Third-Party Risk

Vendor Risk Assessment: A Step-by-Step Guide

A vendor risk assessment is only useful if it's structured and repeatable. Here's a step-by-step approach — and how to keep scores current instead of stale.

The Pelta Team7 min readUpdated

A vendor risk assessment evaluates the risk a third party introduces before you onboard them — and on an ongoing basis afterwards. Done ad hoc, it's a box-ticking exercise. Done as a structured, repeatable process, it's one of the highest-leverage things a security team can do. Here's a step-by-step approach.

Step 1: Inventory and tier your vendors

You can't assess what you can't see. Build a current list of vendors, then rank them by the sensitivity of the data they touch and how critical they are to your operations, so effort matches risk.

Step 2: Send a structured questionnaire

Use a standard questionnaire so results are comparable across vendors, scaled to the vendor's tier — a deeper set for a vendor holding sensitive data, a lighter one for a low-risk tool.

  • Security controls: access, encryption, secure development.
  • Certifications and attestations: ISO 27001, SOC 2, PCI DSS where relevant.
  • Data handling: what data they process, where, and their sub-processors.
  • Incident history and breach-notification commitments.

Step 3: Review evidence, don't take answers at face value

Ask for supporting evidence — certificates, reports, policies — and check it against the answers. A claim without evidence is a gap.

Step 4: Score the risk

Turn the assessment into a comparable risk score that reflects both the vendor's controls and the criticality of what they support. This is what lets you prioritise and report.

The bottleneck is rarely sending questionnaires — it's chasing responses and interpreting them. AI triage that summarises submissions and flags concerning answers is where lean teams get their time back.

Step 5: Remediate and monitor continuously

Track remediation of any gaps, and treat the score as a living number that updates as assessments, contracts and the services a vendor supports change — not a once-a-year snapshot. This continuous approach is the core of Pelta's third-party risk module: a unified vendor profile, a structured assessment pipeline with AI triage, and live risk scoring.

Frequently asked questions

What is a vendor risk assessment?+

A vendor risk assessment evaluates the security, compliance and operational risk a third party introduces, using a structured questionnaire and supporting evidence, both before onboarding and on an ongoing basis.

What questions should a vendor risk assessment include?+

Cover security controls, certifications (ISO 27001, SOC 2, PCI DSS), data handling and sub-processors, and incident history — scaled to how critical the vendor is and how sensitive the data they touch.

How often should you reassess vendors?+

Critical vendors warrant more frequent review, but the best practice is continuous monitoring so risk scores update as circumstances change, rather than relying on an annual reassessment.

Put this into practice with Pelta

Book a walkthrough and see how Pelta turns compliance, third-party risk and resilience into one continuous, evidence-backed program.