1. Purpose
The Supplier Risk Assessment Template is used to identify, analyse, evaluate, and document information-security risks associated with suppliers and third-party service providers.
The assessment helps the organization determine:
- What service the supplier provides
- What information and systems are involved
- How important the supplier is to the business
- What security risks the relationship creates
- What controls are already in place
- What additional controls are required
- Whether the supplier risk is acceptable
- How the supplier should be monitored and reviewed
Core Principle
Supplier → Service → Information/Asset → Threat → Risk → Controls → Residual Risk → Treatment → Review
2. Assessment Information
| Field | Details |
|---|---|
| Assessment ID | |
| Supplier ID | |
| Supplier Name | |
| Assessment Date | |
| Assessment Type | Initial / Periodic / Change / Incident |
| Assessment Period | |
| Business Owner | |
| Supplier Owner | |
| Security/ISMS Reviewer | |
| Procurement Owner | |
| Privacy/Legal Reviewer | |
| Previous Assessment | |
| Next Review Date | |
| Assessment Status | Draft / In Progress / Completed |
3. Supplier Information
| Field | Details |
|---|---|
| Supplier Legal Name | |
| Trading Name | |
| Supplier Type | Cloud / SaaS / IT / Consultant / MSP / Other |
| Service Provided | |
| Business Process Supported | |
| Supplier Contact | |
| Internal Sponsor | |
| Contract/SOW | |
| Contract Start Date | |
| Contract End Date | |
| Service Criticality | Critical / High / Medium / Low |
| Supplier Location | |
| Service Location | |
| Data Location | |
| Subprocessors | Yes / No |
| Status | Active / Proposed / Terminating |
4. Assessment Scope
Define exactly what is being assessed.
Included
☐ Supplier service
☐ Information processed
☐ Systems connected
☐ Supplier personnel
☐ Supplier access
☐ Cloud/SaaS environment
☐ Data processing
☐ Subprocessors
☐ Business continuity
☐ Security controls
☐ Contractual requirements
Excluded
Assessment Boundaries
5. Supplier Service Description
Describe what the supplier does and how the organization depends on the service.
Service Description
Business Purpose
Key Business Dependency
What Happens if the Service Is Unavailable?
6. Information and Asset Assessment
Identify information and assets affected by the supplier relationship.
| Information/Asset | Classification | Owner | Supplier Access | Criticality |
|---|---|---|---|---|
Consider:
- Customer data
- Personal data
- Employee data
- Financial data
- Source code
- Security information
- Credentials/secrets
- Confidential business information
- Restricted information
- Production systems
- Cloud infrastructure
- Audit evidence
7. Supplier Access Assessment
Determine the type of access required.
| Access Type | Required | Details |
|---|---|---|
| Corporate Systems | Yes / No | |
| SaaS | Yes / No | |
| Cloud | Yes / No | |
| Production | Yes / No | |
| Development | Yes / No | |
| Database | Yes / No | |
| Source Code | Yes / No | |
| Customer Systems | Yes / No | |
| Privileged Access | Yes / No | |
| VPN | Yes / No | |
| Physical Access | Yes / No | |
| API/System Integration | Yes / No |
Access Principle
Supplier access should be limited to the minimum required for the approved service.
8. Data Processing Assessment
| Question | Result |
|---|---|
| Does supplier process organizational information? | Yes / No |
| Does supplier process customer data? | Yes / No |
| Does supplier process personal data? | Yes / No |
| Does supplier process financial data? | Yes / No |
| Does supplier process security information? | Yes / No |
| Does supplier access credentials/secrets? | Yes / No |
| Does supplier store organizational data? | Yes / No |
| Does supplier transfer data internationally? | Yes / No |
| Does supplier use subprocessors? | Yes / No |
Data Processing Description
9. Supplier Criticality Assessment
Assess the business impact if the supplier service becomes unavailable, compromised, or unreliable.
| Factor | Low | Medium | High | Critical |
|---|---|---|---|---|
| Business Dependency | ☐ | ☐ | ☐ | ☐ |
| Information Sensitivity | ☐ | ☐ | ☐ | ☐ |
| Customer Impact | ☐ | ☐ | ☐ | ☐ |
| System Criticality | ☐ | ☐ | ☐ | ☐ |
| Security Impact | ☐ | ☐ | ☐ | ☐ |
| Availability Impact | ☐ | ☐ | ☐ | ☐ |
| Regulatory Impact | ☐ | ☐ | ☐ | ☐ |
Overall Supplier Criticality
☐ Low
☐ Medium
☐ High
☐ Critical
Rationale
10. Supplier Risk Factors
Assess relevant risk factors.
