# Vendor Risk Assessment

**Framework:** Data-sensitivity × access-level risk tiering  
**Use for:** Deciding how much security diligence a vendor needs before you send them data or grant access  
**Time required:** 20–40 minutes per vendor

---

## How to use this template

1. Score the vendor on two axes: how sensitive is the data they touch, and how much access do they get. Those two answers set the tier — everything else follows.
2. Match the diligence to the tier. A low-risk marketing tool and a vendor processing customer PII do not get the same scrutiny.
3. Require a SOC 2 Type II report and a signed DPA (Data Processing Agreement) for anything touching personal or regulated data. No report, no data.
4. Re-review high-tier vendors annually. Risk is not a one-time gate at procurement.
5. Record the decision and the evidence. When an auditor or a breach asks "why did you trust this vendor," this sheet is the answer.

---

## Header

| Field | Details |
|-------|---------|
| Vendor | [Name] |
| Service / what they do | [Description] |
| Internal owner | [Name] |
| Date assessed | [Date] |
| Re-review due | [Date — annual for high tier] |

---

## Step 1 — Score the two axes

**Data sensitivity** — what kind of data does this vendor store, process, or transmit?

- [ ] **Low** — public or non-sensitive data only (marketing copy, anonymised metrics)
- [ ] **High** — personal data (PII), regulated data (PHI, cardholder), credentials, or confidential business data

**Access level** — how deeply do they integrate with your systems?

- [ ] **Low** — isolated tool, no production access, exports only
- [ ] **High** — production access, an API into core systems, or the ability to act on your behalf

---

## Step 2 — Read the tier

| | **Low access** | **High access** |
|---|---|---|
| **High sensitivity** | Medium risk — SOC 2 review + DPA | **Full review required** — SOC 2 Type II + security questionnaire + DPA + contract clauses + annual re-review |
| **Low sensitivity** | Standard procurement | Medium risk — SOC 2 + DPA |

**This vendor's tier:** [Standard / Medium / Full review]

---

## Step 3 — Diligence checklist (scale to the tier)

| Control | Required at tier | Status |
|---------|------------------|--------|
| SOC 2 Type II report reviewed (and in date) | Medium, Full | [ ] |
| Signed DPA / data-processing terms | Medium, Full | [ ] |
| Security questionnaire completed | Full | [ ] |
| Sub-processor list reviewed | Full | [ ] |
| Data residency and retention confirmed | Full | [ ] |
| Breach-notification SLA in the contract | Full | [ ] |
| Access scoped to least privilege | Medium, Full | [ ] |
| Offboarding / data-deletion plan | Medium, Full | [ ] |
| Annual re-review scheduled | Full | [ ] |

---

## Decision

| Field | Detail |
|-------|--------|
| Decision | [Approve / Approve with conditions / Reject] |
| Conditions (if any) | [What must be true] |
| Residual risk accepted by | [Name — who owns the risk] |
| Evidence stored at | [Link / location] |

---

*Match the diligence to the data, not to the size of the vendor's logo. More on vendor risk, SOC 2, and DPAs at biztechprimer.com.*
