A vendor risk assessment template is a structured questionnaire and scoring sheet for reviewing third-party suppliers before you onboard them and again each year. It checks security, compliance, resilience and track record, then turns the answers into a risk rating.
It is the standard set of questions and scores you apply to every supplier, so each one is judged against the same bar. A supplier risk assessment template or third party risk assessment template does the same job under a different name.
Procurement, security and compliance teams use it at two moments: before a new vendor is signed, and at each annual review or contract renewal. The depth depends on the vendor's tier, so a payroll provider holding staff data gets far more questions than an office supplies firm.
It is the working core of a vendor risk management template: the questionnaire collects evidence, the scoring sheet rates it, and the rating decides whether you approve, approve with conditions or decline the vendor.
Legal name, ownership, locations, key contacts and what the vendor will do for you.
Encryption at rest and in transit, access controls and how your data is stored, shared and deleted.
Certifications and frameworks that apply, such as SOC 2, ISO 27001, GDPR and HIPAA.
Business continuity and disaster recovery plans, and whether they are tested.
Past breaches or outages and how the vendor notifies customers when something goes wrong.
Ready to use in Excel, Google Sheets and PDF. Fill it in, save it, reuse it.
Rate the vendor by the data it touches, its access to systems and how critical it is to operations.
Send the Tier 1, 2 or 3 questionnaire and request evidence such as reports and certificates.
Check answers against the evidence, and follow up on any gaps or vague replies.
Rate likelihood and impact for each category and calculate the overall risk score.
Approve, approve with conditions or decline, then set the next review date by tier.
The simplest version is one sheet: Vendor, Data accessed, Certifications, Last incident, Risk rating, Next review. Add the tiered questionnaires as your vendor list grows.
Start here for every vendor. Ask the core question in each category, collect the evidence and score the answer. The deeper question banks in the next parts plug into the same five categories.
| Category | Core question | Evidence to request |
|---|---|---|
| Vendor profile | Who owns the company, where does it operate and what will it do for us? | Registration details, ownership chart, service description |
| Vendor profile | Which subcontractors will touch our data or service? | Subprocessor list |
| Data security and privacy | Is our data encrypted at rest and in transit? | Security policy, architecture summary |
| Data security and privacy | Who can access our data, and how is access approved and removed? | Access control policy, access review records |
| Regulatory compliance | Which certifications or attestations do you hold? | SOC 2 Type II report, ISO 27001 certificate |
| Regulatory compliance | How do you meet GDPR, HIPAA or other rules that apply to our data? | DPA, privacy notice, BAA where relevant |
| Operational resilience | Do you have tested business continuity and disaster recovery plans? | BCP and DR summary, last test date and results |
| Incident history | Have you had a breach or major outage in the last three years? | Incident summary, root cause, remediation |
| Incident history | How fast will you notify us of an incident? | Incident response policy, contract clause |
Rate likelihood and impact from 1 to 5 for each category. Works in Excel and Google Sheets.
| Category | Likelihood | Impact | Score | Rating |
|---|---|---|---|---|
| Vendor profile | 2 | 2 | 4 | Low |
| Data security and privacy | 3 | 5 | 15 | High |
| Regulatory compliance | 2 | 4 | 8 | Medium |
| Operational resilience | 2 | 4 | 8 | Medium |
| Incident history | 1 | 5 | 5 | Low |
Illustrative scores for Cedar Health, a fictional Tier 1 payroll vendor. Highest category score sets the overall rating: High.
Sending every vendor a 60-question form wastes their time and yours. Tier first, then send only the questions that match the risk. The download includes the full bank for each tier; the table shows how tiers are set and what each adds.
| Tier | Typical vendor | Questions | Review cycle |
|---|---|---|---|
| Tier 1: high | Holds sensitive or regulated data, or a critical service such as payroll, cloud hosting or payments | 50-60 | Annual, plus at renewal |
| Tier 2: medium | Internal data or system access, such as a CRM or analytics tool | 25-30 | Every 2 years |
| Tier 3: low | No data or system access, such as office supplies or catering | 10-15 | At onboarding, then on change |
Question counts follow common practice; review cycles are a typical starting point.
