Assess new and existing vendors against security, compliance, and operational controls.
A vendor (or third-party) risk assessment evaluates a supplier or SaaS provider against your security, compliance and operational requirements before — and during — the relationship. This tool runs a guided questionnaire, weights the answers, and produces a tiered risk rating you can defend to auditors.
Yes. Use it for onboarding due diligence on a new vendor or for periodic reassessment of an existing one. Each assessment is saved as a reusable record, completed assessments keep point-in-time history snapshots, and a next-review date is set automatically from the residual risk tier (High every 180 days, Medium yearly, Low every 2 years).
Yes — the tool is fully client-side. Nothing you enter about a vendor is uploaded; export to PDF or JSON to store or share it. To record any risks you identify, use the Risk Register.
The tool uses the standard TPRM residual-risk model: Phase 1 scores inherent risk (business criticality, data sensitivity, integration depth, regulatory exposure), Phase 2 measures weighted control effectiveness, and residual risk = inherent × (1 − control effectiveness). Critical controls (MFA, encryption, breach notification, DPA, sanctions screening) force a High rating if failed, and Yes answers without evidence are discounted until verified.
Import a previously exported JSON assessment. If the same ID already exists, it will be updated.