1. Purpose
The Supplier Risk Assessment is used to identify, evaluate, and manage information-security, privacy, operational, business, and technology risks arising from suppliers, vendors, contractors, service providers, consultants, and other third parties.
The assessment helps the organization determine:
- What services the supplier provides
- What information and systems are involved
- What level of access the supplier requires
- How critical the supplier is to the business
- What security threats and vulnerabilities may exist
- What controls are required
- Whether the supplier risk is acceptable
- What additional risk treatment is required
- How the supplier should be monitored and reassessed
Core Principle
Supplier → Service → Information → Access → Dependency → Threat → Vulnerability → Impact → Risk → Controls → Treatment → Residual Risk → Approval → Monitoring
2. When to Perform a Supplier Risk Assessment
A Supplier Risk Assessment should be performed when:
- A new supplier is being onboarded
- A supplier will access company systems
- A supplier will access customer or personal data
- A supplier will process confidential or restricted information
- A supplier provides a critical business service
- A supplier provides cloud or hosting services
- A supplier requires production or privileged access
- A supplier handles source code or security information
- A supplier uses subprocessors
- A major service or contract changes
- A significant security incident occurs
- The supplier’s ownership or operating location changes
- Data location changes
- A supplier introduces a new technology or AI service
- The supplier is due for periodic reassessment
The frequency should be risk-based rather than identical for every supplier.
3. Supplier Risk Assessment Information
| Field | Details |
|---|---|
| Assessment ID | |
| Supplier ID | |
| Supplier Name | |
| Supplier Type | Vendor / SaaS / Cloud / Consultant / Contractor / Other |
| Service/Product | |
| Business Owner | |
| Supplier Owner | |
| Department | |
| Assessment Date | |
| Assessment Type | Initial / Periodic / Triggered |
| Previous Assessment | |
| Criticality | Low / Medium / High / Critical |
| Assessment Status | Draft / In Review / Approved / Action Required |
4. Supplier and Service Description
Document what the supplier actually does for the organization.
| Item | Details |
|---|---|
| Service Description | |
| Business Purpose | |
| Business Process Supported | |
| Primary Users | |
| Service Location | |
| Data Processing Location | |
| Service Dependency | |
| Expected Availability | |
| Contract Period | |
| Critical Business Dependency | Yes / No |
| Alternative Supplier Available | Yes / No |
| Exit/Migration Plan Available | Yes / No |
Example
Supplier: AWS
Service: Cloud infrastructure
Business Process: Production SaaS platform
Information: Customer information, application data, logs and configuration data
Dependency: High
Alternative: Migration to another cloud provider would require significant planning and technical effort.
This information supports the determination of supplier criticality and risk.
5. Information and Data Assessment
Identify what information the supplier can access, receive, process, store, or transmit.
| Information Type | Applicable? | Classification | Description |
|---|---|---|---|
| Public Information | ☐ | Public | |
| Internal Information | ☐ | Internal | |
| Confidential Information | ☐ | Confidential | |
| Restricted Information | ☐ | Restricted | |
| Customer Information | ☐ | ||
| Personal Data | ☐ | ||
| Financial Information | ☐ | ||
| Authentication Information | ☐ | ||
| Source Code | ☐ | ||
| Security Information | ☐ | ||
| Intellectual Property | ☐ |
Assessment Questions
- What information does the supplier receive?
- What information does the supplier store?
- What information does the supplier process?
- Can the supplier modify the information?
- Can the supplier delete information?
- Is customer information involved?
- Is personal data involved?
- Is regulated information involved?
- Is information transferred internationally?
6. Supplier Access Assessment
Identify the access required by the supplier.
| Access Type | Required? | Details |
|---|---|---|
| No system access | ☐ | |
| User application access | ☐ | |
| VPN/Remote access | ☐ | |
| Cloud access | ☐ | |
| Production access | ☐ | |
| Database access | ☐ | |
| Source-code access | ☐ | |
| Security-tool access | ☐ | |
| Administrative access | ☐ | |
| Privileged access | ☐ | |
| API access | ☐ | |
| Physical access | ☐ |
Access Risk Considerations
Assess:
- Least privilege
- Named individual accounts
- MFA
- Privileged access controls
- Access approval
- Access logging
- Temporary access
- Access review
- Access revocation
- Emergency access
7. Supplier Criticality Assessment
Determine how important the supplier is to business operations.
Consider:
- Impact of supplier failure
- Dependency on supplier availability
- Customer impact
- Information-security impact
- Privacy impact
- Regulatory impact
- Financial impact
- Operational impact
- Recovery requirements
- Availability of alternatives
- Migration complexity
Example Classification
| Criticality | Typical Characteristics |
|---|---|
| Low | Limited business impact and no sensitive information |
| Medium | Important business service or confidential information |
| High | Significant business dependency or sensitive information |
| Critical | Failure could materially affect critical operations, customers, security, or regulatory obligations |
The organization should define its own detailed criticality criteria.
8. Threat Assessment
Identify credible threats associated with the supplier.
| Threat | Applicable? | Description |
|---|---|---|
| Unauthorized access | ☐ | |
| Credential compromise | ☐ | |
| Malware/ransomware | ☐ | |
| Data breach | ☐ | |
| Insider threat | ☐ | |
| Supplier employee error | ☐ | |
| Service outage | ☐ | |
| Cyberattack | ☐ | |
| Vulnerability exploitation | ☐ | |
| Subprocessor failure | ☐ | |
| Data loss | ☐ | |
| Unauthorized data disclosure | ☐ | |
| Supply-chain compromise | ☐ | |
| Physical disruption | ☐ | |
| Regulatory/legal issue | ☐ | |
| Fraud | ☐ |
9. Vulnerability / Weakness Assessment
Document weaknesses that could increase supplier risk.
Examples:
- No MFA
- Excessive privileges
- Shared accounts
- Weak access controls
- Lack of security monitoring
- Unsupported software
- Poor vulnerability management
- No independent assurance
- Weak incident notification
- No tested BCP/DR
- Unclear data retention
- Uncontrolled subprocessors
- Unclear data location
- Weak contractual security requirements
- No secure deletion process
- Lack of security testing
10. Impact Assessment
Assess the potential consequences if the supplier’s service or security controls fail.
| Impact Area | Rating | Explanation |
|---|---|---|
| Confidentiality | Low / Medium / High / Critical | |
| Integrity | Low / Medium / High / Critical | |
| Availability | Low / Medium / High / Critical | |
| Privacy | Low / Medium / High / Critical | |
| Customer Impact | Low / Medium / High / Critical | |
| Regulatory Impact | Low / Medium / High / Critical | |
| Financial Impact | Low / Medium / High / Critical | |
| Operational Impact | Low / Medium / High / Critical | |
| Reputation/Trust Impact | Low / Medium / High / Critical |
11. Likelihood Assessment
Estimate the likelihood that the identified risk scenario could occur.
| Rating | Example Description |
|---|---|
| Low | Unlikely under current conditions |
| Medium | Possible and reasonably foreseeable |
| High | Likely or significant exposure exists |
| Critical | Very high likelihood or exposure requiring immediate attention |
The organization should use its approved risk methodology where one exists.
12. Inherent Risk
Inherent risk represents the risk before considering existing controls or additional treatment.
A simple risk model may be:
Risk = Likelihood × Impact
| Likelihood | Impact | Inherent Risk |
|---|---|---|
| Low | Low | Low |
| Low | High |
