Vendor Risk Assessment
Framework: Data-sensitivity × access-level risk tiering
Use for: Deciding how much security diligence a vendor needs before you send them data or grant access
Time required: 20–40 minutes per vendor
How to use this template
- Score the vendor on two axes: how sensitive is the data they touch, and how much access do they get. Those two answers set the tier — everything else follows.
- Match the diligence to the tier. A low-risk marketing tool and a vendor processing customer PII do not get the same scrutiny.
- Require a SOC 2 Type II report and a signed DPA (Data Processing Agreement) for anything touching personal or regulated data. No report, no data.
- Re-review high-tier vendors annually. Risk is not a one-time gate at procurement.
- Record the decision and the evidence. When an auditor or a breach asks "why did you trust this vendor," this sheet is the answer.
Header
| Field | Details |
|---|---|
| Vendor | [Name] |
| Service / what they do | [Description] |
| Internal owner | [Name] |
| Date assessed | [Date] |
| Re-review due | [Date — annual for high tier] |
Step 1 — Score the two axes
Data sensitivity — what kind of data does this vendor store, process, or transmit?
- Low — public or non-sensitive data only (marketing copy, anonymised metrics)
- High — personal data (PII), regulated data (PHI, cardholder), credentials, or confidential business data
Access level — how deeply do they integrate with your systems?
- Low — isolated tool, no production access, exports only
- High — production access, an API into core systems, or the ability to act on your behalf
Step 2 — Read the tier
| Low access | High access | |
|---|---|---|
| High sensitivity | Medium risk — SOC 2 review + DPA | Full review required — SOC 2 Type II + security questionnaire + DPA + contract clauses + annual re-review |
| Low sensitivity | Standard procurement | Medium risk — SOC 2 + DPA |
This vendor's tier: [Standard / Medium / Full review]
Step 3 — Diligence checklist (scale to the tier)
| Control | Required at tier | Status |
|---|---|---|
| SOC 2 Type II report reviewed (and in date) | Medium, Full | [ ] |
| Signed DPA / data-processing terms | Medium, Full | [ ] |
| Security questionnaire completed | Full | [ ] |
| Sub-processor list reviewed | Full | [ ] |
| Data residency and retention confirmed | Full | [ ] |
| Breach-notification SLA in the contract | Full | [ ] |
| Access scoped to least privilege | Medium, Full | [ ] |
| Offboarding / data-deletion plan | Medium, Full | [ ] |
| Annual re-review scheduled | Full | [ ] |
Decision
| Field | Detail |
|---|---|
| Decision | [Approve / Approve with conditions / Reject] |
| Conditions (if any) | [What must be true] |
| Residual risk accepted by | [Name — who owns the risk] |
| Evidence stored at | [Link / location] |
Match the diligence to the data, not to the size of the vendor's logo. More on vendor risk, SOC 2, and DPAs at biztechprimer.com.