Answer these yourself before you send anything. Any yes to the first three makes the vendor Tier 1.
| # | Question | If yes |
|---|---|---|
| 1 | Will the vendor store or process personal, health or payment data? | Tier 1 |
| 2 | Would an outage stop a critical business process for more than a day? | Tier 1 |
| 3 | Will the vendor have privileged access to our systems or network? | Tier 1 |
| 4 | Will the vendor access internal, non-public data? | Tier 2 |
| 5 | Will annual spend exceed our approval threshold? | Tier 2 at least |
| 6 | None of the above | Tier 3 |
If the vendor holds a current SOC 2 Type II report or ISO 27001 certificate, read it first and only ask about gaps it does not cover. That shortens the questionnaire for both sides. Note any exceptions the auditor raised and ask how each was fixed.
| Control area | Question | Good answer |
|---|---|---|
| Governance | Who owns information security, and when was the policy last approved? | Named owner, policy reviewed in the last 12 months |
| Governance | Do staff complete security training at joining and yearly? | Yes, with completion records |
| Access | Is MFA required for all staff and admin accounts? | Yes, enforced, no exceptions |
| Access | How quickly is access removed when someone leaves? | Same day, logged |
| Encryption | Which standards protect data at rest and in transit? | AES-256 at rest, TLS 1.2 or higher in transit |
| Data handling | Where is our data hosted, and can we choose the region? | Named regions, contractual commitment |
| Data handling | How is our data returned or deleted when the contract ends? | Defined process and certificate of deletion |
| Vulnerabilities | How often do you run penetration tests, and by whom? | Yearly, independent firm, summary shared |
| Monitoring | Are security logs centralised and reviewed? | Yes, with alerting and retention period stated |
| Recovery | What are your recovery time and recovery point objectives? | Stated targets, tested in the last year |
Ten of the Tier 1 security questions; the download has the full bank. Expected answers are typical benchmarks, not regulatory requirements.
Use this for SaaS tools with limited data access and for service providers who visit your sites. Most vendors can answer it in under an hour, so it rarely delays a purchase. Ask for one supporting document per answer where one exists.
| # | Question | Answer |
|---|---|---|
| 1 | Do you hold SOC 2, ISO 27001 or another independent security attestation? | Yes / No / In progress |
| 2 | Is customer data encrypted at rest and in transit? | Yes / No |
| 3 | Is multi-factor authentication enforced for staff? | Yes / No |
| 4 | Can customers enforce single sign-on? | Yes / No |
| 5 | Do you use subprocessors that access customer data? List them. | Text |
| 6 | Where is customer data stored? | Country or region |
| 7 | Have you had a data breach in the last three years? | Yes / No, with details |
| 8 | How soon will you notify customers of a breach? | Hours |
| 9 | Do you test backups and recovery at least yearly? | Yes / No |
| 10 | Do you run background checks on staff with data access? | Yes / No |
| 11 | Will you sign our data processing agreement? | Yes / No |
| 12 | Who is your security contact? | Name and email |
A secure vendor can still fail you if it runs out of cash or relies on one key person. These questions cover the business side of supplier risk. Combine the answers with the security score before you approve.
Use the highest score rather than the average, so one serious gap cannot hide behind good answers elsewhere. Record both inherent risk, before controls, and residual risk, after the vendor's controls and your contract terms. Approve on residual risk.
| Col | Header | Entry or formula | What it does |
|---|---|---|---|
| A | Vendor | Text | Supplier name |
| B | Category | Drop-down: five categories | One row per category |
| C | Likelihood | 1-5 | How likely the risk is to occur |
| D | Impact | 1-5 | How bad it would be |
| E | Score | =C2*D2 | Inherent risk, 1-25 |
| F | Rating | =IF(E2>=15, | Rating band |
| G | Vendor score | =MAXIFS(E:E, | Highest category score for the vendor |
| H | Last review | Date | When the assessment was completed |
| I | Next review | =IF(G2>=15, | Review date by rating |
| Score | Rating | Decision |
|---|---|---|
| 15-25 | High | Decline, or approve only with remediation and senior sign-off |
| 8-14 | Medium | Approve with conditions written into the contract |
| 1-7 | Low | Approve |
A common banding; adjust thresholds to your risk appetite. See third-party risk scoring.
