A vendor risk assessment is the structured evaluation of a vendor's security and compliance posture, scaled to the access and data that vendor holds. The depth is the design decision: a payroll processor with employee records warrants certifications and contract review, while a marketing tool holding generic business data needs a documented risk rating and nothing more.
Vendor risk assessment at a glance
- What it evaluates: the vendor's security posture, proportional to the data and system access the vendor has
- Core method: tier vendors by risk, then match assessment depth to the tier
- Evidence commonly accepted: SOC 2 reports, ISO 27001 certificates, completed DDQs, penetration test summaries, contract security clauses
- Where it fits: the assessment and due diligence steps of vendor risk management, inside the broader third-party risk management discipline
- Compliance mapping: SOC 2 CC9.2, ISO 27001 supplier controls (A.5.19 to A.5.22), NIST SP 800-161
- The common failure: assessing every vendor at the same depth, which stalls the program and buries the vendors that matter
A real example makes the case for proportionality. One SaaS company preparing for SOC 2 had entered every vendor into their GRC platform: their bank, open-source tools, low-risk marketing utilities. The dashboard showed dozens of incomplete assessments, when most of those entries needed no formal assessment at all. Proportionality is what makes a vendor security assessment program sustainable, and it is also what auditors expect to see.
How do you tier vendors by risk?
Tiering starts with one question: what can this vendor touch? A practical classification uses four data access categories, and it takes about an hour to run across a full vendor list.
- Production data. The vendor stores, processes, or can reach customer data or production systems. Cloud infrastructure, subprocessors, data platforms.
- Development data. The vendor touches source code, CI/CD pipelines, or pre-production environments.
- Employee information. HR platforms, payroll processors, benefits providers.
- Generic business information. Marketing tools, task trackers, scheduling apps holding nothing sensitive.
A vendor that touches none of the sensitive categories is low risk, and documenting that conclusion is the entire assessment. In the SOC 2 preparation engagement above, this classification cut the vendor assessment workload by more than half in an afternoon.
Data access is the anchor, and four more criteria refine the tier:
- System access. Does the vendor hold credentials, API keys, or network connectivity into the environment? An integration with write access to production is high risk regardless of what data it stores.
- Operational criticality. If this vendor goes down, does the product go down? Criticality raises the tier even when data exposure is low.
- Certifications held. A current SOC 2 report or ISO 27001 certificate does not lower the inherent tier, but it changes what evidence the assessment needs to collect.
- Incident history. A vendor with a recent public breach or a pattern of security advisories warrants a closer look than its data access alone suggests.
Keep it to three tiers
Three tiers are enough for nearly every organization. More granularity than that tends to produce debate about boundaries instead of finished assessments.
What should the assessment include at each tier?
Depth follows tier. The table below is a working default that holds up in audits:
| Tier | Typical vendors | Assessment depth | Evidence accepted |
| High: production data or system access, or business-critical | Cloud infrastructure, subprocessors, managed service providers | Full assessment: DDQ or certification review, contract security clauses, annual reassessment | SOC 2 Type 2 report, ISO 27001 certificate with Statement of Applicability, penetration test summary, completed full DDQ |
| Medium: development or employee data, no production access | HR and payroll platforms, dev tooling, analytics | Focused review: certification check or short-form questionnaire on the relevant risk area | SOC 2 or ISO 27001 certificate, short-form DDQ, security whitepaper plus contract terms |
| Low: generic business information only | Marketing tools, schedulers, internal utilities | Documented risk rating with data categories; reassess only on scope change | The classification record itself |
Two notes on using the table. First, the low-tier row is a complete assessment, and treating it as a shortcut misses the point. Under SOC 2 CC9.2 the auditor wants evidence that vendor risks are assessed and managed through informed decisions, and a documented one-paragraph rating that says this vendor holds no sensitive data and is rated low risk is exactly that evidence. Second, tier assignments are living records: a marketing tool that adds a product integration moves tiers, so the assessment process needs a trigger for scope changes, usually at contract renewal.
ISO 27001's supplier controls (A.5.19 through A.5.22 in the 2022 revision) expect the same shape: identify supplier risks, address security in supplier agreements, and monitor and review supplier services on a cadence. NIST SP 800-161 provides the deep control catalog for organizations that need to go further, particularly in regulated or government supply chains.
When is documentary evidence enough?
Documentary evidence, meaning certifications, audit reports, and completed questionnaires, is sufficient for the large majority of vendors. A deeper review, such as a technical validation call, an architecture review, or in rare cases an on-site audit, is justified when at least one of these holds:
- The vendor is high tier and holds no recognized certification
- The vendor's role is unusual enough that a generic SOC 2 scope does not cover the service being purchased
- Contractual or regulatory obligations flow through the vendor (a customer's PCI DSS or healthcare requirements, for example)
- The relationship involves custom development or dedicated infrastructure rather than standard multi-tenant service
Everything else is disproportionate effort. Insisting on a call with every vendor's security team is how assessment queues grow into quarters-long backlogs.
How do you read a SOC 2 report as assessment evidence?
A SOC 2 report answers most of a vendor risk assessment on its own, but only when it is read rather than filed. Four checks turn the report into a real assessment:
- Report type and period. A Type 2 report covers operating effectiveness over a period, usually 6 to 12 months, and is the meaningful one. A Type 1 is a point-in-time design snapshot. The guide to SOC report types breaks down the differences and which report answers which question.
- Scope. Confirm the system described in the report is the service being purchased. Vendors sometimes certify one product line and sell another.
- Exceptions and qualified opinions. The auditor's exceptions list is where the substance lives. An exception on access reviews at a vendor holding production data is a finding for the assessment, not a footnote.