Information Security
☐ Confidential information
☐ Restricted information
☐ Customer information
☐ Personal data
☐ Financial information
☐ Source code
☐ Security information
☐ Credentials/secrets
Technology
☐ Production access
☐ Privileged access
☐ Cloud integration
☐ API integration
☐ Database access
☐ Network access
☐ Source-code access
☐ Critical SaaS dependency
Business
☐ High business dependency
☐ Limited alternatives
☐ Difficult migration
☐ High availability requirement
☐ Customer-facing service
Supplier
☐ Subprocessors
☐ Multiple geographic locations
☐ Complex supply chain
☐ Limited security assurance
☐ Previous security incidents
☐ Significant organizational change
11. Threat Identification
Identify realistic threats associated with the supplier.
Examples:
- Supplier account compromise
- Supplier employee compromise
- Unauthorized supplier access
- Supplier insider threat
- Supplier ransomware
- Supplier data breach
- Supplier cloud compromise
- Compromise of supplier software
- Supply-chain attack
- Supplier API compromise
- Credential theft
- Malicious subcontractor
- Service outage
- Data loss
- Insecure supplier configuration
- Vulnerability in supplier platform
- Failure to delete data
- Unauthorized data transfer
Threat Register
| Threat ID | Threat | Affected Asset/Information | Potential Impact |
|---|---|---|---|
12. Vulnerability / Weakness Identification
Identify weaknesses that could increase supplier risk.
Examples:
- Excessive access
- Weak authentication
- No MFA
- Poor access review
- Inadequate logging
- Lack of encryption
- Unclear data retention
- Weak incident notification
- Uncontrolled subprocessors
- Poor vulnerability management
- No tested business continuity
- Limited security assurance
- Inadequate contractual protection
- Unclear data deletion
| Weakness ID | Weakness | Related Threat | Impact |
|---|---|---|---|
13. Risk Identification
A supplier risk should connect:
Supplier → Threat → Weakness → Risk Event → Consequence
Example
Supplier: Cloud service provider
Threat: Supplier account compromise
Weakness: Excessive privileged access
Risk Event: Unauthorized supplier administrator gains access to production environment
Consequence: Customer data exposure, service disruption, regulatory/contractual impact
14. Risk Assessment Methodology
The organization should use its approved information-security risk methodology.
An example 5×5 approach is:
Likelihood
| Score | Description |
|---|---|
| 1 | Rare |
| 2 | Unlikely |
| 3 | Possible |
| 4 | Likely |
| 5 | Almost Certain |
Impact
| Score | Description |
|---|---|
| 1 | Insignificant |
| 2 | Minor |
| 3 | Moderate |
| 4 | Major |
| 5 | Severe |
Risk Score
Risk = Likelihood × Impact
Example bands:
| Score | Example Level |
|---|---|
| 1–4 | Low |
| 5–9 | Medium |
| 10–15 | High |
| 16–25 | Critical |
These scoring bands are an example methodology, not a universal ISO 27001 requirement. The organization’s approved risk methodology should be used.
15. Supplier Risk Register
| Risk ID | Supplier | Risk | Threat | Weakness | L | I | Score | Level | Treatment |
|---|---|---|---|---|---|---|---|---|---|
| SR-001 | |||||||||
| SR-002 | |||||||||
| SR-003 |
16. Existing Supplier Controls
Identify controls already implemented.
Examples:
- MFA
- SSO
- Least privilege
- Named accounts
- Encryption
- Network restrictions
- Logging
- Monitoring
- Security testing
- ISO 27001 certification
- SOC 2 assurance
- Incident response
- Business continuity
- Backup
- Contractual security requirements
- Data-processing agreement
- Access reviews
| Risk | Existing Control | Evidence | Effectiveness |
|---|---|---|---|
| Effective / Partial / Unknown |
17. Supplier Security Assurance Review
Record available assurance evidence.
| Evidence | Available | Date/Validity | Scope Relevant | Review Result |
|---|---|---|---|---|
| ISO 27001 | ☐ | Yes / No | ||
| SOC 2 | ☐ | Yes / No | ||
| Penetration Test | ☐ | Yes / No | ||
| Security Assessment | ☐ | Yes / No | ||
| Vulnerability Assessment | ☐ | Yes / No | ||
| Business Continuity Test | ☐ | Yes / No | ||
| Security Questionnaire | ☐ | Yes / No |
Assessment
Assurance evidence should be evaluated for its scope, date, relevance, and limitations.
