Vendor Risk Assessment Checklist Template

Most vendor risk files are strongest the day the contract is signed. Then nobody opens them again until the vendor reports an incident.

A vendor risk assessment is the security and risk due diligence on a third party before you depend on it, repeated while you do. This free vendor risk assessment checklist is for security, risk and privacy teams assessing SaaS, cloud and IT suppliers, outsourcers and other third parties. It takes one vendor from criticality tiering and inherent risk, through questionnaire and assurance evidence, to a residual risk rating, contract clauses and a signed approval, and runs the annual reassessment too. Answers on the first task add a data protection phase for processors and a DORA phase for EU financial entities. Each run leaves a dated record of what you knew, what you accepted and who accepted it.

Use This Template Free See Live Example
No Credit Card Required

Last reviewed: September 2026

Setting Up a Vendor and Assessing Its Risk Are Different Jobs

Onboarding makes a supplier payable. A risk assessment answers a different question. If this vendor failed or was breached, how much harm would it do, and how much of that do its controls and our contract remove? The first half is inherent risk. The second is residual risk, which someone accountable must accept in writing.

Evidence is not all equal. An independent report, such as a SOC 2 Type 2 or an accredited ISO/IEC 27001 certificate whose scope covers the service you buy, outweighs a questionnaire. A standard questionnaire, such as the Shared Assessments SIG or the Cloud Security Alliance’s CAIQ, outweighs a bespoke one. Most failures come from mixing the levels up: treating self-attested answers as assurance, or a certificate for the vendor’s data centre as cover for its SaaS platform.

Vendor onboarding

Run by procurement and accounts payable

Covers: business need, legal entity, tax and bank details, insurance, ERP setup and kickoff.

Cadence: once, when the vendor is added.

Output: an active, payable supplier record.

Vendor risk assessment

Owned by security, risk or privacy

Covers: criticality, inherent risk, assurance evidence, data protection terms, residual risk and exit.

Cadence: before contract, then annually or on a trigger, by tier.

Output: a residual risk rating, remediation actions and a signed approval or risk acceptance.

Tier by impact, not by spend

A cheap vendor can be a critical one

A low-cost analytics script on your checkout page can see every customer’s session. A six-figure facilities contract may touch no data at all. Tier on what the vendor can reach and what stops if it fails, then let the tier decide the questionnaire, the evidence and how often you look again.

What the Vendor Risk Assessment Checklist Covers

Four phases take every vendor from tiering to signed approval. Phases 4, 6 and 7 appear only for processors, annual reassessments and DORA financial entities.

Phase 1

Phase 1: Scope, Inventory & Criticality Tier

The answers on the first task decide whether Phases 4, 6 and 7 appear, and how deep Phase 3 goes.

  • Record the vendor, the service and the assessment type — new engagement or annual reassessment, and the scope answers that shape this checklist
  • Confirm the vendor is on the third-party inventory — with a named business owner and the contract end date
  • Map the data and access involved — data categories, where data is stored and supported from, and any API or privileged access
  • Identify fourth parties — the subprocessors and subcontractors that will handle your data or deliver material parts of the service
  • Assign the criticality tier — from the impact of a failure or breach, not spend; it sets the depth of Phases 2 and 3
Phase 2

Phase 2: Inherent Risk

  • Rate inherent risk by domain — information security, privacy, operational resilience, financial condition and regulatory exposure, before counting any vendor control
  • Assess concentration and substitutability — how many services depend on this vendor, and how long a switch would take
  • Review financial condition and adverse media — filed accounts or a credit report, litigation and changes of ownership
  • Choose the assessment method for the tier — SIG Lite, SIG Core, CAIQ or your own questionnaire, and the evidence required
  • Record the inherent risk rating and rationale — with the reviewer and date, so next year’s reassessment can see what changed
Phase 3

Phase 3: Questionnaire & Assurance Evidence

For Tier 3 vendors only the questionnaire and follow-up tasks appear.

  • Send the questionnaire chosen in Phase 2 — or accept a recent completed SIG or CAIQ the vendor already publishes, and record the version and date
  • Obtain independent assurance — a SOC 2 Type 2 report or an ISO/IEC 27001 certificate, checking the period or expiry date and that the scope covers this service
  • Send the SOC 2 report for detailed review — opinion, exceptions, subservice organisations and the user entity controls you must operate
  • Review the latest penetration test summary — date, tester independence, scope, and the status of high and critical findings
  • Check incident history and resilience — breaches disclosed, the last recovery test and the recovery time for your service
  • Challenge gaps and inconsistencies — unexplained “not applicable” answers, answers the evidence contradicts, and questions left blank
Phase 4

Phase 4: Data Protection Terms

Shown only when the vendor will process personal data on your behalf. Article numbers are the same in the EU GDPR and the UK GDPR.

