is a free set of yes/no questions built on its Cloud Controls Matrix for cloud providers; version 4.1 was released in January 2026. Many cloud vendors publish a completed CAIQ.
It is strong evidence, not a complete assessment. A SOC 2 Type 2 report tells you how the vendor’s controls operated over a past period, for the system and criteria in its scope. It does not tell you whether that scope covers your service, whether the exceptions matter to you or whether you operate the user entity controls it assumes. Read it in full and carry the gaps into the residual risk rating.
Article 28(3) of DORA requires EU financial entities to keep a register of all contractual arrangements for ICT services from third-party providers, distinguishing those that support critical or important functions. Its format is set by Implementing Regulation (EU) 2024/2956. Entities report it to their competent authority at least yearly; the 2026 submissions used a reference date of 31 December 2025. The European Supervisory Authorities used the registers to designate the first critical ICT third-party providers in November 2025.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.