18. Contractual Security Assessment
Check whether appropriate contractual protections exist.
☐ Confidentiality/NDA
☐ Security requirements
☐ Access restrictions
☐ Incident notification
☐ Data protection requirements
☐ Data retention
☐ Data deletion/return
☐ Subprocessor requirements
☐ Security assurance
☐ Business continuity
☐ Audit/assessment rights where appropriate
☐ Termination requirements
☐ Customer requirements
Contract Gaps
19. Subprocessor / Subcontractor Risk
Identify important downstream parties.
| Subprocessor/Subcontractor | Service | Data/Access | Location | Risk | Reviewed |
|---|---|---|---|---|---|
Consider:
- Security controls
- Data access
- Location
- Contractual flow-down
- Incident notification
- Data deletion
- Change notification
20. Data Location and Transfer Risk
Identify where information is:
- Collected
- Processed
- Stored
- Backed up
- Transferred
| Location | Activity | Information | Transfer | Risk |
|---|---|---|---|---|
Where personal or regulated data is involved, applicable privacy and regulatory requirements should be assessed.
21. Business Continuity Risk
Assess supplier dependency.
Questions
- Is the supplier service business-critical?
- How long can the organization operate without it?
- Does the supplier have recovery capabilities?
- Has recovery been tested?
- Are backups available where required?
- Is there an alternative supplier?
- Is migration possible?
- Is critical information recoverable?
Assessment
22. Supplier Incident Risk
Review the supplier’s incident-management capability.
☐ Incident response process exists
☐ Notification process defined
☐ Security contact available
☐ Breach notification requirements defined
☐ Investigation cooperation defined
☐ Evidence preservation considered
☐ Customer/regulatory requirements addressed
☐ Incident history reviewed where appropriate
23. Supplier Vulnerability Management
Assess:
☐ Vulnerability management process
☐ Security patching
☐ Security advisories
☐ Critical vulnerability notification
☐ Penetration testing where appropriate
☐ Software security testing
☐ Dependency management
☐ Security issue remediation
Findings
24. Access Risk Assessment
Evaluate supplier access.
| Factor | Assessment |
|---|---|
| Named user accounts | |
| MFA | |
| Least privilege | |
| Production access | |
| Privileged access | |
| Temporary access | |
| Access expiry | |
| Logging | |
| Monitoring | |
| Periodic review | |
| Offboarding |
Access Risk
☐ Low
☐ Medium
☐ High
☐ Critical
25. Initial Risk
Record the risk before considering additional treatment.
| Risk ID | Likelihood | Impact | Initial Score | Initial Level |
|---|---|---|---|---|
26. Risk Treatment Options
For each supplier risk, consider:
Reduce
Implement additional controls to reduce likelihood or impact.
Avoid
Do not use the supplier/service where risk cannot be appropriately managed.
Share/Transfer
Use contractual, insurance, or other mechanisms to share certain consequences where appropriate.
Accept
Accept the risk through the organization’s formal risk-acceptance process when it falls within approved criteria.
The appropriate treatment should be based on the organization’s risk methodology and acceptance criteria.
27. Supplier Risk Treatment Plan
| Risk ID | Treatment | Required Action | Control | Owner | Due Date | Status |
|---|---|---|---|---|---|---|
Possible treatments:
- Reduce supplier permissions
- Require MFA
- Add contractual security requirements
- Require security assurance
- Restrict data
- Reduce data shared
- Add monitoring
- Require additional testing
- Require incident notification
- Add backup/continuity measures
- Implement compensating controls
- Change supplier
28. Additional Supplier Security Requirements
Document requirements that must be satisfied before approval or continued use.
| Requirement | Reason | Owner | Due Date | Status |
|---|---|---|---|---|
Examples:
- MFA required
- Security assessment required
- DPA required
- Production access restricted
- Data deletion evidence required
- Additional security assurance required
- Subprocessor disclosure required
29. Residual Risk
After implementing existing and planned controls, reassess the risk.
| Risk ID | Initial Risk | Controls | Residual Likelihood | Residual Impact | Residual Score | Level |
|---|---|---|---|---|---|---|
Residual risk should be evaluated against the organization’s approved risk-acceptance criteria.
30. Supplier Risk Acceptance
Where residual risk requires formal acceptance:
| Field | Details |
|---|---|
| Risk ID | |
| Residual Risk | |
| Business Justification | |
| Risk Owner | |
| Treatment Completed | |
| Acceptance Criteria Met | Yes / No |
| Accepted By | |
| Acceptance Date | |
| Review/Expiry Date |
Risk acceptance should be performed by the authorized risk owner or approval authority defined by the organization’s risk-management process.
