Vendor Risk Assessment

Assess new and existing vendors against security, compliance, and operational controls.

Frequently asked questions

What is a vendor risk assessment?

A vendor (or third-party) risk assessment evaluates a supplier or SaaS provider against your security, compliance and operational requirements before — and during — the relationship. This tool runs a guided questionnaire, weights the answers, and produces a tiered risk rating you can defend to auditors.

Does it work for both new and existing vendors?

Yes. Use it for onboarding due diligence on a new vendor or for periodic reassessment of an existing one. Each assessment is saved as a reusable record, completed assessments keep point-in-time history snapshots, and a next-review date is set automatically from the residual risk tier (High every 180 days, Medium yearly, Low every 2 years).

Is the vendor data I enter kept private?

Yes — the tool is fully client-side. Nothing you enter about a vendor is uploaded; export to PDF or JSON to store or share it. To record any risks you identify, use the Risk Register.

How is the vendor risk score calculated?

The tool uses the standard TPRM residual-risk model: Phase 1 scores inherent risk (business criticality, data sensitivity, integration depth, regulatory exposure), Phase 2 measures weighted control effectiveness, and residual risk = inherent × (1 − control effectiveness). Critical controls (MFA, encryption, breach notification, DPA, sanctions screening) force a High rating if failed, and Yes answers without evidence are discounted until verified.