Guide · Assessment

Vendor risk assessment, step by step.

Assessment · 8 min read · Updated July 2026

A vendor risk assessment turns a new supplier relationship from an unknown into a documented, scored decision. Do it well and it protects you; do it as a checkbox and it just generates paper. This guide walks the steps, the evidence that matters, how to score what you find, and how to size the effort to the risk instead of to a form.

In one sentence

A vendor risk assessment is the structured evaluation of the risk a specific supplier poses to your organization — gathering evidence about their security, compliance, and stability, and scoring it so you can make and record an informed decision about the relationship.

What a vendor risk assessment is

A vendor risk assessment is one evaluation of one supplier. It sits inside the wider discipline of third-party risk management: where TPRM is the whole program, the assessment is the specific act of judging what a vendor can access, how well they protect it, and what happens to you if they fail. The output isn't a questionnaire on file — it's a scored, documented decision you can defend to an auditor or a regulator.

A good assessment looks at more than cybersecurity. A vendor can hurt you by suffering a breach, but also by going insolvent, breaching a regulation, or failing to deliver a service you depend on. Cyber, financial, compliance, operational, and reputational risk all belong in the same picture.

When to run one

Assessment isn't a one-time gate at onboarding. Run one at three moments:

  • Onboarding. Before you sign, so findings can shape the contract — security requirements, audit rights, breach-notification clauses.
  • Periodic reassessment. On a cadence set by the vendor's tier: high-exposure vendors more often, low-exposure ones less.
  • On a trigger. Off-cycle, when something material changes — a disclosed breach, a change of ownership, financial distress, or a lapsed certification.

The steps, in order

  1. Scope the relationship. Establish exactly what the vendor will access — which data, which systems, which facilities, whose people — before you send a single question.
  2. Tier by exposure. Let what they hold of yours set the depth, so a high-exposure vendor gets full scrutiny and a low one gets a proportionate check. See vendor tiering for how.
  3. Gather evidence. Collect a security questionnaire, certifications, and policy documents matched to the tier — never the same maximal form for everyone.
  4. Score and decide. Rate the residual risk against your appetite, choose to accept, mitigate, avoid, or transfer it, and record the decision.
  5. Contract and monitor. Translate findings into contract terms, then set the reassessment cadence and watch for change.

What evidence to gather

Match the evidence to the tier rather than demanding everything from everyone. For a high-exposure vendor, that typically means a completed security questionnaire, a current SOC 2 Type II report or ISO/IEC 27001 certificate, a penetration-test summary, financial stability signals, and the relevant policies. Crucially, accept existing evidence in place of re-asking: if a vendor's SOC 2 already answers a control question, don't make them answer it again. Our guide to SOC 2 vs ISO 27001 covers what each attestation actually proves.

The point of the evidence is to reduce uncertainty about the risk that matters for this vendor — not to fill a folder. If a document doesn't change your decision, it doesn't belong in the assessment.

Scope depth to exposure, not to a form

The most common mistake is sending every vendor the same enormous questionnaire to feel thorough. It backfires: it buries the answers that matter, delays onboarding, and trains vendors to autopilot through your questions. The fix is to let the vendor's own exposure — across data, network, facilities, designs, people, and supply — decide how hard you look.

That is the inside-out approach, and it makes assessment proportionate again: full-depth scrutiny for the few vendors who could genuinely hurt you, a signed attestation for the print shop. Depth follows exposure — not spend, and not an external security score that only measures what a vendor shows the public internet.

Assess by exposure
Polestead scopes assessment depth to what a vendor holds.

It classifies every vendor in your register by your exposure, then applies full-depth scrutiny only where it's warranted — so assessments land where the risk actually is, across the whole register rather than a sample.

How inside-out classification works →
FAQ

Common questions.

What is a vendor risk assessment?+

The structured evaluation of the risk a specific supplier poses — gathering evidence about their security, compliance, and financial stability, and scoring it to make and record an informed decision about the relationship.

How often should vendors be reassessed?+

On a cadence set by tier: high-exposure vendors more frequently, low-exposure ones less. Material change — a breach, ownership change, or lapsed certification — should trigger an off-cycle review regardless of schedule.

What evidence should an assessment gather?+

Matched to the tier: a security questionnaire, certifications such as SOC 2 or ISO 27001, penetration-test summaries, financials, and relevant policies. Accept existing evidence in place of re-asking questions it already answers.

How is a vendor risk assessment different from a security rating?+

A security rating grades a vendor's internet-facing posture from the outside. A vendor risk assessment evaluates what that vendor holds or can reach of yours and how they protect it — the exposure a rating can't see. Ratings are one input; the assessment is the decision.

Keep reading
Third-party risk management
The full program this sits inside.
Vendor tiering
How to set assessment depth by risk.
Inside-out risk →
How Polestead scopes depth.