Cybersecurity GRC 12 items
Third-Party & Vendor Risk Management Assessment
Assesses the third-party risk management lifecycle from onboarding due diligence through ongoing monitoring and offboarding.
SOC 2ISO 27001:2022NIST CSF 2.0
Free PDF · enter your email to download.
Program & Inventory
- Is a third-party risk management (TPRM) policy documented and approved? *
- Is a current inventory of vendors maintained with data access and criticality tiers? *
- Are fourth-party (subprocessor) dependencies identified for critical vendors? *
Onboarding Due Diligence
- Is a security assessment performed before onboarding based on risk tier? *
- Are attestations (SOC 2, ISO 27001) or questionnaires collected and reviewed? *
- Is the vendor's financial and operational stability considered for critical services? *
Contracts & Requirements
- Do contracts include information security, breach notification, and audit rights clauses? *
- Are data processing terms (DPA/BAA) in place where required? *
- Are right-to-audit and right-to-terminate provisions included? *
Ongoing Monitoring & Offboarding
- Are vendors reassessed periodically based on their risk tier? *
- Are vendor security incidents tracked and evaluated for impact? *
- Is access revoked and data returned or destroyed at contract termination? *
Download the full Third-Party & Vendor Risk Management Assessment checklist
Get it as a clean, printable PDF — free.
