A vendor risk assessment evaluates the risk a third party introduces before you onboard them — and on an ongoing basis afterwards. Done ad hoc, it's a box-ticking exercise. Done as a structured, repeatable process, it's one of the highest-leverage things a security team can do. Here's a step-by-step approach.
Step 1: Inventory and tier your vendors
You can't assess what you can't see. Build a current list of vendors, then rank them by the sensitivity of the data they touch and how critical they are to your operations, so effort matches risk.
Step 2: Send a structured questionnaire
Use a standard questionnaire so results are comparable across vendors, scaled to the vendor's tier — a deeper set for a vendor holding sensitive data, a lighter one for a low-risk tool.
- Security controls: access, encryption, secure development.
- Certifications and attestations: ISO 27001, SOC 2, PCI DSS where relevant.
- Data handling: what data they process, where, and their sub-processors.
- Incident history and breach-notification commitments.
Step 3: Review evidence, don't take answers at face value
Ask for supporting evidence — certificates, reports, policies — and check it against the answers. A claim without evidence is a gap.
Step 4: Score the risk
Turn the assessment into a comparable risk score that reflects both the vendor's controls and the criticality of what they support. This is what lets you prioritise and report.
Step 5: Remediate and monitor continuously
Track remediation of any gaps, and treat the score as a living number that updates as assessments, contracts and the services a vendor supports change — not a once-a-year snapshot. This continuous approach is the core of Pelta's third-party risk module: a unified vendor profile, a structured assessment pipeline with AI triage, and live risk scoring.
Frequently asked questions
What is a vendor risk assessment?+
A vendor risk assessment evaluates the security, compliance and operational risk a third party introduces, using a structured questionnaire and supporting evidence, both before onboarding and on an ongoing basis.
What questions should a vendor risk assessment include?+
Cover security controls, certifications (ISO 27001, SOC 2, PCI DSS), data handling and sub-processors, and incident history — scaled to how critical the vendor is and how sensitive the data they touch.
How often should you reassess vendors?+
Critical vendors warrant more frequent review, but the best practice is continuous monitoring so risk scores update as circumstances change, rather than relying on an annual reassessment.