31. Overall Supplier Risk Rating
Based on the organization’s methodology:
☐ Low
☐ Medium
☐ High
☐ Critical
Rating Rationale
The rating should reflect the organization’s documented assessment methodology rather than a generic supplier category.
32. Supplier Approval Recommendation
Record the factual outcome of the assessment:
☐ Security requirements satisfied
☐ Additional controls required before approval
☐ Risk treatment required
☐ Formal risk acceptance required
☐ Additional assessment required
☐ Supplier relationship requires escalation
Conditions
33. Supplier Review and Monitoring Plan
Define how the supplier will be monitored.
| Monitoring Area | Method | Frequency | Owner |
|---|---|---|---|
| Security assurance | |||
| Access review | |||
| Incidents | |||
| Vulnerabilities | |||
| Contract | |||
| Subprocessors | |||
| Business continuity | |||
| Risk assessment |
Review frequency should be risk-based.
34. Reassessment Triggers
Supplier risk should be reassessed when relevant changes occur.
☐ New service
☐ New data
☐ New customer requirement
☐ New regulatory requirement
☐ Security incident
☐ Major vulnerability
☐ Supplier ownership change
☐ New subprocessor
☐ New data location
☐ New production access
☐ New privileged access
☐ Major architecture change
☐ Business criticality changes
☐ Contract change
35. Supplier Change Assessment
| Change | Impact | Risk Change | Required Action | Owner | Status |
|---|---|---|---|---|---|
Process
Change Identified → Assess Impact → Reassess Risk → Update Controls → Approve → Record
36. Supplier Risk Findings
| Finding ID | Finding | Risk | Requirement | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|
37. Corrective Action Verification
For each action:
☐ Action completed
☐ Control implemented
☐ Evidence obtained
☐ Supplier evidence reviewed
☐ Effectiveness assessed
☐ Risk reassessed
☐ Supplier Register updated
☐ Risk Register updated where applicable
☐ Reviewer approved closure
38. Supplier Risk Decision Record
Assessment Outcome
☐ Proceed
☐ Proceed with Conditions
☐ Additional Risk Treatment Required
☐ Formal Risk Acceptance Required
☐ Further Assessment Required
☐ Relationship Requires Management Review
Conditions/Actions
Decision Owner
Name: ____________________
Role: ____________________
Date: ____________________
39. Assessment Approval
Business Owner
Name: ____________________
Approval: ____________________
Date: ____________________
Supplier/Procurement Owner
Name: ____________________
Approval: ____________________
Date: ____________________
Security/ISMS
Name: ____________________
Approval: ____________________
Date: ____________________
Privacy/Legal, Where Required
Name: ____________________
Approval: ____________________
Date: ____________________
40. Evidence Repository
Supporting evidence may include:
- Supplier Register
- Supplier Security Assessment
- Security questionnaire
- Supplier certification
- SOC 2 report
- Penetration-testing report/summary
- Vulnerability assessment
- Contract
- NDA
- DPA
- Security schedule
- Access records
- Supplier access review
- Incident records
- Business continuity evidence
- Subprocessor information
- Risk assessment
- Risk treatment plan
- Risk acceptance
- Corrective actions
- Data deletion/return evidence
Do not store passwords, API keys, private keys, access tokens, MFA secrets, or other actual credentials in the assessment.
41. AWS SaaS Startup Example
Consider a SaaS startup using an external cloud/technology supplier that supports a production service.
Supplier
Cloud/technology provider
Information
Customer information stored in production systems.
Assets
- AWS production environment
- Application
- RDS database
- S3 storage
- Application logs
Threat
Supplier account compromise.
Weakness
Supplier personnel have broader access than required.
Risk Event
A compromised supplier identity could obtain unauthorized access to production resources.
Initial Risk
Likelihood = 4
Impact = 5
Initial Risk Score = 20 — Critical
Existing Controls
- MFA
- Named accounts
- Least privilege
- Logging
- Contractual security requirements
- Access review
Treatment
- Reduce supplier privileges
- Restrict production access
- Require named accounts
- Strengthen monitoring
- Review supplier access periodically
Residual Risk
Reassess after the controls are implemented and compare against the organization’s risk-acceptance criteria.
Audit Trail
Supplier → Access → Threat → Risk → Control → Treatment → Residual Risk → Review
42. Startup-Friendly Supplier Risk Model
A practical startup process can be:
Step 1 — Identify
What supplier are we using?
