TPRM
Vendor & Third-Party Risk Assessment Checklist
A third-party risk checklist for inherent-risk tiering, due diligence, contracts, and continuous monitoring.
- Estimated time
- Ongoing / 2–6 Weeks per Critical Vendor
- Audience
- Procurement, Security, and Privacy Teams
- Last updated
Operational reference for vendor risk. Contractual and regulatory duties (NIS2, DORA, HIPAA BAAs) still need counsel.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Inventory & Tier
Phase 2: Diligence
Phase 3: Contract
Phase 4: Monitor & Offboard
FAQ
Is a SOC 2 enough?+–
It is evidence, not a transfer of your risk. Read scope, period, and exceptions.
How often to reassess?+–
Critical vendors at least annually or on material change; low-risk on a lighter cycle.
Does NIS2 require this?+–
NIS2 Article 21 includes supply-chain security for in-scope entities.
What is concentration risk?+–
Over-reliance on one provider for a critical function—explicitly relevant under DORA.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer