A vendor risk assessment evaluates the risk a third party introduces before you onboard them — and on an ongoing basis afterwards. Done ad hoc, it's a box-ticking exercise. Done as a structured, repeatable process, it's one of the highest-leverage things a security team can do. Here's a step-by-step approach.
Step 1: Inventory and tier your vendors
You can't assess what you can't see. Build a current list of vendors, then rank them by the sensitivity of the data they touch and how critical they are to your operations, so effort matches risk.
Step 2: Send a structured questionnaire
Use a standard questionnaire so results are comparable across vendors, scaled to the vendor's tier — a deeper set for a vendor holding sensitive data, a lighter one for a low-risk tool.
- Security controls: access, encryption, secure development.
- Certifications and attestations: ISO 27001, SOC 2, PCI DSS where relevant.
- Data handling: what data they process, where, and their sub-processors.
- Incident history and breach-notification commitments.
Step 3: Review evidence, don't take answers at face value
Ask for supporting evidence — certificates, reports, policies — and check it against the answers. A claim without evidence is a gap.
Step 4: Score the risk
Turn the assessment into a comparable risk score that reflects both the vendor's controls and the criticality of what they support. This is what lets you prioritise and report.
Step 5: Remediate and monitor continuously
Track remediation of any gaps, and treat the score as a living number that updates as assessments, contracts and the services a vendor supports change — not a once-a-year snapshot. This continuous approach is the core of Pelta's third-party risk module: a unified vendor profile, a structured assessment pipeline with AI triage, and live risk scoring.
Frequently asked questions
What is a vendor risk assessment?+
A vendor risk assessment evaluates the security, compliance and operational risk a third party introduces, using a structured questionnaire and supporting evidence, both before onboarding and on an ongoing basis.
What questions should a vendor risk assessment include?+
Cover security controls, certifications (ISO 27001, SOC 2, PCI DSS), data handling and sub-processors, and incident history — scaled to how critical the vendor is and how sensitive the data they touch.
How often should you reassess vendors?+
Critical vendors warrant more frequent review, but the best practice is continuous monitoring so risk scores update as circumstances change, rather than relying on an annual reassessment.
About the author
The Pelta Team
Pelta Technologies
Written and reviewed by Pelta's compliance practitioners.