ZF/blog/vendor-risk-assessment
Practitioner6 min readMay 8, 2025

Vendor Risk Assessment Guide

Vendors expand your attack surface and your compliance scope. Here is a vendor risk assessment program that scales with your business and satisfies audit requirements.


Vendor Tiering

Not all vendors deserve equal attention. Tier vendors by risk to size your assessment effort appropriately:

  • Tier 1 (critical): Vendors with access to sensitive data, vendors providing critical services, vendors with deep system integration. Examples: cloud providers, identity providers, payment processors.
  • Tier 2 (significant): Vendors with limited sensitive data access or moderate operational dependency. Examples: HR systems, marketing tools with customer email lists.
  • Tier 3 (low): Vendors with no sensitive data access and easily replaceable. Examples: office supplies, marketing analytics with anonymized data.

Tier 1 vendors get full due diligence and ongoing monitoring. Tier 2 gets standard due diligence and periodic review. Tier 3 gets light-touch verification and infrequent review.

Tier vendors at procurement and at every renewal. Tier can change as the business relationship deepens or contracts.

Due Diligence Activities

For each new vendor or major change, conduct due diligence appropriate to tier:

  • Security questionnaire: Standard questionnaire (CAIQ, SIG, or custom) covering security controls, certifications, incident history
  • Compliance attestations review: SOC 2, ISO 27001, FedRAMP, HITRUST, or other relevant attestations. Read the actual reports, not just confirm existence.
  • Security architecture review: How does the vendor's architecture interact with your environment? What is the trust boundary?
  • Privacy review: Data flow analysis, retention practices, sub-processor list, geographic data residency
  • Financial due diligence: For Tier 1 vendors providing critical services, financial stability matters. A vendor going out of business creates operational and security risk.
  • References: Talk to other customers, particularly ones in similar regulated industries

Document the due diligence in a vendor risk record. Decisions and rationale should be auditable.

Security Clauses in Contracts

Vendor contracts should include security clauses appropriate to tier. Common clauses:

  • Information security program: Vendor maintains documented security program meeting industry standards
  • Compliance attestations: Vendor maintains specific certifications (SOC 2, ISO 27001) for the term of the agreement
  • Breach notification: Vendor notifies within specific timeframe (typically 24-72 hours) for security incidents involving customer data
  • Data handling: How vendor handles, retains, returns, or destroys customer data
  • Sub-processor restrictions: Vendor identifies sub-processors and obtains permission for changes
  • Audit rights: Customer can audit vendor's security practices, with reasonable notice
  • Insurance: Cyber liability insurance with specific minimum coverage
  • Indemnification: Vendor's liability for breaches of security obligations

Negotiate these clauses upfront. Adding them mid-contract is much harder. For Tier 1 vendors, clauses should be specific and substantive. For Tier 3, simpler clauses suffice.

Ongoing Monitoring

Initial due diligence is one snapshot. Vendors change over time. Ongoing monitoring catches deterioration:

  • Annual reviews: For Tier 1 and 2 vendors, annual review of security posture, certifications, and incidents
  • Continuous monitoring services: Tools like SecurityScorecard, BitSight, and UpGuard provide continuous external visibility into vendor security posture
  • Incident notifications: Track vendor breaches and major incidents publicly reported
  • Certification renewals: Track when vendor certifications expire; request updated reports
  • Sub-processor changes: Track changes in vendor's downstream service providers

For Tier 1 vendors, build dashboards showing each vendor's posture over time. Decline in security signals (lapsed certifications, unresolved breaches, public incidents) trigger deeper review and potentially termination.

Document monitoring activities. Auditors look for evidence of ongoing oversight, not just initial onboarding diligence.

Termination and Transition

Vendor relationships eventually end. Plan for termination at the start:

  • Data extraction: How will customer data be returned? In what format? With what timeline?
  • Data destruction: How will residual customer data be destroyed? With what verification?
  • Access revocation: How will vendor access to customer systems be removed?
  • Transition support: Will the vendor support migration to a replacement? At what cost?
  • Continuing obligations: Confidentiality, non-disclosure, and other obligations that survive termination

Termination provisions should be in the contract. Triggering termination later is much harder if these are not pre-negotiated.

For Tier 1 vendors, plan transitions in advance. Even for vendors you intend to keep, build the playbook for replacement. Vendor lock-in is a risk; reducing lock-in for critical vendors is a strategic concern.

Frequently Asked Questions

Vendor RiskThird PartyComplianceDue Diligence

Related Articles