- Complementary User Entity Controls (CUECs). This section lists the controls the vendor cannot enforce and the customer must implement: SSO configuration, role assignments, log monitoring. Experienced TPRM teams read CUECs early because they reveal how much security work the vendor pushes back across the table. Every CUEC that applies becomes an action item in the buying organization, and skipping them means the assessment approved a system nobody finished securing.
Reading an ISO 27001 certificate
An ISO 27001 certificate confirms a certified management system exists, but the certificate alone says little about specific controls. Ask for the Statement of Applicability to see which Annex A controls are in scope, and confirm the certificate is current and issued by an accredited body.
How do you handle DDQs without drowning in them?
The due diligence questionnaire (DDQ) sits on both sides of vendor risk, and most teams handle both sides badly in the same way: uniformly instead of proportionally.
Sending DDQs. Match the questionnaire to the tier and the service. Sending a janitorial vendor the same DDQ as a cloud provider is disproportionate and counterproductive: the vendor answers badly or slowly, the review stalls, and the noise buries the assessments that matter. High-tier vendors without certifications get the full questionnaire. Vendors with a current SOC 2 or ISO 27001 get a short supplement covering only what the certification does not, such as data residency or breach notification specifics. Low-tier vendors get nothing.
Answering DDQs. Customer questionnaires arrive continuously, and organizations that treat each one as a fresh writing project lose days per response. The working model is a pre-approved answer library: a maintained database of reviewed answers mapped to the recurring topic areas (access control, incident response, patch management, encryption, business continuity), with clear rules about which documents are externally shareable before a contract exists. Responses become assembly rather than authorship. The security questionnaire automation post covers how teams operationalize this side.
The answer library does double duty
The questions customers keep asking are a free map of what enterprise TPRM teams evaluate, which makes them a useful checklist for assessing vendors in turn.
When is a full vendor risk assessment overkill?
An honest program skips assessments in three situations, and documenting the skip is what keeps the auditor comfortable.
Low-risk vendors. A vendor holding only generic business information needs a recorded risk rating, nothing more. A bank processing payroll is a common over-scoping example: payroll flows through the HR system, so the bank typically sits outside assessment scope entirely. Locally-run open-source tools are not vendors at all; they belong in software inventory, not the vendor register.
Standardized hyperscale providers. Sending AWS, Microsoft, or Google a DDQ produces a link to their compliance portal, because their certifications and terms are standardized and non-negotiable. For these providers the risk lives in the configuration, not the provider: the assessment effort belongs on the organization's own IAM policies, encryption settings, and logging, which is where the shared responsibility model places it. The SOC 2 vendor management post for data center providers covers how auditors treat this class of vendor.
When the real gap is the inventory. A company that cannot list its vendors has no basis for assessing them, and assessments run against a partial list create confidence the organization has not earned. If procurement happens by credit card and nobody knows what is under contract, the first project is reconstructing the vendor register from financial records. Assessment comes second.
Where vendor risk assessment fits in a security program
Vendor risk management is one of the roughly 19 security capabilities that make up an effective security program, and the assessment is its engine: tiering decides where attention goes, and the assessment produces the record that decisions were informed. Run this way, the program generates its SOC 2 CC9.2 evidence as a byproduct of normal operation, with the tier rationale, collected reports, and reassessment cadence standing as the audit trail. The third party risk management guide covers the full discipline the assessment step plugs into, from vendor inventory through incident management.
Right-Size Your Vendor Risk Program
Risk tiers, evidence cadence, and a DDQ library, built inside an effective security program.
Frequently Asked Questions
What is the difference between a vendor risk assessment and third-party risk management?
A vendor risk assessment is one activity: evaluating a specific vendor's security and compliance posture. Third-party risk management (TPRM) is the full discipline around it, covering vendor inventory, contracts, ongoing assurance, and incident management, and extending to customers and partners when those relationships carry data or regulatory obligations.
How often should vendors be reassessed?
Annually for high-risk vendors, and at contract renewal or scope change for the rest. Certifications expire and postures drift, so reassessment confirms the evidence is still current. A tier change trigger matters as much as the calendar: a low-risk tool that gains production access needs reassessment immediately.
What is a vendor risk assessment questionnaire?
A structured set of questions, often called a due diligence questionnaire or DDQ, sent to a vendor to evaluate its security controls, covering areas like access control, encryption, incident response, and business continuity. Mature programs scale the questionnaire to the vendor's risk tier instead of sending one master version to everyone.
Is a SOC 2 report enough to pass a vendor assessment?
Often, for the areas it covers. A current Type 2 report with clean opinions, correct scope, and reviewed CUECs answers most control questions for a high-tier vendor. Gaps remain around specifics like data residency and breach notification timelines, which a short supplemental questionnaire or contract clauses should close.
Are free vendor risk assessment templates worth using?
As a starting structure, yes: standardized question sets such as SIG or CAIQ save authoring time. The template is the smaller half of the work, though. Tiering, deciding what evidence to accept, and acting on findings are what make the assessment real, and no template supplies those decisions.
Do low-risk vendors need any assessment at all?
Yes, a minimal one: a documented risk rating recording what data categories the vendor touches and why it is rated low. That record is a complete assessment for a low-risk vendor and satisfies what SOC 2 CC9.2 asks for, which is evidence of informed decisions about vendor risk rather than equal scrutiny for every vendor.
Ready to Start Your Compliance Journey?
Get a clear, actionable roadmap with our readiness assessment.
Contact Us
About the Author
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure.
How Ready Are You for SOC 2?
Score your security program in under 5 minutes. Free.
Take the Scorecard