Vendor Risk Assessment
Assessing and managing the risk third-party vendors introduce.
What is the difference between vendor risk assessment and third-party risk management (TPRM)?
Vendor risk assessment is the process of evaluating a specific vendor. Third-party risk management (TPRM) is the broader programme that includes the policies, processes, tools, and governance structures for managing all third-party relationships. Assessment is a component of TPRM.
How often should we reassess vendors?
It depends on the risk tier. Critical vendors typically warrant annual reassessment plus continuous monitoring. Important vendors are often reassessed every two years. Standard vendors may only need assessment at onboarding and at significant contract renewals. Any vendor should be reassessed when a material change occurs — a breach, an acquisition, a significant change in the services they provide.
Do we need to assess vendors who already hold ISO 27001 or SOC 2?
You can significantly reduce the assessment burden for vendors with current, relevant certifications — but you should not eliminate it entirely. Certifications confirm that an independent auditor validated a management system at a point in time. They do not tell you whether that system is appropriate for your specific use case, or what has changed since the last audit.
What should we do if a vendor refuses to complete an assessment questionnaire?
A vendor's refusal to engage with due diligence is itself a risk signal. At a minimum, you should require them to provide alternative evidence of their security posture (audit reports, certifications). For critical vendors, refusal to engage with proportionate due diligence should be a strong disincentive to onboarding.
How do we handle a vendor breach?
Your contract should define your rights and the vendor's obligations. Typically: (1) receive timely notification per contractual terms; (2) assess the impact on your data and operations; (3) invoke your own incident response plan for the third-party breach scenario; (4) engage legal counsel on breach notification obligations to your customers and regulators; (5) evaluate the longer-term implications for the vendor relationship.
What is fourth-party risk?
Fourth-party risk refers to the vendors of your vendors — organisations you have no direct relationship with, but whose failures can still affect you through your primary vendor. A critical cloud provider may rely on a specific data centre operator; a critical software vendor may process your data using a subcontractor you have never heard of. Managing fourth-party risk requires asking your critical vendors about their own vendor risk management practices and material subcontractors.
Is vendor risk assessment the same as a cybersecurity audit?
No. A cybersecurity audit is a technical examination of a specific system's security controls, typically conducted by a qualified auditor with deep access to the environment. A vendor risk assessment is a broader evaluation of the risk a vendor poses across multiple dimensions — including but not limited to cybersecurity. Assessment typically relies on questionnaires, documents, certifications, and monitoring rather than direct technical testing of the vendor's systems.