Vendor Risk Assessment
Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors.
Usage
Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view.
Assessment Framework
1. Vendor Risk Scorecard (5 Domains, 0-100 each)
Security Posture (0-100)
- SOC 2 Type II current? (+20)
- Penetration test within 12 months? (+15)
- Incident response plan documented? (+15)
- Data encryption at rest and transit? (+15)
- MFA enforced for all access? (+10)
- Security questionnaire completed? (+10)
- Subprocessor list disclosed? (+15)
Financial Stability (0-100)
- Revenue trend (growing +25, flat +10, declining 0)
- Funding runway >18 months? (+20)
- Customer concentration <20%? (+15)
- Public financials or audited statements? (+15)
- No material litigation? (+15)
- Credit rating acceptable? (+10)
Compliance & Regulatory (0-100)
- Industry certifications current? (+20)
- GDPR/CCPA compliant? (+20)
- Data processing agreement signed? (+15)
- Regulatory audit history clean? (+15)
- Right to audit clause? (+15)
- Data residency requirements met? (+15)
Operational Dependency (0-100)
- SLA with financial penalties? (+20)
- Uptime >99.9% trailing 12 months? (+20)
- Disaster recovery tested annually? (+15)
- Single point of failure for your business? (-20)
- Migration plan documented? (+15)
- API/export capability? (+15)
- Vendor lock-in risk assessment? (+15)
Data Handling (0-100)
- Data classification documented? (+20)
- Retention/deletion policies clear? (+20)
- Breach notification <72 hours? (+20)
- Data portability guaranteed? (+15)
- AI/ML training on your data? (opt-out available +15, no opt-out -10)
- Access logging and audit trail? (+10)
2. Risk Tier Classification
| Aggregate Score |
Tier |
Review Cadence |
Action |
| 400-500 |
Low Risk |
Annual |
Standard monitoring |
| 300-399 |
Moderate |
Semi-annual |
Remediation plan required |
| 200-299 |
High Risk |
Quarterly |
Executive escalation, alternatives identified |
| 0-199 |
Critical |
Monthly |
Exit plan required within 90 days |
3. Portfolio Risk View
Total vendors: ___
Critical tier: ___ (target: 0)
High risk: ___ (target: <10%)
Moderate: ___ (target: <30%)
Low risk: ___ (target: >60%)
Top 3 concentration risks:
1. [Vendor] — [function] — [% of operations dependent]
2. [Vendor] — [function] — [% of operations dependent]
3. [Vendor] — [function] — [% of operations dependent]
Annual vendor spend: $___
Spend on high/critical vendors: $___ (___%)
4. Cost of Vendor Failure
| Impact Area |
Calculation |
| Revenue loss |
Daily revenue × expected downtime days |
| Recovery cost |
Migration estimate + emergency procurement |
| Compliance penalty |
Regulatory fine range for data breach via vendor |
| Reputation damage |
Customer churn rate × LTV × affected customers |
| Operational disruption |
Staff idle cost × recovery period |
5. Quarterly Review Template
- Score changes since last review (flag any >10 point drops)
- New subprocessors added by vendor
- SLA performance vs target
- Security incidents or near-misses
- Contract renewal timeline and negotiation leverage
- Alternative vendor benchmarking
6. Red Flags (Immediate Action)
- Vendor acquired by competitor
- Key personnel departures (CISO, CTO)
- Downtime exceeding SLA 2+ months
- Regulatory action or investigation
- Refusal to complete security questionnaire
- Data breach affecting other customers
- Sudden pricing changes >20%
Industry-Specific Vendor Risks
| Industry |
Critical Vendor Category |
Specific Risk |
| Healthcare |
EHR, billing, telehealth |
HIPAA BAA gaps, PHI exposure |
| Financial Services |
Core banking, payments, KYC |
PCI DSS, regulatory reporting |
| Legal |
Case management, ediscovery |
Privilege breach, client data |
| SaaS |
Infrastructure, auth, payments |
Cascading outages, PII |
| Manufacturing |
MES, supply chain, IoT |
IP theft, production stoppage |
| Construction |
Project management, safety |
Compliance documentation gaps |
| Ecommerce |
Payments, fulfillment, CDN |
PCI, availability during peak |
| Recruitment |
ATS, background check, payroll |
Candidate PII, bias in AI screening |
| Real Estate |
MLS, transaction mgmt, title |
Wire fraud, closing delays |
| Professional Services |
CRM, billing, document mgmt |
Client confidentiality breach |
Get the Full Playbook
1---2name: vendor-risk-assessment3description: Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders mana...4---5
6# Vendor Risk Assessment
7
8Score and manage third-party vendor risk across security, financial stability, compliance, operational dependency, and data handling. Built for procurement teams, CISOs, and operations leaders managing 10+ vendors.
9
10## Usage
11Run this assessment for each critical vendor. Aggregate scores into a portfolio risk view.
