Free templateExcel · Google Sheets · PDF

Vendor Risk Assessment Template

A vendor risk assessment template is a structured questionnaire and scoring sheet for reviewing third-party suppliers before you onboard them and again each year. It checks security, compliance, resilience and track record, then turns the answers into a risk rating.

  • Five-category assessment with risk scoring
  • Tier 1, 2 and 3 question banks
  • Security and due diligence questionnaires
Book a demo
Updated 7 Oct 20266 partsReviewed by the Spendflo procurement team
What's inside

Six parts, one vendor risk workbook

One workbook with six parts: the assessment, a tiered questionnaire, a security assessment, a short security questionnaire, due diligence and scoring. Click any card to open that part below.
  1. 1AssessmentThe five-category assessment with questions, evidence and a risk score for each.
  2. 2Tiered questionnaireHow many questions each tier gets, and a starter bank for each.
  3. 3Security assessmentA Tier 1 security question bank grouped by control area.
  4. 4Short questionnaireA 12-question security questionnaire for Tier 2 and Tier 3 vendors.
  5. 5Due diligenceFinancial, legal, ownership and reference checks beyond security.
  6. 6Risk scoringFormulas for scores, ratings and review dates in Excel and Sheets.

Who it's for

  • Procurement managers
  • Vendor risk analysts
  • Information security teams
  • Compliance officers
  • Legal counsel
  • IT managers
Definition

What is a vendor risk assessment template?

It is the standard set of questions and scores you apply to every supplier, so each one is judged against the same bar. A supplier risk assessment template or third party risk assessment template does the same job under a different name.

Procurement, security and compliance teams use it at two moments: before a new vendor is signed, and at each annual review or contract renewal. The depth depends on the vendor's tier, so a payroll provider holding staff data gets far more questions than an office supplies firm.

It is the working core of a vendor risk management template: the questionnaire collects evidence, the scoring sheet rates it, and the rating decides whether you approve, approve with conditions or decline the vendor.

Key components

Vendor profile

Legal name, ownership, locations, key contacts and what the vendor will do for you.

Data security and privacy

Encryption at rest and in transit, access controls and how your data is stored, shared and deleted.

Regulatory compliance

Certifications and frameworks that apply, such as SOC 2, ISO 27001, GDPR and HIPAA.

Operational resilience

Business continuity and disaster recovery plans, and whether they are tested.

Incident history

Past breaches or outages and how the vendor notifies customers when something goes wrong.

Get the vendor risk assessment template free

Ready to use in Excel, Google Sheets and PDF. Fill it in, save it, reuse it.

For beginners

How a vendor risk assessment works

You tier the vendor by risk, send the matching questionnaire, check the evidence and score the answers. The score decides approval, conditions or rejection, and sets the review date.
  1. 1
    Tier

    Rate the vendor by the data it touches, its access to systems and how critical it is to operations.

  2. 2
    Ask

    Send the Tier 1, 2 or 3 questionnaire and request evidence such as reports and certificates.

  3. 3
    Verify

    Check answers against the evidence, and follow up on any gaps or vague replies.

  4. 4
    Score

    Rate likelihood and impact for each category and calculate the overall risk score.

  5. 5
    Decide and monitor

    Approve, approve with conditions or decline, then set the next review date by tier.

Need something simpler?

The simplest version is one sheet: Vendor, Data accessed, Certifications, Last incident, Risk rating, Next review. Add the tiered questionnaires as your vendor list grows.

Part 1 · Assessment

The vendor risk assessment template

Five categories, each with core questions, the evidence to request and a likelihood and impact score. The workbook multiplies the two and rates every category and the vendor overall.

Start here for every vendor. Ask the core question in each category, collect the evidence and score the answer. The deeper question banks in the next parts plug into the same five categories.

