Guides/Vendor risk
Step-by-step guide

How to assess vendor risk

A supplier breach can be as damaging as a direct attack on your own systems — and it is your problem to manage, not theirs. This guide walks you through identifying critical vendors, sending questionnaires, scoring responses, and maintaining a live risk register.

01

Identify your critical vendors

Not every supplier is a security risk. Focus your effort on vendors who have access to your systems, your data, or whose failure would disrupt your operations. Start by listing all your third-party relationships and scoring them against three criteria.

Data access

Does the vendor handle, store, or process personal data, financial data, or confidential business information on your behalf?

System access

Does the vendor have access to your IT systems, networks, source code, or infrastructure — remotely or on-site?

Business dependency

Would your operations be significantly disrupted if this vendor had an outage or security incident? Cloud providers, payment processors, and logistics platforms often qualify.

What they look for

ISO 27001 clause 8.1.4 and NIS2 Article 21 both require documented supply chain risk management. If audited or questioned by a client, you should be able to produce your vendor list with risk ratings, the criteria used to tier them, and a date showing when it was last reviewed.

02

Tier your vendors by risk level

Once you have a list, classify vendors into tiers. Tiering determines how much due diligence to apply and how often to review. Most organisations use three tiers.

Tier 1 — Critical

High data access or business dependency. Requires full security questionnaire, annual review, and evidence of their own certifications (CE+, ISO 27001, SOC 2).

Tier 2 — Important

Moderate access or dependency. Streamlined questionnaire, biennial review, and review of their public security posture.

Tier 3 — Standard

Minimal access, easily replaceable. Lightweight check at onboarding, no ongoing review unless circumstances change.

What they look for

Your vendor tiering criteria should be documented — not just applied. Clients and auditors will ask how you decided a vendor was Tier 1 vs Tier 2. A one-page document explaining your criteria (data access, system access, business dependency) and your review cadence satisfies this.

03

Send security questionnaires

A security questionnaire asks your vendor to self-report their controls across the areas that matter to you. The goal is not a perfect score — it is to identify material gaps and surface conversations you need to have.

Access control

How do they manage access to systems that hold your data? Do they use MFA? Do they have a joiners/movers/leavers process?

Data handling

Where is your data stored? Is it encrypted at rest and in transit? Who can access it? Is it shared with sub-processors?

Incident response

Do they have a documented incident response plan? What is their process for notifying customers of a breach? What is their average detection-to-notification time?

Certifications and audits

Do they hold CE+, ISO 27001, SOC 2, or equivalent? When was their last penetration test? Are they willing to share the executive summary?

Business continuity

What is their RTO and RPO? Do they have documented DR plans? Have they been tested in the last 12 months?

What they look for

A completed questionnaire response from each critical vendor, with your date of receipt. For ISO 27001 and NIS2, this is mandatory for significant suppliers. If a vendor has ISO 27001 certification, request their certificate as a shortcut — but check the scope covers the services they provide to you.

04

Score and document responses

Responses need to be evaluated, not just collected. Score each vendor against your minimum expectations and document any gaps — including whether the gap is acceptable given compensating controls, or whether it is a blocker.

Define your minimum bar

What is the minimum standard you expect from a Tier 1 vendor? MFA, encryption at rest, incident notification within 72 hours, and a security contact are reasonable starting points.

Score against it

Green/amber/red or a numeric score against each domain. The goal is to see the overall picture at a glance and identify vendors that need follow-up.

Record the decision

For vendors with amber or red findings, document whether you accepted the risk, required remediation, or chose not to proceed. The record is the evidence.

What they look for

Your scoring record and the decision you made: accepted, remediation required, or not proceeded. For amber and red findings, the documented decision and rationale is the evidence. Saying 'we were aware and chose to proceed for these reasons' is defensible; having no record of the gap is not.

05

Maintain an ongoing vendor risk register

Vendor risk is not static — suppliers change their infrastructure, get acquired, suffer breaches, or lose certifications. Your register needs to stay live.

Set review schedules

Tier 1 annually, Tier 2 every two years, Tier 3 at a material change. Calendar the reviews and track them the same way you track other compliance tasks.

Monitor for incidents

When a vendor suffers a breach or outage, reassess their tier and review their questionnaire before the next scheduled date.

Offboarding

When a vendor relationship ends, confirm data deletion, revoke access, and close the register entry with a date and evidence of data removal.

What they look for

A dated vendor register with risk rating, last review date, and DPA status. For GDPR, you also need DPAs with every processor — your vendor risk register and your GDPR processor list should cross-reference. Clients doing due diligence on you will ask for evidence of your vendor risk management process.

Where people go wrong

Common vendor risk management mistakes

✕

Assessing vendors at onboarding and never again

Vendors change: they get acquired, they suffer breaches, they migrate to new cloud infrastructure. A vendor that was low-risk at onboarding may have changed significantly in two years. Annual reviews for Tier 1 vendors are not optional.

✕

Accepting 'we are ISO 27001 certified' without checking scope

ISO 27001 certification is scoped. A vendor may be certified for their development team but not for the hosting environment that stores your data. Always ask for the certificate and check what it covers.

✕

No record of the decision when proceeding with a high-risk vendor

Proceeding with a vendor who has amber or red findings is sometimes a reasonable business decision. But without a documented risk acceptance — naming who approved it and why — you have no defensible position if that vendor's gap causes a breach.

✕

Forgetting sub-processors — vendors your vendors use

If your CRM uses AWS and AWS suffers a breach affecting your data, you are still liable. Your vendor questionnaire should ask about sub-processors, and your DPAs should require notification if sub-processors change.

Common questions about vendor risk management

Do we need to assess every supplier we use?

No. Focus on vendors with data access, system access, or critical business dependency. A stationery supplier or a coffee delivery service is not a cyber risk; your cloud storage provider or payroll bureau is. Tiering lets you apply proportionate effort.

What if a vendor refuses to complete a questionnaire?

Refusal is itself useful information. For Tier 1 vendors, it should be a significant concern. You can ask for their ISO 27001 certificate or SOC 2 report in lieu, but an outright refusal to engage with security due diligence should factor into your decision to use them.

What does NIS2 require for supply chain risk?

NIS2 Article 21 explicitly requires essential and important entities to manage information security risks in their supply chains. This means documented supplier risk assessments, contractual security requirements, and ongoing monitoring — not just a one-time questionnaire.

How do we handle a vendor that has been breached?

First, confirm whether your data was affected. Then review whether the vendor met their breach notification obligations. Reassess their tier and questionnaire responses. If material gaps are identified, require a remediation plan or consider an alternative supplier.

Manage vendor risk in the Fortify portal

Send customisable security questionnaires to suppliers, score responses, and maintain a live vendor risk register — with evidence attached and review dates tracked.