Third-Party Risk

Vendor Risk Assessment: A Step-by-Step Guide

A vendor risk assessment is only useful if it's structured and repeatable. Here's a step-by-step approach — and how to keep scores current instead of stale.

The Pelta Team · Pelta Technologies7 min readUpdated

A vendor risk assessment evaluates the risk a third party introduces before you onboard them — and on an ongoing basis afterwards. Done ad hoc, it's a box-ticking exercise. Done as a structured, repeatable process, it's one of the highest-leverage things a security team can do. Here's a step-by-step approach.

Step 1: Inventory and tier your vendors

You can't assess what you can't see. Build a current list of vendors, then rank them by the sensitivity of the data they touch and how critical they are to your operations, so effort matches risk.

Step 2: Send a structured questionnaire

Use a standard questionnaire so results are comparable across vendors, scaled to the vendor's tier — a deeper set for a vendor holding sensitive data, a lighter one for a low-risk tool.

  • Security controls: access, encryption, secure development.
  • Certifications and attestations: ISO 27001, SOC 2, PCI DSS where relevant.
  • Data handling: what data they process, where, and their sub-processors.
  • Incident history and breach-notification commitments.

Step 3: Review evidence, don't take answers at face value

Ask for supporting evidence — certificates, reports, policies — and check it against the answers. A claim without evidence is a gap.

Step 4: Score the risk

Turn the assessment into a comparable risk score that reflects both the vendor's controls and the criticality of what they support. This is what lets you prioritise and report.

The bottleneck is rarely sending questionnaires — it's chasing responses and interpreting them. AI triage that summarises submissions and flags concerning answers is where lean teams get their time back.

Step 5: Remediate and monitor continuously

Track remediation of any gaps, and treat the score as a living number that updates as assessments, contracts and the services a vendor supports change — not a once-a-year snapshot. This continuous approach is the core of Pelta's third-party risk module: a unified vendor profile, a structured assessment pipeline with AI triage, and live risk scoring.

Frequently asked questions

What is a vendor risk assessment?+

A vendor risk assessment evaluates the security, compliance and operational risk a third party introduces, using a structured questionnaire and supporting evidence, both before onboarding and on an ongoing basis.

What questions should a vendor risk assessment include?+

Cover security controls, certifications (ISO 27001, SOC 2, PCI DSS), data handling and sub-processors, and incident history — scaled to how critical the vendor is and how sensitive the data they touch.

How often should you reassess vendors?+

Critical vendors warrant more frequent review, but the best practice is continuous monitoring so risk scores update as circumstances change, rather than relying on an annual reassessment.

About the author

T

The Pelta Team

Pelta Technologies

Written and reviewed by Pelta's compliance practitioners.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.