Vendor risk

What is vendor risk management?

Vendor risk management (also called third-party risk management, or TPRM) is the practice of identifying, assessing, and continuously monitoring the risks that your suppliers and service providers introduce, from data breaches to outages to compliance gaps.

Definition

Vendor risk management is the process of understanding and controlling the risk your organization inherits from the third parties it relies on. It covers assessing a vendor before you onboard them, classifying how critical they are, and monitoring them for as long as the relationship lasts.

Background

Modern companies run on dozens or hundreds of vendors, and each one that touches your data or systems is part of your attack surface. Frameworks like SOC 2 and ISO 27001 explicitly expect a third-party risk program. A typical program tiers vendors by criticality (based on the data they access and how essential they are), assesses each with a security questionnaire and evidence review, and sets a review cadence so higher-risk vendors are re-checked more often.

Why it matters

Many breaches reach companies through a vendor rather than a direct attack. A real vendor risk program is both a security control and an audit requirement, and it is what lets you answer “do you manage your suppliers?” with evidence instead of a shrug.

Step by step

  1. Build an inventory of every vendor and what data or access each one has.
  2. Tier vendors by criticality so effort matches risk.
  3. Assess new and existing vendors with a security questionnaire and evidence (for example, their SOC 2 report).
  4. Record findings and any required remediations, and decide whether to proceed.
  5. Set a review cadence by tier and re-assess on schedule.
  6. Monitor for changes: incidents, sub-processor changes, or a lapsed certification.

Examples

  • A critical vendor that stores customer data is reviewed annually with a full questionnaire and a look at its latest SOC 2 report.
  • A low-risk marketing tool with no access to sensitive data gets a lightweight review on a longer cadence.

Common mistakes

  • Treating every vendor the same instead of tiering by real risk.
  • Assessing vendors once at onboarding and never again.
  • Collecting questionnaires but never acting on the findings.

FAQ

What is the difference between vendor risk management and TPRM?

They are effectively the same thing. Third-party risk management (TPRM) is the broader term; vendor risk management is the most common part of it.

What is vendor tiering?

Classifying vendors by how critical they are, usually based on the sensitivity of the data they access and how essential they are to operations, so you spend the most effort on the vendors that matter most.

How does a security questionnaire fit in?

It is the structured way you ask a vendor about their controls. The answers, plus evidence like a SOC 2 report, form the basis of your assessment and risk decision.

Related

Vendor risk in Keel → Questionnaire automation → What is a risk register? → What is SOC 2? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free