  • Confirm the vendor’s role — processor, independent controller or joint controller; Article 28 terms apply where it processes on your behalf
  • Check the processing terms against Article 28(3) — documented instructions, confidentiality, Article 32 security, assistance, deletion or return, and audits
  • Review subprocessors and the change mechanism — the current list, and your right to object to additions under a general authorisation (Article 28(2))
  • Set a breach notification deadline in the contract — Article 33(2) says only “without undue delay”; fix a number of hours that leaves room for your own 72 hours
  • Check where data is accessed from — hosting and support outside the UK and EEA, and the transfer mechanism
Phase 5

Phase 5: Residual Risk, Contract & Approval

  • Rate residual risk — inherent risk after the controls the evidence actually showed, listing each gap that remains
  • Agree remediation with the vendor — each gap with a vendor owner, a due date and whether it must close before go-live
  • Agree the security and resilience clauses — security requirements, incident notice, audit rights, subcontracting, data location, exit and data return
  • Approve, or record a formal risk acceptance — residual risk above appetite needs sign-off by an accountable executive, never the requester
  • Set the next reassessment date and monitoring triggers — annual for the top tier, with incidents, ownership changes and scope changes as triggers
Phase 6

Phase 6: Annual Reassessment

Shown only for an annual reassessment. Start it alongside Phase 1 so the re-rating reflects what changed.

  • Compare the relationship with last year’s record — new services, data, users or integrations that change the tier
  • Log trigger events since the last assessment — incidents, ownership changes, subprocessor changes and missed service levels
  • Confirm last year’s remediation items closed — with evidence, or carry them forward with a new date
  • Refresh expired evidence — the new SOC 2 period, a renewed certificate and an updated questionnaire where answers have aged
  • Decide whether to renew, remediate or exit — and for exit, confirm data return or deletion and access removal
Phase 7 — DORA Financial Entities Only

Phase 7: DORA ICT Third-Party Requirements

Shown only when the organisation is an EU financial entity in scope of DORA and the vendor provides ICT services.

  • Decide whether the ICT service supports a critical or important function — the first pre-contract assessment in Article 28(4)
  • Complete the rest of the Article 28(4) assessment — supervisory conditions, risks including concentration, due diligence and conflicts of interest
  • Check the contract against Article 30(2) — and against Article 30(3) where the service supports a critical or important function
  • Update the register of information — in the templates of Implementing Regulation (EU) 2024/2956, ready for the yearly report to the competent authority
  • Document and test the exit strategy — Article 28(8) requires one for services supporting critical or important functions

Where Third-Party Risk Requirements Come From

Regulators and frameworks describe the same life cycle in different words: plan, assess before you sign, contract, monitor and exit. The table maps the main sources to the phase that produces the evidence. Which rows bind you depends on your sector and where you operate, so treat the table as a starting point, not legal advice.

Applies to Source and what it expects Evidenced in
US banking organisationsInteragency Guidance on Third-Party Relationships: Risk Management (June 2023): planning, due diligence and selection, contract negotiation, ongoing monitoring and terminationPhases 1–6
EU financial entitiesDORA, Regulation (EU) 2022/2554, applying from 17 January 2025: register of information and pre-contract assessment (Art. 28), key contractual provisions (Art. 30), exit strategies (Art. 28(8))Phases 5 and 7
Controllers using processorsEU GDPR and UK GDPR Art. 28: processors with sufficient guarantees, a written contract with the Art. 28(3) terms, controls on subprocessors; Art. 33(2) breach notice to the controllerPhase 4
NIS2 essential and important entitiesDirective (EU) 2022/2555 Art. 21(2)(d) and 21(3): supply chain security, weighing each direct supplier’s vulnerabilities and security practicesPhases 2 and 3
ISO/IEC 27001:2022 certified organisationsAnnex A 5.19 to 5.23: supplier relationships, supplier agreements, ICT supply chain, monitoring of supplier services, cloud servicesPhases 1, 3, 5 and 6
SOC 2 service organisationsCommon criterion CC9.2: assessing and managing risks from vendors and business partnersPhases 3, 5 and 6
Any organisation using NIST guidanceNIST CSF 2.0 GV.SC-04 to GV.SC-07 and GV.SC-10 (criticality, contract requirements, due diligence, monitoring, post-relationship); NIST SP 800-161 Rev. 1 for supply chain practicesPhases 1–6

