VNDR- 2 Vendor Risk Assessment

Estimated reading: 2 minutes 1666 views

What is this control about?

Vendor Risk Assessment Control talks about how for every vendor, partner, or supplier that your organization deals with, it is good hygiene and a compliance requirement to assess the risk of working with that vendor before exchanging any confidential data. As part of this analysis, determining the criticality of the vendor based on the type of data that will be shared is important.

Each organization can determine the depth of the review.

Typically, the depth of the vendor risk assessment depends on the criticality of the vendor. If sensitive data is to be shared and stored with the vendor, an extensive review needs to be performed. But if the vendor is not accessing any sensitive data and is used for basic administrative functions, the review can be reduced. This judgment is at each organization’s discretion.

You need to document the rationale in the vendor management policy.

Available tools in the marketplace

No tool recommendations are made for this section.

Available templates

TrustCloud has a curated list of templates, internally or externally sourced, to help you get started. Click on the link for a downloadable version.:

Control implementation

To implement this control,

You need to implement a formal and repeatable review process for your vendor risk assessment. The review format is up to each organization; however, at the minimum, the review should include the following key elements:

  1. Financial review to assess the financials and ensure that potential vendors are financially solvent
  2. Media and press releases to assess any legal risks.
  3. Security risks to assess any glaring cybersecurity issues.

What evidence do auditors look for?

Most auditors, at a minimum, are looking for the below-suggested action:

  1. Provide the vendor due diligence performed for the newest vendor added.

Evidence example

For the suggested action, an example is provided below:

  1. Provide the vendor due diligence performed for the newest vendor added.
    The template provided serves as an example.

Join the conversation

