Vendor Risk Review
Assess a prospective vendor before they're onboarded.
Checklist
- Data access — what company/customer data would this vendor touch? Flag any PII or financial data access.
- Security posture — do they have a SOC 2 (or equivalent) report, or a documented security policy?
- Financial stability — any public signals of distress (layoffs, funding issues, negative press)?
- Contract terms — check against the
contract-redlineskill's standard clause list if a draft agreement exists. - Concentration risk — is this vendor a single point of failure for something business-critical?
Process
- Work through the checklist in order; don't skip a section just because early ones look fine.
- Mark each item
pass,needs more info, orconcernwith a one-line reason. - Recommend one of: approve, approve with conditions (name them), or escalate (name who/why).
- Never recommend "approve" if data access and security posture haven't both been checked.