Step 2 — Understand
What service does it provide?
Step 3 — Map
What information, systems, and business processes depend on it?
Step 4 — Assess
What could go wrong?
Step 5 — Check Controls
What security controls does the supplier have?
Step 6 — Treat
What additional controls are required?
Step 7 — Decide
Is the remaining risk acceptable according to the organization’s methodology?
Step 8 — Monitor
What should we review going forward?
Step 9 — Reassess
Reassess when the supplier, service, data, technology, or risk changes.
43. Common Supplier Risk Assessment Mistakes
Avoid:
- Treating supplier risk as only a procurement issue.
- Assessing every supplier identically.
- Ignoring the information processed by the supplier.
- Ignoring production access.
- Ignoring privileged access.
- Relying only on an ISO certificate or SOC report.
- Ignoring subprocessors.
- Ignoring data location.
- Ignoring business continuity.
- Ignoring supplier incidents.
- Ignoring contractual requirements.
- Copying generic supplier risks without assessing actual exposure.
- Accepting residual risk without an authorized decision.
- Failing to reassess suppliers after major changes.
- Failing to link significant supplier risks to the organizational Risk Register.
44. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Supplier Security Management Policy | Defines supplier-security governance |
| Supplier Register | Identifies suppliers |
| Supplier Security Assessment | Assesses supplier controls |
| Supplier Risk Assessment | Evaluates supplier risks |
| Supplier Review Record | Periodic monitoring |
| Third-Party Access Procedure | Controls supplier access |
| Contractor Account Procedure | Controls contractor identities |
| Access Rights Register | Records supplier permissions |
| Privileged Access Register | Records supplier privileged access |
| SaaS Application Register | Tracks SaaS suppliers |
| Cloud Asset Inventory | Tracks cloud dependencies |
| External Data Sharing Procedure | Controls external data sharing |
| Third-Party Information Sharing Agreement | Defines information-sharing requirements |
| Risk Register | Records significant enterprise risks |
| Incident Management | Handles supplier incidents |
| Threat Intelligence Procedure | Handles relevant supplier threat information |
| Business Continuity | Addresses supplier dependency |
| Contract Management | Manages contractual requirements |
45. ISO 27001 Connection
Supplier risk assessment supports the organization’s risk-based implementation of controls relating to:
- Supplier relationships
- Supplier agreements
- ICT supply-chain security
- Supplier service monitoring
- Access control
- Information transfer
- Incident management
- Business continuity
- Information classification
- Risk management
Supplier risks should feed into the organization’s broader information-security risk-management process where they meet the organization’s criteria for inclusion.
The exact controls applicable to the organization should be determined through the organization’s risk assessment and Statement of Applicability (SoA).
46. Quick Audit Checklist
Supplier
☐ Supplier identified
☐ Service documented
☐ Business owner assigned
☐ Criticality assessed
Information
☐ Information identified
☐ Classification identified
☐ Customer data considered
☐ Personal data considered
☐ Sensitive information considered
Access
☐ Supplier access identified
☐ Production access assessed
☐ Privileged access assessed
☐ MFA assessed
☐ Least privilege assessed
Risk
☐ Threats identified
☐ Weaknesses identified
☐ Initial risk assessed
☐ Existing controls documented
☐ Risk treatment defined
☐ Residual risk assessed
☐ Risk acceptance completed where required
Supplier Security
☐ Security assessment completed
☐ Assurance evidence reviewed
☐ Subprocessors considered
☐ Business continuity assessed
☐ Incident management assessed
Contract
☐ Security requirements
☐ Confidentiality
☐ Data protection
☐ Incident notification
☐ Data return/deletion
☐ Subprocessor requirements
☐ Termination requirements
Monitoring
☐ Review frequency defined
☐ Reassessment triggers defined
☐ Findings tracked
☐ Corrective actions verified
Closure
☐ Assessment approved
☐ Supplier Register updated
☐ Risk Register updated where applicable
☐ Evidence retained
47. Final Audit Trail
For each significant supplier, the organization should be able to demonstrate:
What service does the supplier provide?
What information and assets are involved?
What access does the supplier have?
What threats and weaknesses were identified?
What risks were assessed?
What controls already existed?
What additional treatment was required?
What residual risk remained?
Who accepted or approved the risk?
How will the supplier be monitored?
When will the risk be reassessed?
Final Principle
Do not assess a supplier simply by asking whether it is secure. Assess what the supplier does, what information and systems it affects, what could go wrong, what controls exist, what risk remains, and what the organization needs to do about that risk.
