Skip to content

TPRM

Vendor & Third-Party Risk Assessment Checklist

A third-party risk checklist for inherent-risk tiering, due diligence, contracts, and continuous monitoring.

Estimated time
Ongoing / 2–6 Weeks per Critical Vendor
Audience
Procurement, Security, and Privacy Teams
Last updated

Operational reference for vendor risk. Contractual and regulatory duties (NIS2, DORA, HIPAA BAAs) still need counsel.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Inventory & Tier

Phase 2: Diligence

Phase 3: Contract

Phase 4: Monitor & Offboard

FAQ

Is a SOC 2 enough?+

It is evidence, not a transfer of your risk. Read scope, period, and exceptions.

How often to reassess?+

Critical vendors at least annually or on material change; low-risk on a lighter cycle.

Does NIS2 require this?+

NIS2 Article 21 includes supply-chain security for in-scope entities.

What is concentration risk?+

Over-reliance on one provider for a critical function—explicitly relevant under DORA.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer