A vendor risk assessment turns a new supplier relationship from an unknown into a documented, scored decision. Do it well and it protects you; do it as a checkbox and it just generates paper. This guide walks the steps, the evidence that matters, how to score what you find, and how to size the effort to the risk instead of to a form.
A vendor risk assessment is the structured evaluation of the risk a specific supplier poses to your organization — gathering evidence about their security, compliance, and stability, and scoring it so you can make and record an informed decision about the relationship.
A vendor risk assessment is one evaluation of one supplier. It sits inside the wider discipline of third-party risk management: where TPRM is the whole program, the assessment is the specific act of judging what a vendor can access, how well they protect it, and what happens to you if they fail. The output isn't a questionnaire on file — it's a scored, documented decision you can defend to an auditor or a regulator.
A good assessment looks at more than cybersecurity. A vendor can hurt you by suffering a breach, but also by going insolvent, breaching a regulation, or failing to deliver a service you depend on. Cyber, financial, compliance, operational, and reputational risk all belong in the same picture.
Assessment isn't a one-time gate at onboarding. Run one at three moments:
Match the evidence to the tier rather than demanding everything from everyone. For a high-exposure vendor, that typically means a completed security questionnaire, a current SOC 2 Type II report or ISO/IEC 27001 certificate, a penetration-test summary, financial stability signals, and the relevant policies. Crucially, accept existing evidence in place of re-asking: if a vendor's SOC 2 already answers a control question, don't make them answer it again. Our guide to SOC 2 vs ISO 27001 covers what each attestation actually proves.
The point of the evidence is to reduce uncertainty about the risk that matters for this vendor — not to fill a folder. If a document doesn't change your decision, it doesn't belong in the assessment.
The most common mistake is sending every vendor the same enormous questionnaire to feel thorough. It backfires: it buries the answers that matter, delays onboarding, and trains vendors to autopilot through your questions. The fix is to let the vendor's own exposure — across data, network, facilities, designs, people, and supply — decide how hard you look.
That is the inside-out approach, and it makes assessment proportionate again: full-depth scrutiny for the few vendors who could genuinely hurt you, a signed attestation for the print shop. Depth follows exposure — not spend, and not an external security score that only measures what a vendor shows the public internet.
It classifies every vendor in your register by your exposure, then applies full-depth scrutiny only where it's warranted — so assessments land where the risk actually is, across the whole register rather than a sample.
How inside-out classification works →The structured evaluation of the risk a specific supplier poses — gathering evidence about their security, compliance, and financial stability, and scoring it to make and record an informed decision about the relationship.
On a cadence set by tier: high-exposure vendors more frequently, low-exposure ones less. Material change — a breach, ownership change, or lapsed certification — should trigger an off-cycle review regardless of schedule.
Matched to the tier: a security questionnaire, certifications such as SOC 2 or ISO 27001, penetration-test summaries, financials, and relevant policies. Accept existing evidence in place of re-asking questions it already answers.
A security rating grades a vendor's internet-facing posture from the outside. A vendor risk assessment evaluates what that vendor holds or can reach of yours and how they protect it — the exposure a rating can't see. Ratings are one input; the assessment is the decision.