CategoryCore questionEvidence to request
Vendor profileWho owns the company, where does it operate and what will it do for us?Registration details, ownership chart, service description
Vendor profileWhich subcontractors will touch our data or service?Subprocessor list
Data security and privacyIs our data encrypted at rest and in transit?Security policy, architecture summary
Data security and privacyWho can access our data, and how is access approved and removed?Access control policy, access review records
Regulatory complianceWhich certifications or attestations do you hold?SOC 2 Type II report, ISO 27001 certificate
Regulatory complianceHow do you meet GDPR, HIPAA or other rules that apply to our data?DPA, privacy notice, BAA where relevant
Operational resilienceDo you have tested business continuity and disaster recovery plans?BCP and DR summary, last test date and results
Incident historyHave you had a breach or major outage in the last three years?Incident summary, root cause, remediation
Incident historyHow fast will you notify us of an incident?Incident response policy, contract clause

Score it

Rate likelihood and impact from 1 to 5 for each category. Works in Excel and Google Sheets.

CategoryLikelihoodImpactScoreRating
Vendor profile224Low
Data security and privacy3515High
Regulatory compliance248Medium
Operational resilience248Medium
Incident history155Low

Illustrative scores for Cedar Health, a fictional Tier 1 payroll vendor. Highest category score sets the overall rating: High.

Part 2 · Tiered questionnaire

Vendor risk assessment questionnaire template

Ask high-risk Tier 1 vendors 50 to 60 questions, medium-risk Tier 2 vendors 25 to 30, and low-risk Tier 3 vendors 10 to 15. Tier by data access and how critical the service is.

Sending every vendor a 60-question form wastes their time and yours. Tier first, then send only the questions that match the risk. The download includes the full bank for each tier; the table shows how tiers are set and what each adds.

TierTypical vendorQuestionsReview cycle
Tier 1: highHolds sensitive or regulated data, or a critical service such as payroll, cloud hosting or payments50-60Annual, plus at renewal
Tier 2: mediumInternal data or system access, such as a CRM or analytics tool25-30Every 2 years
Tier 3: lowNo data or system access, such as office supplies or catering10-15At onboarding, then on change

Question counts follow common practice; review cycles are a typical starting point.

Tiering questions

Answer these yourself before you send anything. Any yes to the first three makes the vendor Tier 1.

#QuestionIf yes
1Will the vendor store or process personal, health or payment data?Tier 1
2Would an outage stop a critical business process for more than a day?Tier 1
3Will the vendor have privileged access to our systems or network?Tier 1
4Will the vendor access internal, non-public data?Tier 2
5Will annual spend exceed our approval threshold?Tier 2 at least
6None of the aboveTier 3
Part 3 · Security assessment

Vendor security assessment questionnaire template

The security assessment is the deepest part of a Tier 1 review, covering governance, access, encryption, monitoring and recovery. Ask for evidence on every answer rather than accepting a yes.

If the vendor holds a current SOC 2 Type II report or ISO 27001 certificate, read it first and only ask about gaps it does not cover. That shortens the questionnaire for both sides. Note any exceptions the auditor raised and ask how each was fixed.

Control areaQuestionGood answer
GovernanceWho owns information security, and when was the policy last approved?Named owner, policy reviewed in the last 12 months
GovernanceDo staff complete security training at joining and yearly?Yes, with completion records
AccessIs MFA required for all staff and admin accounts?Yes, enforced, no exceptions
AccessHow quickly is access removed when someone leaves?Same day, logged
EncryptionWhich standards protect data at rest and in transit?AES-256 at rest, TLS 1.2 or higher in transit
Data handlingWhere is our data hosted, and can we choose the region?Named regions, contractual commitment
Data handlingHow is our data returned or deleted when the contract ends?Defined process and certificate of deletion
VulnerabilitiesHow often do you run penetration tests, and by whom?Yearly, independent firm, summary shared
MonitoringAre security logs centralised and reviewed?Yes, with alerting and retention period stated
RecoveryWhat are your recovery time and recovery point objectives?Stated targets, tested in the last year

Ten of the Tier 1 security questions; the download has the full bank. Expected answers are typical benchmarks, not regulatory requirements.

Use the framework to decide what to ask, not to replace your judgement. More on vendor risk management.
Part 4 · Short questionnaire

Vendor security questionnaire template: a short security questionnaire

Lower-risk vendors get a short security questionnaire of about 12 questions that covers the basics. If any answer is weak, move the vendor up a tier.

