simpl.
Cybersecurity GRC 12 items

Third-Party & Vendor Risk Management Assessment

Assesses the third-party risk management lifecycle from onboarding due diligence through ongoing monitoring and offboarding.

SOC 2ISO 27001:2022NIST CSF 2.0

Free PDF · enter your email to download.

Program & Inventory

  • Is a third-party risk management (TPRM) policy documented and approved? *
  • Is a current inventory of vendors maintained with data access and criticality tiers? *
  • Are fourth-party (subprocessor) dependencies identified for critical vendors? *

Onboarding Due Diligence

  • Is a security assessment performed before onboarding based on risk tier? *
  • Are attestations (SOC 2, ISO 27001) or questionnaires collected and reviewed? *
  • Is the vendor's financial and operational stability considered for critical services? *

Contracts & Requirements

  • Do contracts include information security, breach notification, and audit rights clauses? *
  • Are data processing terms (DPA/BAA) in place where required? *
  • Are right-to-audit and right-to-terminate provisions included? *

Ongoing Monitoring & Offboarding

  • Are vendors reassessed periodically based on their risk tier? *
  • Are vendor security incidents tracked and evaluated for impact? *
  • Is access revoked and data returned or destroyed at contract termination? *

Download the full Third-Party & Vendor Risk Management Assessment checklist

Get it as a clean, printable PDF — free.