12
13## Assessment Framework
14
15### 1. Vendor Risk Scorecard (5 Domains, 0-100 each)
16
17**Security Posture (0-100)**
18- SOC 2 Type II current? (+20)
19- Penetration test within 12 months? (+15)
20- Incident response plan documented? (+15)
21- Data encryption at rest and transit? (+15)
22- MFA enforced for all access? (+10)
23- Security questionnaire completed? (+10)
24- Subprocessor list disclosed? (+15)
25
26**Financial Stability (0-100)**
27- Revenue trend (growing +25, flat +10, declining 0)
28- Funding runway >18 months? (+20)
29- Customer concentration <20%? (+15)
30- Public financials or audited statements? (+15)
31- No material litigation? (+15)
32- Credit rating acceptable? (+10)
33
34**Compliance & Regulatory (0-100)**
35- Industry certifications current? (+20)
36- GDPR/CCPA compliant? (+20)
37- Data processing agreement signed? (+15)
38- Regulatory audit history clean? (+15)
39- Right to audit clause? (+15)
40- Data residency requirements met? (+15)
41
42**Operational Dependency (0-100)**
43- SLA with financial penalties? (+20)
44- Uptime >99.9% trailing 12 months? (+20)
45- Disaster recovery tested annually? (+15)
46- Single point of failure for your business? (-20)
47- Migration plan documented? (+15)
48- API/export capability? (+15)
49- Vendor lock-in risk assessment? (+15)
50
51**Data Handling (0-100)**
52- Data classification documented? (+20)
53- Retention/deletion policies clear? (+20)
54- Breach notification <72 hours? (+20)
55- Data portability guaranteed? (+15)
56- AI/ML training on your data? (opt-out available +15, no opt-out -10)
57- Access logging and audit trail? (+10)
58
59### 2. Risk Tier Classification
60
61| Aggregate Score | Tier | Review Cadence | Action |
62|----------------|------|---------------|--------|
63| 400-500 | Low Risk | Annual | Standard monitoring |
64| 300-399 | Moderate | Semi-annual | Remediation plan required |
65| 200-299 | High Risk | Quarterly | Executive escalation, alternatives identified |
66| 0-199 | Critical | Monthly | Exit plan required within 90 days |
67
68### 3. Portfolio Risk View
69
70```
71Total vendors: ___
72Critical tier: ___ (target: 0)
73High risk: ___ (target: <10%)
74Moderate: ___ (target: <30%)
75Low risk: ___ (target: >60%)
76
77Top 3 concentration risks:
781. [Vendor] — [function] — [% of operations dependent]
792. [Vendor] — [function] — [% of operations dependent]
803. [Vendor] — [function] — [% of operations dependent]
81
82Annual vendor spend: $___
83Spend on high/critical vendors: $___ (___%)
84```
85
86### 4. Cost of Vendor Failure
87
88| Impact Area | Calculation |
89|------------|-------------|
90| Revenue loss | Daily revenue × expected downtime days |
91| Recovery cost | Migration estimate + emergency procurement |
92| Compliance penalty | Regulatory fine range for data breach via vendor |
93| Reputation damage | Customer churn rate × LTV × affected customers |
94| Operational disruption | Staff idle cost × recovery period |
95
96### 5. Quarterly Review Template
97
98- Score changes since last review (flag any >10 point drops)
99- New subprocessors added by vendor
100- SLA performance vs target
101- Security incidents or near-misses
102- Contract renewal timeline and negotiation leverage
103- Alternative vendor benchmarking
104
105### 6. Red Flags (Immediate Action)
106
107- Vendor acquired by competitor
108- Key personnel departures (CISO, CTO)
109- Downtime exceeding SLA 2+ months
110- Regulatory action or investigation
111- Refusal to complete security questionnaire
112- Data breach affecting other customers
113- Sudden pricing changes >20%
114
115## Industry-Specific Vendor Risks
116
117| Industry | Critical Vendor Category | Specific Risk |
118|----------|------------------------|---------------|
119| Healthcare | EHR, billing, telehealth | HIPAA BAA gaps, PHI exposure |
120| Financial Services | Core banking, payments, KYC | PCI DSS, regulatory reporting |
121| Legal | Case management, ediscovery | Privilege breach, client data |
122| SaaS | Infrastructure, auth, payments | Cascading outages, PII |
123| Manufacturing | MES, supply chain, IoT | IP theft, production stoppage |
124| Construction | Project management, safety | Compliance documentation gaps |
125| Ecommerce | Payments, fulfillment, CDN | PCI, availability during peak |
126| Recruitment | ATS, background check, payroll | Candidate PII, bias in AI screening |
127| Real Estate | MLS, transaction mgmt, title | Wire fraud, closing delays |
128| Professional Services | CRM, billing, document mgmt | Client confidentiality breach |
129
130## Get the Full Playbook
131- [AI Revenue Leak Calculator](https://afrexai-cto.github.io/ai-revenue-calculator/) — Quantify your total automation opportunity
132- [Industry Context Packs](https://afrexai-cto.github.io/context-packs/) — $47 each, deep-dive playbooks
133- [Agent Setup Wizard](https://afrexai-cto.github.io/agent-setup/) — Build your AI agent workforce