Template

Vendor Risk Assessment

Framework: Data-sensitivity × access-level risk tiering
Use for: Deciding how much security diligence a vendor needs before you send them data or grant access
Time required: 20–40 minutes per vendor


How to use this template

  1. Score the vendor on two axes: how sensitive is the data they touch, and how much access do they get. Those two answers set the tier — everything else follows.
  2. Match the diligence to the tier. A low-risk marketing tool and a vendor processing customer PII do not get the same scrutiny.
  3. Require a SOC 2 Type II report and a signed DPA (Data Processing Agreement) for anything touching personal or regulated data. No report, no data.
  4. Re-review high-tier vendors annually. Risk is not a one-time gate at procurement.
  5. Record the decision and the evidence. When an auditor or a breach asks "why did you trust this vendor," this sheet is the answer.

Header

Field Details
Vendor [Name]
Service / what they do [Description]
Internal owner [Name]
Date assessed [Date]
Re-review due [Date — annual for high tier]

Step 1 — Score the two axes

Data sensitivity — what kind of data does this vendor store, process, or transmit?

Access level — how deeply do they integrate with your systems?


Step 2 — Read the tier

Low access High access
High sensitivity Medium risk — SOC 2 review + DPA Full review required — SOC 2 Type II + security questionnaire + DPA + contract clauses + annual re-review
Low sensitivity Standard procurement Medium risk — SOC 2 + DPA

This vendor's tier: [Standard / Medium / Full review]


Step 3 — Diligence checklist (scale to the tier)

Control Required at tier Status
SOC 2 Type II report reviewed (and in date) Medium, Full [ ]
Signed DPA / data-processing terms Medium, Full [ ]
Security questionnaire completed Full [ ]
Sub-processor list reviewed Full [ ]
Data residency and retention confirmed Full [ ]
Breach-notification SLA in the contract Full [ ]
Access scoped to least privilege Medium, Full [ ]
Offboarding / data-deletion plan Medium, Full [ ]
Annual re-review scheduled Full [ ]

Decision

Field Detail
Decision [Approve / Approve with conditions / Reject]
Conditions (if any) [What must be true]
Residual risk accepted by [Name — who owns the risk]
Evidence stored at [Link / location]

Match the diligence to the data, not to the size of the vendor's logo. More on vendor risk, SOC 2, and DPAs at biztechprimer.com.