Spendflo third-party risk management runs vendor assessments inside intake and approvals.
See TPRM in SpendfloAn independent audit report on how a service provider's security controls operated over a period, usually 6-12 months.
An international standard for information security management systems, certified by an accredited body.
The EU and UK data protection regime that applies when personal data of people in those regions is processed.
US rules on protecting health information, relevant when a vendor handles it for a covered organisation.
Inherent risk is before controls; residual risk is what remains after them.
A third party your vendor uses that also processes your data.
Match the questionnaire to the vendor's data access and criticality.
A SOC 2 report or test result beats a yes in a form.
Breach notice times, audit rights and data deletion belong in the agreement.
Set the next review date when you approve, based on the rating.
Store questionnaires, evidence and decisions together for audit.
Long forms for low-risk vendors slow purchases and get rushed answers.
An average lets one critical gap disappear among good answers.
Once the contract is signed, you lose the bargaining power to fix gaps.
A vendor's subprocessors can expose your data just as much.
Pull active vendors from accounts payable and answer the tiering questions for each.
Send Tier 1 the full security and due diligence banks, Tier 3 the short form.
Enter likelihood and impact per category and record the decision and any conditions.
Let the next review formula set dates, and add them to your renewal calendar.
Lumen Retail assessed Cedar Health, a payroll vendor holding staff bank details. Data security scored 15 (likelihood 3, impact 5). Cedar agreed in the contract to enforce MFA within 30 days and send evidence. Residual score dropped to 5 once confirmed, and the next review was set 12 months out. Illustrative example.
Every part on this page, in Excel, Google Sheets and PDF, with the examples filled in.
Use the tiering questions and the short questionnaire, and reserve the full bank for the handful of Tier 1 vendors.
Add questions for HIPAA, payment card and sector rules, and require evidence for every Tier 1 answer.
Focus on SSO, data location, subprocessors and data deletion, since most risk sits in the software stack.
Best for scoring and a vendor register.
Best when security and procurement share the file.
Questionnaires ready to send to vendors.
Run vendor risk reviews, contracts and renewals in one place with Spendflo TPRM.
See how it worksA free vendor risk assessment template gives you a consistent bar for every supplier and a record auditors can follow. The value comes from tiering, asking for evidence and reassessing before each renewal.
Quick answers to what people ask most about the vendor risk assessment template.
Tier the vendor by data access and criticality, send the matching questionnaire, check the evidence, score likelihood and impact, then decide and set a review date. Download the template to get the questionnaires and scoring formulas ready to use.
A common five-step approach is to identify risks, assess likelihood and impact, rate them, decide on controls, and review on a schedule. The free download applies those steps to vendors across five categories, from vendor profile to incident history.
You can download a free vendor risk assessment template from this page in Excel, Google Sheets or PDF. It includes tiered questionnaires, a security question bank, due diligence checks and risk scoring.
Examples include a data breach at a supplier holding your customer data, an outage at a critical provider, a vendor failing financially, sanctions exposure and compliance gaps such as missing GDPR safeguards. Download the template to check each one systematically.
A security questionnaire covers only information security, while a vendor risk assessment also covers financial, legal, operational and compliance risk. The download includes both, plus a due diligence questionnaire.
Vendor management
Purchase orders
Contracts
Sourcing and RFx
Budgets and business cases
Procurement
Accounts payable
Purchasing
Software buying
Supply chain
Spendflo third-party risk management assesses vendors as part of intake, approvals and supplier onboarding, so no one is signed without a review.
Enter your work email and we'll unlock every format.
Didn't start, or need another format? Pick one below.
Google Sheets: upload the file to Google Drive, then open it with Google Sheets.