On 11 September 2026 the OCC, the Federal Reserve, the FDIC and the NCUA proposed guidance that would rescind and replace the 2023 interagency guidance, moving the focus from “critical activities” to the size and likelihood of harm. Comments are due by 16 November 2026; at the time of review the 2023 guidance still applies. Questionnaires change too: Shared Assessments releases a new SIG each year, and the Cloud Security Alliance published CAIQ v4.1 in January 2026, accepting v4.0 in its STAR registry until December 2027. Record which version each vendor answered.

Why Run Your Vendor Risk Assessments in CheckFlow?

1

The tier decides the checklist

Conditional logic reads the first task. A Tier 3 vendor with no personal data gets a short assessment, a processor gets the Article 28 checks, and an ICT provider to a bank gets the DORA phase.

2

Reassessments start on their own

A recurring schedule per vendor starts the annual reassessment before it falls due and assigns it to the vendor’s owner. Keep the vendor inventory in a data set and each checklist opens with tier and owner filled in.

3

Risk acceptance has a name on it

Residual risk sign-off runs as an approval, evidence sits on the task it supports, and the activity trail shows who rated each risk and when. When an auditor samples five vendors, each file is complete.

CheckFlow is not a GRC or third-party risk platform, a security ratings scanner or a certification body, and it does not score questionnaires. It runs the assessment work and sign-offs around your vendors’ evidence. Setting the vendor up is a separate job: the Vendor Onboarding Checklist covers entity details, bank verification and AP setup, and CheckFlow’s vendor onboarding software shows how legal, security and finance steps run in sequence.

When a vendor sends a SOC 2 report, the SOC Report Review Checklist takes the detailed read of opinions, exceptions and user entity controls. Our vendor onboarding guide covers access provisioning and offboarding, and CheckFlow’s compliance checklist software shows how recurring reviews and approvals work across your compliance calendar.

Frequently Asked Questions

What is a vendor risk assessment?

+

It is the due diligence an organisation carries out on a third party to decide whether to accept the risk the relationship creates. It covers what the vendor can access, how critical the service is, what evidence of control it can show and which contract terms are needed. It ends in a rating and a decision, and is repeated on a schedule set by the vendor’s tier.

What is the difference between inherent and residual vendor risk?

+

Inherent risk is the exposure the relationship creates before any control: the data, access and dependency involved. Residual risk is what remains after the vendor’s demonstrated controls and your contract terms. Inherent risk decides how hard you look; residual risk decides whether you proceed.

How often should vendor risk assessments be done?

+

Most rules set no fixed interval and expect monitoring in proportion to risk. A common pattern is annual reassessment for the top tier, every two or three years for the middle tier and review at renewal for the lowest. Reassess early after a breach, a change of ownership or a new subprocessor.

What is the difference between the SIG and the CAIQ?

+

The SIG, from Shared Assessments, is a broad third-party risk questionnaire covering security, privacy, resilience and other risk domains. It is available to members and subscribers, updated every year and scoped at Lite, Core or Detail level. The CAIQ, from the Cloud Security Alliance, is a free set of yes/no questions built on its Cloud Controls Matrix for cloud providers; version 4.1 was released in January 2026. Many cloud vendors publish a completed CAIQ.

Is a SOC 2 report enough for vendor due diligence?

+

It is strong evidence, not a complete assessment. A SOC 2 Type 2 report tells you how the vendor’s controls operated over a past period, for the system and criteria in its scope. It does not tell you whether that scope covers your service, whether the exceptions matter to you or whether you operate the user entity controls it assumes. Read it in full and carry the gaps into the residual risk rating.

What is the DORA register of information?

+

Article 28(3) of DORA requires EU financial entities to keep a register of all contractual arrangements for ICT services from third-party providers, distinguishing those that support critical or important functions. Its format is set by Implementing Regulation (EU) 2024/2956. Entities report it to their competent authority at least yearly; the 2026 submissions used a reference date of 31 December 2025. The European Supervisory Authorities used the registers to designate the first critical ICT third-party providers in November 2025.

Is CheckFlow free for this template?

+

14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.

Every Critical Vendor Reassessed Before Its Evidence Goes Stale

Free trial — no credit card required.