Use this for SaaS tools with limited data access and for service providers who visit your sites. Most vendors can answer it in under an hour, so it rarely delays a purchase. Ask for one supporting document per answer where one exists.

#QuestionAnswer
1Do you hold SOC 2, ISO 27001 or another independent security attestation?Yes / No / In progress
2Is customer data encrypted at rest and in transit?Yes / No
3Is multi-factor authentication enforced for staff?Yes / No
4Can customers enforce single sign-on?Yes / No
5Do you use subprocessors that access customer data? List them.Text
6Where is customer data stored?Country or region
7Have you had a data breach in the last three years?Yes / No, with details
8How soon will you notify customers of a breach?Hours
9Do you test backups and recovery at least yearly?Yes / No
10Do you run background checks on staff with data access?Yes / No
11Will you sign our data processing agreement?Yes / No
12Who is your security contact?Name and email
Part 5 · Due diligence

Vendor due diligence questionnaire template

Due diligence checks whether the vendor is financially sound, legally clean and able to deliver. Run it for Tier 1 and Tier 2 vendors alongside the security review.

A secure vendor can still fail you if it runs out of cash or relies on one key person. These questions cover the business side of supplier risk. Combine the answers with the security score before you approve.

0 of 10 done

Ownership and legal

Financial health

Insurance

Delivery

Ethics

Part 6 · Risk scoring

Vendor risk scoring and rating

Each category score is likelihood times impact, from 1 to 25. The highest category score sets the vendor's rating, and the rating sets the decision and next review date.

Use the highest score rather than the average, so one serious gap cannot hide behind good answers elsewhere. Record both inherent risk, before controls, and residual risk, after the vendor's controls and your contract terms. Approve on residual risk.

ColHeaderEntry or formulaWhat it does
AVendorTextSupplier name
BCategoryDrop-down: five categoriesOne row per category
CLikelihood1-5How likely the risk is to occur
DImpact1-5How bad it would be
EScore=C2*D2Inherent risk, 1-25
FRating=IF(E2>=15,"High",IF(E2>=8,"Medium","Low"))Rating band
GVendor score=MAXIFS(E:E,A:A,A2)Highest category score for the vendor
HLast reviewDateWhen the assessment was completed
INext review=IF(G2>=15,EDATE(H2,12),IF(G2>=8,EDATE(H2,24),EDATE(H2,36)))Review date by rating
ScoreRatingDecision
15-25HighDecline, or approve only with remediation and senior sign-off
8-14MediumApprove with conditions written into the contract
1-7LowApprove

A common banding; adjust thresholds to your risk appetite. See third-party risk scoring.

Spendflo third-party risk management runs vendor assessments inside intake and approvals.

See TPRM in Spendflo
Glossary

Vendor risk terms, explained

These terms come up in almost every vendor risk review. Knowing them makes the evidence vendors send much easier to read.
SOC 2 Type II

An independent audit report on how a service provider's security controls operated over a period, usually 6-12 months.

ISO 27001

An international standard for information security management systems, certified by an accredited body.

GDPR

The EU and UK data protection regime that applies when personal data of people in those regions is processed.

HIPAA

US rules on protecting health information, relevant when a vendor handles it for a covered organisation.

Inherent vs residual risk

Inherent risk is before controls; residual risk is what remains after them.

Subprocessor

A third party your vendor uses that also processes your data.

Best practices

Do this, avoid that

Tier every vendor, ask for evidence rather than assurances and reassess on a schedule. Most third-party incidents involve vendors that were assessed once and never again.

Do

  • ✓
    Tier before you ask

    Match the questionnaire to the vendor's data access and criticality.

  • ✓
    Ask for evidence

    A SOC 2 report or test result beats a yes in a form.

  • ✓
    Put conditions in the contract

    Breach notice times, audit rights and data deletion belong in the agreement.

  • ✓
    Reassess on a schedule

    Set the next review date when you approve, based on the rating.

  • ✓
    Keep one record per vendor

    Store questionnaires, evidence and decisions together for audit.

Avoid

  • ×
    One form for every vendor

    Long forms for low-risk vendors slow purchases and get rushed answers.

  • ×
    Averaging scores

    An average lets one critical gap disappear among good answers.

  • ×
    Assessing after signature

    Once the contract is signed, you lose the bargaining power to fix gaps.

  • ×
    Ignoring fourth parties

    A vendor's subprocessors can expose your data just as much.

How to use it

Run your first assessment this week

List your vendors, tier them, send the matching questionnaire and score the replies. Start with the Tier 1 vendors that hold your most sensitive data.
  1. Step 1

    List and tier

    Pull active vendors from accounts payable and answer the tiering questions for each.

  2. Step 2

    Send questionnaires

    Send Tier 1 the full security and due diligence banks, Tier 3 the short form.

  3. Step 3

    Score and decide

    Enter likelihood and impact per category and record the decision and any conditions.

  4. Step 4

    Schedule reviews

    Let the next review formula set dates, and add them to your renewal calendar.

Example

One Tier 1 vendor, start to finish

Cedar Health scored High on data security because it could not show MFA on admin accounts. It was approved with conditions instead of declined.

Lumen Retail assessed Cedar Health, a payroll vendor holding staff bank details. Data security scored 15 (likelihood 3, impact 5). Cedar agreed in the contract to enforce MFA within 30 days and send evidence. Residual score dropped to 5 once confirmed, and the next review was set 12 months out. Illustrative example.

Ready to use it? Download the vendor risk assessment template

Every part on this page, in Excel, Google Sheets and PDF, with the examples filled in.

Variants

Fit it to your organisation

The five categories stay the same, but regulated sectors add deeper compliance questions. Smaller teams can start with the short questionnaire and scoring sheet alone.
Under 100 vendors

Small teams

Use the tiering questions and the short questionnaire, and reserve the full bank for the handful of Tier 1 vendors.

Healthcare and finance

Regulated sectors

Add questions for HIPAA, payment card and sector rules, and require evidence for every Tier 1 answer.

SaaS-heavy companies

Software buyers

Focus on SSO, data location, subprocessors and data deletion, since most risk sits in the software stack.

Run vendor risk reviews, contracts and renewals in one place with Spendflo TPRM.

See how it works
Bottom line

Assess once, then keep watching

A free vendor risk assessment template gives you a consistent bar for every supplier and a record auditors can follow. The value comes from tiering, asking for evidence and reassessing before each renewal.

FAQ

Frequently asked questions

Quick answers to what people ask most about the vendor risk assessment template.

How to do a vendor risk assessment?

Tier the vendor by data access and criticality, send the matching questionnaire, check the evidence, score likelihood and impact, then decide and set a review date. Download the template to get the questionnaires and scoring formulas ready to use.

What are the 5 parts of a risk assessment?

A common five-step approach is to identify risks, assess likelihood and impact, rate them, decide on controls, and review on a schedule. The free download applies those steps to vendors across five categories, from vendor profile to incident history.

Where can I download a template for risk assessment?

You can download a free vendor risk assessment template from this page in Excel, Google Sheets or PDF. It includes tiered questionnaires, a security question bank, due diligence checks and risk scoring.

What are some examples of vendor risk?

Examples include a data breach at a supplier holding your customer data, an outage at a critical provider, a vendor failing financially, sanctions exposure and compliance gaps such as missing GDPR safeguards. Download the template to check each one systematically.

What is the difference between a vendor risk assessment and a security questionnaire?

A security questionnaire covers only information security, while a vendor risk assessment also covers financial, legal, operational and compliance risk. The download includes both, plus a due diligence questionnaire.

Template library

Browse all procurement templates

See all 60 templates →

Vendor risk belongs inside the buying process.

Spendflo third-party risk management assesses vendors as part of intake, approvals and supplier onboarding, so no one is signed without a review.

Book a demo
  • 5-category risk assessment
  • 3-tier question banks
  • 12-question short form
  • 1-25 risk scoring